All of lore.kernel.org
 help / color / mirror / Atom feed
From: Gary Lin via Grub-devel <grub-devel@gnu.org>
To: The development of GNU GRUB <grub-devel@gnu.org>
Cc: Gary Lin <glin@suse.com>, Daniel Kiper <daniel.kiper@oracle.com>,
	mchang@suse.com, patrick.colp@oracle.com,
	Stefan Berger <stefanb@linux.ibm.com>,
	jejb@linux.ibm.com, Glenn Washburn <development@efficientek.com>
Subject: [PATCH v4 10/12] tests/tpm2_key_protector_test: Add more NV index mode tests
Date: Fri, 21 Mar 2025 15:59:06 +0800	[thread overview]
Message-ID: <20250321075908.10523-11-glin@suse.com> (raw)
In-Reply-To: <20250321075908.10523-1-glin@suse.com>

Two more NV index test cases are added to test key sealing and
unsealing with the NV index handle 0x1000000.

Signed-off-by: Gary Lin <glin@suse.com>
---
 tests/tpm2_key_protector_test.in | 55 ++++++++++++++++++++++----------
 1 file changed, 39 insertions(+), 16 deletions(-)

diff --git a/tests/tpm2_key_protector_test.in b/tests/tpm2_key_protector_test.in
index 0d1115e02..1ba70a3d5 100644
--- a/tests/tpm2_key_protector_test.in
+++ b/tests/tpm2_key_protector_test.in
@@ -226,7 +226,23 @@ EOF
 }
 
 tpm2_seal_unseal_nv() {
-    nv_index="0x81000000"
+    handle_type="$1"
+    key_type="$2"
+
+    extra_opt=""
+    extra_grub_opt=""
+
+    if [ "$handle_type" == "nvindex" ]; then
+	nv_index="0x1000000"
+    else
+	nv_index="0x81000000"
+    fi
+
+    if [ "$key_type" == "tpm2key" ]; then
+	extra_opt="--tpm2key"
+    else
+	extra_grub_opt="--pcrs=0,1"
+    fi
 
     grub_cfg=${tpm2testdir}/testcase.cfg
 
@@ -247,7 +263,7 @@ tpm2_seal_unseal_nv() {
     # Write the TPM unsealing script
     cat > ${grub_cfg} <<EOF
 loopback luks (host)${luksfile}
-tpm2_key_protector_init --mode=nv --nvindex=${nv_index} --pcrs=0,1
+tpm2_key_protector_init --mode=nv --nvindex=${nv_index} ${extra_grub_opt}
 if cryptomount -a --protector tpm2; then
     cat (crypto0)+1
 fi
@@ -288,26 +304,33 @@ srktests+=("ECC transient fallback_srk")
 for i in "${!srktests[@]}"; do
     tpm2_seal_unseal ${srktests[$i]} || ret=$?
     if [ "${ret}" -eq 0 ]; then
-        echo "TPM2 [${srktests[$i]}]: PASS"
+	echo "TPM2 [SRK][${srktests[$i]}]: PASS"
     elif [ "${ret}" -eq 1 ]; then
-        echo "TPM2 [${srktests[$i]}]: FAIL"
+	echo "TPM2 [SRK][${srktests[$i]}]: FAIL"
 	ret=0
     else
-	echo "Unexpected failure [${srktests[$i]}]" >&2
+	echo "Unexpected failure [SRK][${srktests[$i]}]" >&2
 	exit ${ret}
     fi
 done
 
