From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from list by lists.gnu.org with archive (Exim 4.90_1) id 1iO3Vx-0008Lj-Df for mharc-grub-devel@gnu.org; Fri, 25 Oct 2019 13:36:41 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:47024) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1iO3Vs-0007iW-T5 for grub-devel@gnu.org; Fri, 25 Oct 2019 13:36:39 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1iO3Vp-0003d0-Ug for grub-devel@gnu.org; Fri, 25 Oct 2019 13:36:35 -0400 Received: from us-smtp-delivery-1.mimecast.com ([207.211.31.120]:47093 helo=us-smtp-1.mimecast.com) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1iO3Vp-0003Zd-Qg for grub-devel@gnu.org; Fri, 25 Oct 2019 13:36:33 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1572024992; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=OBrpZXDSoznmSdyAX3aZSuzHg0RIlocC2z6VGInslvg=; b=AdWX38zMyMt9BohmC98csaYjYWPlUJxAbk+WagFYtDYKmmfD2AcSqRaACJjdbBgOf3PdFM MZRDEuMGfEDB6S0OHJmncQp+G2oi/YNhQkumL7OYelt2cslgSlB6Kiu8oEmKnH7tRXlKGN rHkJ481e4IK1TVbT9ScAHHPaiTPXqHs= Received: from mail-wr1-f70.google.com (mail-wr1-f70.google.com [209.85.221.70]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-297-Aybhig6rPPOt7rZ9PgrOcw-1; Fri, 25 Oct 2019 13:36:28 -0400 Received: by mail-wr1-f70.google.com with SMTP id 92so1620780wro.14 for ; Fri, 25 Oct 2019 10:36:27 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=b1oUUbnVbqODHl+I/4bF89wnDa0xJ+eNOja9PvbO+Rs=; b=r8rnR7xo5fwHM2Deji804tqTjVQ2+uBm4nUgs8fD4dJ58YdiLZplqQT6FzACbiHv9S w+gyxZ4yyH8CpRz76mtC4O8eOUvtFCmcXmsugTKsk4jq83H73Dx+D1dYCMyBp+q/l4Wt cJ2lsZe+d/D79cb+m5q7+koDSzWbBRku3XDBnsOwoN0SKT2sowZsIWPPo0V0tZmE7BDC OlI4ttUB6njNLzMtsmW2B6Tou1gONGDXmReCS5V1OA6YVyYIneIyy1N08dO8GgsiZjrS n5EdeG9UTfytChuywUt20pHr8HdCd+YhZBV/4S8V6y3ld5ZPeO8FVPqMoDYoYbNmMvGB IeKQ== X-Gm-Message-State: APjAAAWX/T3widOCTnKJ839dat4vetgE42hZZKgMgFtllcYFxii31rjJ u33iPz5+4+EoMKiqiCh8m7ID+XDRxrT8OoNKwVswvYpYfEvdR+lfkMH8Ed0DDq6lcnTzZySZftD j2pm6pp6gGNM= X-Received: by 2002:a05:600c:2152:: with SMTP id v18mr4663045wml.170.1572024986977; Fri, 25 Oct 2019 10:36:26 -0700 (PDT) X-Google-Smtp-Source: APXvYqzzoH/gIq0uXXs2x6180IPdicHhjKO/lXCaOfcoTF54CXEVCYp9CpIXnQQUq4/3LAUACVzK7Q== X-Received: by 2002:a05:600c:2152:: with SMTP id v18mr4663029wml.170.1572024986685; Fri, 25 Oct 2019 10:36:26 -0700 (PDT) Received: from [192.168.1.13] ([90.168.169.92]) by smtp.gmail.com with ESMTPSA id g69sm2672521wme.31.2019.10.25.10.36.25 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 25 Oct 2019 10:36:26 -0700 (PDT) Subject: Re: [PATCH] tpm: Pass unknown error as non-fatal, but debug print the error we got To: The development of GNU GRUB , Mathieu Trudel-Lapierre , Mathieu Trudel-Lapierre References: <20191025142754.1514-1-mathieu.trudel-lapierre@canonical.com> From: Javier Martinez Canillas Message-ID: <7bc13635-52bd-9caa-14f5-312bffe682e2@redhat.com> Date: Fri, 25 Oct 2019 19:36:25 +0200 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Thunderbird/68.1.0 MIME-Version: 1.0 In-Reply-To: Content-Language: en-US X-MC-Unique: Aybhig6rPPOt7rZ9PgrOcw-1 X-Mimecast-Spam-Score: 0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] [fuzzy] X-Received-From: 207.211.31.120 X-BeenThere: grub-devel@gnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: The development of GNU GRUB List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 25 Oct 2019 17:36:39 -0000 Hello Mathieu, On 10/25/19 4:48 PM, Mathieu Trudel-Lapierre wrote: > On Fri, Oct 25, 2019 at 10:28 AM Mathieu Trudel-Lapierre > wrote: >> >> Signed-off-by: Mathieu Trudel-Lapierre >> Patch-Name: ubuntu-tpm-unknown-error-non-fatal.patch >> --- >> grub-core/commands/efi/tpm.c | 12 ++++++++---- >> 1 file changed, 8 insertions(+), 4 deletions(-) >> >=20 > I see I omitted to explain why I'm proposing this. >=20 > I've seen a couple of reports so far of issues with booting with TPM > measurement enabled, when the firmware has TPM enabled, on some > hardware. >=20 > In particular, this has happened on a Dell laptop at Plumbers this > year (an older model XPS15 