* [LTP] [PATCH] ima_tpm.sh: properly detect failure to verify the IMA measurement list
@ 2026-08-26 0:34 ` Mimi Zohar
0 siblings, 0 replies; 3+ messages in thread
From: Mimi Zohar @ 2026-08-26 0:34 UTC (permalink / raw)
To: ltp; +Cc: linux-integrity
test2 attempts to compare the aggregate PCR-10 value with the current
TPM PCR value based on the current measurement list, but does not take
into account that the measurement list might have been extended.
evmctl returns success/failure when verifying the IMA measurement list
and displays the measurement list line number that matched. Update
test2.
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
---
.../security/integrity/ima/tests/ima_tpm.sh | 34 +++++++++++++------
1 file changed, 23 insertions(+), 11 deletions(-)
diff --git a/testcases/kernel/security/integrity/ima/tests/ima_tpm.sh b/testcases/kernel/security/integrity/ima/tests/ima_tpm.sh
index acd8b6d30..5f7a5e983 100755
--- a/testcases/kernel/security/integrity/ima/tests/ima_tpm.sh
+++ b/testcases/kernel/security/integrity/ima/tests/ima_tpm.sh
@@ -146,7 +146,7 @@ get_pcr10_aggregate()
local num_violations=0
local msg="$ERRMSG_EVMCTL"
local res=TCONF
- local pcr ret
+ local lineno pcr ret
if [ -z "$MISSING_EVMCTL" ]; then
msg=
@@ -178,10 +178,13 @@ get_pcr10_aggregate()
tst_res $res "failed to find aggregate PCR-10 $msg"
tst_res TINFO "hash file:"
cat hash.txt >&2
- return
+ return 1
fi
- echo "$pcr"
+ lineno=$(grep -E "^($ALGORITHM )*PCR(.*10)*: succeed at entry" hash.txt | tail -1 \
+ | awk '{print $NF}')
+ echo "$pcr $lineno"
+ return $ret
}
test1_tpm_bypass_mode()
@@ -249,7 +252,9 @@ test1()
test2()
{
- local hash pcr_aggregate out ret
+ local hash pcr_aggregate lineno out ret
+ local measurement_count="$IMA_DIR/runtime_measurements_count"
+ local total_measurements
tst_res TINFO "verify PCR values"
@@ -288,14 +293,21 @@ test2()
tst_res TINFO "real PCR-10: '$hash'"
get_pcr10_aggregate > tmp.txt
- pcr_aggregate="$(cat tmp.txt)"
- if [ -z "$pcr_aggregate" ]; then
- return
- fi
- tst_res TINFO "aggregate PCR-10: '$pcr_aggregate'"
+ if [ $? -eq 0 ]; then
+ pcr_aggregate="$(cat tmp.txt | cut -d " " -f1)"
+ if [ -z "$pcr_aggregate" ]; then
+ return
+ fi
+ tst_res TINFO "aggregate PCR-10: '$pcr_aggregate'"
- if [ "$hash" = "$pcr_aggregate" ]; then
- tst_res TPASS "aggregate PCR value matches real PCR value"
+ lineno="$(cat tmp.txt | cut -d " " -f2)"
+
+ if [ "$hash" = "$pcr_aggregate" ]; then
+ tst_res TPASS "aggregate PCR value matches real PCR value (line: $lineno)"
+ else
+ total_measurements=$(cat "$measurement_count")
+ tst_res TPASS "aggregate PCR value matched real PCR value (line: $lineno/$total_measurements)"
+ fi
else
tst_res TFAIL "aggregate PCR value does not match real PCR value"
fi
--
2.55.0
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply related [flat|nested] 3+ messages in thread* [PATCH] ima_tpm.sh: properly detect failure to verify the IMA measurement list
@ 2026-08-26 0:34 ` Mimi Zohar
0 siblings, 0 replies; 3+ messages in thread
From: Mimi Zohar @ 2026-08-26 0:34 UTC (permalink / raw)
To: ltp; +Cc: Petr Vorel, linux-integrity, Mimi Zohar
test2 attempts to compare the aggregate PCR-10 value with the current
TPM PCR value based on the current measurement list, but does not take
into account that the measurement list might have been extended.
evmctl returns success/failure when verifying the IMA measurement list
and displays the measurement list line number that matched. Update
test2.
