From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from list by lists.gnu.org with archive (Exim 4.90_1) id 1pWqeM-0000mA-NX for mharc-grub-devel@gnu.org; Mon, 27 Feb 2023 22:27:34 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1pWqeL-0000lz-HH for grub-devel@gnu.org; Mon, 27 Feb 2023 22:27:33 -0500 Received: from mail-db5eur01on0600.outbound.protection.outlook.com ([2a01:111:f400:fe02::600] helo=EUR01-DB5-obe.outbound.protection.outlook.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1pWqeJ-0003Ce-9q for grub-devel@gnu.org; Mon, 27 Feb 2023 22:27:33 -0500 ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=VnFrjgVv8jmkqE2egclkXzy2pHL2uoAUW6SI2/Xx7Rlxmvh2LGZCdCmUAOx6/uab2WFQCJxLAIBPqLAYU7BtqGOC16FycawMdXuXyg9GrbFbK4ss1BcSRx72Mcdp9IbsUNh9e70joAT8Od7EeK2fMvy9bnu8W7cbQvP3//CdIrXRxxIjWHqEUjHp1hwt/bfFhEUCoia71dqfnKYSFB5QGXMaTS6XUiu6yF6VYfgq7My2QITynEAG2/ZpJfakfMppWBPj2VVyI1Fx68uXcaGzvcREZejMwBdOmogqk4VY06ha0aKo42gKkFd4XS6TestTWB6FwAadjkgc+rsAOUNbcg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=TdfbFk5SrLBWok/QxLXHRNUhkHBMs3N2qn7VHeO2FoM=; b=Vtf1qSHQtXgzsDVNzBTV0b/vyfBJI8kvzTGf5wQvcQQGbAgHVhzBWowuW6oPDT10h0xGSctVm1J6iQVXrquIMaZWN2wFkBbFiQoqaWYZ1T2/RaRiMzha6q16fgN5r2Mpg2ZmlgoMJddvDBXVyXxhOs4omVEgS9K0+YWZ43GMX+BPhVvVlKeGI34sZc6Gbj3X8B0IiIkJidCyYu4+cN3pxzpZaiWN2Q26PjDNJVFVWw9EFjtUOWVmOpkOZSH23qr1Ad/oD/wP7mVYdey04ozoFoS638jXVOItlhwGE+0ipihoFOARPsNPVtKfEQHUzNgQabHFnT1qm5c1PJmwsqslIw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=suse.com; dmarc=pass action=none header.from=suse.com; dkim=pass header.d=suse.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=TdfbFk5SrLBWok/QxLXHRNUhkHBMs3N2qn7VHeO2FoM=; b=gU/17PniTyg1XuM8S643nsgZMpmcspS3CqCcXjHsBNDyDlfRdT0fqYqDA5rUuzQtQD/VjTYMZ3TlNY69bSHQzAHCrNTeLHorMF09XJlyPhjhJFAUcF2baCrmPd+sNtWJlzsqXmEyPtj+p24JHhddeknaZ0VP2jLWNLbUaVFwVOKIjUgGF9vE/oB5wUISC6usQYaxSRiX4IgQVsOc1Gt9GXHtwQPMcaWZTOu6eOTIcBTZLFp6faBVIFXF/V7ubIugirc+L0Jq6Lf/alvScDTdGh/Y4Vb/HPHDgnrn86PiIJFK38T/sdhEdLAZMuti0DQa4g2xusC3PFvfxOnQF/x08w== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=suse.com; Received: from DU2PR04MB9081.eurprd04.prod.outlook.com (2603:10a6:10:2f0::13) by AS1PR04MB9682.eurprd04.prod.outlook.com (2603:10a6:20b:472::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6134.26; Tue, 28 Feb 2023 03:22:24 +0000 Received: from DU2PR04MB9081.eurprd04.prod.outlook.com ([fe80::f24e:f7d1:14f:b945]) by DU2PR04MB9081.eurprd04.prod.outlook.com ([fe80::f24e:f7d1:14f:b945%4]) with mapi id 15.20.6134.029; Tue, 28 Feb 2023 03:22:24 +0000 Date: Tue, 28 Feb 2023 11:22:14 +0800 From: Michael Chang To: The development of GNU GRUB Cc: jejb@linux.ibm.com, stefanb@linux.ibm.com, rharwood@redhat.com Subject: Re: [PATCH v2] tpm: Disable tpm verifier if tpm is not present Message-ID: <20230228032214.bsnpbyixvswkczvr@lore> References: <20221007053710.18345-1-mchang@suse.com> <20221014094001.dqoncqektby34etb@tomti.i.net-space.pl> <20221017051908.GA21185@mazu> <20221124160448.zzcuix5atyhggj7j@tomti.i.net-space.pl> <20221125070048.GA5792@mazu> <20221129151148.rwt2rfwql2ufhfew@tomti.i.net-space.pl> <20230220045701.h2tf5q3jzcsyurim@lore> <20230223132227.2727gstzxsk4od5v@tomti.i.net-space.pl> Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20230223132227.2727gstzxsk4od5v@tomti.i.net-space.pl> X-ClientProxiedBy: TYCP301CA0016.JPNP301.PROD.OUTLOOK.COM (2603:1096:400:381::17) To DU2PR04MB9081.eurprd04.prod.outlook.com (2603:10a6:10:2f0::13) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DU2PR04MB9081:EE_|AS1PR04MB9682:EE_ X-MS-Office365-Filtering-Correlation-Id: bec314ea-096a-4ccc-7681-08db193b0289 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: 8MIglYN0vEq9pJjNo8fMz6Wqdd/kLWJ2jNJiqHTbEWXlMnsoZXFXCFsypyE5rww/SRM/HvqoNiwwgU0QT3mu3yADTvKr2yRs5udPs7J5qF2h8f0/dj6aM0uD3rhHDvSP2lOf75bdBUFiVH3RFhqm3J+mlW3HsL2ys/joK6wDF2NnV8udWu/roMsx+Z1Bq5jQiTSDJNLW/tjBMeSrFGXQ4gi5G7v/Uuk6bSQ1mzb49pkpcBkttfPXQNqcVNVSX/Na69Go5Tnc3rmvGlbxGBjfa4cs+6CluzpczwrArfgVYXPOeRFIzBeElqJOQnF29GtBOdKzYJqR8MuzKB2wwtgyICNZJUKYdoxiJ/3K4D7d9LrgCzxwC8IkuUyB/KLg8cPWWXB9loWZQBZhrK8Zvx4/22D3cSSzbyp2lnIBYXbn110bnGCD5yNd+CeaM/29t7EsX3Ebt/Eu28o0BN9NPRNrDI8eJRAAKpNK4lGBMCpXCr39dUHWz2zW3XmidcDCuwaq8YAcLCEsnR0Zj9GGs3Tc8pvlATLkUXvVWCDvc5ggNI1Zvf9bxWfUF9zqqYuHCGonN7PrJxyxjzb4tsa4UClmn3BYqZg6H3yJTQEEr9wJyXt9ei2mYmTjF3PlK8WK1TOl X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DU2PR04MB9081.eurprd04.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230025)(7916004)(346002)(376002)(396003)(366004)(136003)(39860400002)(451199018)(186003)(1076003)(6666004)(66946007)(9686003)(6506007)(41300700001)(6512007)(6916009)(478600001)(66556008)(66476007)(4326008)(966005)(6486002)(316002)(86362001)(8676002)(8936002)(33716001)(83380400001)(5660300002)(38100700002)(66899018)(2906002)(3716004); DIR:OUT; SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?1I/Yqk5icS7ynZP7LZ29vLbawpsRhXatkQ0eYL+1aCHBYJOw7soBbzbO3Jyx?= =?us-ascii?Q?e+F4hnOH0bZCngaUFltpW8YiOY1k9hmZ+3yJa+JJD/D2y0vIHLTdWIgtBLsd?= =?us-ascii?Q?G6Ks70Vk9WGtc94deAWN1weY3sDOzXdSJQDDVihl6BzCa+4dCvBaS57T/sWl?= =?us-ascii?Q?IpuuO99ITd2CW1jOEAofxs5OoMgAXIYgYELq8WGgz2A++WkDvzY5YUHHpj4v?= =?us-ascii?Q?DVi7vpZY8uwn1CBwc/89r9ONPorIpKEkKyqGtDiJPboiw5z+udHK5INoC3qU?= =?us-ascii?Q?zvaSWqU+B8NZGw3Rvvur/aNVFkiGWPNnx9IRymhavA7HoVga2OWLR2Nefw65?= =?us-ascii?Q?m8UYuKGsnS63x5veEWdm+Dasb8BogkBfkTBBCMvZskJsR800BdwNPN0DEd2N?= =?us-ascii?Q?AOhFLSuNBjdTEcQmXE4tSLmTbFv1srfu67+ZlRCHilGWP76L/arb25A6dixP?= =?us-ascii?Q?iikDzgUr6EVSXY4FDGPBxL9DBOuOrxcyLTRJgl5e34ldM4qjbJKPpqkpfx76?= =?us-ascii?Q?iRu742kRUwME7rfVTvonm7Vv+DU/zsCvhHTOQ4j+bwER8CFDD7X5GHKeM8We?= =?us-ascii?Q?Nim/srCfJj3J5bEGXYituALGziEX3OHxxYkX6lbKtpoTlQdxf4P3oGcvVa91?= =?us-ascii?Q?ejIWtpXNH3OUzTFxveWKJTYu8FMqWEMVXk5k3dNEUHPEaos9OgK5ED1kdLKs?= =?us-ascii?Q?oi7xba+C5bZzZ4ilMlfW1RVgu/z4/O8YPpcivlWHl148ti9EOPN6eC8fqPVC?= =?us-ascii?Q?+sGwhPdL1Rj6dCIz1ZIH+GMrOeJhQZkZ/YXX6xC8R/DsN3h784dpM3pGF+zi?= =?us-ascii?Q?SjCG6cyvYF4m3tSDP4NYQbDpW8kGjuDyLWRL+ndd151eGmj9h3oACtq0jvjO?= =?us-ascii?Q?gnk4xVLakE1Nywu5fVbIdyHYeemWCMVh/37Eqlx5z49oxvHlEYBm+GCf7keK?= =?us-ascii?Q?OJKJB6EFnAHylFAFVevYQXGmEkNQvul7pOzq2dqPtqiL4uf71Ra/VlYPKs8j?