Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 28 additions & 4 deletions plugin/kvm/src/main/java/org/zstack/kvm/tpm/KvmTpmManager.java
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,7 @@
import org.zstack.header.message.APIMessage;
import org.zstack.header.message.Message;
import org.zstack.header.message.MessageReply;
import org.zstack.header.keyprovider.EncryptedResourceKeyManager;
import org.zstack.header.secret.SecretHostDeleteMsg;
import org.zstack.header.tpm.api.APIAddTpmEvent;
import org.zstack.header.tpm.api.APIAddTpmMsg;
Expand Down Expand Up @@ -105,6 +106,8 @@ public class KvmTpmManager extends AbstractService {
@Autowired
private TpmEncryptedResourceKeyBackend tpmKeyBackend;
@Autowired
private EncryptedResourceKeyManager resourceKeyManager;
@Autowired
private KvmSecureBootExtensions secureBootExtensions;

@Override
Expand Down Expand Up @@ -253,11 +256,32 @@ private void addTpmToVm(AddTpmToVmContext context, Completion completion) {
.then(Flow.of("attach-key-provider-to-tpm")
.skipIf(data -> VmGlobalConfig.ALLOWED_TPM_VM_WITHOUT_KMS.value(Boolean.class))
.handle(trigger -> {
if (context.keyProviderUuid != null) {
tpmKeyBackend.attachKeyProviderToTpm(context.createdTpmUuid, context.keyProviderUuid);
context.keyProviderAttached = true;
if (context.keyProviderUuid == null) {
trigger.fail(operr("keyProviderUuid is required when adding TPM to VM[uuid:%s]",
context.vmInstanceUuid));
return;
}
trigger.next();

tpmKeyBackend.attachKeyProviderToTpm(context.createdTpmUuid, context.keyProviderUuid);
context.keyProviderAttached = true;

EncryptedResourceKeyManager.GetOrCreateResourceKeyContext keyCtx =
new EncryptedResourceKeyManager.GetOrCreateResourceKeyContext();
keyCtx.setResourceUuid(context.createdTpmUuid);
keyCtx.setResourceType(TpmVO.class.getSimpleName());
keyCtx.setKeyProviderUuid(context.keyProviderUuid);
keyCtx.setPurpose("vtpm");
resourceKeyManager.getOrCreateKey(keyCtx, new ReturnValueCompletion<EncryptedResourceKeyManager.ResourceKeyResult>(trigger) {
@Override
public void success(EncryptedResourceKeyManager.ResourceKeyResult returnValue) {
trigger.next();
}

@Override
public void fail(ErrorCode errorCode) {
trigger.fail(errorCode);
}
});
})
Comment thread
coderabbitai[bot] marked this conversation as resolved.
.rollback(trigger -> {
if (context.keyProviderAttached && context.createdTpmUuid != null) {
Expand Down