* Add TPM measured boot support
@ 2017-07-05 21:19 Matthew Garrett
2017-07-05 21:19 ` [PATCH 1/2] Verify commands executed by grub Matthew Garrett
` (2 more replies)
0 siblings, 3 replies; 17+ messages in thread
From: Matthew Garrett @ 2017-07-05 21:19 UTC (permalink / raw)
To: grub-devel
This patchset extends the verifier framework to support verifying commands
executed by Grub, and makes use of this to add support for measuring files
and commands executed by grub into the TPM on UEFI-based systems.
^ permalink raw reply [flat|nested] 17+ messages in thread
* [PATCH 1/2] Verify commands executed by grub
2017-07-05 21:19 Add TPM measured boot support Matthew Garrett
@ 2017-07-05 21:19 ` Matthew Garrett
2017-07-21 14:23 ` Javier Martinez Canillas
2017-07-21 14:39 ` Vladimir 'phcoder' Serbinenko
2017-07-05 21:19 ` [PATCH 2/2] Core TPM support Matthew Garrett
2017-07-20 22:41 ` Add TPM measured boot support Matthew Garrett
2 siblings, 2 replies; 17+ messages in thread
From: Matthew Garrett @ 2017-07-05 21:19 UTC (permalink / raw)
To: grub-devel; +Cc: Matthew Garrett
Pass commands to the verification code. We want to be able to log these
in the TPM verification case.
---
grub-core/script/execute.c | 27 ++++++++++++++++++++++++---
include/grub/verify.h | 1 +
2 files changed, 25 insertions(+), 3 deletions(-)
diff --git a/grub-core/script/execute.c b/grub-core/script/execute.c
index a8502d907..ee299fd0e 100644
--- a/grub-core/script/execute.c
+++ b/grub-core/script/execute.c
@@ -27,6 +27,7 @@
#include <grub/normal.h>
#include <grub/extcmd.h>
#include <grub/i18n.h>
+#include <grub/verify.h>
/* Max digits for a char is 3 (0xFF is 255), similarly for an int it
is sizeof (int) * 3, and one extra for a possible -ve sign. */
@@ -929,8 +930,9 @@ grub_script_execute_cmdline (struct grub_script_cmd *cmd)
grub_err_t ret = 0;
grub_script_function_t func = 0;
char errnobuf[18];
- char *cmdname;
- int argc;
+ char *cmdname, *cmdstring;
+ int argc, offset = 0, cmdlen = 0;
+ unsigned int i;
char **args;
int invert;
struct grub_script_argv argv = { 0, 0, 0 };
@@ -939,6 +941,26 @@ grub_script_execute_cmdline (struct grub_script_cmd *cmd)
if (grub_script_arglist_to_argv (cmdline->arglist, &argv) || ! argv.args[0])
return grub_errno;
+ for (i = 0; i < argv.argc; i++)
+ {
+ cmdlen += grub_strlen (argv.args[i]) + 1;
+ }
+
+ cmdstring = grub_malloc (cmdlen);
+ if (!cmdstring)
+ {
+ return grub_error (GRUB_ERR_OUT_OF_MEMORY,
+ N_("cannot allocate command buffer"));
+ }
+
+ for (i = 0; i < argv.argc; i++)
+ {
+ offset += grub_snprintf (cmdstring + offset, cmdlen - offset, "%s ",
+ argv.args[i]);
+ }
+ cmdstring[cmdlen - 1] = '\0';
+ grub_verify_string (cmdstring, GRUB_VERIFY_COMMAND);
+ grub_free (cmdstring);
invert = 0;
argc = argv.argc - 1;
args = argv.args + 1;
@@ -1163,4 +1185,3 @@ grub_script_execute (struct grub_script *script)
return grub_script_execute_cmd (script->cmd);
}
-
diff --git a/include/grub/verify.h b/include/grub/verify.h
index acab4f437..517d386d0 100644
--- a/include/grub/verify.h
+++ b/include/grub/verify.h
@@ -11,6 +11,7 @@ enum grub_verify_string_type
{
GRUB_VERIFY_KERNEL_CMDLINE,
GRUB_VERIFY_MODULE_CMDLINE,
+ GRUB_VERIFY_COMMAND,
};
struct grub_file_verifier
--
2.13.2.725.g09c95d1e9-goog
^ permalink raw reply related [flat|nested] 17+ messages in thread
* [PATCH 2/2] Core TPM support
2017-07-05 21:19 Add TPM measured boot support Matthew Garrett
2017-07-05 21:19 ` [PATCH 1/2] Verify commands executed by grub Matthew Garrett
@ 2017-07-05 21:19 ` Matthew Garrett
2017-07-21 14:27 ` Javier Martinez Canillas
2017-07-24 11:16 ` Michael Chang
2017-07-20 22:41 ` Add TPM measured boot support Matthew Garrett
2 siblings, 2 replies; 17+ messages in thread
From: Matthew Garrett @ 2017-07-05 21:19 UTC (permalink / raw)
To: grub-devel; +Cc: Matthew Garrett
Add support for performing basic TPM measurements. Right now this only
supports extending PCRs statically and only on UEFI.
---
grub-core/Makefile.core.def | 7 +
grub-core/commands/efi/tpm.c | 282 +++++++++++++++++++++++++++++++++++++++++
grub-core/commands/tpm.c | 87 +++++++++++++
grub-core/kern/i386/efi/init.c | 1 +
include/grub/efi/tpm.h | 153 ++++++++++++++++++++++
include/grub/tpm.h | 74 +++++++++++
6 files changed, 604 insertions(+)
create mode 100644 grub-core/commands/efi/tpm.c
create mode 100644 grub-core/commands/tpm.c
create mode 100644 include/grub/efi/tpm.h
create mode 100644 include/grub/tpm.h
diff --git a/grub-core/Makefile.core.def b/grub-core/Makefile.core.def
index 16c4d0ea5..ca1caa1fe 100644
--- a/grub-core/Makefile.core.def
+++ b/grub-core/Makefile.core.def
@@ -2375,6 +2375,13 @@ module = {
common = commands/testspeed.c;
};
+module = {
+ name = tpm;
+ common = commands/tpm.c;
+ efi = commands/efi/tpm.c;
+ enable = efi;
+};
+
module = {
name = tr;
common = commands/tr.c;
diff --git a/grub-core/commands/efi/tpm.c b/grub-core/commands/efi/tpm.c
new file mode 100644
index 000000000..c9fb3c133
--- /dev/null
+++ b/grub-core/commands/efi/tpm.c
@@ -0,0 +1,282 @@
+#include <grub/err.h>
+#include <grub/i18n.h>
+#include <grub/efi/api.h>
+#include <grub/efi/efi.h>
+#include <grub/efi/tpm.h>
+#include <grub/mm.h>
+#include <grub/tpm.h>
+#include <grub/term.h>
+
+static grub_efi_guid_t tpm_guid = EFI_TPM_GUID;
+static grub_efi_guid_t tpm2_guid = EFI_TPM2_GUID;
+
+static grub_efi_boolean_t grub_tpm_present(grub_efi_tpm_protocol_t *tpm)
+{
+ grub_efi_status_t status;
+ TCG_EFI_BOOT_SERVICE_CAPABILITY caps;
+ grub_uint32_t flags;
+ grub_efi_physical_address_t eventlog, lastevent;
+
+ caps.Size = (grub_uint8_t)sizeof(caps);
+
+ status = efi_call_5(tpm->status_check, tpm, &caps, &flags, &eventlog,
+ &lastevent);
+
+ if (status != GRUB_EFI_SUCCESS || caps.TPMDeactivatedFlag
+ || !caps.TPMPresentFlag)
+ return 0;
+
+ return 1;
+}
+
+static grub_efi_boolean_t grub_tpm2_present(grub_efi_tpm2_protocol_t *tpm)
+{
+ grub_efi_status_t status;
+ EFI_TCG2_BOOT_SERVICE_CAPABILITY caps;
+
+ caps.Size = (grub_uint8_t)sizeof(caps);
+
+ status = efi_call_2(tpm->get_capability, tpm, &caps);
+
+ if (status != GRUB_EFI_SUCCESS || !caps.TPMPresentFlag)
+ return 0;
+
+ return 1;
+}
+
+static grub_efi_boolean_t grub_tpm_handle_find(grub_efi_handle_t *tpm_handle,
+ grub_efi_uint8_t *protocol_version)
+{
+ grub_efi_handle_t *handles;
+ grub_efi_uintn_t num_handles;
+
+ handles = grub_efi_locate_handle (GRUB_EFI_BY_PROTOCOL, &tpm_guid, NULL,
+ &num_handles);
+ if (handles && num_handles > 0) {
+ *tpm_handle = handles[0];
+ *protocol_version = 1;
+ return 1;
+ }
+
+ handles = grub_efi_locate_handle (GRUB_EFI_BY_PROTOCOL, &tpm2_guid, NULL,
+ &num_handles);
+ if (handles && num_handles > 0) {
+ *tpm_handle = handles[0];
+ *protocol_version = 2;
+ return 1;
+ }
+
+ return 0;
+}
+
+static grub_err_t
+grub_tpm1_execute(grub_efi_handle_t tpm_handle,
+ PassThroughToTPM_InputParamBlock *inbuf,
+ PassThroughToTPM_OutputParamBlock *outbuf)
+{
+ grub_efi_status_t status;
+ grub_efi_tpm_protocol_t *tpm;
+ grub_uint32_t inhdrsize = sizeof(*inbuf) - sizeof(inbuf->TPMOperandIn);
+ grub_uint32_t outhdrsize = sizeof(*outbuf) - sizeof(outbuf->TPMOperandOut);
+
+ tpm = grub_efi_open_protocol (tpm_handle, &tpm_guid,
+ GRUB_EFI_OPEN_PROTOCOL_GET_PROTOCOL);
+
+ if (!grub_tpm_present(tpm))
+ return 0;
+
+ /* UEFI TPM protocol takes the raw operand block, no param block header */
+ status = efi_call_5 (tpm->pass_through_to_tpm, tpm,
+ inbuf->IPBLength - inhdrsize, inbuf->TPMOperandIn,
+ outbuf->OPBLength - outhdrsize, outbuf->TPMOperandOut);
+
+ switch (status) {
+ case GRUB_EFI_SUCCESS:
+ return 0;
+ case GRUB_EFI_DEVICE_ERROR:
+ return grub_error (GRUB_ERR_IO, N_("Command failed"));
+ case GRUB_EFI_INVALID_PARAMETER:
+ return grub_error (GRUB_ERR_BAD_ARGUMENT, N_("Invalid parameter"));
+ case GRUB_EFI_BUFFER_TOO_SMALL:
+ return grub_error (GRUB_ERR_BAD_ARGUMENT, N_("Output buffer too small"));
+ case GRUB_EFI_NOT_FOUND:
+ return grub_error (GRUB_ERR_UNKNOWN_DEVICE, N_("TPM unavailable"));
+ default:
+ return grub_error (GRUB_ERR_UNKNOWN_DEVICE, N_("Unknown TPM error"));
+ }
+}
+
+static grub_err_t
+grub_tpm2_execute(grub_efi_handle_t tpm_handle,
+ PassThroughToTPM_InputParamBlock *inbuf,
