From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 98D32C61DA3 for ; Tue, 21 Feb 2023 22:39:15 +0000 (UTC) Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id D288685A55; Tue, 21 Feb 2023 23:39:12 +0100 (CET) Authentication-Results: phobos.denx.de; dmarc=none (p=none dis=none) header.from=linux.ibm.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (2048-bit key; unprotected) header.d=ibm.com header.i=@ibm.com header.b="ntzR0uXR"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id 6271685A55; Tue, 21 Feb 2023 23:39:11 +0100 (CET) Received: from mx0a-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id C97858590C for ; Tue, 21 Feb 2023 23:39:04 +0100 (CET) Authentication-Results: phobos.denx.de; dmarc=none (p=none dis=none) header.from=linux.ibm.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=eajames@linux.ibm.com Received: from pps.filterd (m0098416.ppops.net [127.0.0.1]) by mx0b-001b2d01.pphosted.com (8.17.1.19/8.17.1.19) with ESMTP id 31LLluhl021941; Tue, 21 Feb 2023 22:39:02 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=message-id : date : subject : to : cc : references : from : in-reply-to : content-type : content-transfer-encoding : mime-version; s=pp1; bh=0el1XXeQSLcOeY1NVixbd5P16UnfCom2rZjcDsmzECs=; b=ntzR0uXR6ie/P3pq2o7iMSXDPJ0CxbQyZL2xcBuskj/S/zpTrCM6E7nFvLhyK7uoC1/8 nmhM68LKaK8OJWsgdawAo0pg8L3v5/vE7jqxuzVuTq7qsRlVQtuFJZihqv7qDpcsYkzn HhA5o4gSJR5sv/mX0+b0LQu8VNAQdhEXMl/8ZZbw8zlhW6W0pXX+h3S4ludDF0eh3n8N enpVqeFj1xnFpuySsoYTuNmUpHxOl7Hlz5A+BBn080uGjAXSa7vN1DJ+mEaJBFRfxRxK hmanEfeWCjA1aEXskLeKjxPCcrSTybFa/NftIcZSTkY32GImM//tTlrvJPqatEU0oyWT Dw== Received: from pps.reinject (localhost [127.0.0.1]) by mx0b-001b2d01.pphosted.com (PPS) with ESMTPS id 3nw66j12cg-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 21 Feb 2023 22:39:01 +0000 Received: from m0098416.ppops.net (m0098416.ppops.net [127.0.0.1]) by pps.reinject (8.17.1.5/8.17.1.5) with ESMTP id 31LMRV20002971; Tue, 21 Feb 2023 22:39:01 GMT Received: from ppma04wdc.us.ibm.com (1a.90.2fa9.ip4.static.sl-reverse.com [169.47.144.26]) by mx0b-001b2d01.pphosted.com (PPS) with ESMTPS id 3nw66j12c8-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 21 Feb 2023 22:39:01 +0000 Received: from pps.filterd (ppma04wdc.us.ibm.com [127.0.0.1]) by ppma04wdc.us.ibm.com (8.17.1.19/8.17.1.19) with ESMTP id 31LLaxrh014152; Tue, 21 Feb 2023 22:39:00 GMT Received: from smtprelay06.wdc07v.mail.ibm.com ([9.208.129.118]) by ppma04wdc.us.ibm.com (PPS) with ESMTPS id 3ntpa75213-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 21 Feb 2023 22:39:00 +0000 Received: from smtpav05.wdc07v.mail.ibm.com (smtpav05.wdc07v.mail.ibm.com [10.39.53.232]) by smtprelay06.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 31LMcxxu5702264 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Tue, 21 Feb 2023 22:38:59 GMT Received: from smtpav05.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 9F2A058053; Tue, 21 Feb 2023 22:38:59 +0000 (GMT) Received: from smtpav05.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id EB32958043; Tue, 21 Feb 2023 22:38:58 +0000 (GMT) Received: from [9.65.223.120] (unknown [9.65.223.120]) by smtpav05.wdc07v.mail.ibm.com (Postfix) with ESMTP; Tue, 21 Feb 2023 22:38:58 +0000 (GMT) Message-ID: <18e0f808-b250-28cf-08fd-ddf84d21ba6b@linux.ibm.com> Date: Tue, 21 Feb 2023 16:38:58 -0600 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.6.0 Subject: Re: [PATCH v5 0/6] tpm: Support boot measurements To: Ilias Apalodimas Cc: u-boot@lists.denx.de, sjg@chromium.org, xypron.glpk@gmx.de References: <20230202170531.119796-1-eajames@linux.ibm.com> Content-Language: en-US From: Eddie James In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed X-TM-AS-GCONF: 00 X-Proofpoint-GUID: MeIMlBlQum7etZbUqr7MtZKZ3SfL5i-Z X-Proofpoint-ORIG-GUID: wozDVPLaCfv3No9GmIu1raa1V5YkE0z2 Content-Transfer-Encoding: 7bit X-Proofpoint-UnRewURL: 0 URL was un-rewritten MIME-Version: 1.0 