This patch set moves TPM 1.2 specific code to a new function called
tpm1_pcr_extend(). The purpose of splitting is to isolate TPM 2.0 code,
so that it can be more easily modified to handle multiple digests.
With TPM 2.0, a Platform Configuration Register (PCR) could have multiple
values, stored in locations called banks. Each bank stores the values
of PCRs extended with the same hash algorithm.
Currently, the TPM kernel driver does not take advantage of stronger
algorithms because PCRs are always extended with a SHA1 digest, padded
with zeros to match the length of the input for the hash algorithm
being used. Shortly after these patches, a new patch set will be provided
to allow callers of tpm_pcr_extend() to pass a digest for each algorithm
supported by the TPM.
In this patch set, TPM 1.2 specific code will prepare the command buffer
with tpm_buf_init() which, in respect to the previous method, offers
protection against buffer overflow. Moreover, CPU native to big-endian
conversion has been removed from tags and ordinals definitions, as it is
already done by tpm_buf_init().
Changelog:
v2
- restored TPM_TAG_RQU_COMMAND definition in drivers/char/tpm/tpm.h
- removed endianness conversion in TPM_TAG_RQU_COMMAND definition
- removed '#include <linux/tpm_command.h>' in tpm-interface.c
and tpm-sysfs.c
- restored TPM_ORD_ definitions in tpm-interface.c and tpm-sysfs.c
Roberto Sassu (3):
tpm: move endianness conversion of TPM_TAG_RQU_COMMAND to
tpm_input_header
tpm: move endianness conversion of ordinals to tpm_input_header
tpm: move TPM 1.2 code of tpm_pcr_extend() to tpm1_pcr_extend()
drivers/char/tpm/tpm-interface.c | 79 ++++++++++++++++++++++------------------
drivers/char/tpm/tpm-sysfs.c | 6 +--
drivers/char/tpm/tpm.h | 2 +-
3 files changed, 47 insertions(+), 40 deletions(-)
--
2.9.3
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
In the long term, TPM 1.2 functions in the driver interface will be
modified to use tpm_buf_init().
However, tag and ordinals cannot be passed directly to tpm_buf_init(),
because this function performs CPU native to big-endian conversion of these
arguments. Since TPM_TAG_RQU_COMMAND and TPM_ORD_ are already converted,
passing them to the function will undo the previous conversion.
This patch moves the conversion of TPM_TAG_RQU_COMMAND from the tpm.h
header file in the driver directory to the tpm_input_header declarations
in the driver interface and tpm-sysfs.c.
Signed-off-by: Roberto Sassu <roberto.sassu@huawei.com>
---
v2
- restored TPM_TAG_RQU_COMMAND definition in drivers/char/tpm/tpm.h
- removed endianness conversion in TPM_TAG_RQU_COMMAND definition
- removed '#include <linux/tpm_command.h>' in tpm-interface.c
and tpm-sysfs.c
drivers/char/tpm/tpm-interface.c | 14 +++++++-------
drivers/char/tpm/tpm-sysfs.c | 2 +-
drivers/char/tpm/tpm.h | 2 +-
3 files changed, 9 insertions(+), 9 deletions(-)
--
2.9.3
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
From: Jarkko Sakkinen <hidden> Date: 2017-05-04 17:34:30
On Wed, May 03, 2017 at 06:19:09PM +0200, Roberto Sassu wrote:
In the long term, TPM 1.2 functions in the driver interface will be
modified to use tpm_buf_init().
However, tag and ordinals cannot be passed directly to tpm_buf_init(),
because this function performs CPU native to big-endian conversion of these
arguments. Since TPM_TAG_RQU_COMMAND and TPM_ORD_ are already converted,
passing them to the function will undo the previous conversion.
This patch moves the conversion of TPM_TAG_RQU_COMMAND from the tpm.h
header file in the driver directory to the tpm_input_header declarations
in the driver interface and tpm-sysfs.c.
Signed-off-by: Roberto Sassu <roberto.sassu@huawei.com>
Reviwed-by: Jarkko Sakkinen [off-list ref]
Tested-by: Jarkko Sakkinen <redacted>
--
2.9.3
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
tpmdd-devel mailing list
tpmdd-devel at lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/tpmdd-devel
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Move CPU native value to big-endian conversion of ordinals to the
tpm_input_header declarations.