+ PassThroughToTPM_OutputParamBlock *outbuf)
+{
+ grub_efi_status_t status;
+ grub_efi_tpm2_protocol_t *tpm;
+ grub_uint32_t inhdrsize = sizeof(*inbuf) - sizeof(inbuf->TPMOperandIn);
+ grub_uint32_t outhdrsize = sizeof(*outbuf) - sizeof(outbuf->TPMOperandOut);
+
+ tpm = grub_efi_open_protocol (tpm_handle, &tpm2_guid,
+ GRUB_EFI_OPEN_PROTOCOL_GET_PROTOCOL);
+
+ if (!grub_tpm2_present(tpm))
+ return 0;
+
+ /* UEFI TPM protocol takes the raw operand block, no param block header */
+ status = efi_call_5 (tpm->submit_command, tpm,
+ inbuf->IPBLength - inhdrsize, inbuf->TPMOperandIn,
+ outbuf->OPBLength - outhdrsize, outbuf->TPMOperandOut);
+
+ switch (status) {
+ case GRUB_EFI_SUCCESS:
+ return 0;
+ case GRUB_EFI_DEVICE_ERROR:
+ return grub_error (GRUB_ERR_IO, N_("Command failed"));
+ case GRUB_EFI_INVALID_PARAMETER:
+ return grub_error (GRUB_ERR_BAD_ARGUMENT, N_("Invalid parameter"));
+ case GRUB_EFI_BUFFER_TOO_SMALL:
+ return grub_error (GRUB_ERR_BAD_ARGUMENT, N_("Output buffer too small"));
+ case GRUB_EFI_NOT_FOUND:
+ return grub_error (GRUB_ERR_UNKNOWN_DEVICE, N_("TPM unavailable"));
+ default:
+ return grub_error (GRUB_ERR_UNKNOWN_DEVICE, N_("Unknown TPM error"));
+ }
+}
+
+grub_err_t
+grub_tpm_execute(PassThroughToTPM_InputParamBlock *inbuf,
+ PassThroughToTPM_OutputParamBlock *outbuf)
+{
+ grub_efi_handle_t tpm_handle;
+ grub_uint8_t protocol_version;
+
+ /* It's not a hard failure for there to be no TPM */
+ if (!grub_tpm_handle_find(&tpm_handle, &protocol_version))
+ return 0;
+
+ if (protocol_version == 1) {
+ return grub_tpm1_execute(tpm_handle, inbuf, outbuf);
+ } else {
+ return grub_tpm2_execute(tpm_handle, inbuf, outbuf);
+ }
+}
+
+typedef struct {
+ grub_uint32_t pcrindex;
+ grub_uint32_t eventtype;
+ grub_uint8_t digest[20];
+ grub_uint32_t eventsize;
+ grub_uint8_t event[1];
+} Event;
+
+
+static grub_err_t
+grub_tpm1_log_event(grub_efi_handle_t tpm_handle, unsigned char *buf,
+ grub_size_t size, grub_uint8_t pcr,
+ const char *description)
+{
+ Event *event;
+ grub_efi_status_t status;
+ grub_efi_tpm_protocol_t *tpm;
+ grub_efi_physical_address_t lastevent;
+ grub_uint32_t algorithm;
+ grub_uint32_t eventnum = 0;
+
+ tpm = grub_efi_open_protocol (tpm_handle, &tpm_guid,
+ GRUB_EFI_OPEN_PROTOCOL_GET_PROTOCOL);
+
+ if (!grub_tpm_present(tpm))
+ return 0;
+
+ event = grub_zalloc(sizeof (Event) + grub_strlen(description) + 1);
+ if (!event)
+ return grub_error (GRUB_ERR_OUT_OF_MEMORY,
+ N_("cannot allocate TPM event buffer"));
+
+ event->pcrindex = pcr;
+ event->eventtype = EV_IPL;
+ event->eventsize = grub_strlen(description) + 1;
+ grub_memcpy(event->event, description, event->eventsize);
+
+ algorithm = TCG_ALG_SHA;
+ status = efi_call_7 (tpm->log_extend_event, tpm, buf, (grub_uint64_t) size,
+ algorithm, event, &eventnum, &lastevent);
+
+ switch (status) {
+ case GRUB_EFI_SUCCESS:
+ return 0;
+ case GRUB_EFI_DEVICE_ERROR:
+ return grub_error (GRUB_ERR_IO, N_("Command failed"));
+ case GRUB_EFI_INVALID_PARAMETER:
+ return grub_error (GRUB_ERR_BAD_ARGUMENT, N_("Invalid parameter"));
+ case GRUB_EFI_BUFFER_TOO_SMALL:
+ return grub_error (GRUB_ERR_BAD_ARGUMENT, N_("Output buffer too small"));
+ case GRUB_EFI_NOT_FOUND:
+ return grub_error (GRUB_ERR_UNKNOWN_DEVICE, N_("TPM unavailable"));
+ default:
+ return grub_error (GRUB_ERR_UNKNOWN_DEVICE, N_("Unknown TPM error"));
+ }
+}
+
+static grub_err_t
+grub_tpm2_log_event(grub_efi_handle_t tpm_handle, unsigned char *buf,
+ grub_size_t size, grub_uint8_t pcr,
+ const char *description)
+{
+ EFI_TCG2_EVENT *event;
+ grub_efi_status_t status;
+ grub_efi_tpm2_protocol_t *tpm;
+
+ tpm = grub_efi_open_protocol (tpm_handle, &tpm2_guid,
+ GRUB_EFI_OPEN_PROTOCOL_GET_PROTOCOL);
+
+ if (!grub_tpm2_present(tpm))
+ return 0;
+
+ event = grub_zalloc(sizeof (EFI_TCG2_EVENT) + grub_strlen(description) + 1);
+ if (!event)
+ return grub_error (GRUB_ERR_OUT_OF_MEMORY,
+ N_("cannot allocate TPM event buffer"));
+
+ event->Header.HeaderSize = sizeof(EFI_TCG2_EVENT_HEADER);
+ event->Header.HeaderVersion = 1;
+ event->Header.PCRIndex = pcr;
+ event->Header.EventType = EV_IPL;
+ event->Size = sizeof(*event) - sizeof(event->Event) + grub_strlen(description) + 1;
+ grub_memcpy(event->Event, description, grub_strlen(description) + 1);
+
+ status = efi_call_5 (tpm->hash_log_extend_event, tpm, 0, buf,
+ (grub_uint64_t) size, event);
+
+ switch (status) {
+ case GRUB_EFI_SUCCESS:
+ return 0;
+ case GRUB_EFI_DEVICE_ERROR:
+ return grub_error (GRUB_ERR_IO, N_("Command failed"));
+ case GRUB_EFI_INVALID_PARAMETER:
+ return grub_error (GRUB_ERR_BAD_ARGUMENT, N_("Invalid parameter"));
+ case GRUB_EFI_BUFFER_TOO_SMALL:
+ return grub_error (GRUB_ERR_BAD_ARGUMENT, N_("Output buffer too small"));
+ case GRUB_EFI_NOT_FOUND:
+ return grub_error (GRUB_ERR_UNKNOWN_DEVICE, N_("TPM unavailable"));
+ default:
+ return grub_error (GRUB_ERR_UNKNOWN_DEVICE, N_("Unknown TPM error"));
+ }
+}
+
+grub_err_t
+grub_tpm_log_event(unsigned char *buf, grub_size_t size, grub_uint8_t pcr,
+ const char *description)
+{
+ grub_efi_handle_t tpm_handle;
+ grub_efi_uint8_t protocol_version;
+
+ if (!grub_tpm_handle_find(&tpm_handle, &protocol_version))
+ return 0;
+
+ if (protocol_version == 1) {
+ return grub_tpm1_log_event(tpm_handle, buf, size, pcr, description);
+ } else {
+ return grub_tpm2_log_event(tpm_handle, buf, size, pcr, description);
+ }
+}
diff --git a/grub-core/commands/tpm.c b/grub-core/commands/tpm.c
new file mode 100644
index 000000000..e047b5fe0
--- /dev/null
+++ b/grub-core/commands/tpm.c
@@ -0,0 +1,87 @@
+#include <grub/err.h>
+#include <grub/i18n.h>
+#include <grub/misc.h>
+#include <grub/mm.h>
+#include <grub/tpm.h>
+#include <grub/term.h>
+#include <grub/verify.h>
+#include <grub/dl.h>
+
+GRUB_MOD_LICENSE ("GPLv3+")
+
+grub_err_t
+grub_tpm_measure (unsigned char *buf, grub_size_t size, grub_uint8_t pcr,
+ const char *description)
+{
+ return grub_tpm_log_event (buf, size, pcr, description);
+}
+
+static grub_err_t
+grub_tpm_verify_init (grub_file_t io,
+ enum grub_file_type type __attribute__ ((unused)),
+ void **context, enum grub_verify_flags *flags)
+{
+ *context = io->name;
+ *flags |= GRUB_VERIFY_FLAGS_SINGLE_CHUNK;
+ return GRUB_ERR_NONE;
+}
+
+static grub_err_t
+grub_tpm_verify_write (void *context, void *buf, grub_size_t size)
+{
+ return grub_tpm_measure (buf, size, 9, context);
+}
+
+static void
+grub_tpm_verify_close (void *ctxt __attribute__ ((unused)))
+{
+ return;
+}
+
+static grub_err_t
+grub_tpm_verify_string (char *str, enum grub_verify_string_type type)
+{
+ const char *prefix = NULL;
+ char *description;
+ grub_err_t status;
+
+ switch (type)
+ {
+ case GRUB_VERIFY_KERNEL_CMDLINE:
+ prefix = "kernel_cmdline: ";
+ break;
+ case GRUB_VERIFY_MODULE_CMDLINE:
+ prefix = "module_cmdline: ";
+ break;
+ case GRUB_VERIFY_COMMAND:
+ prefix = "grub_cmd: ";
+ break;
+ }
+ description = grub_malloc(grub_strlen(str) + grub_strlen(prefix) + 1);
+ if (!description)
+ return grub_errno;
+ grub_memcpy(description, prefix, grub_strlen(prefix));
+ grub_memcpy(description + grub_strlen(prefix), str, grub_strlen(str) + 1);
+ status = grub_tpm_measure ((unsigned char *) str, grub_strlen (str), 8,
+ description);
+ grub_free(description);
+ return status;
+}
+
+struct grub_file_verifier grub_tpm_verifier = {
+ .name = "tpm",
+ .init = grub_tpm_verify_init,
+ .write = grub_tpm_verify_write,
+ .close = grub_tpm_verify_close,
+ .verify_string = grub_tpm_verify_string,
+};
+
+GRUB_MOD_INIT(tpm)
+{
+ grub_verifier_register (&grub_tpm_verifier);
+}
+
+GRUB_MOD_FINI(tpm)
+{
+ grub_verifier_unregister (&grub_tpm_verifier);
+}
diff --git a/grub-core/kern/i386/efi/init.c b/grub-core/kern/i386/efi/init.c
index a28316cc6..da499aba0 100644
--- a/grub-core/kern/i386/efi/init.c
+++ b/grub-core/kern/i386/efi/init.c
@@ -27,6 +27,7 @@
#include <grub/efi/efi.h>
#include <grub/i386/tsc.h>
#include <grub/loader.h>
+#include <grub/tpm.h>
void
grub_machine_init (void)
diff --git a/include/grub/efi/tpm.h b/include/grub/efi/tpm.h
new file mode 100644
index 000000000..e2aff4a3c
--- /dev/null
+++ b/include/grub/efi/tpm.h
@@ -0,0 +1,153 @@
+/*
+ * GRUB -- GRand Unified Bootloader
+ * Copyright (C) 2015 Free Software Foundation, Inc.