= =?us-ascii?Q?rf1ZxxWOcyarRzz57mzvOezGNfBCROMYlhmR99AODqekQ/hpU0/xnHHGH8pF?= =?us-ascii?Q?gE58VFBKdDfHxFMAVCsgqzBvUYOuVBZxg+M8RgB6mCPZOqCCANZpxHEvzmQJ?= =?us-ascii?Q?U9lvWQ/+joHvG18WglV5gdnj7ij3lIZIboeSOyv4eYFXunzYcmp+ZAokC3V6?= =?us-ascii?Q?pzX2dyCSsO+/2YfpbSW6LrWL8CecHzHteWOuSLpi6RN3gfG8CvNqXHpPJjBl?= =?us-ascii?Q?/a7g/3Yo3vopxgO7cD3Vuk6nCVx0K2DWav773QBL2GZRq5pvd36U5WP9BoGC?= =?us-ascii?Q?JwTTv0LdX0cOPtxzHtQUXMrTtnv18TY6z6JJdj+BCuyHUuyzzj7G7EY6jghx?= =?us-ascii?Q?ugpfnY4SdiaGXbwcfA1EzctLJoptH6vPCc7GwEBjq+HIT9pZZuw2xPnlNSB2?= =?us-ascii?Q?+jUNrGIPpVXMLaUxr0aFiIlVwqvtC9fadoabapZBsADSnlsMSoeE6bk/749a?= =?us-ascii?Q?8iqY48Gn11qcQcQIe1N6Ja0tK8jaFw4uD2MVqzlBpOn/UHW03n0ujc/85cbb?= =?us-ascii?Q?9CHdSzHUsGXKvVGud6blDxG394K4HFwvsFVT8804MWnkoT/Thl/zyopfyANp?= =?us-ascii?Q?jiWTZzM2C2uVK2kGZrpLj6K0vDQE4HIFLqBYxGAw7D3d?= X-OriginatorOrg: suse.com X-MS-Exchange-CrossTenant-Network-Message-Id: bec314ea-096a-4ccc-7681-08db193b0289 X-MS-Exchange-CrossTenant-AuthSource: DU2PR04MB9081.eurprd04.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 28 Feb 2023 03:22:24.3759 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: f7a17af6-1c5c-4a36-aa8b-f5be247aa4ba X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: f4GzY8iDM+dkfm50TWP5z04RlXEUuy8x5vXdCITbywTRzOp29fTIrwBSYQxuaNBp X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS1PR04MB9682 Received-SPF: pass client-ip=2a01:111:f400:fe02::600; envelope-from=MChang@suse.com; helo=EUR01-DB5-obe.outbound.protection.outlook.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: grub-devel@gnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: The development of GNU GRUB List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 28 Feb 2023 03:27:33 -0000 On Thu, Feb 23, 2023 at 02:22:27PM +0100, Daniel Kiper wrote: > Adding James, Stefan and Robbie... > > On Mon, Feb 20, 2023 at 12:57:01PM +0800, Michael Chang via Grub-devel wrote: > > On Tue, Nov 29, 2022 at 04:11:48PM +0100, Daniel Kiper wrote: > > > On Fri, Nov 25, 2022 at 03:00:48PM +0800, Michael Chang via Grub-devel wrote: > > > > On Thu, Nov 24, 2022 at 05:04:48PM +0100, Daniel Kiper wrote: > > > > > On Mon, Oct 17, 2022 at 01:19:08PM +0800, Michael Chang via Grub-devel wrote: > > > > > > On Fri, Oct 14, 2022 at 11:40:01AM +0200, Daniel Kiper wrote: > > > > > > > On Fri, Oct 07, 2022 at 01:37:10PM +0800, Michael Chang via Grub-devel wrote: > > > > > > > > This helps to prevent out of memory error when reading large files via disabling > > > > > > > > tpm device as verifier has to read all content into memory in one chunk to > > > > > > > > measure the hash and extend to tpm. > > > > > > > > > > > > > > How does this patch help when the TPM is present in the system? > > > > > > > > > > > > If the firmware menu offers option to disable TPM device, then this > > > > > > patch can be useful to get around 'out of memory error' through > > > > > > disabling TPM device from firmware in order to make tpm verifier won't > > > > > > be in the way of reading huge files. > > > > > > > > > > > > This is essentially a compromised