Received: by 2002:ac0:a5a6:0:0:0:0:0 with SMTP id m35-v6csp3757025imm; Mon, 17 Sep 2018 02:41:57 -0700 (PDT) X-Google-Smtp-Source: ANB0VdYFa9RRmkRHYpfW1sLaHOsNeWkQobpXXkv8d+Q1KM7QY7T1oRxoOb/qW8C/5QYNIzhciZDZ X-Received: by 2002:a17:902:a5c5:: with SMTP id t5-v6mr23739816plq.6.1537177317857; Mon, 17 Sep 2018 02:41:57 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1537177317; cv=none; d=google.com; s=arc-20160816; b=tO6WVOCtTiQhjqtDiAtOfaQFGiaHI6BayXUfb+fAqFx62QmKuZPRGlkpCqfbc1yCi3 mIOqvBU1snO/hYtf28FTAF10DUQhjGF48ZAW3fIk9G/9eDVFzjqI0+lX7uFOX8WyHEhM 28eHuNTSV/yi/gtWninogEaUGuOxzSI7808Jaa4tvJDvh0GNeZ/FPwADy9Bf4SHdssye bUCFtR8mm2tiLjvZtx0yDJp/ak8pH309uk8TAStXzaOidxbSyb0EVkcTSAjcm5Y5Tt4Q NrQJcVa0u5oI+a8tfWDHJpQFkmNRNDfZwfVcgx1LSbtn8+DYlN4eJmbt7dfn7Z0xipfx zL4Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from; bh=1BaWwlJawchGPLiWBAfABSSY/p7jzShAi99w0n747Qs=; b=owW6gmlOi+/xS3e6eMT93D12KNPlk95jq/AB3Qd71bc1qygt9RyAtF9T5LnwJN7JsF JCJhsZpvVk7azcaewWQ6nJFnpZkooyDBL8rie/k31v3BwhGB/qCqZSGCHSo8JznSOiKw BKhYK3UTeR782Xb6MGHg+NSJWIwfQfdPD1FeSLQH9SRIhTCPd7WWB6QTjJINbpqEmhlQ tGsOGqL63gsim2FvnRTU1eF5PqV0vEQ2FRd3hUubKeBZV9H6Z3lH+oTQrjyz2Y+1RpQS 3ljMInAhMMQKqQPi2IYxouhwHdxhzSAvPhgn9c4WnMnLtCB65WCGLmwdrFWDsZWUFncO Rbgw== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id b124-v6si15256028pgc.620.2018.09.17.02.41.42; Mon, 17 Sep 2018 02:41:57 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1728137AbeIQPII (ORCPT + 99 others); Mon, 17 Sep 2018 11:08:08 -0400 Received: from lhrrgout.huawei.com ([185.176.76.210]:2081 "EHLO huawei.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1726979AbeIQPIH (ORCPT ); Mon, 17 Sep 2018 11:08:07 -0400 Received: from LHREML712-CAH.china.huawei.com (unknown [172.18.7.107]) by Forcepoint Email with ESMTP id C55D4760BE9CB; Mon, 17 Sep 2018 10:41:25 +0100 (IST) Received: from roberto-HP-EliteDesk-800-G2-DM-65W.huawei.com (10.204.65.153) by smtpsuk.huawei.com (10.201.108.35) with Microsoft SMTP Server (TLS) id 14.3.399.0; Mon, 17 Sep 2018 10:41:03 +0100 From: Roberto Sassu To: CC: , , , Roberto Sassu Subject: [PATCH v2, RESEND 2/3] tpm: modify tpm_pcr_read() definition to pass TPM hash algorithms Date: Mon, 17 Sep 2018 11:38:19 +0200 Message-ID: <20180917093820.20500-3-roberto.sassu@huawei.com> X-Mailer: git-send-email 2.14.1 In-Reply-To: <20180917093820.20500-1-roberto.sassu@huawei.com> References: <20180917093820.20500-1-roberto.sassu@huawei.com> MIME-Version: 1.0 Content-Type: text/plain X-Originating-IP: [10.204.65.153] X-CFilter-Loop: Reflected Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Currently the TPM driver allows other kernel subsystems to read only the SHA1 PCR bank. This patch modifies the parameters of tpm_pcr_read() and tpm2_pcr_read() to pass an array of tpm_digest structures, which contains the desired hash algorithms. Initially, the array size is limited to 1. Due to the API change, IMA functions have been modified. Signed-off-by: Roberto Sassu --- drivers/char/tpm/tpm-interface.c | 13 +++++++++---- drivers/char/tpm/tpm.h | 3 ++- drivers/char/tpm/tpm2-cmd.c | 17 +++++++++++------ include/linux/tpm.h | 6 ++++-- security/integrity/ima/ima_crypto.c | 10 +++++----- 5 files changed, 31 insertions(+), 18 deletions(-) diff --git a/drivers/char/tpm/tpm-interface.c b/drivers/char/tpm/tpm-interface.c index 645c9aa7677a..81872880b5f1 100644 --- a/drivers/char/tpm/tpm-interface.c +++ b/drivers/char/tpm/tpm-interface.c @@ -976,21 +976,26 @@ EXPORT_SYMBOL_GPL(tpm_is_tpm2); * tpm_pcr_read - read a PCR value from SHA1 bank * @chip: a &struct tpm_chip instance, %NULL for the default chip * @pcr_idx: the PCR to be retrieved - * @res_buf: the value of the PCR + * @count: number of digests passed + * @digests: list of pcr banks and buffers current PCR values are written to * * Return: same as with tpm_transmit_cmd() */ -int tpm_pcr_read(struct tpm_chip *chip, int pcr_idx, u8 *res_buf) +int tpm_pcr_read(struct tpm_chip *chip, int pcr_idx, u32 count, + struct tpm_digest *digests) { int rc; + if (count != 1) + return -EINVAL; + chip = tpm_find_get_ops(chip); if (!chip) return -ENODEV; if (chip->flags & TPM_CHIP_FLAG_TPM2) - rc = tpm2_pcr_read(chip, pcr_idx, res_buf); + rc = tpm2_pcr_read(chip, pcr_idx, count, digests); else - rc = tpm_pcr_read_dev(chip, pcr_idx, res_buf); + rc = tpm_pcr_read_dev(chip, pcr_idx, digests[0].digest); tpm_put_ops(chip); return rc; } diff --git a/drivers/char/tpm/tpm.h b/drivers/char/tpm/tpm.h index b928ba44d864..9479e1ae1b4c 100644 --- a/drivers/char/tpm/tpm.h +++ b/drivers/char/tpm/tpm.h @@ -564,7 +564,8 @@ static inline u32 tpm2_rc_value(u32 rc) return (rc & BIT(7)) ? rc & 0xff : rc; } -int tpm2_pcr_read(struct tpm_chip *chip, int pcr_idx, u8 *res_buf); +int tpm2_pcr_read(struct tpm_chip *chip, int pcr_idx, u32 count, + struct tpm_digest *digests); int tpm2_pcr_extend(struct tpm_chip *chip, int pcr_idx, u32 count, struct tpm_digest *digests); int tpm2_get_random(struct tpm_chip *chip, u8 *dest, size_t max); diff --git a/drivers/char/tpm/tpm2-cmd.c b/drivers/char/tpm/tpm2-cmd.c index 2d7397b8a0d1..601d67c76c1e 100644 --- a/drivers/char/tpm/tpm2-cmd.c +++ b/drivers/char/tpm/tpm2-cmd.c @@ -179,11 +179,13 @@ struct tpm2_pcr_read_out { * tpm2_pcr_read() - read a PCR value * @chip: TPM chip to use. * @pcr_idx: index of the PCR to read. - * @res_buf: buffer to store the resulting hash. + * @count: number of digests passed. + * @digests: list of pcr banks and buffers current PCR values are written to. * * Return: Same as with tpm_transmit_cmd. */ -int tpm2_pcr_read(struct tpm_chip *chip, int pcr_idx, u8 *res_buf) +int tpm2_pcr_read(struct tpm_chip *chip, int pcr_idx, u32 count, + struct tpm_digest *digests) { int rc; struct tpm_buf buf; @@ -192,6 +194,8 @@ int tpm2_pcr_read(struct tpm_chip *chip, int pcr_idx, u8 *res_buf) if (pcr_idx >= TPM2_PLATFORM_PCR) return -EINVAL; + if (count > 1) + return -EINVAL; rc = tpm_buf_init(&buf, TPM2_ST_NO_SESSIONS, TPM2_CC_PCR_READ); if (rc) @@ -200,16 +204,17 @@ int tpm2_pcr_read(struct tpm_chip *chip, int pcr_idx, u8 *res_buf) pcr_select[pcr_idx >> 3] = 1 << (pcr_idx & 0x7); tpm_buf_append_u32(&buf, 1); - tpm_buf_append_u16(&buf, TPM_ALG_SHA1); + tpm_buf_append_u16(&buf, count ? digests[0].alg_id : TPM_ALG_SHA1); tpm_buf_append_u8(&buf, TPM2_PCR_SELECT_MIN); tpm_buf_append(&buf, (const unsigned char *)pcr_select, sizeof(pcr_select)); rc = tpm_transmit_cmd(chip, NULL, buf.data, PAGE_SIZE, 0, 0, - res_buf ? "attempting to read a pcr value" : NULL); - if (rc == 0 && res_buf) { + count ? "attempting to read a pcr value" : NULL); + if (rc == 0 && count) { out = (struct tpm2_pcr_read_out *)&buf.data[TPM_HEADER_SIZE]; - memcpy(res_buf, out->digest, SHA1_DIGEST_SIZE); + memcpy(digests[0].digest, out->digest, + be16_to_cpu(out->digest_size)); } tpm_buf_destroy(&buf); diff --git a/include/linux/tpm.h b/include/linux/tpm.h index 71d7bbf5f690..ac9fc47f4494 100644 --- a/include/linux/tpm.h +++ b/include/linux/tpm.h @@ -71,7 +71,8 @@ struct tpm_class_ops { #if defined(CONFIG_TCG_TPM) || defined(CONFIG_TCG_TPM_MODULE) extern int tpm_is_tpm2(struct tpm_chip *chip); -extern int tpm_pcr_read(struct tpm_chip *chip, int pcr_idx, u8 *res_buf); +extern int tpm_pcr_read(struct tpm_chip *chip, int pcr_idx, u32 count, + struct tpm_digest *digests); extern int tpm_pcr_extend(struct tpm_chip *chip, int pcr_idx, const u8 *hash); extern int tpm_send(struct tpm_chip *chip, void *cmd, size_t buflen); extern int tpm_get_random(struct tpm_chip *chip, u8 *data, size_t max); @@ -87,7 +88,8 @@ static inline int tpm_is_tpm2(struct tpm_chip *chip) { return -ENODEV; } -static inline int tpm_pcr_read(struct tpm_chip *chip, int pcr_idx, u8 *res_buf) +static inline int tpm_pcr_read(struct tpm_chip *chip, int pcr_idx, u32 count, + struct tpm_digest *digests) { return -ENODEV; } diff --git a/security/integrity/ima/ima_crypto.c b/security/integrity/ima/ima_crypto.c index 7e7e7e7c250a..4c94cf810d15 100644 --- a/security/integrity/ima/ima_crypto.c +++ b/security/integrity/ima/ima_crypto.c @@ -629,12 +629,12 @@ int ima_calc_buffer_hash(const void *buf, loff_t len, return calc_buffer_shash(buf, len, hash); } -static void __init ima_pcrread(int idx, u8 *pcr) +static void __init ima_pcrread(int idx, struct tpm_digest *d) { if (!ima_tpm_chip) return; - if (tpm_pcr_read(ima_tpm_chip, idx, pcr) != 0) + if (tpm_pcr_read(ima_tpm_chip, idx, 1, d) != 0) pr_err("Error Communicating to TPM chip\n"); } @@ -644,7 +644,7 @@ static void __init ima_pcrread(int idx, u8 *pcr) static int __init ima_calc_boot_aggregate_tfm(char *digest, struct crypto_shash *tfm) { - u8 pcr_i[TPM_DIGEST_SIZE]; + struct tpm_digest d = {.alg_id = TPM_ALG_SHA1}; int rc, i; SHASH_DESC_ON_STACK(shash, tfm); @@ -657,9 +657,9 @@ static int __init ima_calc_boot_aggregate_tfm(char *digest, /* cumulative sha1 over tpm registers 0-7 */ for (i = TPM_PCR0; i < TPM_PCR8; i++) { - ima_pcrread(i, pcr_i); + ima_pcrread(i, &d); /* now accumulate with current aggregate */ - rc = crypto_shash_update(shash, pcr_i, TPM_DIGEST_SIZE); + rc = crypto_shash_update(shash, d.digest, TPM_DIGEST_SIZE); } if (!rc) crypto_shash_final(shash, digest); -- 2.14.1