From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 302F9C433FE for ; Fri, 1 Oct 2021 16:43:39 +0000 (UTC) Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 7895C61A6E for ; Fri, 1 Oct 2021 16:43:38 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.4.1 mail.kernel.org 7895C61A6E Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=gmx.de Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=lists.denx.de Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id AB7D182021; Fri, 1 Oct 2021 18:43:36 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=fail (p=none dis=none) header.from=gmx.de Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (1024-bit key; secure) header.d=gmx.net header.i=@gmx.net header.b="EBtiuptC"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id E981B82006; Fri, 1 Oct 2021 18:43:32 +0200 (CEST) Received: from mout.gmx.net (mout.gmx.net [212.227.17.21]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id 1375081FEC for ; Fri, 1 Oct 2021 18:43:29 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=gmx.de Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=xypron.glpk@gmx.de DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=gmx.net; s=badeba3b8450; t=1633106607; bh=5Jjp/Px7omxn+4eGKSKyByfpADnulKXBWqSLPMZtKeI=; h=X-UI-Sender-Class:Date:Subject:To:Cc:References:From:In-Reply-To; b=EBtiuptCfwcMas266gTJjFmwO5P3KO5e8FRO1Bdp20MPrAA4bI5fBDhncC245kmI4 4scLtsD2wRRGTYFsA/pzBs4g1USzXq65so0VVTz9ZWd+gzdnkeGtd6qI6ximPq15RO Gi+dBVF53H9BKxLc137B85tKrngHZlPmsSSeYcSw= X-UI-Sender-Class: 01bb95c1-4bf8-414a-932a-4f6e2808ef9c Received: from [192.168.123.55] ([88.152.144.157]) by mail.gmx.net (mrgmx104 [212.227.17.168]) with ESMTPSA (Nemesis) id 1Ma20q-1mI4Ql2cSa-00VxoQ; Fri, 01 Oct 2021 18:43:27 +0200 Message-ID: <9944b9ef-e47b-7f57-1b78-ca797358d1cf@gmx.de> Date: Fri, 1 Oct 2021 18:43:27 +0200 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Thunderbird/91.1.1 Subject: Re: [PATCH v3 3/3] efi_loader: add DeployedMode and AuditMode variable measurement Content-Language: en-US To: Masahisa Kojima Cc: Ilias Apalodimas , Alexander Graf , u-boot@lists.denx.de References: <20211001111844.7422-1-masahisa.kojima@linaro.org> <20211001111844.7422-4-masahisa.kojima@linaro.org> From: Heinrich Schuchardt In-Reply-To: <20211001111844.7422-4-masahisa.kojima@linaro.org> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: quoted-printable X-Provags-ID: V03:K1:qeCAwcyf9l7sL4U879mQDZC4f0FYikOTjD/byrxIrqklLdrnYji G1zgdLB3XCQiWBJHXyeFvYRA0U4YZOa2hlz0wDciTLjk6EADUdKZVlE4oq/AFtZYNGRNEEl yrpJNfIeXoiWLcE28x5MS93RJNiF9LoQEu2SFf2oqecXAKPR2EMQ58mlJo/f5ROWEOfgu72 WG8G8f1f/xMEBPVRdkpUw== X-UI-Out-Filterresults: notjunk:1;V03:K0:iulKiA43l48=:66qudXrCim3UM0H/E2cn9j qgxCLckv0x+abj5XgUySGAIos9MXFH3+ErK2ihkWXskNjRUoDfSNgkXiFtO9uUY48FijcnKaH 7zig40q9FBuGvyVhpPXH5wTw8QfJ2LdOTWNpR9Dc49Q0+vXOMc9lH7MEzL8ZbxImNh+OT+XNw 8EQpvZhNyWiiw9JzV/eObr1RPsDGkzThyjZx8fLREShi6/toU2TCEG52fFdRY3BML1qnyD8/P w9n8qxpHMoVo5RQ3DnNHvasSVdc983ux3phJBTzj2CdzLBgIbqXHGdUQ2en7Abok/0hebvWgC n3AAyul2UViUNPvYByaUHXzCywraQbKyVAnyI7CLuZC3zJf1fui7Ms3WQzcdsYgBTycT51+o2 9PJ+yDxL/crmzopdLh9RV2cmDsTbekr64YOKY7ZDpmU1isR9hf0LFxpogJqABOCqFvxYboTVr 