From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 14581C433EF for ; Mon, 14 Feb 2022 06:18:12 +0000 (UTC) Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id 7964B82D3B; Mon, 14 Feb 2022 07:18:10 +0100 (CET) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=linaro.org Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (2048-bit key; unprotected) header.d=linaro.org header.i=@linaro.org header.b="G1vdgWlU"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id 562CB83BEB; Mon, 14 Feb 2022 07:18:09 +0100 (CET) Received: from mail-wr1-x42b.google.com (mail-wr1-x42b.google.com [IPv6:2a00:1450:4864:20::42b]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id 1809D80615 for ; Mon, 14 Feb 2022 07:18:06 +0100 (CET) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=linaro.org Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=ilias.apalodimas@linaro.org Received: by mail-wr1-x42b.google.com with SMTP id u1so11310870wrg.11 for ; Sun, 13 Feb 2022 22:18:06 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; h=date:from:to:subject:message-id:references:mime-version :content-disposition:in-reply-to; bh=06/EB/7VnDkZ0ezNIt2K0B0vHDc5tcStVZ/Ya23LrSo=; b=G1vdgWlUZhNKg4eo4SZJdgWhEW0brad5m+fAy8EJNFtSFZv0qUjgXNG63SfqIun+hS eGyJUJlo7mlN97s/dtUcFpJtQkjMo8NSgOGvsEQ/FUnx0rV5sxif85JUa6oHArbLsMWd wwgH/e2L2vYZmM5VzFgNpjMDX9SyD6my69pedClkpcyRsAbq4S2VQtYQdXQQCeHT9m+E YmHsr3X6D2K+G3riKBErQe97UVtdGQJLRCccGFFD6Xl50/lEWHalhx+BcQiVq99okPxQ jPqIr0e0hZau2Hj+SMP23gyvLYtIxlmx0jGQMbuKaUhHA4pRHKHpCLeBXSBSNfSzOv7/ 0nmg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:date:from:to:subject:message-id:references :mime-version:content-disposition:in-reply-to; bh=06/EB/7VnDkZ0ezNIt2K0B0vHDc5tcStVZ/Ya23LrSo=; b=a9SucyfwGpFT1YF1wXDHYemNXSrp3hv89KRj5/05f86eVB/ud7PMn4cOtDsA/uyTdz nHYMECMYjc5X1Q1uuJeo27EcNFRYYvyxIM4TB5CyTNK8k1UvD2n68iiD0Ja2n4QB2SzV xpF5BYbWRbhMvKcH4wxvbYqkaIQQLaPt9Adv8Sw20Tv12Z582vG9nnhIPyy/Zk4kC1S0 ZF7QMqmDuSe81Sy04JJmUzrzEgg66PHs5p/UFziLdMcK0LgB1XZxj/zpS9T++Wi5V/r1 4eLA6t0ZpicIiCIsGeJQQ1OHPIOc0hb08shP+gUd1n3oAuNmSuKDFF+7wdsULl3su7/k AEIw== X-Gm-Message-State: AOAM532ZPJY5WMD9GKfA8aSSuqqhPPaGidCvk2vASoQHcW4vIB/scjGs 0f3i+QdrAGWGBrKkTxUp4UvxDw== X-Google-Smtp-Source: ABdhPJyrsbz+BV2RJV85IJzPMXKrvj19nFQ6o7o8YDEWb5/TOSdj9kg7P+lt+ef6gnP8BTAY02CSBQ== X-Received: by 2002:adf:fe81:: with SMTP id l1mr9975779wrr.194.1644819485610; Sun, 13 Feb 2022 22:18:05 -0800 (PST) Received: from hades (athedsl-4461669.home.otenet.gr. [94.71.4.85]) by smtp.gmail.com with ESMTPSA id c13sm28195286wrv.24.2022.02.13.22.18.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 13 Feb 2022 22:18:05 -0800 (PST) Date: Mon, 14 Feb 2022 08:18:03 +0200 From: Ilias Apalodimas To: AKASHI Takahiro , xypron.glpk@gmx.de, u-boot@lists.denx.de Subject: Re: [PATCH 2/2] test/py: efi_secboot: adjust secure boot tests to code changes Message-ID: References: <20220211073750.733348-1-ilias.apalodimas@linaro.org> <20220211073750.733348-2-ilias.apalodimas@linaro.org> <20220214015008.GD39639@laputa> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20220214015008.GD39639@laputa> X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.39 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.5 at phobos.denx.de X-Virus-Status: Clean On Mon, Feb 14, 2022 at 10:50:08AM +0900, AKASHI Takahiro wrote: > Ilias, > > On Fri, Feb 11, 2022 at 09:37:50AM +0200, Ilias Apalodimas wrote: > > The previous patch is changing U-Boot's behavior wrt certificate based > > binary authentication. Specifically an image who's digest of a > > certificate is found in dbx is now rejected. Fix the test accordingly > > and add another one testing signatures in reverse order > > > > Signed-off-by: Ilias Apalodimas > > --- > > changes since RFC: > > - Added another test cases