freenode
Kernel & Low-Level

Kernel gains Rust SPDM requester for untrusted device auth

Alistair Francis posts a standalone Rust SPDM stack and PCIe CMA TSM path so the kernel can verify devices before trusting them.

Alistair Francis has submitted a fourth-round Linux kernel series that implements a Security Protocol and Data Model (SPDM) requester in Rust, with supporting PCI changes for Component Measurement and Authentication (CMA).

SPDM is the DMTF protocol used for device authentication, attestation, and key exchange over transports such as PCIe, MCTP, NVMe, and TCP. In the kernel threat model a peripheral stays untrusted until SPDM verification succeeds, so the host must parse hostile, complex responses. The 1.2 and 1.3 specifications run to roughly 200 and 250 pages. Francis frames that combination of untrusted input and a large state machine as the kind of surface where Rust is meant to reduce memory-safety risk.

The work is a standalone Rust library rather than a dependency on Lukas Wunner's earlier C SPDM code, though it reuses pieces of that effort where required. Packet validation copies bytes into ordinary Rust structures instead of relying on packed C layouts and pointer casts, so endianness and field checks happen once up front and much of the unsafe path and panic-prone indexing drops away. Jonathan Cameron has reviewed the SPDM portions through earlier iterations.

On the PCI side the series generalizes Trusted Security Module (TSM) host handling beyond TEE and IDE-only devices, caches CMA DOE capability on the PCI device, and adds a CMA TSM driver so authentication can hook existing TSM probe policy. CMA is the PCIe vehicle for SPDM-based measurement and authentication and is also how Integrity and Data Encryption (IDE) moves session key material. Certificate support fetches digests and chains, runs basic structural and blacklist checks in-kernel, and leaves root-of-trust policy to userspace. A related change parses the leaf certificate Subject Alternative Name so the signed device identity matches Config Space, limiting simple certificate-reuse attacks against driver binding.

Evidence export to userspace is not finished yet. The immediate goal is a memory-safer in-kernel requester and a path to treat PCIe devices as authenticated only after SPDM succeeds.