+ *
+ * GRUB is free software: you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+ * the Free Software Foundation, either version 3 of the License, or
+ * (at your option) any later version.
+ *
+ * GRUB is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License
+ * along with GRUB. If not, see <http://www.gnu.org/licenses/>.
+ */
+
+#ifndef GRUB_EFI_TPM_HEADER
+#define GRUB_EFI_TPM_HEADER 1
+
+#define EFI_TPM_GUID {0xf541796d, 0xa62e, 0x4954, {0xa7, 0x75, 0x95, 0x84, 0xf6, 0x1b, 0x9c, 0xdd }};
+#define EFI_TPM2_GUID {0x607f766c, 0x7455, 0x42be, {0x93, 0x0b, 0xe4, 0xd7, 0x6d, 0xb2, 0x72, 0x0f }};
+
+typedef struct {
+ grub_efi_uint8_t Major;
+ grub_efi_uint8_t Minor;
+ grub_efi_uint8_t RevMajor;
+ grub_efi_uint8_t RevMinor;
+} TCG_VERSION;
+
+typedef struct _TCG_EFI_BOOT_SERVICE_CAPABILITY {
+ grub_efi_uint8_t Size; /// Size of this structure.
+ TCG_VERSION StructureVersion;
+ TCG_VERSION ProtocolSpecVersion;
+ grub_efi_uint8_t HashAlgorithmBitmap; /// Hash algorithms .
+ char TPMPresentFlag; /// 00h = TPM not present.
+ char TPMDeactivatedFlag; /// 01h = TPM currently deactivated.
+} TCG_EFI_BOOT_SERVICE_CAPABILITY;
+
+typedef struct {
+ grub_efi_uint32_t PCRIndex;
+ grub_efi_uint32_t EventType;
+ grub_efi_uint8_t digest[20];
+ grub_efi_uint32_t EventSize;
+ grub_efi_uint8_t Event[1];
+} TCG_PCR_EVENT;
+
+struct grub_efi_tpm_protocol
+{
+ grub_efi_status_t (*status_check) (struct grub_efi_tpm_protocol *this,
+ TCG_EFI_BOOT_SERVICE_CAPABILITY *ProtocolCapability,
+ grub_efi_uint32_t *TCGFeatureFlags,
+ grub_efi_physical_address_t *EventLogLocation,
+ grub_efi_physical_address_t *EventLogLastEntry);
+ grub_efi_status_t (*hash_all) (struct grub_efi_tpm_protocol *this,
+ grub_efi_uint8_t *HashData,
+ grub_efi_uint64_t HashLen,
+ grub_efi_uint32_t AlgorithmId,
+ grub_efi_uint64_t *HashedDataLen,
+ grub_efi_uint8_t **HashedDataResult);
+ grub_efi_status_t (*log_event) (struct grub_efi_tpm_protocol *this,
+ TCG_PCR_EVENT *TCGLogData,
+ grub_efi_uint32_t *EventNumber,
+ grub_efi_uint32_t Flags);
+ grub_efi_status_t (*pass_through_to_tpm) (struct grub_efi_tpm_protocol *this,
+ grub_efi_uint32_t TpmInputParameterBlockSize,
+ grub_efi_uint8_t *TpmInputParameterBlock,
+ grub_efi_uint32_t TpmOutputParameterBlockSize,
+ grub_efi_uint8_t *TpmOutputParameterBlock);
+ grub_efi_status_t (*log_extend_event) (struct grub_efi_tpm_protocol *this,
+ grub_efi_physical_address_t HashData,
+ grub_efi_uint64_t HashDataLen,
+ grub_efi_uint32_t AlgorithmId,
+ TCG_PCR_EVENT *TCGLogData,
+ grub_efi_uint32_t *EventNumber,
+ grub_efi_physical_address_t *EventLogLastEntry);
+};
+
+typedef struct grub_efi_tpm_protocol grub_efi_tpm_protocol_t;
+
+typedef grub_efi_uint32_t EFI_TCG2_EVENT_LOG_BITMAP;
+typedef grub_efi_uint32_t EFI_TCG2_EVENT_LOG_FORMAT;
+typedef grub_efi_uint32_t EFI_TCG2_EVENT_ALGORITHM_BITMAP;
+
+typedef struct tdEFI_TCG2_VERSION {
+ grub_efi_uint8_t Major;
+ grub_efi_uint8_t Minor;
+} GRUB_PACKED EFI_TCG2_VERSION;
+
+typedef struct tdEFI_TCG2_BOOT_SERVICE_CAPABILITY {
+ grub_efi_uint8_t Size;
+ EFI_TCG2_VERSION StructureVersion;
+ EFI_TCG2_VERSION ProtocolVersion;
+ EFI_TCG2_EVENT_ALGORITHM_BITMAP HashAlgorithmBitmap;
+ EFI_TCG2_EVENT_LOG_BITMAP SupportedEventLogs;
+ grub_efi_boolean_t TPMPresentFlag;
+ grub_efi_uint16_t MaxCommandSize;
+ grub_efi_uint16_t MaxResponseSize;
+ grub_efi_uint32_t ManufacturerID;
+ grub_efi_uint32_t NumberOfPcrBanks;
+ EFI_TCG2_EVENT_ALGORITHM_BITMAP ActivePcrBanks;
+} EFI_TCG2_BOOT_SERVICE_CAPABILITY;
+
+typedef grub_efi_uint32_t TCG_PCRINDEX;
+typedef grub_efi_uint32_t TCG_EVENTTYPE;
+
+typedef struct tdEFI_TCG2_EVENT_HEADER {
+ grub_efi_uint32_t HeaderSize;
+ grub_efi_uint16_t HeaderVersion;
+ TCG_PCRINDEX PCRIndex;
+ TCG_EVENTTYPE EventType;
+} GRUB_PACKED EFI_TCG2_EVENT_HEADER;
+
+typedef struct tdEFI_TCG2_EVENT {
+ grub_efi_uint32_t Size;
+ EFI_TCG2_EVENT_HEADER Header;
+ grub_efi_uint8_t Event[1];
+} GRUB_PACKED EFI_TCG2_EVENT;
+
+struct grub_efi_tpm2_protocol
+{
+ grub_efi_status_t (*get_capability) (struct grub_efi_tpm2_protocol *this,
+ EFI_TCG2_BOOT_SERVICE_CAPABILITY *ProtocolCapability);
+ grub_efi_status_t (*get_event_log) (struct grub_efi_tpm2_protocol *this,
+ EFI_TCG2_EVENT_LOG_FORMAT EventLogFormat,
+ grub_efi_physical_address_t *EventLogLocation,
+ grub_efi_physical_address_t *EventLogLastEntry,
+ grub_efi_boolean_t *EventLogTruncated);
+ grub_efi_status_t (*hash_log_extend_event) (struct grub_efi_tpm2_protocol *this,
+ grub_efi_uint64_t Flags,
+ grub_efi_physical_address_t *DataToHash,
+ grub_efi_uint64_t DataToHashLen,
+ EFI_TCG2_EVENT *EfiTcgEvent);
+ grub_efi_status_t (*submit_command) (struct grub_efi_tpm2_protocol *this,
+ grub_efi_uint32_t InputParameterBlockSize,
+ grub_efi_uint8_t *InputParameterBlock,
+ grub_efi_uint32_t OutputParameterBlockSize,
+ grub_efi_uint8_t *OutputParameterBlock);
+ grub_efi_status_t (*get_active_pcr_blanks) (struct grub_efi_tpm2_protocol *this,
+ grub_efi_uint32_t *ActivePcrBanks);
+ grub_efi_status_t (*set_active_pcr_banks) (struct grub_efi_tpm2_protocol *this,
+ grub_efi_uint32_t ActivePcrBanks);
+ grub_efi_status_t (*get_result_of_set_active_pcr_banks) (struct grub_efi_tpm2_protocol *this,
+ grub_efi_uint32_t *OperationPresent,
+ grub_efi_uint32_t *Response);
+};
+
+typedef struct grub_efi_tpm2_protocol grub_efi_tpm2_protocol_t;
+
+#define TCG_ALG_SHA 0x00000004
+
+#endif
diff --git a/include/grub/tpm.h b/include/grub/tpm.h
new file mode 100644
index 000000000..d6757b57b
--- /dev/null
+++ b/include/grub/tpm.h
@@ -0,0 +1,74 @@
+/*
+ * GRUB -- GRand Unified Bootloader
+ * Copyright (C) 2015 Free Software Foundation, Inc.
+ *
+ * GRUB is free software: you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+ * the Free Software Foundation, either version 3 of the License, or
+ * (at your option) any later version.
+ *
+ * GRUB is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License
+ * along with GRUB. If not, see <http://www.gnu.org/licenses/>.
