abbbi / abbbi/virtnbdbackup

Backup (SW)TPM Device related state files in a consistent way

未关闭
#169 3 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
enhancement need-more-info
主要语言
Python
星标
518
派生
57
PR 合并指标
30 天内没有已合并 PR

描述

New Windows versions often depend von TPM devices beeing attached (at least during installation).
Libvirt allows for two types of TPM devices:

* emulated devices (swtpm based)
* passthrough devices

it may make sense to include the swtpm related files within the backup too, even if i currently dont see
a way to guarantee the data beeing consistent.

If an emulated device is attached, libvirt starts an swtpm process:

`/usr/bin/swtpm socket --ctrl type=unixio,path=/run/libvirt/qemu/swtpm/2-backuptest-swtpm.sock,mode=0600 --tpmstate dir=/var/lib/libvirt/swtpm/*vm_uuid*/tpm2,mode=0600 -`

it makes sense to add the files from _/var/lib/libvirt/swtpm/*vm_uuid*/_ to the backup.
In case the complete host system is lost or these files are missing, i think it may be troublesome to boot the actual virtual machine (uefi / secureboot)

The files in /var/lib/libvirt/swtpm are owned by special "tss" user with no read rights. So this might only work if backup is executed as root user. More information required.

For now backup at least prints a warning that further action may be required by user.

Outstanding:

* Clarify which user most distributions use for the swtpm process (on Debian it is "tss")
* ssh client needs to be enhanced to be able to put/get directory trees and not single files for remote backup
* Fail backup with warning if we dont have access to the files (we need to be part of the "tss" group if run as regular user)
* Adopt restore utility

More info and Limitations:

https://www.ovirt.org/develop/release-management/features/virt/tpm-device.html

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。