class

Pyrite::Providers::TPM2Direct

Inherits Pyrite::Provider < Reference < Object

Provider for standalone and embedded Linux systems with direct TPM 2.0 access via /dev/tpmrm0.

Interacts directly with the Linux kernel TPM Resource Manager (/dev/tpmrm0) using tpm2_unseal (tpm2-tools), injecting TPM2TOOLS_TCTI=device:<device_path> into the process environment.

Prerequisites

  • Physical or virtual TPM 2.0 chip exposed at /dev/tpmrm0 or /dev/tpm0.
  • Package tpm2-tools installed (tpm2_unseal in $PATH).

Example

provider = Pyrite::Providers::TPM2Direct.new("/dev/tpmrm0")
config = Pyrite.bootstrap!(AppConfig, provider: provider)

Constructors

new(device_path : String = "/dev/tpmrm0")

Initializes the provider with a TPM device node path (defaults to "/dev/tpmrm0").

Source

Instance methods

device_path

Filesystem path to the TPM device node

Source
name

Human-readable provider name

Source
unwrap(envelope_path : String) : String

Unseals the TPM context file at envelope_path against PCR registers.

Source