+ */
+
+#ifndef GRUB_TPM_HEADER
+#define GRUB_TPM_HEADER 1
+
+#define SHA1_DIGEST_SIZE 20
+
+#define TPM_BASE 0x0
+#define TPM_SUCCESS TPM_BASE
+#define TPM_AUTHFAIL (TPM_BASE + 0x1)
+#define TPM_BADINDEX (TPM_BASE + 0x2)
+
+#define TPM_TAG_RQU_COMMAND 0x00C1
+#define TPM_ORD_Extend 0x14
+
+#define EV_IPL 0x0d
+
+/* TCG_PassThroughToTPM Input Parameter Block */
+typedef struct {
+ grub_uint16_t IPBLength;
+ grub_uint16_t Reserved1;
+ grub_uint16_t OPBLength;
+ grub_uint16_t Reserved2;
+ grub_uint8_t TPMOperandIn[1];
+} GRUB_PACKED PassThroughToTPM_InputParamBlock;
+
+/* TCG_PassThroughToTPM Output Parameter Block */
+typedef struct {
+ grub_uint16_t OPBLength;
+ grub_uint16_t Reserved;
+ grub_uint8_t TPMOperandOut[1];
+} GRUB_PACKED PassThroughToTPM_OutputParamBlock;
+
+typedef struct {
+ grub_uint16_t tag;
+ grub_uint32_t paramSize;
+ grub_uint32_t ordinal;
+ grub_uint32_t pcrNum;
+ grub_uint8_t inDigest[SHA1_DIGEST_SIZE]; /* The 160 bit value representing the event to be recorded. */
+} GRUB_PACKED ExtendIncoming;
+
+/* TPM_Extend Outgoing Operand */
+typedef struct {
+ grub_uint16_t tag;
+ grub_uint32_t paramSize;
+ grub_uint32_t returnCode;
+ grub_uint8_t outDigest[SHA1_DIGEST_SIZE]; /* The PCR value after execution of the command. */
+} GRUB_PACKED ExtendOutgoing;
+
+grub_err_t grub_tpm_measure (unsigned char *buf, grub_size_t size,
+ grub_uint8_t pcr,
+ const char *description);
+grub_err_t grub_tpm_init(void);
+grub_err_t grub_tpm_execute(PassThroughToTPM_InputParamBlock *inbuf,
+ PassThroughToTPM_OutputParamBlock *outbuf);
+grub_err_t grub_tpm_log_event(unsigned char *buf, grub_size_t size,
+ grub_uint8_t pcr, const char *description);
+#endif
--
2.13.2.725.g09c95d1e9-goog
^ permalink raw reply related [flat|nested] 17+ messages in thread
* Re: Add TPM measured boot support
2017-07-05 21:19 Add TPM measured boot support Matthew Garrett
2017-07-05 21:19 ` [PATCH 1/2] Verify commands executed by grub Matthew Garrett
2017-07-05 21:19 ` [PATCH 2/2] Core TPM support Matthew Garrett
@ 2017-07-20 22:41 ` Matthew Garrett
2017-07-21 14:22 ` Javier Martinez Canillas
2017-07-21 14:32 ` Daniel Kiper
2 siblings, 2 replies; 17+ messages in thread
From: Matthew Garrett @ 2017-07-20 22:41 UTC (permalink / raw)
To: The development of GNU GRUB
On Wed, Jul 05, 2017 at 02:19:55PM -0700, Matthew Garrett wrote:
> This patchset extends the verifier framework to support verifying commands
> executed by Grub, and makes use of this to add support for measuring files
> and commands executed by grub into the TPM on UEFI-based systems.
Any feedback on this? Vladimir, are you planning on merging your
verifier branch?
--
Matthew Garrett | mjg59@srcf.ucam.org
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: Add TPM measured boot support
2017-07-20 22:41 ` Add TPM measured boot support Matthew Garrett
@ 2017-07-21 14:22 ` Javier Martinez Canillas
2017-07-21 14:32 ` Daniel Kiper
1 sibling, 0 replies; 17+ messages in thread
From: Javier Martinez Canillas @ 2017-07-21 14:22 UTC (permalink / raw)
To: The development of GNU GRUB, Matthew Garrett
Hello Matthew,
On 07/21/2017 12:41 AM, Matthew Garrett wrote:
> On Wed, Jul 05, 2017 at 02:19:55PM -0700, Matthew Garrett wrote:
>> This patchset extends the verifier framework to support verifying commands
>> executed by Grub, and makes use of this to add support for measuring files
>> and commands executed by grub into the TPM on UEFI-based systems.
>
> Any feedback on this? Vladimir, are you planning on merging your
> verifier branch?
>
I've given a try to this new version of your patches and it worked correctly:
$ tpm2_listpcrs -L 0x4:8,9
Bank/Algorithm: TPM_ALG_SHA1(0x0004)
PCR_08: fb 91 4b bb 62 48 00 7f 5f 32 d0 58 24 23 92 a6 a8 39 7a c4
PCR_09: 78 cc c7 b8 4c 95 dc 21 8e bd a2 07 d9 94 0a 4c 95 e6 44 d2
Without your patches:
$ tpm2_listpcrs -L 0x4:8,9
PCR_08: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_09: aa 40 46 af 96 b1 62 d0 8e 9c 10 b2 1a 2f a8 5e ac 84 cd e4
I've also tested changing the linux image, modifying the kernel command line
parameters, inserting other grub modules and changing the grub commands. In
all cases I see that the PCR hashes changed.
Best regards,
--
Javier Martinez Canillas
Software Engineer - Desktop Hardware Enablement
Red Hat
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH 1/2] Verify commands executed by grub
2017-07-05 21:19 ` [PATCH 1/2] Verify commands executed by grub Matthew Garrett
@ 2017-07-21 14:23 ` Javier Martinez Canillas
2017-07-21 14:39 ` Vladimir 'phcoder' Serbinenko
1 sibling, 0 replies; 17+ messages in thread
From: Javier Martinez Canillas @ 2017-07-21 14:23 UTC (permalink / raw)
To: The development of GNU GRUB, Matthew Garrett
On 07/05/2017 11:19 PM, Matthew Garrett wrote:
> Pass commands to the verification code. We want to be able to log these
> in the TPM verification case.
> ---
> grub-core/script/execute.c | 27 ++++++++++++++++++++++++---
> include/grub/verify.h | 1 +
> 2 files changed, 25 insertions(+), 3 deletions(-)
>
Reviewed-by: Javier Martinez Canillas <javierm@redhat.com>
Tested-by: Javier Martinez Canillas <javierm@redhat.com>
Best regards,
--
Javier Martinez Canillas
Software Engineer - Desktop Hardware Enablement
Red Hat
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH 2/2] Core TPM support
2017-07-05 21:19 ` [PATCH 2/2] Core TPM support Matthew Garrett
@ 2017-07-21 14:27 ` Javier Martinez Canillas
2017-07-24 11:16 ` Michael Chang
1 sibling, 0 replies; 17+ messages in thread
From: Javier Martinez Canillas @ 2017-07-21 14:27 UTC (permalink / raw)
To: The development of GNU GRUB, Matthew Garrett
On 07/05/2017 11:19 PM, Matthew Garrett wrote:
> Add support for performing basic TPM measurements. Right now this only
> supports extending PCRs statically and only on UEFI.
> ---
[snip]
> +grub_err_t grub_tpm_init(void);
You forgot to remove this function prototype, since the function doesn't exist
anymore in this new version. The rest looks good to me.
Reviewed-by: Javier Martinez Canillas <javierm@redhat.com>
Tested-by: Javier Martinez Canillas <javierm@redhat.com>
Best regards,
--
Javier Martinez Canillas
Software Engineer - Desktop Hardware Enablement
Red Hat
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: Add TPM measured boot support
2017-07-20 22:41 ` Add TPM measured boot support Matthew Garrett
2017-07-21 14:22 ` Javier Martinez Canillas
@ 2017-07-21 14:32 ` Daniel Kiper
2018-01-19 9:32 ` Javier Martinez Canillas
1 sibling, 1 reply; 17+ messages in thread
From: Daniel Kiper @ 2017-07-21 14:32 UTC (permalink / raw)
To: grub-devel, mjg59; +Cc: keng-yu.lin, leif.lindholm
On Thu, Jul 20, 2017 at 11:41:11PM +0100, Matthew Garrett wrote:
> On Wed, Jul 05, 2017 at 02:19:55PM -0700, Matthew Garrett wrote:
> > This patchset extends the verifier framework to support verifying commands
> > executed by Grub, and makes use of this to add support for measuring files
> > and commands executed by grub into the TPM on UEFI-based systems.
>
> Any feedback on this? Vladimir, are you planning on merging your
Will take a look next week (well, I was going to do some review this
week but still recovering after Xen conference). Sorry for delays.
> verifier branch?
Yes, we are going to merge this. Though we are still discussing some details.
Please be patient...
Daniel
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH 1/2] Verify commands executed by grub
2017-07-05 21:19 ` [PATCH 1/2] Verify commands executed by grub Matthew Garrett
2017-07-21 14:23 ` Javier Martinez Canillas
@ 2017-07-21 14:39 ` Vladimir 'phcoder' Serbinenko
2017-07-21 22:13 ` Matthew Garrett
1 sibling, 1 reply; 17+ messages in thread
From: Vladimir 'phcoder' Serbinenko @ 2017-07-21 14:39 UTC (permalink / raw)
To: The development of GNU GRUB; +Cc: Matthew Garrett
[-- Attachment #1: Type: text/plain, Size: 2896 bytes --]
On Wed, Jul 5, 2017, 23:26 Matthew Garrett <mjg59@google.com> wrote:
> Pass commands to the verification code. We want to be able to log these
> in the TPM verification case.
> ---
> grub-core/script/execute.c | 27 ++++++++++++++++++++++++---
> include/grub/verify.h | 1 +
> 2 files changed, 25 insertions(+), 3 deletions(-)
>
> diff --git a/grub-core/script/execute.c b/grub-core/script/execute.c
> index a8502d907..ee299fd0e 100644
> --- a/grub-core/script/execute.c
> +++ b/grub-core/script/execute.c
> @@ -27,6 +27,7 @@
> #include <grub/normal.h>
> #include <grub/extcmd.h>
> #include <grub/i18n.h>
> +#include <grub/verify.h>
>
> /* Max digits for a char is 3 (0xFF is 255), similarly for an int it
> is sizeof (int) * 3, and one extra for a possible -ve sign. */
> @@ -929,8 +930,9 @@ grub_script_execute_cmdline (struct grub_script_cmd
> *cmd)
> grub_err_t ret = 0;
> grub_script_function_t func = 0;
> char errnobuf[18];
> - char *cmdname;
> - int argc;
> + char *cmdname, *cmdstring;
> + int argc, offset = 0, cmdlen = 0;
> + unsigned int i;
> char **args;
> int invert;
> struct grub_script_argv argv = { 0, 0, 0 };
> @@ -939,6 +941,26 @@ grub_script_execute_cmdline (struct grub_script_cmd
> *cmd)
> if (grub_script_arglist_to_argv (cmdline->arglist, &argv) || !
