Re: [PATCH v2 3/3] virt: arm-cca-guest: Add support for measurement registers

From: Jason Gunthorpe

Date: Wed Sep 30 2026 - 10:38:20 EST


On Wed, Sep 30, 2026 at 07:40:02AM +0100, Yeoreum Yun wrote:
> > My remaining concern is that since sysfs_kf_bin_write() truncates
> > oversized writes to the binary attribute size before invoking the
> > callback, tm_digest_write() sees an exact-sized write and extends the
> > MR. The following validation is useless in this case.
> >
> > static ssize_t tm_digest_write(struct file *filp, struct kobject *kobj,
> > const struct bin_attribute *attr, char *buffer,
> > loff_t off, size_t count)
> > {
> > [...]
> > /* partial writes are not supported */
> > if (off != 0 || count != attr->size)
> > return -EINVAL;
> >
> > IMO this is not specific to Arm CCA, but do you have any thoughts on
> > this?
>
> I think this is ultimately a limitation of sysfs. At this layer,
> simply knowing that userspace supplied a larger buffer does not allow us to
> determine whether all of the data in that buffer is valid.

sysfs is a bad choice for this interface, it always was, this is one
more example why.

We should have learned that from TPM's mistakes, not copied its bad
ideas into tsm_mr.

Jason