With the previous and this patch it will now be possible to modify TPM 1.2
functions to use tpm_buf_init(), which expects CPU native value for the
tag and ordinal arguments.
Signed-off-by: Roberto Sassu <roberto.sassu@huawei.com>
---
v2
- restored TPM_ORD_ definitions in tpm-interface.c and tpm-sysfs.c
drivers/char/tpm/tpm-interface.c | 24 ++++++++++++------------
drivers/char/tpm/tpm-sysfs.c | 4 ++--
2 files changed, 14 insertions(+), 14 deletions(-)
--
2.9.3
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
From: Jarkko Sakkinen <hidden> Date: 2017-05-04 17:35:03
On Wed, May 03, 2017 at 06:19:10PM +0200, Roberto Sassu wrote:
Move CPU native value to big-endian conversion of ordinals to the
tpm_input_header declarations.
With the previous and this patch it will now be possible to modify TPM 1.2
functions to use tpm_buf_init(), which expects CPU native value for the
tag and ordinal arguments.
Signed-off-by: Roberto Sassu <roberto.sassu@huawei.com>
Reviwed-by: Jarkko Sakkinen [off-list ref]
Tested-by: Jarkko Sakkinen <redacted>
/Jarkko
--
2.9.3
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
In preparation of the modifications to tpm_pcr_extend(), which will
allow callers to supply a digest for each PCR bank of a TPM 2.0,
the TPM 1.2 specific code has been moved to tpm1_pcr_extend().
tpm1_pcr_extend() uses tpm_buf_init() to prepare the command buffer,
which offers protection against buffer overflow. It is called by
tpm_pcr_extend() and tpm_pm_suspend().
Signed-off-by: Roberto Sassu <roberto.sassu@huawei.com>
---
drivers/char/tpm/tpm-interface.c | 41 +++++++++++++++++++++++-----------------
1 file changed, 24 insertions(+), 17 deletions(-)
@@ -812,13 +830,8 @@ int tpm_pcr_extend(u32 chip_num, int pcr_idx, const u8 *hash)returnrc;}-cmd.header.in=pcrextend_header;-cmd.params.pcrextend_in.pcr_idx=cpu_to_be32(pcr_idx);-memcpy(cmd.params.pcrextend_in.hash,hash,TPM_DIGEST_SIZE);-rc=tpm_transmit_cmd(chip,&cmd,EXTEND_PCR_RESULT_SIZE,-EXTEND_PCR_RESULT_BODY_SIZE,0,-"attempting extend a PCR value");-+rc=tpm1_pcr_extend(chip,pcr_idx,hash,+"attempting extend a PCR value");tpm_put_ops(chip);returnrc;}
@@ -1017,15 +1030,9 @@ int tpm_pm_suspend(struct device *dev)}/* for buggy tpm, flush pcrs with extend to selected dummy */-if(tpm_suspend_pcr){-cmd.header.in=pcrextend_header;-cmd.params.pcrextend_in.pcr_idx=cpu_to_be32(tpm_suspend_pcr);-memcpy(cmd.params.pcrextend_in.hash,dummy_hash,-TPM_DIGEST_SIZE);-rc=tpm_transmit_cmd(chip,&cmd,EXTEND_PCR_RESULT_SIZE,-EXTEND_PCR_RESULT_BODY_SIZE,0,-"extending dummy pcr before suspend");-}+if(tpm_suspend_pcr)+rc=tpm1_pcr_extend(chip,tpm_suspend_pcr,dummy_hash,+"extending dummy pcr before suspend");/* now do the actual savestate */for(try=0;try<TPM_RETRY;try++){
--
2.9.3
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info@ http://vger.kernel.org/majordomo-info.html
From: Jarkko Sakkinen <hidden> Date: 2017-05-04 10:08:06
On Wed, May 03, 2017 at 06:19:11PM +0200, Roberto Sassu wrote:
In preparation of the modifications to tpm_pcr_extend(), which will
allow callers to supply a digest for each PCR bank of a TPM 2.0,
the TPM 1.2 specific code has been moved to tpm1_pcr_extend().
tpm1_pcr_extend() uses tpm_buf_init() to prepare the command buffer,
which offers protection against buffer overflow. It is called by
tpm_pcr_extend() and tpm_pm_suspend().
