From nobody Tue Feb 06 15:25:37 2024 X-Original-To: freebsd-hackers@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4TTnBm1ZfPz59RfQ for ; Tue, 6 Feb 2024 15:25:52 +0000 (UTC) (envelope-from andrea@cocito.eu) Received: from mail-wm1-x32e.google.com (mail-wm1-x32e.google.com [IPv6:2a00:1450:4864:20::32e]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "GTS CA 1D4" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4TTnBl4vd0z4jVm for ; Tue, 6 Feb 2024 15:25:51 +0000 (UTC) (envelope-from andrea@cocito.eu) Authentication-Results: mx1.freebsd.org; none Received: by mail-wm1-x32e.google.com with SMTP id 5b1f17b1804b1-40efcb37373so8647945e9.2 for ; Tue, 06 Feb 2024 07:25:51 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cocito-eu.20230601.gappssmtp.com; s=20230601; t=1707233150; x=1707837950; darn=freebsd.org; h=references:to:cc:in-reply-to:date:subject:mime-version:message-id :from:from:to:cc:subject:date:message-id:reply-to; bh=zShXJELUXceceIW/94TZHY2t9Wjhvg/AN9zDS4epZs4=; b=GvuXHCo7MPfjmPmup1yILkzjObr4A2PbFTuqjaQKlxC7aTQEXQiG+M4uxwOUcxm7Jg IaFFNjuAeIlnKceeYM2C6W4e2423KcEUufddZ+BYcKR/4ggt9HXIk8UdWv9FO7CFe8EC MDg2TF5hAULDxmD+hg/2UOYObMdMXukq8Sg8476UlQS9sKv6UmZjb4uUJQOOoxqXCj+6 szhd4i3zE2jwHrfpqRrdVY/21x1/IWunXnMsJkJvJOGSmnTIlkm0xmSDT68TNoZznNvE LhjmnkyMo6onYRwpguCG0Z3g6t1G1mfmQ3wMzglPlbT93ZWqU7s7jAiK/aIoul7G6sQZ UbPQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1707233150; x=1707837950; h=references:to:cc:in-reply-to:date:subject:mime-version:message-id :from:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=zShXJELUXceceIW/94TZHY2t9Wjhvg/AN9zDS4epZs4=; b=AK9xRrOfPr9wRKFCkVmMyO+PGPF/iM+0ROVdVn3X91pW4Me0/P/D/CahNPAue55Te7 AaXyN8fISUS76v5q0wCdwh11sU+zRKzW+OKzGxoPWVpMklXE9nvBCb3uQyawjZCfwLkV s1L0k6osyZAUVJnkG+qCe/vLWUWEB4/nW8vsiUQHoV56Qs2gZGog7Tn/UnQs56AqBpL1 vwq1UEzzis54Hdol4RALmn/oqWeNDzXdSALQvIdwMaX2KrbSy9wEDHjwsk8oMR5kC+Yl dMzkhwYVgulFMjkBIKOmykWA2UKmfLmC4jAzQWbJS4mSxLtil3ts6GAdTHgMkzu4mkKx VeNQ== X-Gm-Message-State: AOJu0YxIfhFZkhI6jL/lxXDMFpij9PGfYLIDE06CsS9/+oH2N2756V0d fwmENoFmgo9LU0V3L6Dun7yEBaurYrPYKCf/GO6sZkgtM6LNP4F3e6wl1gjHrWNVLjfIIRKPWeT 6 X-Google-Smtp-Source: AGHT+IFqJr92htcr8BhIQWPL5qD+52e7vXZkBO2NzJU2TlR9bW8rxf4cXD0rQY5Frvrev+eKZFZAuQ== X-Received: by 2002:a05:600c:5249:b0:40f:d22e:f9e9 with SMTP id fc9-20020a05600c524900b0040fd22ef9e9mr2609219wmb.10.1707233149316; Tue, 06 Feb 2024 07:25:49 -0800 (PST) Received: from smtpclient.apple ([185.8.198.100]) by smtp.gmail.com with ESMTPSA id u20-20020a05600c19d400b0040fddd8de88sm2370105wmq.15.2024.02.06.07.25.48 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 06 Feb 2024 07:25:48 -0800 (PST) From: Andrea Cocito Message-Id: Content-Type: multipart/alternative; boundary="Apple-Mail=_21C8DA0F-5045-4026-90DD-32FD30402225" List-Id: Technical discussions relating to FreeBSD List-Archive: https://lists.freebsd.org/archives/freebsd-hackers List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-hackers@freebsd.org Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3774.300.61.1.2\)) Subject: Re: TPM2 on AMD Rizen (fTPM) Date: Tue, 6 Feb 2024 16:25:37 +0100 In-Reply-To: <400978a4-31eb-4cb6-b914-911ffba380aa@bruelltuete.com> Cc: freebsd-hackers@freebsd.org To: Johannes Totz References: <51A26E14-9374-4B1A-9DA1-A9E2A2B4E2EA@cocito.eu> <71AF606D-1685-43E5-9455-E1882EAECE96@cocito.eu> <400978a4-31eb-4cb6-b914-911ffba380aa@bruelltuete.com> X-Mailer: Apple Mail (2.3774.300.61.1.2) X-Rspamd-Queue-Id: 4TTnBl4vd0z4jVm X-Spamd-Bar: ---- X-Rspamd-Pre-Result: action=no action; module=replies; Message is reply to one we originated X-Spamd-Result: