From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id D4CF6C433EF for ; Thu, 25 Nov 2021 20:27:43 +0000 (UTC) Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id 07B1482FE5; Thu, 25 Nov 2021 21:27:41 +0100 (CET) Authentication-Results: phobos.denx.de; dmarc=fail (p=none dis=none) header.from=gmx.de Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (1024-bit key; secure) header.d=gmx.net header.i=@gmx.net header.b="eohap30X"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id EDEA283257; Thu, 25 Nov 2021 21:27:38 +0100 (CET) Received: from mout.gmx.net (mout.gmx.net [212.227.15.15]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id 1ACBF82FA2 for ; Thu, 25 Nov 2021 21:27:35 +0100 (CET) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=gmx.de Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=xypron.glpk@gmx.de DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=gmx.net; s=badeba3b8450; t=1637872052; bh=jMyIgIVXMa0MkwUMFfBWDwgNHi7tiJek/GFeDL9kkRg=; h=X-UI-Sender-Class:Date:Subject:To:Cc:References:From:In-Reply-To; b=eohap30XnjQz8Jrwq08y662GK4v0KvvUEA4fFY5Aredf7W/fEoQ/VRprEiaUwsMsn rBdFlRvKD7sO32rD38/iLg9hSpQSDqyqGdcm1NXz5bwQtxN/yTFB624TKcmDUG96ZC sw4J0EqHPX+ZohMKW8wBCY0uygWF+9/kX7LHR2Zo= X-UI-Sender-Class: 01bb95c1-4bf8-414a-932a-4f6e2808ef9c Received: from [192.168.123.55] ([88.152.144.157]) by mail.gmx.net (mrgmx005 [212.227.17.190]) with ESMTPSA (Nemesis) id 1ML9yS-1n7KGE20UE-00IAwL; Thu, 25 Nov 2021 21:27:32 +0100 Message-ID: <4d7b1c20-fd4a-cfed-4a7d-d584a73de312@gmx.de> Date: Thu, 25 Nov 2021 21:27:17 +0100 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Thunderbird/91.3.2 Subject: Re: [PATCH v2] efi_loader: check tcg2 protocol installation outside the TCG protocol Content-Language: en-US To: Ilias Apalodimas Cc: u-boot@lists.denx.de, Simon Glass , Ruchika Gupta , Alexander Graf , Masahisa Kojima , Tom Rini References: <20211125113628.29609-1-masahisa.kojima@linaro.org> From: Heinrich Schuchardt In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: quoted-printable X-Provags-ID: V03:K1:S5axK6cjXb6SqA/A6BhIOvnWShGtzVIWi5Not560inGwwDsgEIp xiKG7jAIeA71ZUiID/DQF4LHg1MHPw9aZVkZJbOQ8VycSTN0znq1uEExxN/ysXXRnAycOF9 qOYQODGX1L/4Jfuz68gfcj2WJol//6ljcCZeXLX4QSQ06FpL+X0mazxwCtTq2eG88NWrdnM VBUajEwv2UlXAmEGwHRag== X-UI-Out-Filterresults: notjunk:1;V03:K0:H7az/KgUXg8=:FWlOzyOLMJtoDM6IIAxIAY O5A3+5vC1MjAa8zIsdl7wJzlVgV49jiGDKrcxAhVKzkl567koT//LYQd2IamktEOV7KNwAPFc n/yMgy3P/xl3s+RjE2Li791KAfCYaMkYM/n84QikqCh9ZbVTrhphpRgq5I6DzSFxwE+R8Ahsw 83pJDyGNhi7Q4Dep4/Pdnur4V9fRUPl83CdWumqaqxfg4X3KqHtidDlijjsoIXcmY/nvcqu8X pH5D75334T4PE0/eJWckAWlZdxwZc65fZ9j5YU8XO4TxALtqmLFKW3AtzpGBLa+2YCRE13xBR L5BC5nwoME3n5a2pwTIoBNKzpSEP6l96dp/cKBAhaAh5SSy2OBVF+NxblKSn25ogIU67DcdEt Hw7pushynSqWEf7EGOu4Ytdy0jF8QsVjQNoi0v/jgg9VcKUdh8+L2Lt6LZOmPUlJK2G7h97ow ePF43ndQeyTm80fuzMOBiSAaz3UdW4KYOcxGAu2XAoaE7Q/B/ytNMPp80mTgjbMDf/9kKKNIq eKkNe3HXBAvzEk7CtUJ6pdUrwfDIoU3khwNLzCIib6H4/1CY9J5ku8FSA30Ie+tSsHd7KvLfj