[tpm2] Re: tpm2_flushcontext stuck

Roberts, William C <william.c.roberts at intel.com>
Newsgroups dev.linux.lists.tpm2
Message-ID <SN6PR11MB34371336904EF1DF2C479899B87C9@SN6PR11MB3437.namprd11.prod.outlook.com>
FYI I reported this bug to the linux integrity mailing list:
  - https://marc.info/?l=linux-integrity&m=164009679300941&w=2
________________________________
From: Juergen Repp <Juergen.Repp(a)sit.fraunhofer.de>
Sent: Monday, December 20, 2021 4:06 PM
To: Kenneth Goldman <kgoldman(a)us.ibm.com>
Cc: tpm2(a)lists.01.org <tpm2(a)lists.01.org>
Subject: [tpm2] Re: tpm2_flushcontext stuck

When /dev/tpmrm0 was used with kernel 5.10.
After sending the command read public:
0x80 0x01 0x00 0x00 0x00 0x0e 0x00 0x00 0x01 0x73 0x80 0x00 0x00 0x00
the write worked but the poll call in  tcti_device_receive did stuck.
With kernel 4.19 write for this command did return -1



Am 20.12.21 um 21:04 schrieb Kenneth Goldman:
> They way I use it:
>
>
>
> /dev/tpm0 is locking, one user at a time.  I use it for debug only.  IMHO, production applications should not use it.
>
>
>
> /dev/tpmrm0 is the multi-user interface.  Use it for production applications, where the TPM is shared.
>
>
>
> I suspect (not sure) that /dev/tpm0 will have unexpected effects when the kernel is also trying to use the TPM.
>
>
>
>
>
> And as a newbie, I felt that the fact TPM exposes two devices (/dev/tpm0 and /dev/tpmrm0) under Linux is confusing and is making things more complicated.  The architecture diagram (https://github.com/tpm2-software/tpm2-tss <https://github.com/tpm2-software/tpm2-tss>) shows all calls go through the Resource Manager but that is not the case in reality.  I was wondering what is the benefit to have 2 devices instead of just one device in linux?
>
>
>
>
> _______________________________________________
> tpm2 mailing list -- tpm2(a)lists.01.org
> To unsubscribe send an email to tpm2-leave(a)lists.01.org
> %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s
>
_______________________________________________
tpm2 mailing list -- tpm2(a)lists.01.org
To unsubscribe send an email to tpm2-leave(a)lists.01.org
%(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s
attachment.htm (text/html, 3.2 KB)
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
FYI I reported this bug to the linux integrity mailing list:</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
&nbsp; -&nbsp;<a href="https://marc.info/?l=linux-integrity&amp;m=164009679300941&amp;w=2" id="LPlnk533842">https://marc.info/?l=linux-integrity&amp;m=164009679300941&amp;w=2</a></div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> Juergen Repp &lt;[email protected]&gt;<br>
<b>Sent:</b> Monday, December 20, 2021 4:06 PM<br>
<b>To:</b> Kenneth Goldman &lt;[email protected]&gt;<br>
<b>Cc:</b> [email protected] &lt;[email protected]&gt;<br>
<b>Subject:</b> [tpm2] Re: tpm2_flushcontext stuck</font>
<div>&nbsp;</div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">When /dev/tpmrm0 was used with kernel 5.10.<br>
After sending the command read public:<br>
0x80 0x01 0x00 0x00 0x00 0x0e 0x00 0x00 0x01 0x73 0x80 0x00 0x00 0x00<br>
the write worked but the poll call in&nbsp; tcti_device_receive did stuck.<br>
With kernel 4.19 write for this command did return -1<br>
<br>
<br>
<br>
Am 20.12.21 um 21:04 schrieb Kenneth Goldman:<br>
&gt; They way I use it:<br>
&gt; <br>
&gt; &nbsp;<br>
&gt; <br>
&gt; /dev/tpm0 is locking, one user at a time.&nbsp; I use it for debug only.&nbsp; IMHO, production applications should not use it.<br>
&gt; <br>
&gt; &nbsp;<br>
&gt; <br>
&gt; /dev/tpmrm0 is the multi-user interface.&nbsp; Use it for production applications, where the TPM is shared.<br>
&gt; <br>
&gt; &nbsp;<br>
&gt; <br>
&gt; I suspect (not sure) that /dev/tpm0 will have unexpected effects when the kernel is also trying to use the TPM.<br>
&gt; <br>
&gt; &nbsp;<br>
&gt; <br>
&gt; &nbsp;<br>
&gt; <br>
&gt; And as a newbie, I felt that the fact TPM exposes two devices (/dev/tpm0 and /dev/tpmrm0) under Linux is confusing and is making things&nbsp;more&nbsp;complicated.&nbsp; The architecture diagram (<a href=""></a>https://github.com/tpm2-software/tpm2-tss &lt;<a href="https://github.com/tpm2-software/tpm2-tss">https://github.com/tpm2-software/tpm2-tss</a>&gt;)
 shows all calls go through the Resource Manager but that is not the case in reality.&nbsp; I was wondering what is the benefit to have 2 devices instead of just one device in linux?&nbsp;<br>
&gt; <br>
&gt; &nbsp;<br>
&gt; <br>
&gt; <br>
&gt; _______________________________________________<br>
&gt; tpm2 mailing list -- [email protected]<br>
&gt; To unsubscribe send an email to [email protected]<br>
&gt; %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s<br>
&gt; <br>
_______________________________________________<br>
tpm2 mailing list -- [email protected]<br>
To unsubscribe send an email to [email protected]<br>
%(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s</div>
</span></font></div>
</body>
</html>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.