6i1TNVpxu335HuPAN7O7SD1VShTKWEsHpxk1B9HC5vinR9WQloydh07kR2HO20OAKtH0H7EeS gRhg+NwUl00+Q7omQdyEo0cezHOd29EHk/Ym41RGNsq2s7QZyFltgCVai180CwtTzFd5JgoNO SamrAh891GD4gldE7YcjXMKG3jS3IrGiNOAdC1GhyrSGAeKDPXRUoY9OAAoQgkNPT0L0f1Rq1 K3yU4upFVfnI0jIa9Z2EyLAEGNcFP+0L3zofqRcaSdymjzS5up91VR4rsc0pbhQfZILy1TD5h GCqtbCtZL43Odx8VHyImf8i3VadBXwRBOkiOvkFZJ/ghd6rLcb9EHg3oyJYHk/5O7g+qZ7VoJ y4kac+q9L7c0m2NIvOlQ2sbnpM0bZxZ5ll/EBFkJwvsT8y7Riqw+nZiqjnPbmwbEP6oUcK6qd /9O61G7xQbAGr3zd19NAjErsV3S0+6XnPFNLs3v33tcq4m45Kc8VaRlQogxlwgTP6o6YlpSW+ Clza/zaeMWg/UqLRHbWd5U6DzCQF7WTm0NUGSpILvTtnR96peD7cXdDOyk02zIH3nNtV4plLQ cV7wZD3SDWyFG7qYORN1tPzwQIq7jnQt2SCwX50a7ctLVf81rO/7xGUglqqL139tVX6jWwO67 lcwV/4F0Hto+lw= X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.34 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.2 at phobos.denx.de X-Virus-Status: Clean On 10/1/21 13:18, Masahisa Kojima wrote: > This commit adds the DeployedMode and AuditMode variable > measurement required in TCG PC Client PFP Spec. > > Signed-off-by: Masahisa Kojima > --- > > Changes in v3: > - read variable first, then mesure the variable > > lib/efi_loader/efi_tcg2.c | 50 +++++++++++++++++++++++++++++++++++++++ > 1 file changed, 50 insertions(+) > > diff --git a/lib/efi_loader/efi_tcg2.c b/lib/efi_loader/efi_tcg2.c > index 28e0362bf2..7fba4bc458 100644 > --- a/lib/efi_loader/efi_tcg2.c > +++ b/lib/efi_loader/efi_tcg2.c > @@ -12,6 +12,7 @@ > #include > #include > #include > +#include > #include > #include > #include > @@ -1822,6 +1823,53 @@ out: > return ret; > } > > +/** > + * tcg2_measure_deployed_audit_mode() - measure deployedmode and auditm= ode > + * > + * @dev: TPM device > + * > + * Return: status code > + */ > +static efi_status_t tcg2_measure_deployed_audit_mode(struct udevice *de= v) > +{ > + u8 deployed_mode; > + u8 audit_mode; > + efi_uintn_t size; > + efi_status_t ret; > + u32 pcr_index; > + > + size =3D sizeof(deployed_mode); > + ret =3D efi_get_variable_int(L"DeployedMode", &efi_global_variable_gui= d, > + NULL, &size, &deployed_mode, NULL); > + if (ret !=3D EFI_SUCCESS) > + return ret; > + > + size =3D sizeof(audit_mode); > + ret =3D efi_get_variable_int(L"AuditMode", &efi_global_variable_guid, > + NULL, &size, &audit_mode, NULL); > + if (ret !=3D EFI_SUCCESS) > + return ret; > + > + pcr_index =3D (deployed_mode ? 1 : 7); > + > + ret =3D tcg2_measure_variable(dev, pcr_index, > + EV_EFI_VARIABLE_DRIVER_CONFIG, > + L"DeployedMode", > + &efi_global_variable_guid, > + size, &deployed_mode); > + if (ret !=3D EFI_SUCCESS) > + return ret; > + > + > + ret =3D tcg2_measure_variable(dev, pcr_index, > + EV_EFI_VARIABLE_DRIVER_CONFIG, > + L"AuditMode", > + &efi_global_variable_guid, > + size, &audit_mode); > + > + return ret; > +} > + > /** > * tcg2_measure_secure_boot_variable() - measure secure boot variables > * > @@ -1885,6 +1933,8 @@ static efi_status_t tcg2_measure_secure_boot_varia= ble(struct udevice *dev) > free(data); > } > > + ret =3D tcg2_measure_deployed_audit_mode(dev); You do the same thing four times. A loop is preferable. Best regards Heinrich > + > error: > return ret; > } >