Enable the passing of a file descriptor via fd=<..> to access the host's TPM device using the TPM passthrough driver.
v12: - added documentation part Signed-off-by: Stefan Berger <stef...@linux.vnet.ibm.com> --- hw/tpm_passthrough.c | 74 +++++++++++++++++++++++++++++++++------------------ qemu-config.c | 5 +++ qemu-options.hx | 6 +++- 3 files changed, 58 insertions(+), 27 deletions(-) Index: qemu-git.pt/qemu-config.c =================================================================== --- qemu-git.pt.orig/qemu-config.c +++ qemu-git.pt/qemu-config.c @@ -523,6 +523,11 @@ static QemuOptsList qemu_tpmdev_opts = { .type = QEMU_OPT_STRING, .help = "Persistent storage for TPM state", }, + { + .name = "fd", + .type = QEMU_OPT_STRING, + .help = "Filedescriptor for accessing the TPM", + }, { /* end of list */ } }, }; Index: qemu-git.pt/hw/tpm_passthrough.c =================================================================== --- qemu-git.pt.orig/hw/tpm_passthrough.c +++ qemu-git.pt/hw/tpm_passthrough.c @@ -362,32 +362,54 @@ static int tpm_passthrough_handle_device char buf[64]; int n; - value = qemu_opt_get(opts, "path"); - if (!value) { - value = TPM_PASSTHROUGH_DEFAULT_DEVICE; - } - - n = snprintf(tb->s.tpm_pt->tpm_dev, sizeof(tb->s.tpm_pt->tpm_dev), - "%s", value); - - if (n >= sizeof(tb->s.tpm_pt->tpm_dev)) { - error_report("TPM device path is too long.\n"); - goto err_exit; - } - - snprintf(buf, sizeof(buf), "path=%s", tb->s.tpm_pt->tpm_dev); - - tb->parameters = g_strdup(buf); - - if (tb->parameters == NULL) { - return 1; - } - - tb->s.tpm_pt->tpm_fd = open(tb->s.tpm_pt->tpm_dev, O_RDWR); - if (tb->s.tpm_pt->tpm_fd < 0) { - error_report("Cannot access TPM device using '%s'.\n", - tb->s.tpm_pt->tpm_dev); - goto err_exit; + value = qemu_opt_get(opts, "fd"); + if (value) { + if (qemu_opt_get(opts, "path")) { + error_report("fd= is invalid with path="); + return -1; + } + + tb->s.tpm_pt->tpm_fd = qemu_parse_fd(value); + if (tb->s.tpm_pt->tpm_fd < 0) { + error_report("Illegal file descriptor for TPM device.\n"); + return -1; + } + + snprintf(buf, sizeof(buf), "fd=%d", tb->s.tpm_pt->tpm_fd); + + tb->parameters = g_strdup(buf); + + if (tb->parameters == NULL) { + goto err_close_tpmdev; + } + } else { + value = qemu_opt_get(opts, "path"); + if (!value) { + value = TPM_PASSTHROUGH_DEFAULT_DEVICE; + } + + n = snprintf(tb->s.tpm_pt->tpm_dev, sizeof(tb->s.tpm_pt->tpm_dev), + "%s", value); + + if (n >= sizeof(tb->s.tpm_pt->tpm_dev)) { + error_report("TPM device path is too long.\n"); + goto err_exit; + } + + snprintf(buf, sizeof(buf), "path=%s", tb->s.tpm_pt->tpm_dev); + + tb->parameters = g_strdup(buf); + + if (tb->parameters == NULL) { + return 1; + } + + tb->s.tpm_pt->tpm_fd = open(tb->s.tpm_pt->tpm_dev, O_RDWR); + if (tb->s.tpm_pt->tpm_fd < 0) { + error_report("Cannot access TPM device using '%s'.\n", + tb->s.tpm_pt->tpm_dev); + goto err_exit; + } } if (tpm_passthrough_test_tpmdev(tb->s.tpm_pt->tpm_fd)) { Index: qemu-git.pt/qemu-options.hx =================================================================== --- qemu-git.pt.orig/qemu-options.hx +++ qemu-git.pt/qemu-options.hx @@ -1789,7 +1789,7 @@ Use ? to print all available TPM backend qemu -tpmdev ? @end example -@item -tpmdev passthrough, id=@var{id}, path=@var{path} +@item -tpmdev passthrough, id=@var{id}, path=@var{path}, fd=@var{h} (Linux-host only) Enable access to the host's TPM using the passthrough driver. @@ -1798,6 +1798,10 @@ driver. a Linux host this would be @code{/dev/tpm0}. @option{path} is optional and by default @code{/dev/tpm0} is used. +@option{fd} specifies the file descriptor of the host's TPM device. +@option{fd} and @option{path} are mutually exclusive. +@option{fd} is optional. + Some notes about using the host's TPM with the passthrough driver: The TPM device accessed by the passthrough driver must not be