Re: [RFC] power/hibernate: TPM2 image encryption to allow hibernation under lockdown

From: Daniel Ramos

Date: Thu Oct 08 2026 - 10:25:53 EST


Hi Jhon, hi Matthew,

Jhon, thank you for starting this.
I build Sparky Stereo OS, a SparkyLinux edition, and we want Secure Boot
and hibernation together, so we ran your RFC through a small test bench
on 7.3-rc6: QEMU with OVMF and Secure Boot, swtpm as the TPM 2.0, a
scripted hibernate and resume, and tamper checks.
Here is what we measured, in case it helps the next version.

The patch does not apply as posted (git apply reports a corrupt patch at
line 59; the hunk line counts do not match their bodies), and the
lockdown hunk breaks the build even with the option off: the enum is
LOCKDOWN_HIBERNATION, and snapenc_is_active() is declared nowhere.
With 17 small fixes it builds and boots. Sealing and unsealing could not
be mapped to the in-tree API (tpm2_seal_trusted() needs a parent key and
a PolicyPCR digest that nothing in the tree computes), so we stubbed
them for the run.
Under lockdown=confidentiality hibernation is then allowed, but on the
default LZO path the image is written in plaintext while the kernel logs
that it is encrypted: the hooks are only in save_image() and
load_image(), the nocompress path.
With hibernate=nocompress the kernel oopses while saving, because the
AEAD associated data are not in the scatterlists.
With those chained, the image is still plaintext (the ciphertext buffer
is never written), and resume crashes because the decryption context
exists only in the memory of the kernel being replaced.
A tampered image is caught only by the existing CRC32 and LZO checks,
and a change of PCR 23 between the boots is not noticed.

The detailed logs and the fixes are available if they help, and the
bench can run any later version unchanged, including a design built on
the requirements Matthew described:
https://github.com/Sparky-OS/sparky-stereo-os/tree/main/tools/hibernate-bench
Disclosure: the measurements were made with AI assistance (Claude),
directed and checked by me.

Daniel Ramos