Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1334096 > unrolled thread
| Started by | Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> |
|---|---|
| First post | 2016-02-15 02:50 +0100 |
| Last post | 2016-02-15 02:50 +0100 |
| Articles | 3 — 1 participant |
Back to article view | Back to linux.kernel
[PATCH 0/3] Remaining fixes for v4.5 (post tpmdd-next-20160120) Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2016-02-15 02:50 +0100
[PATCH 1/3] tpm: fix: keep auth session intact after unseal operation Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2016-02-15 02:50 +0100
[PATCH 3/3] tpm_eventlog.c: fix binary_bios_measurements Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2016-02-15 02:50 +0100
| From | Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> |
|---|---|
| Date | 2016-02-15 02:50 +0100 |
| Subject | [PATCH 0/3] Remaining fixes for v4.5 (post tpmdd-next-20160120) |
| Message-ID | <r2gsx-2w1-3@gated-at.bofh.it> |
Fixes remaining after tpmdd-next-20160120 has been pulled and API change so that session object stays intact after a successful unseal operation. Harald Hoyer (1): tpm_eventlog.c: fix binary_bios_measurements Jarkko Sakkinen (2): tpm: fix: keep auth session intact after unseal operation tpm: fix: return rc when devm_add_action() fails drivers/char/tpm/tpm-chip.c | 7 ++++++- drivers/char/tpm/tpm2-cmd.c | 10 +++++++--- drivers/char/tpm/tpm_eventlog.c | 10 ++++++++-- 3 files changed, 21 insertions(+), 6 deletions(-) -- 2.7.0
[toc] | [next] | [standalone]
| From | Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> |
|---|---|
| Date | 2016-02-15 02:50 +0100 |
| Subject | [PATCH 1/3] tpm: fix: keep auth session intact after unseal operation |
| Message-ID | <r2gsx-2w1-7@gated-at.bofh.it> |
| In reply to | #1334096 |
The behavior of policy based unseal operation is not consistent:
* When there is an error in TPM2_Unseal operation, the session object
stays in the TPM transient memory.
* When the unseal is successful, the TPM automatically removes the
session object.
This patch sets the continueSession attribute to keep the session intact
after a successful unseal operation thus making the behavior consistent.
Signed-off-by: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
Fixes: 5beb0c435b ("keys, trusted: seal with a TPM2 authorization policy")
---
drivers/char/tpm/tpm2-cmd.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/drivers/char/tpm/tpm2-cmd.c b/drivers/char/tpm/tpm2-cmd.c
index 66e04b4..b28e4da 100644
--- a/drivers/char/tpm/tpm2-cmd.c
+++ b/drivers/char/tpm/tpm2-cmd.c
@@ -20,7 +20,11 @@
#include <keys/trusted-type.h>
enum tpm2_object_attributes {
- TPM2_ATTR_USER_WITH_AUTH = BIT(6),
+ TPM2_OA_USER_WITH_AUTH = BIT(6),
+};
+
+enum tpm2_session_attributes {
+ TPM2_SA_CONTINUE_SESSION = BIT(0),
};
struct tpm2_startup_in {
@@ -489,7 +493,7 @@ int tpm2_seal_trusted(struct tpm_chip *chip,
tpm_buf_append(&buf, options->policydigest,
options->policydigest_len);
} else {
- tpm_buf_append_u32(&buf, TPM2_ATTR_USER_WITH_AUTH);
+ tpm_buf_append_u32(&buf, TPM2_OA_USER_WITH_AUTH);
tpm_buf_append_u16(&buf, 0);
}
@@ -627,7 +631,7 @@ static int tpm2_unseal(struct tpm_chip *chip,
options->policyhandle ?
options->policyhandle : TPM2_RS_PW,
NULL /* nonce */, 0,
- 0 /* session_attributes */,
+ TPM2_SA_CONTINUE_SESSION,
options->blobauth /* hmac */,
TPM_DIGEST_SIZE);
--
2.7.0
[toc] | [prev] | [next] | [standalone]
| From | Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> |
|---|---|
| Date | 2016-02-15 02:50 +0100 |
| Subject | [PATCH 3/3] tpm_eventlog.c: fix binary_bios_measurements |
| Message-ID | <r2gsx-2w1-9@gated-at.bofh.it> |
| In reply to | #1334096 |
From: Harald Hoyer <harald@redhat.com>
The commit 0cc698af36ff ("vTPM: support little endian guests") copied
the event, but without the event data, did an endian conversion on the
size and tried to output the event data from the copied version, which
has only have one byte of the data, resulting in garbage event data.
Signed-off-by: Harald Hoyer <harald@redhat.com>
Fixes: 0cc698af36ff ("vTPM: support little endian guests")
Reviewed-by: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
cc: stable@vger.kernel.org
---
drivers/char/tpm/tpm_eventlog.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/char/tpm/tpm_eventlog.c b/drivers/char/tpm/tpm_eventlog.c
index bd72fb0..27fc887 100644
--- a/drivers/char/tpm/tpm_eventlog.c
+++ b/drivers/char/tpm/tpm_eventlog.c
@@ -242,9 +242,15 @@ static int tpm_binary_bios_measurements_show(struct seq_file *m, void *v)
temp_event.event_type = do_endian_conversion(event->event_type);
temp_event.event_size = do_endian_conversion(event->event_size);
- tempPtr = (char *)&temp_event;
+ tempPtr = (char *) &temp_event;
- for (i = 0; i < sizeof(struct tcpa_event) + temp_event.event_size; i++)
+ for (i = 0; i < (sizeof(struct tcpa_event) - 1) ; i++)
+ seq_putc(m, tempPtr[i]);
+
+ tempPtr = (char *) v;
+
+ for (i = (sizeof(struct tcpa_event) - 1);
+ i < (sizeof(struct tcpa_event) + temp_event.event_size); i++)
seq_putc(m, tempPtr[i]);
return 0;
--
2.7.0
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web