> argv.args[0])
> return grub_errno;
>
> + for (i = 0; i < argv.argc; i++)
> + {
> + cmdlen += grub_strlen (argv.args[i]) + 1;
> + }
> +
> + cmdstring = grub_malloc (cmdlen);
> + if (!cmdstring)
> + {
> + return grub_error (GRUB_ERR_OUT_OF_MEMORY,
> + N_("cannot allocate command buffer"));
> + }
> +
> + for (i = 0; i < argv.argc; i++)
> + {
> + offset += grub_snprintf (cmdstring + offset, cmdlen - offset, "%s ",
> + argv.args[i]);
> + }
>
This omits all separators. So it considers e.g. ab and a b to be the same.
Can we have a better array serialization? I.a. following 3 need to be
distinguished:
ab
a b
"a b"
> + cmdstring[cmdlen - 1] = '\0';
> + grub_verify_string (cmdstring, GRUB_VERIFY_COMMAND);
> + grub_free (cmdstring);
> invert = 0;
> argc = argv.argc - 1;
> args = argv.args + 1;
> @@ -1163,4 +1185,3 @@ grub_script_execute (struct grub_script *script)
>
> return grub_script_execute_cmd (script->cmd);
> }
> -
> diff --git a/include/grub/verify.h b/include/grub/verify.h
> index acab4f437..517d386d0 100644
> --- a/include/grub/verify.h
> +++ b/include/grub/verify.h
> @@ -11,6 +11,7 @@ enum grub_verify_string_type
> {
> GRUB_VERIFY_KERNEL_CMDLINE,
> GRUB_VERIFY_MODULE_CMDLINE,
> + GRUB_VERIFY_COMMAND,
> };
>
> struct grub_file_verifier
> --
> 2.13.2.725.g09c95d1e9-goog
>
>
> _______________________________________________
> Grub-devel mailing list
> Grub-devel@gnu.org
> https://lists.gnu.org/mailman/listinfo/grub-devel
>
[-- Attachment #2: Type: text/html, Size: 3894 bytes --]
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH 1/2] Verify commands executed by grub
2017-07-21 14:39 ` Vladimir 'phcoder' Serbinenko
@ 2017-07-21 22:13 ` Matthew Garrett
2017-07-24 11:19 ` Vladimir 'phcoder' Serbinenko
0 siblings, 1 reply; 17+ messages in thread
From: Matthew Garrett @ 2017-07-21 22:13 UTC (permalink / raw)
To: Vladimir 'phcoder' Serbinenko; +Cc: The development of GNU GRUB
On Fri, Jul 21, 2017 at 7:39 AM, Vladimir 'phcoder' Serbinenko
<phcoder@gmail.com> wrote:
> This omits all separators. So it considers e.g. ab and a b to be the same.
> Can we have a better array serialization? I.a. following 3 need to be
> distinguished:
> ab
> a b
> "a b"
It inserts a space after each argv, so I think ab and a b are already
distinguishable in the output? "a b" isn't, however, and that's
certainly a problem. I can see a few approaches to this:
1) Delimit with \0. That makes parsing the result more annoying, but
avoids any ambiguity.
2) Add quotes back in for any arguments that contain spaces
3) Do the verification before any parsing. Downside is that we don't
get any variable expansion, which doesn't really matter for the TPM
case but might not work for other use cases?
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH 2/2] Core TPM support
2017-07-05 21:19 ` [PATCH 2/2] Core TPM support Matthew Garrett
2017-07-21 14:27 ` Javier Martinez Canillas
@ 2017-07-24 11:16 ` Michael Chang
2017-07-24 11:24 ` Matthew Garrett
1 sibling, 1 reply; 17+ messages in thread
From: Michael Chang @ 2017-07-24 11:16 UTC (permalink / raw)
To: The development of GNU GRUB; +Cc: Matthew Garrett
On Wed, Jul 05, 2017 at 02:19:57PM -0700, Matthew Garrett wrote:
> Add support for performing basic TPM measurements. Right now this only
> supports extending PCRs statically and only on UEFI.
> ---
> grub-core/Makefile.core.def | 7 +
> grub-core/commands/efi/tpm.c | 282 +++++++++++++++++++++++++++++++++++++++++
> grub-core/commands/tpm.c | 87 +++++++++++++
> grub-core/kern/i386/efi/init.c | 1 +
> include/grub/efi/tpm.h | 153 ++++++++++++++++++++++
> include/grub/tpm.h | 74 +++++++++++
> 6 files changed, 604 insertions(+)
> create mode 100644 grub-core/commands/efi/tpm.c
> create mode 100644 grub-core/commands/tpm.c
> create mode 100644 include/grub/efi/tpm.h
> create mode 100644 include/grub/tpm.h
>
> diff --git a/grub-core/Makefile.core.def b/grub-core/Makefile.core.def
> index 16c4d0ea5..ca1caa1fe 100644
> --- a/grub-core/Makefile.core.def
> +++ b/grub-core/Makefile.core.def
> @@ -2375,6 +2375,13 @@ module = {
> common = commands/testspeed.c;
> };
>
> +module = {
> + name = tpm;
> + common = commands/tpm.c;
> + efi = commands/efi/tpm.c;
> + enable = efi;
> +};
> +
> module = {
> name = tr;
> common = commands/tr.c;
> diff --git a/grub-core/commands/efi/tpm.c b/grub-core/commands/efi/tpm.c
> new file mode 100644
> index 000000000..c9fb3c133
> --- /dev/null
> +++ b/grub-core/commands/efi/tpm.c
> @@ -0,0 +1,282 @@
> +#include <grub/err.h>
> +#include <grub/i18n.h>
> +#include <grub/efi/api.h>
> +#include <grub/efi/efi.h>
> +#include <grub/efi/tpm.h>
> +#include <grub/mm.h>
> +#include <grub/tpm.h>
> +#include <grub/term.h>
> +
> +static grub_efi_guid_t tpm_guid = EFI_TPM_GUID;
> +static grub_efi_guid_t tpm2_guid = EFI_TPM2_GUID;
> +
> +static grub_efi_boolean_t grub_tpm_present(grub_efi_tpm_protocol_t *tpm)
> +{
> + grub_efi_status_t status;
> + TCG_EFI_BOOT_SERVICE_CAPABILITY caps;
> + grub_uint32_t flags;
> + grub_efi_physical_address_t eventlog, lastevent;
> +
> + caps.Size = (grub_uint8_t)sizeof(caps);
> +
> + status = efi_call_5(tpm->status_check, tpm, &caps, &flags, &eventlog,
> + &lastevent);
> +
> + if (status != GRUB_EFI_SUCCESS || caps.TPMDeactivatedFlag
> + || !caps.TPMPresentFlag)
> + return 0;
> +
> + return 1;
> +}
> +
> +static grub_efi_boolean_t grub_tpm2_present(grub_efi_tpm2_protocol_t *tpm)
> +{
> + grub_efi_status_t status;
> + EFI_TCG2_BOOT_SERVICE_CAPABILITY caps;
> +
> + caps.Size = (grub_uint8_t)sizeof(caps);
> +
> + status = efi_call_2(tpm->get_capability, tpm, &caps);
> +
> + if (status != GRUB_EFI_SUCCESS || !caps.TPMPresentFlag)
> + return 0;
> +
> + return 1;
> +}
> +
> +static grub_efi_boolean_t grub_tpm_handle_find(grub_efi_handle_t *tpm_handle,
> + grub_efi_uint8_t *protocol_version)
> +{
> + grub_efi_handle_t *handles;
> + grub_efi_uintn_t num_handles;
> +
> + handles = grub_efi_locate_handle (GRUB_EFI_BY_PROTOCOL, &tpm_guid, NULL,
> + &num_handles);
> + if (handles && num_handles > 0) {
> + *tpm_handle = handles[0];
> + *protocol_version = 1;
> + return 1;
> + }
> +
> + handles = grub_efi_locate_handle (GRUB_EFI_BY_PROTOCOL, &tpm2_guid, NULL,
> + &num_handles);
> + if (handles && num_handles > 0) {
> + *tpm_handle = handles[0];
> + *protocol_version = 2;
> + return 1;
> + }
> +
> + return 0;
> +}
> +
> +static grub_err_t
> +grub_tpm1_execute(grub_efi_handle_t tpm_handle,
> + PassThroughToTPM_InputParamBlock *inbuf,
> + PassThroughToTPM_OutputParamBlock *outbuf)
> +{
> + grub_efi_status_t status;
> + grub_efi_tpm_protocol_t *tpm;
> + grub_uint32_t inhdrsize = sizeof(*inbuf) - sizeof(inbuf->TPMOperandIn);
> + grub_uint32_t outhdrsize = sizeof(*outbuf) - sizeof(outbuf->TPMOperandOut);
> +
> + tpm = grub_efi_open_protocol (tpm_handle, &tpm_guid,
> + GRUB_EFI_OPEN_PROTOCOL_GET_PROTOCOL);
> +
> + if (!grub_tpm_present(tpm))
> + return 0;
> +
> + /* UEFI TPM protocol takes the raw operand block, no param block header */
> + status = efi_call_5 (tpm->pass_through_to_tpm, tpm,
> + inbuf->IPBLength - inhdrsize, inbuf->TPMOperandIn,
> + outbuf->OPBLength - outhdrsize, outbuf->TPMOperandOut);
> +
> + switch (status) {
> + case GRUB_EFI_SUCCESS:
> + return 0;
> + case GRUB_EFI_DEVICE_ERROR:
> + return grub_error (GRUB_ERR_IO, N_("Command failed"));
> + case GRUB_EFI_INVALID_PARAMETER:
> + return grub_error (GRUB_ERR_BAD_ARGUMENT, N_("Invalid parameter"));
> + case GRUB_EFI_BUFFER_TOO_SMALL:
> + return grub_error (GRUB_ERR_BAD_ARGUMENT, N_("Output buffer too small"));
> + case GRUB_EFI_NOT_FOUND:
> + return grub_error (GRUB_ERR_UNKNOWN_DEVICE, N_("TPM unavailable"));
> + default:
> + return grub_error (GRUB_ERR_UNKNOWN_DEVICE, N_("Unknown TPM error"));
> + }
> +}
> +
> +static grub_err_t
> +grub_tpm2_execute(grub_efi_handle_t tpm_handle,
> + PassThroughToTPM_InputParamBlock *inbuf,
> + PassThroughToTPM_OutputParamBlock *outbuf)
> +{
> + grub_efi_status_t status;
> + grub_efi_tpm2_protocol_t *tpm;
> + grub_uint32_t inhdrsize = sizeof(*inbuf) - sizeof(inbuf->TPMOperandIn);
> + grub_uint32_t outhdrsize = sizeof(*outbuf) - sizeof(outbuf->TPMOperandOut);
> +
> + tpm = grub_efi_open_protocol (tpm_handle, &tpm2_guid,
> + GRUB_EFI_OPEN_PROTOCOL_GET_PROTOCOL);
> +
> + if (!grub_tpm2_present(tpm))
> + return 0;
> +
> + /* UEFI TPM protocol takes the raw operand block, no param block header */
> + status = efi_call_5 (tpm->submit_command, tpm,
> + inbuf->IPBLength - inhdrsize, inbuf->TPMOperandIn,
> + outbuf->OPBLength - outhdrsize, outbuf->TPMOperandOut);
> +
> + switch (status) {
> + case GRUB_EFI_SUCCESS:
> + return 0;
> + case GRUB_EFI_DEVICE_ERROR:
> + return grub_error (GRUB_ERR_IO, N_("Command failed"));
> + case GRUB_EFI_INVALID_PARAMETER:
> + return grub_error (GRUB_ERR_BAD_ARGUMENT, N_("Invalid parameter"));
> + case GRUB_EFI_BUFFER_TOO_SMALL:
> + return grub_error (GRUB_ERR_BAD_ARGUMENT, N_("Output buffer too small"));
> + case GRUB_EFI_NOT_FOUND:
> + return grub_error (GRUB_ERR_UNKNOWN_DEVICE, N_("TPM unavailable"));
> + default:
> + return grub_error (GRUB_ERR_UNKNOWN_DEVICE, N_("Unknown TPM error"));
> + }
> +}
> +
> +grub_err_t
> +grub_tpm_execute(PassThroughToTPM_InputParamBlock *inbuf,
> + PassThroughToTPM_OutputParamBlock *outbuf)
> +{
> + grub_efi_handle_t tpm_handle;
> + grub_uint8_t protocol_version;
> +
> + /* It's not a hard failure for there to be no TPM */
> + if (!grub_tpm_handle_find(&tpm_handle, &protocol_version))
> + return 0;
> +
> + if (protocol_version == 1) {
> + return grub_tpm1_execute(tpm_handle, inbuf, outbuf);
> + } else {
> + return grub_tpm2_execute(tpm_handle, inbuf, outbuf);
> + }
> +}
> +
> +typedef struct {
> + grub_uint32_t pcrindex;
> + grub_uint32_t eventtype;
> + grub_uint8_t digest[20];
> + grub_uint32_t eventsize;
> + grub_uint8_t event[1];
> +} Event;
The struct is the same with TCG_PCR_EVENT defined in efi/tpm.h, what's the
point to locally redefine here ?
