Received: by 2002:a05:6520:4211:b029:f4:110d:56bc with SMTP id o17csp1622335lkv; Wed, 19 May 2021 14:16:55 -0700 (PDT) X-Google-Smtp-Source: ABdhPJwek2l2dcGar0W1IfatsYmoEpiMNwIWTrY/Leb8D8uLAXkpOKMb0wY6pb57uetVyUR87ts9 X-Received: by 2002:a5d:94d5:: with SMTP id y21mr1795926ior.110.1621459015394; Wed, 19 May 2021 14:16:55 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1621459015; cv=none; d=google.com; s=arc-20160816; b=YDV29aaRGu1yICenx2TIdPtfwUnpksGJizelCq4eHmwoSBgF4VLRzJSf9NcTBZkaY7 xbJv2JKCdlGyJrOMFMqqd+dJ2spmkaTIn1uLTWoRrQwD5WII1J/n7PM8F3VrHCKCyfK4 C7gcFJjxURwMYJ6hF6pMe0odqTneTEcd8TyUZEeFotXIzz3htDxhMiA6E1g825llV0QQ pKnRexHe9He7DRzTa5es/FswVNwEUkwyaNUIVfT/8QyNwaM9mhIyFE7se5jDWV+P2JWO 4hTy9zIanCps5sBqKDaY5a3+2vufK6Yi0Ckj5ichnIq2wneJQcExXlDZWXxnvJLzz8iC RLnA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from; bh=GBhvGQHsmcfveJ0wEC6/kMDberHiZIj1FanuaUd88Dc=; b=rkj5G8gd6gJbvomhaDPXtj36UkdC4bVkmPJLqv4RYI2Icv11ldX1ixloscSd0fY411 oqHqR497V+vRROTb6rGTZk5uJvVbzpQZ4PEKVh0WufCrnMQOx7pIoZF+aRt6N/0iOQ6X v6wR+UCS9AND3uyr80Tw+zy45Dp55khF5T9+R+7nIHCWaVDFAxNAjezg6m0pFA8D3zRK zjZ9SMIMd7Ka/C48HqCt+8ttS8FLjphJVeaMVO6koiV+1w5AnPOf4FnBFY3lz03ljSkY VS4EEbyVXdTL4PWt994QkA0cVSricKxAVuoL9enDmxSBO2Px7DuciD4cmbByJYYkJEEo E2Tw== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id 4si737174iln.143.2021.05.19.14.16.41; Wed, 19 May 2021 14:16:55 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1345034AbhESOCs (ORCPT + 99 others); Wed, 19 May 2021 10:02:48 -0400 Received: from 212.199.177.27.static.012.net.il ([212.199.177.27]:59773 "EHLO herzl.nuvoton.co.il" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S231627AbhESOCm (ORCPT ); Wed, 19 May 2021 10:02:42 -0400 Received: from taln60.nuvoton.co.il (ntil-fw [212.199.177.25]) by herzl.nuvoton.co.il (8.13.8/8.13.8) with ESMTP id 14JE17L5031401; Wed, 19 May 2021 17:01:07 +0300 Received: by taln60.nuvoton.co.il (Postfix, from userid 10140) id 07EFA63A1B; Wed, 19 May 2021 17:01:14 +0300 (IDT) From: amirmizi6@gmail.com To: Eyal.Cohen@nuvoton.com, jarkko@kernel.org, peterhuewe@gmx.de, jgg@ziepe.ca Cc: linux-kernel@vger.kernel.org, linux-integrity@vger.kernel.org, Dan.Morav@nuvoton.com, oren.tanami@nuvoton.com, shmulik.hager@nuvoton.com, amir.mizinski@nuvoton.com, Amir Mizinski Subject: [PATCH v2] tpm2: add longer timeout for verify signature command Date: Wed, 19 May 2021 17:00:59 +0300 Message-Id: <20210519140059.85919-2-amirmizi6@gmail.com> X-Mailer: git-send-email 2.22.0 In-Reply-To: <20210519140059.85919-1-amirmizi6@gmail.com> References: <20210519140059.85919-1-amirmizi6@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Amir Mizinski While running a TPM2_CC_VERIFY_SIGNATURE(0x177) operation with RSA 3070-bit keys the TPM driver fails with the following error: "kernel: [ 2416.187522] tpm tpm0: Operation Timed out" Since a) the TPM PC Client specification does not specify a number for verify signature operation timeout, and b) the duration of TPM2_CC_VERIFY_SIGNATURE with RSA 3070-bit keys exceeds the current timeout of TPM_LONG (2 seconds), it is preferable to pick the longest timeout possible. Therefore, set the duration for TPM2_CC_VERIFY_SIGNATUE to TPM_LONG_LONG (5 minutes). Signed-off-by: Amir Mizinski --- drivers/char/tpm/tpm2-cmd.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/char/tpm/tpm2-cmd.c b/drivers/char/tpm/tpm2-cmd.c index 7603295..e71154b 100644 --- a/drivers/char/tpm/tpm2-cmd.c +++ b/drivers/char/tpm/tpm2-cmd.c @@ -87,7 +87,7 @@ static u8 tpm2_ordinal_duration_index(u32 ordinal) return TPM_MEDIUM; case TPM2_CC_VERIFY_SIGNATURE: /* 177 */ - return TPM_LONG; + return TPM_LONG_LONG; case TPM2_CC_PCR_EXTEND: /* 182 */ return TPM_MEDIUM; -- 2.7.4