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
---
.../security/integrity/ima/tests/ima_tpm.sh | 34 +++++++++++++------
1 file changed, 23 insertions(+), 11 deletions(-)
diff --git a/testcases/kernel/security/integrity/ima/tests/ima_tpm.sh b/testcases/kernel/security/integrity/ima/tests/ima_tpm.sh
index acd8b6d30..5f7a5e983 100755
--- a/testcases/kernel/security/integrity/ima/tests/ima_tpm.sh
+++ b/testcases/kernel/security/integrity/ima/tests/ima_tpm.sh
@@ -146,7 +146,7 @@ get_pcr10_aggregate()
local num_violations=0
local msg="$ERRMSG_EVMCTL"
local res=TCONF
- local pcr ret
+ local lineno pcr ret
if [ -z "$MISSING_EVMCTL" ]; then
msg=
@@ -178,10 +178,13 @@ get_pcr10_aggregate()
tst_res $res "failed to find aggregate PCR-10 $msg"
tst_res TINFO "hash file:"
cat hash.txt >&2
- return
+ return 1
fi
- echo "$pcr"
+ lineno=$(grep -E "^($ALGORITHM )*PCR(.*10)*: succeed at entry" hash.txt | tail -1 \
+ | awk '{print $NF}')
+ echo "$pcr $lineno"
+ return $ret
}
test1_tpm_bypass_mode()
@@ -249,7 +252,9 @@ test1()
test2()
{
- local hash pcr_aggregate out ret
+ local hash pcr_aggregate lineno out ret
+ local measurement_count="$IMA_DIR/runtime_measurements_count"
+ local total_measurements
tst_res TINFO "verify PCR values"
@@ -288,14 +293,21 @@ test2()
tst_res TINFO "real PCR-10: '$hash'"
get_pcr10_aggregate > tmp.txt
- pcr_aggregate="$(cat tmp.txt)"
- if [ -z "$pcr_aggregate" ]; then
- return
- fi
- tst_res TINFO "aggregate PCR-10: '$pcr_aggregate'"
+ if [ $? -eq 0 ]; then
+ pcr_aggregate="$(cat tmp.txt | cut -d " " -f1)"
+ if [ -z "$pcr_aggregate" ]; then
+ return
+ fi
+ tst_res TINFO "aggregate PCR-10: '$pcr_aggregate'"
- if [ "$hash" = "$pcr_aggregate" ]; then
- tst_res TPASS "aggregate PCR value matches real PCR value"
+ lineno="$(cat tmp.txt | cut -d " " -f2)"
+
+ if [ "$hash" = "$pcr_aggregate" ]; then
+ tst_res TPASS "aggregate PCR value matches real PCR value (line: $lineno)"
+ else
+ total_measurements=$(cat "$measurement_count")
+ tst_res TPASS "aggregate PCR value matched real PCR value (line: $lineno/$total_measurements)"
+ fi
else
tst_res TFAIL "aggregate PCR value does not match real PCR value"
fi
--
2.55.0
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [LTP] ima_tpm.sh: properly detect failure to verify the IMA measurement list
2026-08-26 0:34 ` Mimi Zohar
(?)
@ 2026-08-26 1:15 ` linuxtestproject.agent
-1 siblings, 0 replies; 3+ messages in thread
From: linuxtestproject.agent @ 2026-08-26 1:15 UTC (permalink / raw)
To: Mimi Zohar; +Cc: ltp
Hi Mimi,
On Tue, 25 Aug 2026, Mimi Zohar wrote:
> ima_tpm.sh: properly detect failure to verify the IMA measurement list
> if [ -z "$pcr" ]; then
> tst_res $res "failed to find aggregate PCR-10 $msg"
> tst_res TINFO "hash file:"
> cat hash.txt >&2
> - return
> + return 1
> fi
> + else
> + tst_res TFAIL "aggregate PCR value does not match real PCR value"
> + fi
Could the helper's result classification be preserved here instead of
unconditionally adding TFAIL for every nonzero return?
When evmctl is older than 1.3.1 with a SHA-1 measurement list, setup allows
the test to continue with MISSING_EVMCTL=1. If that evmctl does not produce
a parseable aggregate, the helper reports TCONF through $res, but the new
return path then also records TFAIL. Since tst_res retains both result bits,
this unsupported-tool path becomes a test failure.
Verdict - Needs revision
---
Note:
The agent can sometimes produce false positives although often its
findings are genuine. If you find issues with the review, please
comment this email or ignore the suggestions.
Regards,
LTP AI Reviewer
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-08-26 1:15 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-26 0:34 [LTP] [PATCH] ima_tpm.sh: properly detect failure to verify the IMA measurement list Mimi Zohar
2026-08-26 0:34 ` Mimi Zohar
2026-08-26 1:15 ` [LTP] " linuxtestproject.agent
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.