Signed-off-by: Roberto Sassu <roberto.sassu@huawei.com>
Please rebase this to the latest tree. It does not apply cleanly.
No need to send two other patches.
Use --subject-prefix="PATCH v2, RESEND" as tag.
/Jarkko
@@ -812,13 +830,8 @@ int tpm_pcr_extend(u32 chip_num, int pcr_idx, const u8 *hash)returnrc;}-cmd.header.in=pcrextend_header;-cmd.params.pcrextend_in.pcr_idx=cpu_to_be32(pcr_idx);-memcpy(cmd.params.pcrextend_in.hash,hash,TPM_DIGEST_SIZE);-rc=tpm_transmit_cmd(chip,&cmd,EXTEND_PCR_RESULT_SIZE,-EXTEND_PCR_RESULT_BODY_SIZE,0,-"attempting extend a PCR value");-+rc=tpm1_pcr_extend(chip,pcr_idx,hash,+"attempting extend a PCR value");tpm_put_ops(chip);returnrc;}
@@ -1017,15 +1030,9 @@ int tpm_pm_suspend(struct device *dev)}/* for buggy tpm, flush pcrs with extend to selected dummy */-if(tpm_suspend_pcr){-cmd.header.in=pcrextend_header;-cmd.params.pcrextend_in.pcr_idx=cpu_to_be32(tpm_suspend_pcr);-memcpy(cmd.params.pcrextend_in.hash,dummy_hash,-TPM_DIGEST_SIZE);-rc=tpm_transmit_cmd(chip,&cmd,EXTEND_PCR_RESULT_SIZE,-EXTEND_PCR_RESULT_BODY_SIZE,0,-"extending dummy pcr before suspend");-}+if(tpm_suspend_pcr)+rc=tpm1_pcr_extend(chip,tpm_suspend_pcr,dummy_hash,+"extending dummy pcr before suspend");/* now do the actual savestate */for(try=0;try<TPM_RETRY;try++){
--
2.9.3
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
From: Jarkko Sakkinen <hidden> Date: 2017-05-04 09:25:05
On Wed, May 03, 2017 at 06:19:08PM +0200, Roberto Sassu wrote:
This patch set moves TPM 1.2 specific code to a new function called
tpm1_pcr_extend(). The purpose of splitting is to isolate TPM 2.0 code,
so that it can be more easily modified to handle multiple digests.
With TPM 2.0, a Platform Configuration Register (PCR) could have multiple
values, stored in locations called banks. Each bank stores the values
of PCRs extended with the same hash algorithm.
Currently, the TPM kernel driver does not take advantage of stronger
algorithms because PCRs are always extended with a SHA1 digest, padded
with zeros to match the length of the input for the hash algorithm
being used. Shortly after these patches, a new patch set will be provided
to allow callers of tpm_pcr_extend() to pass a digest for each algorithm
supported by the TPM.
In this patch set, TPM 1.2 specific code will prepare the command buffer
with tpm_buf_init() which, in respect to the previous method, offers
protection against buffer overflow. Moreover, CPU native to big-endian
conversion has been removed from tags and ordinals definitions, as it is
already done by tpm_buf_init().
Changelog:
v2
- restored TPM_TAG_RQU_COMMAND definition in drivers/char/tpm/tpm.h
- removed endianness conversion in TPM_TAG_RQU_COMMAND definition
- removed '#include <linux/tpm_command.h>' in tpm-interface.c
and tpm-sysfs.c
- restored TPM_ORD_ definitions in tpm-interface.c and tpm-sysfs.c
Roberto Sassu (3):
tpm: move endianness conversion of TPM_TAG_RQU_COMMAND to
tpm_input_header
tpm: move endianness conversion of ordinals to tpm_input_header
tpm: move TPM 1.2 code of tpm_pcr_extend() to tpm1_pcr_extend()
drivers/char/tpm/tpm-interface.c | 79 ++++++++++++++++++++++------------------
drivers/char/tpm/tpm-sysfs.c | 6 +--
drivers/char/tpm/tpm.h | 2 +-
3 files changed, 47 insertions(+), 40 deletions(-)
Thanks for good quality patches! I'll test these but with quick skim
no complains whatsoever :-)
/Jarkko
--
2.9.3
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
On Wed, May 03, 2017 at 06:19:08PM +0200, Roberto Sassu wrote:
quoted
This patch set moves TPM 1.2 specific code to a new function called
tpm1_pcr_extend(). The purpose of splitting is to isolate TPM 2.0 code,
so that it can be more easily modified to handle multiple digests.