-# Testcase for NV index mode
-tpm2_seal_unseal_nv || ret=$?
-if [ "${ret}" -eq 0 ]; then
-    echo "TPM2 [NV Index]: PASS"
-elif [ "${ret}" -eq 1 ]; then
-    echo "TPM2 [NV Index]: FAIL"
-    ret=0
-else
-    echo "Unexpected failure [NV index]" >&2
-    exit ${ret}
-fi
+# Testcases for NV index mode
+declare -a nvtests=()
+nvtests+=("persistent raw")
+nvtests+=("nvindex raw")
+nvtests+=("nvindex tpm2key")
+
+for i in "${!nvtests[@]}"; do
+    tpm2_seal_unseal_nv ${nvtests[$i]} || ret=$?
+    if [ "${ret}" -eq 0 ]; then
+	echo "TPM2 [NV Index][${nvtests[$i]}]: PASS"
+    elif [ "${ret}" -eq 1 ]; then
+	echo "TPM2 [NV Index][${nvtests[$i]}]: FAIL"
+	ret=0
+    else
+	echo "Unexpected failure [NV index][${nvtests[$i]}]" >&2
+	exit ${ret}
+    fi
+done
 
 exit 0
-- 
2.43.0


_______________________________________________
Grub-devel mailing list
Grub-devel@gnu.org
https://lists.gnu.org/mailman/listinfo/grub-devel

  parent reply	other threads:[~2025-03-21  8:02 UTC|newest]

Thread overview: 24+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-03-21  7:58 [PATCH v4 00/12] TPM2 key protector follow-up patches Gary Lin via Grub-devel
2025-03-21  7:58 ` [PATCH v4 01/12] tpm2_key_protector: dump PCRs on policy fail Gary Lin via Grub-devel
2025-03-21  7:58 ` [PATCH v4 02/12] tpm2_key_protector: Add 'tpm2_dump_pcr' command Gary Lin via Grub-devel
2025-03-21  7:58 ` [PATCH v4 03/12] tss2: Fix the missing authCommand Gary Lin via Grub-devel
2025-03-21  7:59 ` [PATCH v4 04/12] tss2: Add TPM 2.0 NV index commands Gary Lin via Grub-devel
2025-03-21  7:59 ` [PATCH v4 05/12] tpm2_key_protector: Unseal key from a buffer Gary Lin via Grub-devel
2025-03-25 16:01   ` Daniel Kiper via Grub-devel
2025-03-26  7:54     ` Gary Lin via Grub-devel
2025-03-21  7:59 ` [PATCH v4 06/12] tpm2_key_protector: Support NV index handles Gary Lin via Grub-devel
2025-03-21  7:59 ` [PATCH v4 07/12] util/grub-protect: Support NV index mode Gary Lin via Grub-devel
2025-03-26 16:14   ` Daniel Kiper via Grub-devel
2025-03-21  7:59 ` [PATCH v4 08/12] tests/tpm2_key_protector_test: Simplify the NV index mode test Gary Lin via Grub-devel
2025-03-24 14:21   ` Stefan Berger
2025-03-26 16:16   ` Daniel Kiper via Grub-devel
2025-03-21  7:59 ` [PATCH v4 09/12] tests/tpm2_key_protector_test: Reset 'ret' on fail Gary Lin via Grub-devel
2025-03-24 13:48   ` Stefan Berger
2025-03-24 14:29   ` Vladimir 'phcoder' Serbinenko
2025-03-24 14:35     ` Stefan Berger
2025-03-25  7:18       ` Gary Lin via Grub-devel
2025-03-21  7:59 ` Gary Lin via Grub-devel [this message]
2025-03-24 14:19   ` [PATCH v4 10/12] tests/tpm2_key_protector_test: Add more NV index mode tests Stefan Berger
2025-03-21  7:59 ` [PATCH v4 11/12] docs: Update NV index mode of TPM2 key protector Gary Lin via Grub-devel
2025-03-21  7:59 ` [PATCH v4 12/12] INSTALL: Document the packages needed for TPM2 key protector tests Gary Lin via Grub-devel
2025-03-26 16:19   ` Daniel Kiper via Grub-devel

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250321075908.10523-11-glin@suse.com \
    --to=grub-devel@gnu.org \
    --cc=daniel.kiper@oracle.com \
    --cc=development@efficientek.com \
    --cc=glin@suse.com \
    --cc=jejb@linux.ibm.com \
    --cc=mchang@suse.com \
    --cc=patrick.colp@oracle.com \
    --cc=stefanb@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.