IIRC), and a few different models of > laptops/motherboards. Some report having a TPM, and some do not: >=20 > HP EliteBook 820 G4 (Infineon SLB9670?) > ASUS M32CD4-K motherboard (unknown) > ASUS ROG GL553VE Laptop (unknown) > ASUS ZenBook 3 UX390UA (unknown) > ASUS Zenbook UX305FA (unspecified TPM) > ASUS ZenBook UX303UA (unknown) > ASUS 2O7HSV6 ?? >=20 > See https://bugs.launchpad.net/ubuntu/+source/grub2/+bug/1848892. > Yes, we also got similar reports for Fedora, i.e: https://bugzilla.redhat.com/show_bug.cgi?id=3D1645903 =20 > Unfortunately the reports are not of great quality, but I'm starting > to worry about what exactly is wrong, if it's really a firmware / TPM > issue or a bug in the TPM code. >=20 > For now, it seems like the best is to get more information as to what > exactly the failure is (hence grub_dprintf()), and treating these Agreed. It would be good to get know the exact EFI status code returned by the firmware in the case of a failure. > errors as non-fatal so people can still boot. > I think that we should go even further and make all the TPM measurement errors to be non-fatal. For example something like the following patch [0]. > After briefly discussing this with others, it's not clear whether all > the affected systems really do have a TPM, but they might still report > in firmware that they do. Are we running into a case where the > firmware wrongly reports there is a TPM, but fails to do any > measurements? >=20 That's interesting. I see that EFI_TCG2_PROTOCOL.GetCapability() is called and the EFI_TCG2_BOOT_SERVICE_CAPABILITY.TPMPresentFlag checked to know if a TPM is present or not. So would be very weird that the firmware reported that a TPM is present but that's not the case. Maybe the machines did have a TPM but the reporter just didn't know? [0]: >From 0d404b65cddcf92e96d3cfa6e23b82e336d2535b Mon Sep 17 00:00:00 2001 From: Javier Martinez Canillas Date: Fri, 25 Oct 2019 19:27:26 +0200 Subject: [RFC PATCH] tpm: Don't propagate TPM measurement failures to the verifiers layer Currently if the EFI firmware fails to do a TPM measurement for a file, the error will be propagated to the verifiers framework and so opening the file will not succeed. This mean that buggy firmwares will prevent an operating system to boot since the loader won't be able to open the kernel binaries. But failing to do TPM measurements shouldn't be a fatal error and the system should still be able to boot. Signed-off-by: Javier Martinez Canillas --- grub-core/commands/tpm.c | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git grub-core/commands/tpm.c grub-core/commands/tpm.c index 1441c494d81..dbaeae46dfa 100644 --- grub-core/commands/tpm.c +++ grub-core/commands/tpm.c @@ -49,7 +49,8 @@ grub_tpm_verify_init (grub_file_t io, static grub_err_t grub_tpm_verify_write (void *context, void *buf, grub_size_t size) { - return grub_tpm_measure (buf, size, GRUB_BINARY_PCR, context); + grub_tpm_measure (buf, size, GRUB_BINARY_PCR, context); + return GRUB_ERR_NONE; } =20 static grub_err_t @@ -57,7 +58,6 @@ grub_tpm_verify_string (char *str, enum grub_verify_strin= g_type type) { const char *prefix =3D NULL; char *description; - grub_err_t status; =20 switch (type) { @@ -73,15 +73,15 @@ grub_tpm_verify_string (char *str, enum grub_verify_str= ing_type type) } description =3D grub_malloc (grub_strlen (str) + grub_strlen (prefix) + = 1); if (!description) - return grub_errno; + return GRUB_ERR_NONE; grub_memcpy (description, prefix, grub_strlen (prefix)); grub_memcpy (description + grub_strlen (prefix), str, =09 grub_strlen (str) + 1); - status =3D - grub_tpm_measure ((unsigned char *) str, grub_strlen (str), -=09=09 GRUB_STRING_PCR, description); + + grub_tpm_measure ((unsigned char *) str, grub_strlen (str), GRUB_STRING_= PCR, + description); grub_free (description); - return status; + return GRUB_ERR_NONE; } =20 struct grub_file_verifier grub_tpm_verifier =3D { --=20 2.21.0 Best regards, --=20 Javier Martinez Canillas Software Engineer - Desktop Hardware Enablement Red Hat