> +
> +
> +static grub_err_t
> +grub_tpm1_log_event(grub_efi_handle_t tpm_handle, unsigned char *buf,
> + grub_size_t size, grub_uint8_t pcr,
> + const char *description)
> +{
> + Event *event;
> + grub_efi_status_t status;
> + grub_efi_tpm_protocol_t *tpm;
> + grub_efi_physical_address_t lastevent;
> + grub_uint32_t algorithm;
> + grub_uint32_t eventnum = 0;
> +
> + tpm = grub_efi_open_protocol (tpm_handle, &tpm_guid,
> + GRUB_EFI_OPEN_PROTOCOL_GET_PROTOCOL);
> +
> + if (!grub_tpm_present(tpm))
> + return 0;
> +
> + event = grub_zalloc(sizeof (Event) + grub_strlen(description) + 1);
> + if (!event)
> + return grub_error (GRUB_ERR_OUT_OF_MEMORY,
> + N_("cannot allocate TPM event buffer"));
> +
> + event->pcrindex = pcr;
> + event->eventtype = EV_IPL;
> + event->eventsize = grub_strlen(description) + 1;
> + grub_memcpy(event->event, description, event->eventsize);
> +
> + algorithm = TCG_ALG_SHA;
> + status = efi_call_7 (tpm->log_extend_event, tpm, buf, (grub_uint64_t) size,
> + algorithm, event, &eventnum, &lastevent);
> +
> + switch (status) {
> + case GRUB_EFI_SUCCESS:
> + return 0;
> + case GRUB_EFI_DEVICE_ERROR:
> + return grub_error (GRUB_ERR_IO, N_("Command failed"));
> + case GRUB_EFI_INVALID_PARAMETER:
> + return grub_error (GRUB_ERR_BAD_ARGUMENT, N_("Invalid parameter"));
> + case GRUB_EFI_BUFFER_TOO_SMALL:
> + return grub_error (GRUB_ERR_BAD_ARGUMENT, N_("Output buffer too small"));
> + case GRUB_EFI_NOT_FOUND:
> + return grub_error (GRUB_ERR_UNKNOWN_DEVICE, N_("TPM unavailable"));
> + default:
> + return grub_error (GRUB_ERR_UNKNOWN_DEVICE, N_("Unknown TPM error"));
> + }
> +}
> +
> +static grub_err_t
> +grub_tpm2_log_event(grub_efi_handle_t tpm_handle, unsigned char *buf,
> + grub_size_t size, grub_uint8_t pcr,
> + const char *description)
> +{
> + EFI_TCG2_EVENT *event;
> + grub_efi_status_t status;
> + grub_efi_tpm2_protocol_t *tpm;
> +
> + tpm = grub_efi_open_protocol (tpm_handle, &tpm2_guid,
> + GRUB_EFI_OPEN_PROTOCOL_GET_PROTOCOL);
> +
> + if (!grub_tpm2_present(tpm))
> + return 0;
> +
> + event = grub_zalloc(sizeof (EFI_TCG2_EVENT) + grub_strlen(description) + 1);
> + if (!event)
> + return grub_error (GRUB_ERR_OUT_OF_MEMORY,
> + N_("cannot allocate TPM event buffer"));
> +
> + event->Header.HeaderSize = sizeof(EFI_TCG2_EVENT_HEADER);
> + event->Header.HeaderVersion = 1;
> + event->Header.PCRIndex = pcr;
> + event->Header.EventType = EV_IPL;
> + event->Size = sizeof(*event) - sizeof(event->Event) + grub_strlen(description) + 1;
> + grub_memcpy(event->Event, description, grub_strlen(description) + 1);
> +
> + status = efi_call_5 (tpm->hash_log_extend_event, tpm, 0, buf,
> + (grub_uint64_t) size, event);
> +
> + switch (status) {
> + case GRUB_EFI_SUCCESS:
> + return 0;
> + case GRUB_EFI_DEVICE_ERROR:
> + return grub_error (GRUB_ERR_IO, N_("Command failed"));
> + case GRUB_EFI_INVALID_PARAMETER:
> + return grub_error (GRUB_ERR_BAD_ARGUMENT, N_("Invalid parameter"));
> + case GRUB_EFI_BUFFER_TOO_SMALL:
> + return grub_error (GRUB_ERR_BAD_ARGUMENT, N_("Output buffer too small"));
> + case GRUB_EFI_NOT_FOUND:
> + return grub_error (GRUB_ERR_UNKNOWN_DEVICE, N_("TPM unavailable"));
> + default:
> + return grub_error (GRUB_ERR_UNKNOWN_DEVICE, N_("Unknown TPM error"));
> + }
> +}
> +
> +grub_err_t
> +grub_tpm_log_event(unsigned char *buf, grub_size_t size, grub_uint8_t pcr,
> + const char *description)
> +{
> + grub_efi_handle_t tpm_handle;
> + grub_efi_uint8_t protocol_version;
> +
> + if (!grub_tpm_handle_find(&tpm_handle, &protocol_version))
> + return 0;
> +
> + if (protocol_version == 1) {
> + return grub_tpm1_log_event(tpm_handle, buf, size, pcr, description);
> + } else {
> + return grub_tpm2_log_event(tpm_handle, buf, size, pcr, description);
> + }
> +}
> diff --git a/grub-core/commands/tpm.c b/grub-core/commands/tpm.c
> new file mode 100644
> index 000000000..e047b5fe0
> --- /dev/null
> +++ b/grub-core/commands/tpm.c
> @@ -0,0 +1,87 @@
> +#include <grub/err.h>
> +#include <grub/i18n.h>
> +#include <grub/misc.h>
> +#include <grub/mm.h>
> +#include <grub/tpm.h>
> +#include <grub/term.h>
> +#include <grub/verify.h>
> +#include <grub/dl.h>
> +
> +GRUB_MOD_LICENSE ("GPLv3+")
> +
> +grub_err_t
> +grub_tpm_measure (unsigned char *buf, grub_size_t size, grub_uint8_t pcr,
> + const char *description)
> +{
> + return grub_tpm_log_event (buf, size, pcr, description);
> +}
> +
> +static grub_err_t
> +grub_tpm_verify_init (grub_file_t io,
> + enum grub_file_type type __attribute__ ((unused)),
> + void **context, enum grub_verify_flags *flags)
> +{
> + *context = io->name;
> + *flags |= GRUB_VERIFY_FLAGS_SINGLE_CHUNK;
> + return GRUB_ERR_NONE;
> +}
> +
> +static grub_err_t
> +grub_tpm_verify_write (void *context, void *buf, grub_size_t size)
> +{
> + return grub_tpm_measure (buf, size, 9, context);
> +}
> +
> +static void
> +grub_tpm_verify_close (void *ctxt __attribute__ ((unused)))
> +{
> + return;
> +}
> +
> +static grub_err_t
> +grub_tpm_verify_string (char *str, enum grub_verify_string_type type)
> +{
> + const char *prefix = NULL;
> + char *description;
> + grub_err_t status;
> +
> + switch (type)
> + {
> + case GRUB_VERIFY_KERNEL_CMDLINE:
> + prefix = "kernel_cmdline: ";
> + break;
> + case GRUB_VERIFY_MODULE_CMDLINE:
> + prefix = "module_cmdline: ";
> + break;
> + case GRUB_VERIFY_COMMAND:
> + prefix = "grub_cmd: ";
> + break;
> + }
> + description = grub_malloc(grub_strlen(str) + grub_strlen(prefix) + 1);
> + if (!description)
> + return grub_errno;
> + grub_memcpy(description, prefix, grub_strlen(prefix));
> + grub_memcpy(description + grub_strlen(prefix), str, grub_strlen(str) + 1);
> + status = grub_tpm_measure ((unsigned char *) str, grub_strlen (str), 8,
> + description);
> + grub_free(description);
> + return status;
> +}
> +
> +struct grub_file_verifier grub_tpm_verifier = {
> + .name = "tpm",
> + .init = grub_tpm_verify_init,
> + .write = grub_tpm_verify_write,
> + .close = grub_tpm_verify_close,
> + .verify_string = grub_tpm_verify_string,
> +};
> +
> +GRUB_MOD_INIT(tpm)
> +{
> + grub_verifier_register (&grub_tpm_verifier);
> +}
> +
> +GRUB_MOD_FINI(tpm)
> +{
> + grub_verifier_unregister (&grub_tpm_verifier);
> +}
> diff --git a/grub-core/kern/i386/efi/init.c b/grub-core/kern/i386/efi/init.c
> index a28316cc6..da499aba0 100644
> --- a/grub-core/kern/i386/efi/init.c
> +++ b/grub-core/kern/i386/efi/init.c
> @@ -27,6 +27,7 @@
> #include <grub/efi/efi.h>
> #include <grub/i386/tsc.h>
> #include <grub/loader.h>
> +#include <grub/tpm.h>
>
> void
> grub_machine_init (void)
> diff --git a/include/grub/efi/tpm.h b/include/grub/efi/tpm.h
> new file mode 100644
> index 000000000..e2aff4a3c
> --- /dev/null
> +++ b/include/grub/efi/tpm.h
> @@ -0,0 +1,153 @@
> +/*
> + * GRUB -- GRand Unified Bootloader
> + * Copyright (C) 2015 Free Software Foundation, Inc.