With TPM 2.0, a Platform Configuration Register (PCR) could have multiple
values, stored in locations called banks. Each bank stores the values
of PCRs extended with the same hash algorithm.
Currently, the TPM kernel driver does not take advantage of stronger
algorithms because PCRs are always extended with a SHA1 digest, padded
with zeros to match the length of the input for the hash algorithm
being used. Shortly after these patches, a new patch set will be provided
to allow callers of tpm_pcr_extend() to pass a digest for each algorithm
supported by the TPM.
In this patch set, TPM 1.2 specific code will prepare the command buffer
with tpm_buf_init() which, in respect to the previous method, offers
protection against buffer overflow. Moreover, CPU native to big-endian
conversion has been removed from tags and ordinals definitions, as it is
already done by tpm_buf_init().
Changelog:
v2
- restored TPM_TAG_RQU_COMMAND definition in drivers/char/tpm/tpm.h
- removed endianness conversion in TPM_TAG_RQU_COMMAND definition
- removed '#include <linux/tpm_command.h>' in tpm-interface.c
and tpm-sysfs.c
- restored TPM_ORD_ definitions in tpm-interface.c and tpm-sysfs.c
Roberto Sassu (3):
tpm: move endianness conversion of TPM_TAG_RQU_COMMAND to
tpm_input_header
tpm: move endianness conversion of ordinals to tpm_input_header
tpm: move TPM 1.2 code of tpm_pcr_extend() to tpm1_pcr_extend()
drivers/char/tpm/tpm-interface.c | 79 ++++++++++++++++++++++------------------
drivers/char/tpm/tpm-sysfs.c | 6 +--
drivers/char/tpm/tpm.h | 2 +-
3 files changed, 47 insertions(+), 40 deletions(-)
Thanks for good quality patches! I'll test these but with quick skim
no complains whatsoever :-)
Very good! We will see if it will be the same for the next patch set!
Roberto
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
From: Jarkko Sakkinen <hidden> Date: 2017-05-04 17:37:34
On Thu, May 04, 2017 at 12:24:47PM +0300, Jarkko Sakkinen wrote:
On Wed, May 03, 2017 at 06:19:08PM +0200, Roberto Sassu wrote:
quoted
This patch set moves TPM 1.2 specific code to a new function called
tpm1_pcr_extend(). The purpose of splitting is to isolate TPM 2.0 code,
so that it can be more easily modified to handle multiple digests.
With TPM 2.0, a Platform Configuration Register (PCR) could have multiple
values, stored in locations called banks. Each bank stores the values
of PCRs extended with the same hash algorithm.
Currently, the TPM kernel driver does not take advantage of stronger
algorithms because PCRs are always extended with a SHA1 digest, padded
with zeros to match the length of the input for the hash algorithm
being used. Shortly after these patches, a new patch set will be provided
to allow callers of tpm_pcr_extend() to pass a digest for each algorithm
supported by the TPM.
In this patch set, TPM 1.2 specific code will prepare the command buffer
with tpm_buf_init() which, in respect to the previous method, offers
protection against buffer overflow. Moreover, CPU native to big-endian
conversion has been removed from tags and ordinals definitions, as it is
already done by tpm_buf_init().
