Re: [PATCH v2 3/3] virt: arm-cca-guest: Add support for measurement registers

From: Jason Gunthorpe

Date: Wed Sep 30 2026 - 12:46:51 EST


On Wed, Sep 30, 2026 at 03:12:34PM +0100, Yeoreum Yun wrote:
> > On Wed, Sep 30, 2026 at 07:40:02AM +0100, Yeoreum Yun wrote:
> > > > My remaining concern is that since sysfs_kf_bin_write() truncates
> > > > oversized writes to the binary attribute size before invoking the
> > > > callback, tm_digest_write() sees an exact-sized write and extends the
> > > > MR. The following validation is useless in this case.
> > > >
> > > > static ssize_t tm_digest_write(struct file *filp, struct kobject *kobj,
> > > > const struct bin_attribute *attr, char *buffer,
> > > > loff_t off, size_t count)
> > > > {
> > > > [...]
> > > > /* partial writes are not supported */
> > > > if (off != 0 || count != attr->size)
> > > > return -EINVAL;
> > > >
> > > > IMO this is not specific to Arm CCA, but do you have any thoughts on
> > > > this?
> > >
> > > I think this is ultimately a limitation of sysfs. At this layer,
> > > simply knowing that userspace supplied a larger buffer does not allow us to
> > > determine whether all of the data in that buffer is valid.
> >
> > sysfs is a bad choice for this interface, it always was, this is one
> > more example why.
> >
> > We should have learned that from TPM's mistakes, not copied its bad
> > ideas into tsm_mr.
>
> This sounds you plan to make a dedicate fs (whatever via configfs or
> other) for attestation subsystem which you mention in [0].
>
> Link: [0] https://lore.kernel.org/all/arwNEWUEEk7jdGir@xxxxxxxxxxxxxxx/

Jiri's working proposal is to move it to a char dev, like the sane
TPM interface ..

I'm skeptical about any fs being a good idea for this kind of stuff..

Jason