> + *
> + * GRUB is free software: you can redistribute it and/or modify
> + * it under the terms of the GNU General Public License as published by
> + * the Free Software Foundation, either version 3 of the License, or
> + * (at your option) any later version.
> + *
> + * GRUB is distributed in the hope that it will be useful,
> + * but WITHOUT ANY WARRANTY; without even the implied warranty of
> + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
> + * GNU General Public License for more details.
> + *
> + * You should have received a copy of the GNU General Public License
> + * along with GRUB. If not, see <http://www.gnu.org/licenses/>.
> + */
> +
> +#ifndef GRUB_EFI_TPM_HEADER
> +#define GRUB_EFI_TPM_HEADER 1
> +
> +#define EFI_TPM_GUID {0xf541796d, 0xa62e, 0x4954, {0xa7, 0x75, 0x95, 0x84, 0xf6, 0x1b, 0x9c, 0xdd }};
> +#define EFI_TPM2_GUID {0x607f766c, 0x7455, 0x42be, {0x93, 0x0b, 0xe4, 0xd7, 0x6d, 0xb2, 0x72, 0x0f }};
> +
> +typedef struct {
> + grub_efi_uint8_t Major;
> + grub_efi_uint8_t Minor;
> + grub_efi_uint8_t RevMajor;
> + grub_efi_uint8_t RevMinor;
> +} TCG_VERSION;
> +
> +typedef struct _TCG_EFI_BOOT_SERVICE_CAPABILITY {
> + grub_efi_uint8_t Size; /// Size of this structure.
> + TCG_VERSION StructureVersion;
> + TCG_VERSION ProtocolSpecVersion;
> + grub_efi_uint8_t HashAlgorithmBitmap; /// Hash algorithms .
> + char TPMPresentFlag; /// 00h = TPM not present.
> + char TPMDeactivatedFlag; /// 01h = TPM currently deactivated.
> +} TCG_EFI_BOOT_SERVICE_CAPABILITY;
> +
> +typedef struct {
> + grub_efi_uint32_t PCRIndex;
> + grub_efi_uint32_t EventType;
> + grub_efi_uint8_t digest[20];
> + grub_efi_uint32_t EventSize;
> + grub_efi_uint8_t Event[1];
> +} TCG_PCR_EVENT;
> +
> +struct grub_efi_tpm_protocol
> +{
> + grub_efi_status_t (*status_check) (struct grub_efi_tpm_protocol *this,
> + TCG_EFI_BOOT_SERVICE_CAPABILITY *ProtocolCapability,
> + grub_efi_uint32_t *TCGFeatureFlags,
> + grub_efi_physical_address_t *EventLogLocation,
> + grub_efi_physical_address_t *EventLogLastEntry);
> + grub_efi_status_t (*hash_all) (struct grub_efi_tpm_protocol *this,
> + grub_efi_uint8_t *HashData,
> + grub_efi_uint64_t HashLen,
> + grub_efi_uint32_t AlgorithmId,
> + grub_efi_uint64_t *HashedDataLen,
> + grub_efi_uint8_t **HashedDataResult);
> + grub_efi_status_t (*log_event) (struct grub_efi_tpm_protocol *this,
> + TCG_PCR_EVENT *TCGLogData,
> + grub_efi_uint32_t *EventNumber,
> + grub_efi_uint32_t Flags);
> + grub_efi_status_t (*pass_through_to_tpm) (struct grub_efi_tpm_protocol *this,
> + grub_efi_uint32_t TpmInputParameterBlockSize,
> + grub_efi_uint8_t *TpmInputParameterBlock,
> + grub_efi_uint32_t TpmOutputParameterBlockSize,
> + grub_efi_uint8_t *TpmOutputParameterBlock);
> + grub_efi_status_t (*log_extend_event) (struct grub_efi_tpm_protocol *this,
> + grub_efi_physical_address_t HashData,
> + grub_efi_uint64_t HashDataLen,
> + grub_efi_uint32_t AlgorithmId,
> + TCG_PCR_EVENT *TCGLogData,
> + grub_efi_uint32_t *EventNumber,
> + grub_efi_physical_address_t *EventLogLastEntry);
> +};
> +
> +typedef struct grub_efi_tpm_protocol grub_efi_tpm_protocol_t;
> +
> +typedef grub_efi_uint32_t EFI_TCG2_EVENT_LOG_BITMAP;
> +typedef grub_efi_uint32_t EFI_TCG2_EVENT_LOG_FORMAT;
> +typedef grub_efi_uint32_t EFI_TCG2_EVENT_ALGORITHM_BITMAP;
> +
> +typedef struct tdEFI_TCG2_VERSION {
> + grub_efi_uint8_t Major;
> + grub_efi_uint8_t Minor;
> +} GRUB_PACKED EFI_TCG2_VERSION;
> +
> +typedef struct tdEFI_TCG2_BOOT_SERVICE_CAPABILITY {
> + grub_efi_uint8_t Size;
> + EFI_TCG2_VERSION StructureVersion;
> + EFI_TCG2_VERSION ProtocolVersion;
> + EFI_TCG2_EVENT_ALGORITHM_BITMAP HashAlgorithmBitmap;
> + EFI_TCG2_EVENT_LOG_BITMAP SupportedEventLogs;
> + grub_efi_boolean_t TPMPresentFlag;
> + grub_efi_uint16_t MaxCommandSize;
> + grub_efi_uint16_t MaxResponseSize;
> + grub_efi_uint32_t ManufacturerID;
> + grub_efi_uint32_t NumberOfPcrBanks;
> + EFI_TCG2_EVENT_ALGORITHM_BITMAP ActivePcrBanks;
> +} EFI_TCG2_BOOT_SERVICE_CAPABILITY;
> +
> +typedef grub_efi_uint32_t TCG_PCRINDEX;
> +typedef grub_efi_uint32_t TCG_EVENTTYPE;
> +
> +typedef struct tdEFI_TCG2_EVENT_HEADER {
> + grub_efi_uint32_t HeaderSize;
> + grub_efi_uint16_t HeaderVersion;
> + TCG_PCRINDEX PCRIndex;
> + TCG_EVENTTYPE EventType;
> +} GRUB_PACKED EFI_TCG2_EVENT_HEADER;
> +
> +typedef struct tdEFI_TCG2_EVENT {
> + grub_efi_uint32_t Size;
> + EFI_TCG2_EVENT_HEADER Header;
> + grub_efi_uint8_t Event[1];
> +} GRUB_PACKED EFI_TCG2_EVENT;
> +
> +struct grub_efi_tpm2_protocol
> +{
> + grub_efi_status_t (*get_capability) (struct grub_efi_tpm2_protocol *this,
> + EFI_TCG2_BOOT_SERVICE_CAPABILITY *ProtocolCapability);
> + grub_efi_status_t (*get_event_log) (struct grub_efi_tpm2_protocol *this,
> + EFI_TCG2_EVENT_LOG_FORMAT EventLogFormat,
> + grub_efi_physical_address_t *EventLogLocation,
> + grub_efi_physical_address_t *EventLogLastEntry,
> + grub_efi_boolean_t *EventLogTruncated);
> + grub_efi_status_t (*hash_log_extend_event) (struct grub_efi_tpm2_protocol *this,
> + grub_efi_uint64_t Flags,
> + grub_efi_physical_address_t *DataToHash,
According to EFI TCG Protocol specification the DataToHash should be defined as
grub_efi_physical_address_t DataToHash
It seems problematic to use "grub_efi_physical_address_t *" as on IA32 build
that will result in different length of address "value" (32bit vs 64bit) to the
parameters of caller and callee, likely a ABI breakage.
Thanks,
Michael
> + grub_efi_uint64_t DataToHashLen,
> + EFI_TCG2_EVENT *EfiTcgEvent);
> + grub_efi_status_t (*submit_command) (struct grub_efi_tpm2_protocol *this,
> + grub_efi_uint32_t InputParameterBlockSize,
> + grub_efi_uint8_t *InputParameterBlock,
> + grub_efi_uint32_t OutputParameterBlockSize,
> + grub_efi_uint8_t *OutputParameterBlock);
> + grub_efi_status_t (*get_active_pcr_blanks) (struct grub_efi_tpm2_protocol *this,
> + grub_efi_uint32_t *ActivePcrBanks);
> + grub_efi_status_t (*set_active_pcr_banks) (struct grub_efi_tpm2_protocol *this,
> + grub_efi_uint32_t ActivePcrBanks);
> + grub_efi_status_t (*get_result_of_set_active_pcr_banks) (struct grub_efi_tpm2_protocol *this,
> + grub_efi_uint32_t *OperationPresent,
> + grub_efi_uint32_t *Response);
> +};
> +
> +typedef struct grub_efi_tpm2_protocol grub_efi_tpm2_protocol_t;
> +
> +#define TCG_ALG_SHA 0x00000004
> +
> +#endif
> diff --git a/include/grub/tpm.h b/include/grub/tpm.h
> new file mode 100644
> index 000000000..d6757b57b
> --- /dev/null
> +++ b/include/grub/tpm.h
> @@ -0,0 +1,74 @@
> +/*
> + * GRUB -- GRand Unified Bootloader
> + * Copyright (C) 2015 Free Software Foundation, Inc.
> + *
> + * GRUB is free software: you can redistribute it and/or modify
> + * it under the terms of the GNU General Public License as published by
> + * the Free Software Foundation, either version 3 of the License, or
> + * (at your option) any later version.
> + *
> + * GRUB is distributed in the hope that it will be useful,
> + * but WITHOUT ANY WARRANTY; without even the implied warranty of
> + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
> + * GNU General Public License for more details.
> + *
> + * You should have received a copy of the GNU General Public License
> + * along with GRUB. If not, see <http://www.gnu.org/licenses/>.