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.219,Aquarius:18.0.930,Hydra:6.0.562,FMLib:17.11.170.22 definitions=2023-02-21_12,2023-02-20_02,2023-02-09_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 lowpriorityscore=0 impostorscore=0 mlxscore=0 clxscore=1011 spamscore=0 priorityscore=1501 adultscore=0 mlxlogscore=999 bulkscore=0 malwarescore=0 phishscore=0 suspectscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2212070000 definitions=main-2302210194 X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.39 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.6 at phobos.denx.de X-Virus-Status: Clean On 2/6/23 06:20, Ilias Apalodimas wrote: > Thanks Eddie, > > I quickly tested this but the EFI subsystem fails to initialize the TCG > protocol properly now. Unfortunately I am on a business trip and I won't > be able to take a look into why till next week Hi Ilias, I haven't had the opportunity to test this, have you? Thanks, Eddie > > Cheers > /Ilias > > On Thu, Feb 02, 2023 at 11:05:25AM -0600, Eddie James wrote: >> This series adds support for measuring the boot images more generically >> than the existing EFI support. Several EFI functions have been moved to >> the TPM layer. The series includes optional measurement from the bootm >> command. >> A new test case has been added for the bootm measurement to test the new >> path, and the sandbox TPM2 driver has been updated to support this use >> case. >> This series is based on Ilias' auto-startup series: >> https://lore.kernel.org/u-boot/20230126081844.591148-1-ilias.apalodimas@linaro.org/ >> >> Changes since v4: >> - Remove tcg2_measure_event function and check for NULL data in >> tcg2_measure_data >> - Use tpm_auto_startup >> - Fix efi_tcg2.c compilation for removing tcg2_pcr_read function >> - Change PCR indexes for initrd and dtb >> - Drop u8 casting in measurement test >> - Use bullets in documentation >> >> Changes since v3: >> - Reordered headers >> - Refactored more of EFI code into common code >> Removed digest_info structure and instead used the common alg_to_mask >> and alg_to_len >> Improved event log parsing in common code to get it equivalent to EFI >> Common code now extends PCR if previous bootloader stage couldn't >> No need to allocate memory in the common code, so EFI copies the >> discovered buffer like it did before >> Rename efi measure_event function >> >> Changes since v2: >> - Add documentation. >> - Changed reserved memory address to the top of the RAM for sandbox dts. >> - Add measure state to booti and bootz. >> - Skip measurement for EFI images that should be measured >> >> Changes since v1: >> - Refactor TPM layer functions to allow EFI system to use them, and >> remove duplicate EFI functions. >> - Add test case >> - Drop #ifdefs for bootm >> - Add devicetree measurement config option >> - Update sandbox TPM driver >> >> Eddie James (6): >> tpm: Fix spelling for tpmu_ha union >> tpm: Support boot measurements >> bootm: Support boot measurement >> tpm: sandbox: Update for needed TPM2 capabilities >> test: Add sandbox TPM boot measurement >> doc: Add measured boot documentation >> >> arch/sandbox/dts/sandbox.dtsi | 14 + >> arch/sandbox/dts/test.dts | 13 + >> boot/Kconfig | 23 + >> boot/bootm.c | 70 +++ >> cmd/booti.c | 1 + >> cmd/bootm.c | 2 + >> cmd/bootz.c | 1 + >> configs/sandbox_defconfig | 1 + >> doc/usage/index.rst | 1 + >> doc/usage/measured_boot.rst | 23 + >> drivers/tpm/tpm2_tis_sandbox.c | 100 +++- >> include/bootm.h | 2 + >> include/efi_tcg2.h | 44 -- >> include/image.h | 1 + >> include/test/suites.h | 1 + >> include/tpm-v2.h | 246 +++++++- >> lib/efi_loader/efi_tcg2.c | 1010 +++----------------------------- >> lib/tpm-v2.c | 771 ++++++++++++++++++++++++ >> test/boot/Makefile | 1 + >> test/boot/measurement.c | 66 +++ >> test/cmd_ut.c | 2 + >> 21 files changed, 1383 insertions(+), 1010 deletions(-) >> create mode 100644 doc/usage/measured_boot.rst >> create mode 100644 test/boot/measurement.c >> >> -- >> 2.31.1 >>