apache / apache/cloudstack

vTPM on KVM does not persist data (ACS 4.20.1.0, Ubuntu 24.04)

Abierto
#11,842 15 comentarios 0 reacciones 0 asignados Ver en GitHub
component:documentation
Lenguaje dominante
Java
Estrellas
3.1k
Forks
1.4k
Merge medio
6 d 19 h
PR fusionados (30 d)
32

Descripción

>### problem

after a shutdown, the /var/lib/libvirt/swtpm/ which holds the tpm data is gone. When starting the vm again, the folder is re-created with empty tpm files.

I am using a similar tpm definition in manually configured kvm guests, if those vm are powered off the folder remains.

### versions

4.20.1.0
Ubuntu 24.04

### The steps to reproduce the bug

```
root@VM-647bf7bc-bdca-48fa-8329-8b7a103f9ab6:~# echo "Hello, TPM!" > datafile
root@VM-647bf7bc-bdca-48fa-8329-8b7a103f9ab6:~# tpm2_nvwrite -C o -i datafile 0x1500016
root@VM-647bf7bc-bdca-48fa-8329-8b7a103f9ab6:~# tpm2_nvread -C o 0x1500016
WARN: Reading full size of the NV index
Hello, TPM!
```

Instance power cycle, and tryi to read our value again from the tpm

```
root@VM-647bf7bc-bdca-48fa-8329-8b7a103f9ab6:~# tpm2_nvread -C o 0x1500016
WARN: Reading full size of the NV index
WARNING:esys:src/tss2-esys/api/Esys_NV_ReadPublic.c:309:Esys_NV_ReadPublic_Finish() Received TPM Error
ERROR:esys:src/tss2-esys/esys_tr.c:243:Esys_TR_FromTPMPublic_Finish() Error NV_ReadPublic ErrorCode (0x0000018b)
ERROR:esys:src/tss2-esys/esys_tr.c:398:Esys_TR_FromTPMPublic() Error TR FromTPMPublic ErrorCode (0x0000018b)
ERROR: Esys_TR_FromTPMPublic(0x18B) - tpm:handle(1):the handle is not correct for the use
ERROR: Unable to run tpm2_nvread
root@VM-647bf7bc-bdca-48fa-8329-8b7a103f9ab6:
```

### What to do about it?

_No response_

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Comienza reproduciendo la secuencia de power-cycle en Ubuntu 24.04 e inspecciona cómo se gestiona el directorio /var/lib/libvirt/swtpm/ cuando la VM se apaga. Se considera completado cuando el valor NV del TPM sigue siendo legible después del reinicio y el directorio no se vuelve a crear con archivos TPM vacíos.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
linux, ubuntu
Área
infrastructure, operating-systems, security
Tipo de issue
Error
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Tranquilo
Claridad
Bastante claro
Aptitud para principiantes
48/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.