mirror of
https://github.com/systemd/systemd
synced 2024-10-06 16:21:34 +00:00
man: briefly document that we are now keeping an event log in userspace for out measurements
This commit is contained in:
parent
b0d00ec60a
commit
75174a5de9
|
@ -204,6 +204,30 @@
|
|||
</variablelist>
|
||||
</refsect1>
|
||||
|
||||
<refsect1>
|
||||
<title>Files</title>
|
||||
|
||||
<variablelist>
|
||||
<varlistentry>
|
||||
<term><filename>/var/log/systemd/tpm2-measure.log</filename></term>
|
||||
|
||||
<listitem><para>Measurements are logged into an event log file maintained in
|
||||
<filename>/var/log/systemd/tpm2-measure.log</filename>, which contains a <ulink
|
||||
url="https://www.rfc-editor.org/rfc/rfc7464.html">JSON-SEQ</ulink> series of objects that follow the
|
||||
general structure of the <ulink
|
||||
url="https://trustedcomputinggroup.org/resource/canonical-event-log-format/">TCG Common Event Log
|
||||
Format (CEL-JSON)</ulink> event objects (but lack the <literal>recnum</literal>
|
||||
field).</para>
|
||||
|
||||
<para>A <constant>LOCK_EX</constant> BSD file lock (<citerefentry
|
||||
project='man-pages'><refentrytitle>flock</refentrytitle><manvolnum>2</manvolnum></citerefentry>) on
|
||||
the log file is acquired while the measurement is made and the file is updated. Thus, applications
|
||||
that intend to acquire a consistent quote from the TPM with the associated snapshot of the event log
|
||||
should acquire a <constant>LOCK_SH</constant> lock while doing so.</para></listitem>
|
||||
</varlistentry>
|
||||
</variablelist>
|
||||
</refsect1>
|
||||
|
||||
<refsect1>
|
||||
<title>See Also</title>
|
||||
<para>
|
||||
|
|
Loading…
Reference in a new issue