checking signature hashes in reverse order > > test/py/tests/test_efi_secboot/test_signed.py | 30 +++++++++++++++++-- > > 1 file changed, 28 insertions(+), 2 deletions(-) > > > > diff --git a/test/py/tests/test_efi_secboot/test_signed.py b/test/py/tests/test_efi_secboot/test_signed.py > > index 0aee34479f55..cc9396a11d48 100644 > > --- a/test/py/tests/test_efi_secboot/test_signed.py > > +++ b/test/py/tests/test_efi_secboot/test_signed.py > > @@ -186,7 +186,7 @@ class TestEfiSignedImage(object): > > assert 'Hello, world!' in ''.join(output) > > > > with u_boot_console.log.section('Test Case 5c'): > > - # Test Case 5c, not rejected if one of signatures (digest of > > + # Test Case 5c, rejected if one of signatures (digest of > > # certificate) is revoked > > output = u_boot_console.run_command_list([ > > 'fatload host 0:1 4000000 dbx_hash.auth', > > @@ -195,7 +195,8 @@ class TestEfiSignedImage(object): > > output = u_boot_console.run_command_list([ > > 'efidebug boot next 1', > > 'efidebug test bootmgr']) > > - assert 'Hello, world!' in ''.join(output) > > + assert '\'HELLO\' failed' in ''.join(output) > > + assert 'efi_start_image() returned: 26' in ''.join(output) > > > > with u_boot_console.log.section('Test Case 5d'): > > # Test Case 5d, rejected if both of signatures are revoked > > @@ -209,6 +210,31 @@ class TestEfiSignedImage(object): > > assert '\'HELLO\' failed' in ''.join(output) > > assert 'efi_start_image() returned: 26' in ''.join(output) > > > > + # Try rejection in reverse order. > > "Reverse order" of what? Of the test right above > > > + u_boot_console.restart_uboot() > > I don't think we need 'restart' here. > I added it in each test function (not test case), IIRC, because we didn't > have file-based non-volatile variables at that time. You do. dbx already holds dbx_hash.auth and dbx1_hash.auth (in that order) at that point. The point is cleaning up dbx and testing against dbx1_hash. > > > + with u_boot_console.log.section('Test Case 5e'): > > + # Test Case 5e, authenticated even if only one of signatures > > + # is verified. Same as before but reject dbx_hash1.auth only > > Please specify what test case "before" means. The test that run right before that > > > + output = u_boot_console.run_command_list([ > > + 'host bind 0 %s' % disk_img, > > + 'fatload host 0:1 4000000 db.auth', > > + 'setenv -e -nv -bs -rt -at -i 4000000:$filesize db', > > + 'fatload host 0:1 4000000 KEK.auth', > > + 'setenv -e -nv -bs -rt -at -i 4000000:$filesize KEK', > > + 'fatload host 0:1 4000000 PK.auth', > > + 'setenv -e -nv -bs -rt -at -i 4000000:$filesize PK', > > + 'fatload host 0:1 4000000 db1.auth', > > + 'setenv -e -nv -bs -rt -at -a -i 4000000:$filesize db', > > + 'fatload host 0:1 4000000 dbx_hash1.auth', > > + 'setenv -e -nv -bs -rt -at -i 4000000:$filesize dbx']) > > Now "db" has db.auth and db1.auth in this order and > 'dbx" has dbx_hash1.auth. > Is this what you intend to test? Yes. The patchset solved 2 bugs. One was not rejecting the image when a single dbx entry was found. The second was that depending on the order the image was signed and the keys inserted into dbx, the code could reject or accept the image. > > -Takahiro Akashi > > > + assert 'Failed to set EFI variable' not in ''.join(output) > > + output = u_boot_console.run_command_list([ > > + 'efidebug boot add -b 1 HELLO host 0:1 /helloworld.efi.signed_2sigs -s ""', > > + 'efidebug boot next 1', > > + 'efidebug test bootmgr']) > > + assert '\'HELLO\' failed' in ''.join(output) > > + assert 'efi_start_image() returned: 26' in ''.join(output) > > + > > def test_efi_signed_image_auth6(self, u_boot_console, efi_boot_env): > > """ > > Test Case 6 - using digest of signed image in database > > -- > > 2.32.0 > > Regards /Ilias