iKEmGvPWPdkcABqrYX5W/WRK0CjCYB82GDW6mIrK1IzXbpBAO5wzSMH+CccSTNCMrIaCOSqT5 8D2A0kaJs36wU9XflFoCeuhNPdp+wJgoArNcYwJ14ApSoS5+RgbFlOEfp7u2vItghmRwYLq4L zTtczGUVvhp1mKf4XCN8uhjsV2ti71a4DTqzvN3uGhZVU82AULiPOWiV/PWQ2KrPJL1ZcYcZO Ezhz5iBjjArbHAOhwsMBDuOlZFO9BZg7FF6Y7uefwnE8h+8kwuXWhaNX6Qw8CktvVA05hpZvk sZBg/sMyhKhhv18AP4dqisLzvlDM3QLApSCwI8pO0n6RbrxmvhqY0ZKih9IlSLKLYbuUztMuU pVQweHEGBviRFfpmh/rvPgGKGDrcGU0E2AgN7ICcf0kTQk8ISpOjb2V5vZmymQu7c5y4stCTH irQl51SauIafVEHJKzzwsCGeLitXDmIHRVLx/F8+gSVS0vAIZEb5DqUMluLae6v/56dWFzJyB gkkNTgNO8uTNB0= X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.37 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.2 at phobos.denx.de X-Virus-Status: Clean On 11/25/21 14:22, Ilias Apalodimas wrote: > Hi Kojima-san, > > On Thu, Nov 25, 2021 at 08:36:28PM +0900, Masahisa Kojima wrote: >> +/** > > [...] > >> + * is_tcg2_protocol_installed - chech whether tcg2 protocol is install= ed >> + * >> + * @Return: true if tcg2 protocol is installed, false if not >> + */ >> +bool is_tcg2_protocol_installed(void) >> +{ >> + struct efi_handler *handler; >> + efi_status_t ret; >> + >> + ret =3D efi_search_protocol(efi_root, &efi_guid_tcg2_protocol, &handl= er); >> + return ((ret =3D=3D EFI_SUCCESS) ? true : false); >> +} > > return ret =3D=3D EFI_SUCCESS; is enough here. > >> + >> static u32 tcg_event_final_size(struct tpml_digest_values *digest_lis= t) >> { >> u32 len; >> @@ -962,6 +976,9 @@ efi_status_t tcg2_measure_pe_image(void *efi, u64 e= fi_size, >> IMAGE_NT_HEADERS32 *nt; >> struct efi_handler *handler; >> >> + if (!is_tcg2_protocol_installed()) >> + return EFI_NOT_READY; >> + >> ret =3D platform_get_tpm2_device(&dev); >> if (ret !=3D EFI_SUCCESS) >> return ret; >> @@ -2140,6 +2157,9 @@ efi_status_t efi_tcg2_measure_efi_app_invocation(= struct efi_loaded_image_obj *ha >> u32 event =3D 0; >> struct smbios_entry *entry; >> >> + if (!is_tcg2_protocol_installed()) >> + return EFI_NOT_READY; >> + >> if (tcg2_efi_app_invoked) >> return EFI_SUCCESS; >> >> @@ -2190,6 +2210,9 @@ efi_status_t efi_tcg2_measure_efi_app_exit(void) >> efi_status_t ret; >> struct udevice *dev; >> >> + if (!is_tcg2_protocol_installed()) > > [...] > > Heinrich, this whole patch is needed because installing the tcg2 protoc= ol > always returns EFI_SUCCESS. The reason is that some sandbox tests with > sandbox_tpm used to fail. Do you want to keep this or perhaps just fail= ing > the boot now is the protocol fails to install is an option ? Which test failed? We should consistently test the TCG2 protocol using swtpm both on QEMU and on the sandbox. I am still waiting for Tom to apply [U-BOOT-TEST-HOOKS,1/1] Enable TPMv2 emulation https://patchwork.ozlabs.org/project/uboot/patch/20211115101106.36479-1-he= inrich.schuchardt@canonical.com/ to move to that target. Until then we can disable the tcg2 test or the TCG2 protocol on the sandbo= x. Best regards Heinrich