Changelog:
v2
- restored TPM_TAG_RQU_COMMAND definition in drivers/char/tpm/tpm.h
- removed endianness conversion in TPM_TAG_RQU_COMMAND definition
- removed '#include <linux/tpm_command.h>' in tpm-interface.c
and tpm-sysfs.c
- restored TPM_ORD_ definitions in tpm-interface.c and tpm-sysfs.c
Roberto Sassu (3):
tpm: move endianness conversion of TPM_TAG_RQU_COMMAND to
tpm_input_header
tpm: move endianness conversion of ordinals to tpm_input_header
tpm: move TPM 1.2 code of tpm_pcr_extend() to tpm1_pcr_extend()
drivers/char/tpm/tpm-interface.c | 79 ++++++++++++++++++++++------------------
drivers/char/tpm/tpm-sysfs.c | 6 +--
drivers/char/tpm/tpm.h | 2 +-
3 files changed, 47 insertions(+), 40 deletions(-)
Thanks for good quality patches! I'll test these but with quick skim
no complains whatsoever :-)
1/3 and 2/3 are now applied to master and next (which will be pulled to
linux-next).
/Jarkko
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
In preparation of the modifications to tpm_pcr_extend(), which will
allow callers to supply a digest for each PCR bank of a TPM 2.0,
the TPM 1.2 specific code has been moved to tpm1_pcr_extend().
tpm1_pcr_extend() uses tpm_buf_init() to prepare the command buffer,
which offers protection against buffer overflow. It is called by
tpm_pcr_extend() and tpm_pm_suspend().
Signed-off-by: Roberto Sassu <roberto.sassu@huawei.com>
---
drivers/char/tpm/tpm-interface.c | 41 +++++++++++++++++++++++-----------------
1 file changed, 24 insertions(+), 17 deletions(-)
@@ -885,13 +903,8 @@ int tpm_pcr_extend(u32 chip_num, int pcr_idx, const u8 *hash)returnrc;}-cmd.header.in=pcrextend_header;-cmd.params.pcrextend_in.pcr_idx=cpu_to_be32(pcr_idx);-memcpy(cmd.params.pcrextend_in.hash,hash,TPM_DIGEST_SIZE);-rc=tpm_transmit_cmd(chip,NULL,&cmd,EXTEND_PCR_RESULT_SIZE,-EXTEND_PCR_RESULT_BODY_SIZE,0,-"attempting extend a PCR value");-+rc=tpm1_pcr_extend(chip,pcr_idx,hash,+"attempting extend a PCR value");tpm_put_ops(chip);returnrc;}
@@ -1090,15 +1103,9 @@ int tpm_pm_suspend(struct device *dev)}/* for buggy tpm, flush pcrs with extend to selected dummy */-if(tpm_suspend_pcr){-cmd.header.in=pcrextend_header;-cmd.params.pcrextend_in.pcr_idx=cpu_to_be32(tpm_suspend_pcr);-memcpy(cmd.params.pcrextend_in.hash,dummy_hash,-TPM_DIGEST_SIZE);-rc=tpm_transmit_cmd(chip,NULL,&cmd,EXTEND_PCR_RESULT_SIZE,-EXTEND_PCR_RESULT_BODY_SIZE,0,-"extending dummy pcr before suspend");-}+if(tpm_suspend_pcr)+rc=tpm1_pcr_extend(chip,tpm_suspend_pcr,dummy_hash,+"extending dummy pcr before suspend");/* now do the actual savestate */for(try=0;try<TPM_RETRY;try++){
--
2.9.3
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info@ http://vger.kernel.org/majordomo-info.html
From: Jarkko Sakkinen <hidden> Date: 2017-05-05 10:55:51
On Thu, May 04, 2017 at 01:16:47PM +0200, Roberto Sassu wrote:
In preparation of the modifications to tpm_pcr_extend(), which will
allow callers to supply a digest for each PCR bank of a TPM 2.0,
the TPM 1.2 specific code has been moved to tpm1_pcr_extend().
tpm1_pcr_extend() uses tpm_buf_init() to prepare the command buffer,
which offers protection against buffer overflow. It is called by
tpm_pcr_extend() and tpm_pm_suspend().
Signed-off-by: Roberto Sassu <roberto.sassu@huawei.com>
Reviewed-by: Jarkko Sakkinen <redacted>
Tested-by: Jarkko Sakkinen <redacted>
/Jarkko
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html