From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 8F865C61DA4 for ; Mon, 6 Feb 2023 12:20:24 +0000 (UTC) Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id CC7E685BBD; Mon, 6 Feb 2023 13:20:21 +0100 (CET) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=linaro.org Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (2048-bit key; unprotected) header.d=linaro.org header.i=@linaro.org header.b="GLaLR9am"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id C48F185821; Mon, 6 Feb 2023 13:20:19 +0100 (CET) Received: from mail-ej1-x629.google.com (mail-ej1-x629.google.com [IPv6:2a00:1450:4864:20::629]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id AF30F85BC8 for ; Mon, 6 Feb 2023 13:20:10 +0100 (CET) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=linaro.org Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=ilias.apalodimas@linaro.org Received: by mail-ej1-x629.google.com with SMTP id sa10so3210222ejc.9 for ; Mon, 06 Feb 2023 04:20:10 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=TaeSAXbh/55bHWXJlgQo+gPiw1bz81IiWamPOr0B9Q4=; b=GLaLR9amllxXSqEaXPlU/JicmQrAbuemR1Yv2fbAYnG5IlUxlOScM8Gnca4odBgFub UYUNvUwVOqpcEAm/OoYep+54a+ToApUfkwLd6RKOFVS7OeZJfjQFWpcjKJbGFUMtA1LV UMOOthLGdejG4VhmKvelHqoOj7YEWSm0d49XgsHJwLUi8Mn6wWXuVMY5tCaBsJLcZrIb M541wLRuegNFZ+GTB+yFy5LljM4lFB6PrVj350SjHrSpVa0NoIL8up3N5Tgmku5z0T3r 03of6B007BB9uWkzN/t+1LusLl4Sn8gnhDMRa8ErqS/79kY+885hDxfk8t/PYYJv0UV0 sEzg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=TaeSAXbh/55bHWXJlgQo+gPiw1bz81IiWamPOr0B9Q4=; b=x6jsy39lM/6sLXaZ/5SCZVwiSyWiLn5jUV0cnW7aV9nWbxgIQATklLICeGQ1/+p8X8 /k64m7tk8a+s+VDPbmdorTZG3oeXKhuPK/taxIh8DEZWw5vtkfjBrNm8VwrYpdfVvCUU rMvhjK/+n1/HCVURCOW8RFJjNi0sNhadiIBRtX8MCXqIOijqd8t9KnrNxPlCw+UnvksF 46XYpnjhQZoiIXz7b5IPYkYvIeQyE+2HR5p8H8i1OBfqs2zHZGrLQn2B8KIQ64NkJDO+ YClN9rVsmm+d2ZfeltFRxi9M1V/KUmom5kvqovZflSkOApM6RFm4VRKRTtSMqTDmAnVh h46A== X-Gm-Message-State: AO0yUKU1PzLFlTkNjZGDGEXQL2c0i8PwrU0rS62csZOJ7Ng/+RO9iZsQ /ojLMwSDhOm0x+kbqSf6ulmF9Q== X-Google-Smtp-Source: AK7set+mLoFEbl4BiLUDygGvqBGshJwTFmKHalZ+yKsUKZYc2wYrOY3XLa8BxGq9HsdtGcmPPLIhfQ== X-Received: by 2002:a17:907:3e82:b0:878:6755:9089 with SMTP id hs2-20020a1709073e8200b0087867559089mr26660808ejc.39.1675686010216; Mon, 06 Feb 2023 04:20:10 -0800 (PST) Received: from hades (ppp079167090036.access.hol.gr. [79.167.90.36]) by smtp.gmail.com with ESMTPSA id v21-20020a170906339500b008838b040454sm5427557eja.95.2023.02.06.04.20.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 06 Feb 2023 04:20:09 -0800 (PST) Date: Mon, 6 Feb 2023 14:20:07 +0200 From: Ilias Apalodimas To: Eddie James Cc: u-boot@lists.denx.de, sjg@chromium.org, xypron.glpk@gmx.de Subject: Re: [PATCH v5 0/6] tpm: Support boot measurements Message-ID: References: <20230202170531.119796-1-eajames@linux.ibm.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20230202170531.119796-1-eajames@linux.ibm.com> X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.39 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.6 at phobos.denx.de X-Virus-Status: Clean Thanks Eddie, I quickly tested this but the EFI subsystem fails to initialize the TCG protocol properly now. Unfortunately I am on a business trip and I won't be able to take a look into why till next week Cheers /Ilias On Thu, Feb 02, 2023 at 11:05:25AM -0600, Eddie James wrote: > This series adds support for measuring the boot images more generically > than the existing EFI support. Several EFI functions have been moved to > the TPM layer. The series includes optional measurement from the bootm > command. > A new test case has been added for the bootm measurement to test the new > path, and the sandbox TPM2 driver has been updated to support this use > case. > This series is based on Ilias' auto-startup series: > https://lore.kernel.org/u-boot/20230126081844.591148-1-ilias.apalodimas@linaro.org/ > > Changes since v4: > - Remove tcg2_measure_event function and check for NULL data in > tcg2_measure_data > - Use tpm_auto_startup > - Fix efi_tcg2.c compilation for removing tcg2_pcr_read function > - Change PCR indexes for initrd and dtb > - Drop u8 casting in measurement test > - Use bullets in documentation > > Changes since v3: > - Reordered headers > - Refactored more of EFI code into common code > Removed digest_info structure and instead used the common alg_to_mask > and alg_to_len > Improved event log parsing in common code to get it equivalent to EFI > Common code now extends PCR if previous bootloader stage couldn't > No need to allocate memory in the common code, so EFI copies the > discovered buffer like it did before > Rename efi measure_event function > > Changes since v2: > - Add documentation. > - Changed reserved memory address to the top of the RAM for sandbox dts. > - Add measure state to booti and bootz. > - Skip measurement for EFI images that should be measured > > Changes since v1: > - Refactor TPM layer functions to allow EFI system to use them, and > remove duplicate EFI functions. > - Add test case > - Drop #ifdefs for bootm > - Add devicetree measurement config option > - Update sandbox TPM driver > > Eddie James (6): > tpm: Fix spelling for tpmu_ha union > tpm: Support boot measurements > bootm: Support boot measurement > tpm: sandbox: Update for needed TPM2 capabilities > test: Add sandbox TPM boot measurement > doc: Add measured boot documentation > > arch/sandbox/dts/sandbox.dtsi | 14 + > arch/sandbox/dts/test.dts | 13 + > boot/Kconfig | 23 + > boot/bootm.c | 70 +++ > cmd/booti.c | 1 + > cmd/bootm.c | 2 + > cmd/bootz.c | 1 + > configs/sandbox_defconfig | 1 + > doc/usage/index.rst | 1 + > doc/usage/measured_boot.rst | 23 + > drivers/tpm/tpm2_tis_sandbox.c | 100 +++- > include/bootm.h | 2 + > include/efi_tcg2.h | 44 -- > include/image.h | 1 + > include/test/suites.h | 1 + > include/tpm-v2.h | 246 +++++++- > lib/efi_loader/efi_tcg2.c | 1010 +++----------------------------- > lib/tpm-v2.c | 771 ++++++++++++++++++++++++ > test/boot/Makefile | 1 + > test/boot/measurement.c | 66 +++ > test/cmd_ut.c | 2 + > 21 files changed, 1383 insertions(+), 1010 deletions(-) > create mode 100644 doc/usage/measured_boot.rst > create mode 100644 test/boot/measurement.c > > -- > 2.31.1 >