default: False [-4.00 / 15.00]; REPLY(-4.00)[]; ASN(0.00)[asn:15169, ipnet:2a00:1450::/32, country:US] --Apple-Mail=_21C8DA0F-5045-4026-90DD-32FD30402225 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 Thanks for the reference, Despite a long search I had not seen that thread; it=E2=80=99s a lot = helpful as it can head me at the pertinent parts in the source. I=E2=80=99ll try to take a look at the code. A. > On 6 Feb 2024, at 00:45, Johannes Totz wrote: >=20 > On 04/02/2024 13:43, Andrea Cocito wrote: >> Hello again, >> First thing: apologies for my email client messing up with charset = encoding, hope is fixed now. >> Second, I add some detail/information. >> The machine is a bare metal on Hetzner, I do not have many details, = it=E2=80=99s an AMD Ryzen 9 3900 12-Core/24-Threads toy with some = motherboard using American Megatrends firmware; unfortunately I have = very limited access to the console (one hour upon request=E2=80=A6). >> As said the =E2=80=9CfTPM=E2=80=9D has been enabled in the firmare, = and I also tried all the possible combinations of the settings in the = firmware which could seem anyhow pertinent (SCM etc). >> The kernel is a custom-built one, simply stripped down to include = statically all used devices/modules and drop the rest, compiled with = -march=3Dnative as all the userland; no problem in rebooting with the = GENERIC kernel, but I cannot imagine how it could help. >> Should any additional information be useful to give me some advice = just ask, the machine is there to experiment. >> Thanks for any advice, >> A. >=20 > I have previously made an attempt but got nowhere: = https://lists.freebsd.org/archives/freebsd-hackers/2023-June/002334.html >=20 >=20 > cheers, >=20 > Johannes >=20 >>> On 3 Feb 2024, at 18:21, Andrea Cocito wrote: >>>=20 >>> Hi, >>>=20 >>> I=E2=80=99m trying to enable TPM support on a box in order to = experiment a bit with it, but the driver does not seem to load and/or = see the device. >>>=20 >>> In the firmware the =E2=80=9CfTPM=E2=80=9D option has been enabled, = tried both with SCM enabled and disabled, basically I tried all the = possible firmware options combinations with no success. >>>=20 >>> I have tpm_load=3D=E2=80=9CYES=E2=80=9D in /boot/loader.conf and = also tried the hints suggested by the man page is /boot/device.hints >>>=20 >>> No way to have the tpm? device(s) appear, the best I achieved so far = on dmesg in a verbose boot is: >>> =E2=80=A6 >>> Preloaded elf obj module "/boot/kernel.old/geom_mirror.ko" at = 0xffffffff8196d8c0. >>> Preloaded elf obj module "/boot/kernel.old/tpm.ko" at = 0xffffffff8196dfb0. >>> =E2=80=A6 >>> tpm0 failed to probe at iomem 0xfffffffffed40000-0xfffffffffed44fff = on isa0 >>> tpm1 failed to probe at iomem 0xfffffffffed40000-0xfffffffffed40fff = on isa0 >>> =E2=80=A6 >>>=20 >>> I am all but an expert about TPM architecture (this is why I am = willing to play with it), but as far as I understand AMD=E2=80=99s fTPM = is a TPM2 built into the CPU, I have no idea on which bus it should be = seen and how. >>>=20 >>> So my questions are: >>> - Is AMD=E2=80=99s fTPM supported at all by the driver? >>> - Am I missing something very obvious? >>>=20 >>> I have been digging around for information quite a bit, but there = does not seem to be much information around. Hope I am hitting the = correct list (accept my apologies if it is not). >>>=20 >>> Thanks in advance for any advice. --Apple-Mail=_21C8DA0F-5045-4026-90DD-32FD30402225 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 Thanks for the = reference,