> + */
> +
> +#ifndef GRUB_TPM_HEADER
> +#define GRUB_TPM_HEADER 1
> +
> +#define SHA1_DIGEST_SIZE 20
> +
> +#define TPM_BASE 0x0
> +#define TPM_SUCCESS TPM_BASE
> +#define TPM_AUTHFAIL (TPM_BASE + 0x1)
> +#define TPM_BADINDEX (TPM_BASE + 0x2)
> +
> +#define TPM_TAG_RQU_COMMAND 0x00C1
> +#define TPM_ORD_Extend 0x14
> +
> +#define EV_IPL 0x0d
> +
> +/* TCG_PassThroughToTPM Input Parameter Block */
> +typedef struct {
> + grub_uint16_t IPBLength;
> + grub_uint16_t Reserved1;
> + grub_uint16_t OPBLength;
> + grub_uint16_t Reserved2;
> + grub_uint8_t TPMOperandIn[1];
> +} GRUB_PACKED PassThroughToTPM_InputParamBlock;
> +
> +/* TCG_PassThroughToTPM Output Parameter Block */
> +typedef struct {
> + grub_uint16_t OPBLength;
> + grub_uint16_t Reserved;
> + grub_uint8_t TPMOperandOut[1];
> +} GRUB_PACKED PassThroughToTPM_OutputParamBlock;
> +
> +typedef struct {
> + grub_uint16_t tag;
> + grub_uint32_t paramSize;
> + grub_uint32_t ordinal;
> + grub_uint32_t pcrNum;
> + grub_uint8_t inDigest[SHA1_DIGEST_SIZE]; /* The 160 bit value representing the event to be recorded. */
> +} GRUB_PACKED ExtendIncoming;
> +
> +/* TPM_Extend Outgoing Operand */
> +typedef struct {
> + grub_uint16_t tag;
> + grub_uint32_t paramSize;
> + grub_uint32_t returnCode;
> + grub_uint8_t outDigest[SHA1_DIGEST_SIZE]; /* The PCR value after execution of the command. */
> +} GRUB_PACKED ExtendOutgoing;
> +
> +grub_err_t grub_tpm_measure (unsigned char *buf, grub_size_t size,
> + grub_uint8_t pcr,
> + const char *description);
> +grub_err_t grub_tpm_init(void);
> +grub_err_t grub_tpm_execute(PassThroughToTPM_InputParamBlock *inbuf,
> + PassThroughToTPM_OutputParamBlock *outbuf);
> +grub_err_t grub_tpm_log_event(unsigned char *buf, grub_size_t size,
> + grub_uint8_t pcr, const char *description);
> +#endif
> --
> 2.13.2.725.g09c95d1e9-goog
>
>
> _______________________________________________
> Grub-devel mailing list
> Grub-devel@gnu.org
> https://lists.gnu.org/mailman/listinfo/grub-devel
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH 1/2] Verify commands executed by grub
2017-07-21 22:13 ` Matthew Garrett
@ 2017-07-24 11:19 ` Vladimir 'phcoder' Serbinenko
0 siblings, 0 replies; 17+ messages in thread
From: Vladimir 'phcoder' Serbinenko @ 2017-07-24 11:19 UTC (permalink / raw)
To: Matthew Garrett; +Cc: The development of GNU GRUB
[-- Attachment #1: Type: text/plain, Size: 1008 bytes --]
On Sat, Jul 22, 2017, 00:13 Matthew Garrett <mjg59@google.com> wrote:
> On Fri, Jul 21, 2017 at 7:39 AM, Vladimir 'phcoder' Serbinenko
> <phcoder@gmail.com> wrote:
> > This omits all separators. So it considers e.g. ab and a b to be the
> same.
> > Can we have a better array serialization? I.a. following 3 need to be
> > distinguished:
> > ab
> > a b
> > "a b"
>
> It inserts a space after each argv, so I think ab and a b are already
> distinguishable in the output? "a b" isn't, however, and that's
> certainly a problem. I can see a few approaches to this:
>
> 1) Delimit with \0. That makes parsing the result more annoying, but
> avoids any ambiguity.
>
I like this possibility. I'll change string hashing to a byte array hashing
in verifiers API
> 2) Add quotes back in for any arguments that contain spaces
> 3) Do the verification before any parsing. Downside is that we don't
> get any variable expansion, which doesn't really matter for the TPM
> case but might not work for other use cases?
>
[-- Attachment #2: Type: text/html, Size: 1566 bytes --]
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: [PATCH 2/2] Core TPM support
2017-07-24 11:16 ` Michael Chang
@ 2017-07-24 11:24 ` Matthew Garrett
0 siblings, 0 replies; 17+ messages in thread
From: Matthew Garrett @ 2017-07-24 11:24 UTC (permalink / raw)
To: The development of GNU GRUB
Thanks, fixed those up.
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: Add TPM measured boot support
2017-07-21 14:32 ` Daniel Kiper
@ 2018-01-19 9:32 ` Javier Martinez Canillas
2018-01-23 11:45 ` Daniel Kiper
0 siblings, 1 reply; 17+ messages in thread
From: Javier Martinez Canillas @ 2018-01-19 9:32 UTC (permalink / raw)
To: The development of GNU GRUB, Daniel Kiper, mjg59
Cc: keng-yu.lin, leif.lindholm, Peter Jones
On 07/21/2017 04:32 PM, Daniel Kiper wrote:
> On Thu, Jul 20, 2017 at 11:41:11PM +0100, Matthew Garrett wrote:
>> On Wed, Jul 05, 2017 at 02:19:55PM -0700, Matthew Garrett wrote:
>>> This patchset extends the verifier framework to support verifying commands
>>> executed by Grub, and makes use of this to add support for measuring files
>>> and commands executed by grub into the TPM on UEFI-based systems.
>>
>> Any feedback on this? Vladimir, are you planning on merging your
>
> Will take a look next week (well, I was going to do some review this
> week but still recovering after Xen conference). Sorry for delays.
>
>> verifier branch?
>
> Yes, we are going to merge this. Though we are still discussing some details.
> Please be patient...
>
Any update on this series? I see that even the verifier framework hasn't
been merged yet.
> Daniel
>
Best regards,
--
Javier Martinez Canillas
Software Engineer - Desktop Hardware Enablement
Red Hat
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: Add TPM measured boot support
2018-01-19 9:32 ` Javier Martinez Canillas
@ 2018-01-23 11:45 ` Daniel Kiper
2018-04-07 0:36 ` Matthew Garrett
0 siblings, 1 reply; 17+ messages in thread
From: Daniel Kiper @ 2018-01-23 11:45 UTC (permalink / raw)
To: Javier Martinez Canillas
Cc: The development of GNU GRUB, Daniel Kiper, mjg59, keng-yu.lin,
leif.lindholm, Peter Jones
On Fri, Jan 19, 2018 at 10:32:49AM +0100, Javier Martinez Canillas wrote:
> On 07/21/2017 04:32 PM, Daniel Kiper wrote:
> > On Thu, Jul 20, 2017 at 11:41:11PM +0100, Matthew Garrett wrote:
> >> On Wed, Jul 05, 2017 at 02:19:55PM -0700, Matthew Garrett wrote:
> >>> This patchset extends the verifier framework to support verifying commands
> >>> executed by Grub, and makes use of this to add support for measuring files
> >>> and commands executed by grub into the TPM on UEFI-based systems.
> >>
> >> Any feedback on this? Vladimir, are you planning on merging your
> >
> > Will take a look next week (well, I was going to do some review this
> > week but still recovering after Xen conference). Sorry for delays.
> >
> >> verifier branch?
> >
> > Yes, we are going to merge this. Though we are still discussing some details.
> > Please be patient...
>
> Any update on this series? I see that even the verifier framework hasn't
> been merged yet.
Sadly yes. Sorry about that. However, this is still on my radar. I hope that
I come back to work on this in a few weeks.
Daniel
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: Add TPM measured boot support
2018-01-23 11:45 ` Daniel Kiper
@ 2018-04-07 0:36 ` Matthew Garrett
2018-04-09 8:26 ` Daniel Kiper
0 siblings, 1 reply; 17+ messages in thread
From: Matthew Garrett @ 2018-04-07 0:36 UTC (permalink / raw)
To: The development of GNU GRUB
Cc: Javier Martinez Canillas, leif.lindholm, keng-yu.lin,
Daniel Kiper
On Tue, Jan 23, 2018 at 12:45:14PM +0100, Daniel Kiper wrote:
> Sadly yes. Sorry about that. However, this is still on my radar. I hope that
> I come back to work on this in a few weeks.
Hi Daniel,
Any news on this front? Thanks!
--
Matthew Garrett | mjg59@srcf.ucam.org
^ permalink raw reply [flat|nested] 17+ messages in thread
* Re: Add TPM measured boot support
2018-04-07 0:36 ` Matthew Garrett
@ 2018-04-09 8:26 ` Daniel Kiper
0 siblings, 0 replies; 17+ messages in thread
From: Daniel Kiper @ 2018-04-09 8:26 UTC (permalink / raw)
To: Matthew Garrett
Cc: The development of GNU GRUB, Javier Martinez Canillas,
leif.lindholm, keng-yu.lin, Daniel Kiper
Hi Matthew,
On Sat, Apr 07, 2018 at 01:36:28AM +0100, Matthew Garrett wrote:
> On Tue, Jan 23, 2018 at 12:45:14PM +0100, Daniel Kiper wrote:
>
> > Sadly yes. Sorry about that. However, this is still on my radar. I hope that
> > I come back to work on this in a few weeks.
>
> Hi Daniel,
>
> Any news on this front? Thanks!
Good news is that my plans has not changed. Bad news is that
everything moves much slower than I expected. However, this
task is the second one on my TODO list. Right now I have to
post some Xen secure boot patches (this is also delayed a few
months) which depend on this work to some extent too. So,
I expect that I will take a stab at it in May or June. Anyway,
sorry for delays.
Daniel
^ permalink raw reply [flat|nested] 17+ messages in thread
end of thread, other threads:[~2018-04-09 8:26 UTC | newest]
Thread overview: 17+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-07-05 21:19 Add TPM measured boot support Matthew Garrett
2017-07-05 21:19 ` [PATCH 1/2] Verify commands executed by grub Matthew Garrett
2017-07-21 14:23 ` Javier Martinez Canillas
2017-07-21 14:39 ` Vladimir 'phcoder' Serbinenko
2017-07-21 22:13 ` Matthew Garrett
2017-07-24 11:19 ` Vladimir 'phcoder' Serbinenko
2017-07-05 21:19 ` [PATCH 2/2] Core TPM support Matthew Garrett
2017-07-21 14:27 ` Javier Martinez Canillas
2017-07-24 11:16 ` Michael Chang
2017-07-24 11:24 ` Matthew Garrett
2017-07-20 22:41 ` Add TPM measured boot support Matthew Garrett
2017-07-21 14:22 ` Javier Martinez Canillas
2017-07-21 14:32 ` Daniel Kiper
2018-01-19 9:32 ` Javier Martinez Canillas
2018-01-23 11:45 ` Daniel Kiper
2018-04-07 0:36 ` Matthew Garrett
2018-04-09 8:26 ` Daniel Kiper
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.