solution as long as tpm module can be > > > > > > a built-in module in signed image and at the same time user may come > > > > > > across the need to open huge files, for eg, loopback mount in grub for > > > > > > the rescue image. In this case they could be opted in to disable tpm > > > > > > device from firmware to proceed if they run into out of memory or other > > > > > > (slow) reading issues. > > > > > > > > > > I think I would prefer something similar to this [1] patch. Of course > > > > > if [1] is not enough... > > > > > > > > The tpm verifier attempts to set GRUB_VERIFY_FLAGS_SINGLE_CHUNK for all > > > > incoming files, which gets loaded into memory in its entirety as an > > > > duplicated copy to disk files. The overhead is too huge to some low > > > > profile hardwares with smaller memory or when the boot path has to cover > > > > very large files, hence the out of memory error. > > > > > > > > I think it inevitable to use GRUB_VERIFY_FLAGS_SINGLE_CHUNK as tpm > > > > measures and extends file intergrity. But we ought to avoid the overhead > > > > when TPM device is not present or disabled by the user. > > > > > > > > The patch [1] seems to deal with the tpm error which prevents a file > > > > from being opened, which is orthogonal to the memory allocation issue in > > > > the common verifier before tpm doing measurement. > > > > > > This is what I expected. So, that is why I said "Of course if [1] is not > > > enough..."... :-) Now I think it would be nice if TPM verifier is > > > disabled when the TPM device is broken/disabled/... and/or somebody sets > > > a separate environemnt variable in the GRUB. WDYT? > > > > I'm not sure if a separate environment a good idea, because it would > > expose the funtion to disable verifier in a way much readily accessible > > through one of grub command line interface, grub.cfg and grubenv file so > > that the intention have to be very carefully reviewed here. > > I think it should be safe because even if somebody is doing nasty things > with disabling the TPM verifier they can be easily detected or will lead > to early boot failures when the TPM is used to store secrets. Of course > there is small chance somebody disables the TPM verifier during platform > initialization/installation. However, this should be also easily to > detect due to, e.g., lack of measurements. IMHO it is hardly be detectable, there's no clear distinction to it is a result of lack of measurement or a compromised system if we know that tpm is active and working ... > Anyway, I would extend the > GRUB documentation with a note saying that platform > initialization/installation should happen in well controlled > environment. Just in case... Yes the initial bootstrapping environemt or process is important, but also there's system update which should happen in a well controlled environment as well. Thanks, Michael > > Daniel > > _______________________________________________ > Grub-devel mailing list > Grub-devel@gnu.org > https://lists.gnu.org/mailman/listinfo/grub-devel