Despite a long search I had not seen that = thread; it=E2=80=99s a lot helpful as it can head me at the pertinent = parts in the source.

I=E2=80=99ll try to take a = look at the code.

A.

On 6 Feb 2024, at 00:45, Johannes Totz = <jo@bruelltuete.com> wrote:

On 04/02/2024 13:43, Andrea Cocito = wrote:
Hello again,
First thing: apologies for my = email client messing up with charset encoding, hope is fixed = now.
Second, I add some detail/information.
The machine is a bare = metal on Hetzner, I do not have many details, it=E2=80=99s an AMD Ryzen = 9 3900 12-Core/24-Threads toy with some motherboard using American = Megatrends firmware; unfortunately I have very limited access to the = console (one hour upon request=E2=80=A6).
As said the =E2=80=9CfTPM=E2=80= =9D has been enabled in the firmare, and I also tried all the possible = combinations of the settings in the firmware which could seem anyhow = pertinent (SCM etc).
The kernel is a custom-built one, simply = stripped down to include statically all used devices/modules and drop = the rest, compiled with -march=3Dnative as all the userland; no problem = in rebooting with the GENERIC kernel, but I cannot imagine how it could = help.
Should any additional information be useful to give me some = advice just ask, the machine is there to experiment.
Thanks for any = advice,
A.

I have = previously made an attempt but got nowhere: https://lists.freebsd.org/archives/freebsd-hackers/2023-June/002334.= html


cheers,

Johannes

On 3 Feb 2024, at = 18:21, Andrea Cocito <andrea@cocito.eu> = wrote:

Hi,

I=E2=80=99m trying to enable TPM support on a = box in order to experiment a bit with it, but the driver does not seem = to load and/or see the device.

In the firmware the =E2=80=9CfTPM=E2= =80=9D option has been enabled, tried both with SCM enabled and = disabled, basically I tried all the possible firmware options = combinations with no success.

I have tpm_load=3D=E2=80=9CYES=E2=80=9D= in /boot/loader.conf and also tried the hints suggested by the man page = is /boot/device.hints

No way to have the tpm? device(s) appear, = the best I achieved so far on dmesg in a verbose boot = is:
=E2=80=A6
Preloaded elf obj module = "/boot/kernel.old/geom_mirror.ko" at 0xffffffff8196d8c0.
Preloaded = elf obj module "/boot/kernel.old/tpm.ko" at = 0xffffffff8196dfb0.
=E2=80=A6
tpm0 failed to probe at iomem = 0xfffffffffed40000-0xfffffffffed44fff on isa0
tpm1 failed to probe at = iomem 0xfffffffffed40000-0xfffffffffed40fff on isa0
=E2=80=A6

I = am all but an expert about TPM architecture (this is why I am willing to = play with it), but as far as I understand AMD=E2=80=99s fTPM is a TPM2 = built into the CPU, I have no idea on which bus it should be seen and = how.

So my questions are:
- Is AMD=E2=80=99s fTPM supported at = all by the driver?
- Am I missing something very obvious?

I = have been digging around for information quite a bit, but there does not = seem to be much information around. Hope I am hitting the correct list = (accept my apologies if it is not).

Thanks in advance for any = advice.

= --Apple-Mail=_21C8DA0F-5045-4026-90DD-32FD30402225--