|
|
Log in / Subscribe / Register

Create and consolidate trusted keys subsystem

From:  Sumit Garg <sumit.garg-AT-linaro.org>
To:  jarkko.sakkinen-AT-linux.intel.com, dhowells-AT-redhat.com, peterhuewe-AT-gmx.de
Subject:  [Patch v8 0/4] Create and consolidate trusted keys subsystem
Date:  Wed, 16 Oct 2019 10:44:51 +0530
Message-ID:  <1571202895-32651-1-git-send-email-sumit.garg@linaro.org>
Cc:  keyrings-AT-vger.kernel.org, linux-integrity-AT-vger.kernel.org, linux-crypto-AT-vger.kernel.org, linux-security-module-AT-vger.kernel.org, herbert-AT-gondor.apana.org.au, davem-AT-davemloft.net, jgg-AT-ziepe.ca, arnd-AT-arndb.de, gregkh-AT-linuxfoundation.org, jejb-AT-linux.ibm.com, zohar-AT-linux.ibm.com, jmorris-AT-namei.org, serge-AT-hallyn.com, jsnitsel-AT-redhat.com, linux-kernel-AT-vger.kernel.org, daniel.thompson-AT-linaro.org, Sumit Garg <sumit.garg-AT-linaro.org>
Archive-link:  Article

This patch-set does restructuring of trusted keys code to create and
consolidate trusted keys subsystem.

Also, patch #2 replaces tpm1_buf code used in security/keys/trusted.c and
crypto/asymmertic_keys/asym_tpm.c files to use the common tpm_buf code.

Changes in v8:
1. Rebased to latest tpmdd/master.
2. Added Reviewed-by tags.

Changes in v7:
1. Rebased to top of tpmdd/master
2. Patch #4: update tpm2 trusted keys code to use tpm_send() instead of
   tpm_transmit_cmd() which is an internal function.

Changes in v6:
1. Switch TPM asymmetric code also to use common tpm_buf code. These
   changes required patches #1 and #2 update, so I have dropped review
   tags from those patches.
2. Incorporated miscellaneous comments from Jarkko.

Changes in v5:
1. Drop 5/5 patch as its more relavant along with TEE patch-set.
2. Add Reviewed-by tag for patch #2.
3. Fix build failure when "CONFIG_HEADER_TEST" and
   "CONFIG_KERNEL_HEADER_TEST" config options are enabled.
4. Misc changes to rename files.

Changes in v4:
1. Separate patch for export of tpm_buf code to include/linux/tpm.h
2. Change TPM1.x trusted keys code to use common tpm_buf
3. Keep module name as trusted.ko only

Changes in v3:

Move TPM2 trusted keys code to trusted keys subsystem.

Changes in v2:

Split trusted keys abstraction patch for ease of review.

Sumit Garg (4):
  tpm: Move tpm_buf code to include/linux/
  KEYS: Use common tpm_buf for trusted and asymmetric keys
  KEYS: trusted: Create trusted keys subsystem
  KEYS: trusted: Move TPM2 trusted keys code

 crypto/asymmetric_keys/asym_tpm.c                  | 101 +++----
 drivers/char/tpm/tpm-interface.c                   |  56 ----
 drivers/char/tpm/tpm.h                             | 223 ---------------
 drivers/char/tpm/tpm2-cmd.c                        | 307 --------------------
 include/Kbuild                                     |   1 -
 include/keys/{trusted.h => trusted_tpm.h}          |  49 +---
 include/linux/tpm.h                                | 248 ++++++++++++++--
 security/keys/Makefile                             |   2 +-
 security/keys/trusted-keys/Makefile                |   8 +
 .../{trusted.c => trusted-keys/trusted_tpm1.c}     |  96 +++----
 security/keys/trusted-keys/trusted_tpm2.c          | 314 +++++++++++++++++++++
 11 files changed, 649 insertions(+), 756 deletions(-)
 rename include/keys/{trusted.h => trusted_tpm.h} (77%)
 create mode 100644 security/keys/trusted-keys/Makefile
 rename security/keys/{trusted.c => trusted-keys/trusted_tpm1.c} (94%)
 create mode 100644 security/keys/trusted-keys/trusted_tpm2.c

-- 
2.7.4



Copyright © 2019, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds