Message ID | 20200127170443.21538-2-roberto.sassu@huawei.com (mailing list archive) |
---|---|
State | New, archived |
Headers | show |
Series | ima: support stronger algorithms for attestation | expand |
Hi Roberto, > chip->allocated_banks contains the list of TPM algorithm IDs of allocated > PCR banks. It also contains the corresponding ID of the crypto subsystem, > so that users of the TPM driver can calculate a digest for a PCR extend > operation. > However, if there is no mapping between TPM algorithm ID and crypto ID, the > crypto_id field in chip->allocated_banks remains set to zero (the array is > allocated and initialized with kcalloc() in tpm2_get_pcr_allocation()). > Zero should not be used as value for unknown mappings, as it is a valid > crypto ID (HASH_ALGO_MD4). > This patch initializes crypto_id to HASH_ALGO__LAST. Make sense. Reviewed-by: Petr Vorel <pvorel@suse.cz> Kind regards, Petr
On Mon, 2020-01-27 at 18:04 +0100, Roberto Sassu wrote: > chip->allocated_banks contains the list of TPM algorithm IDs of allocated > PCR banks. It also contains the corresponding ID of the crypto subsystem, > so that users of the TPM driver can calculate a digest for a PCR extend > operation. > > However, if there is no mapping between TPM algorithm ID and crypto ID, the > crypto_id field in chip->allocated_banks remains set to zero (the array is > allocated and initialized with kcalloc() in tpm2_get_pcr_allocation()). > Zero should not be used as value for unknown mappings, as it is a valid > crypto ID (HASH_ALGO_MD4). > > This patch initializes crypto_id to HASH_ALGO__LAST. > > Signed-off-by: Roberto Sassu <roberto.sassu@huawei.com>--- Remarks: * After the subsystem tag, short summary starts with a capital lettter. * Missing fixes tag and cc tag to stable. * A struct called allocated_banks does not exist. * Please prefer using an imperative sentence when describing the action to take e.g. "Thus, initialize crypto_id to HASH_ALGO__LAST". /Jarkko
> -----Original Message----- > From: Jarkko Sakkinen [mailto:jarkko.sakkinen@linux.intel.com] > Sent: Thursday, January 30, 2020 9:48 AM > To: Roberto Sassu <roberto.sassu@huawei.com>; zohar@linux.ibm.com; > james.bottomley@hansenpartnership.com; linux-integrity@vger.kernel.org > Cc: linux-security-module@vger.kernel.org; linux-kernel@vger.kernel.org; > Silviu Vlasceanu <Silviu.Vlasceanu@huawei.com> > Subject: Re: [PATCH 1/8] tpm: initialize crypto_id of allocated_banks to > HASH_ALGO__LAST > > On Mon, 2020-01-27 at 18:04 +0100, Roberto Sassu wrote: > > chip->allocated_banks contains the list of TPM algorithm IDs of allocated > > PCR banks. It also contains the corresponding ID of the crypto subsystem, > > so that users of the TPM driver can calculate a digest for a PCR extend > > operation. > > > > However, if there is no mapping between TPM algorithm ID and crypto ID, > the > > crypto_id field in chip->allocated_banks remains set to zero (the array is > > allocated and initialized with kcalloc() in tpm2_get_pcr_allocation()). > > Zero should not be used as value for unknown mappings, as it is a valid > > crypto ID (HASH_ALGO_MD4). > > > > This patch initializes crypto_id to HASH_ALGO__LAST. > > > > Signed-off-by: Roberto Sassu <roberto.sassu@huawei.com>--- > > Remarks: > > * After the subsystem tag, short summary starts with a capital lettter. > * Missing fixes tag and cc tag to stable. > * A struct called allocated_banks does not exist. > * Please prefer using an imperative sentence when describing the action > to take e.g. "Thus, initialize crypto_id to HASH_ALGO__LAST". Thanks. I will fix these issues in the next version of the patch set. Roberto HUAWEI TECHNOLOGIES Duesseldorf GmbH, HRB 56063 Managing Director: Li Peng, Li Jian, Shi Yanli
On Thu, 2020-01-30 at 16:11 +0000, Roberto Sassu wrote: > > -----Original Message----- > > From: Jarkko Sakkinen [mailto:jarkko.sakkinen@linux.intel.com] > > Sent: Thursday, January 30, 2020 9:48 AM > > To: Roberto Sassu <roberto.sassu@huawei.com>; zohar@linux.ibm.com; > > james.bottomley@hansenpartnership.com; linux-integrity@vger.kernel.org > > Cc: linux-security-module@vger.kernel.org; linux-kernel@vger.kernel.org; > > Silviu Vlasceanu <Silviu.Vlasceanu@huawei.com> > > Subject: Re: [PATCH 1/8] tpm: initialize crypto_id of allocated_banks to > > HASH_ALGO__LAST > > > > On Mon, 2020-01-27 at 18:04 +0100, Roberto Sassu wrote: > > > chip->allocated_banks contains the list of TPM algorithm IDs of allocated > > > PCR banks. It also contains the corresponding ID of the crypto subsystem, > > > so that users of the TPM driver can calculate a digest for a PCR extend > > > operation. > > > > > > However, if there is no mapping between TPM algorithm ID and crypto ID, > > the > > > crypto_id field in chip->allocated_banks remains set to zero (the array is > > > allocated and initialized with kcalloc() in tpm2_get_pcr_allocation()). > > > Zero should not be used as value for unknown mappings, as it is a valid > > > crypto ID (HASH_ALGO_MD4). > > > > > > This patch initializes crypto_id to HASH_ALGO__LAST. > > > > > > Signed-off-by: Roberto Sassu <roberto.sassu@huawei.com>--- > > > > Remarks: > > > > * After the subsystem tag, short summary starts with a capital lettter. > > * Missing fixes tag and cc tag to stable. > > * A struct called allocated_banks does not exist. > > * Please prefer using an imperative sentence when describing the action > > to take e.g. "Thus, initialize crypto_id to HASH_ALGO__LAST". > > Thanks. I will fix these issues in the next version of the patch set. Jarkko, I realize this is a TPM patch, but this patch set is dependent on it. When this patch is ready, could you create a topic branch, which both of us could merge? thanks, Mimi
On Fri, Jan 31, 2020 at 08:33:10AM -0500, Mimi Zohar wrote: > On Thu, 2020-01-30 at 16:11 +0000, Roberto Sassu wrote: > > > -----Original Message----- > > > From: Jarkko Sakkinen [mailto:jarkko.sakkinen@linux.intel.com] > > > Sent: Thursday, January 30, 2020 9:48 AM > > > To: Roberto Sassu <roberto.sassu@huawei.com>; zohar@linux.ibm.com; > > > james.bottomley@hansenpartnership.com; linux-integrity@vger.kernel.org > > > Cc: linux-security-module@vger.kernel.org; linux-kernel@vger.kernel.org; > > > Silviu Vlasceanu <Silviu.Vlasceanu@huawei.com> > > > Subject: Re: [PATCH 1/8] tpm: initialize crypto_id of allocated_banks to > > > HASH_ALGO__LAST > > > > > > On Mon, 2020-01-27 at 18:04 +0100, Roberto Sassu wrote: > > > > chip->allocated_banks contains the list of TPM algorithm IDs of allocated > > > > PCR banks. It also contains the corresponding ID of the crypto subsystem, > > > > so that users of the TPM driver can calculate a digest for a PCR extend > > > > operation. > > > > > > > > However, if there is no mapping between TPM algorithm ID and crypto ID, > > > the > > > > crypto_id field in chip->allocated_banks remains set to zero (the array is > > > > allocated and initialized with kcalloc() in tpm2_get_pcr_allocation()). > > > > Zero should not be used as value for unknown mappings, as it is a valid > > > > crypto ID (HASH_ALGO_MD4). > > > > > > > > This patch initializes crypto_id to HASH_ALGO__LAST. > > > > > > > > Signed-off-by: Roberto Sassu <roberto.sassu@huawei.com>--- > > > > > > Remarks: > > > > > > * After the subsystem tag, short summary starts with a capital lettter. > > > * Missing fixes tag and cc tag to stable. > > > * A struct called allocated_banks does not exist. > > > * Please prefer using an imperative sentence when describing the action > > > to take e.g. "Thus, initialize crypto_id to HASH_ALGO__LAST". > > > > Thanks. I will fix these issues in the next version of the patch set. > > Jarkko, I realize this is a TPM patch, but this patch set is dependent > on it. When this patch is ready, could you create a topic branch, > which both of us could merge? WFM. /Jarkko
diff --git a/drivers/char/tpm/tpm2-cmd.c b/drivers/char/tpm/tpm2-cmd.c index 13696deceae8..760329598b99 100644 --- a/drivers/char/tpm/tpm2-cmd.c +++ b/drivers/char/tpm/tpm2-cmd.c @@ -525,6 +525,8 @@ static int tpm2_init_bank_info(struct tpm_chip *chip, u32 bank_index) return 0; } + bank->crypto_id = HASH_ALGO__LAST; + return tpm2_pcr_read(chip, 0, &digest, &bank->digest_size); }
chip->allocated_banks contains the list of TPM algorithm IDs of allocated PCR banks. It also contains the corresponding ID of the crypto subsystem, so that users of the TPM driver can calculate a digest for a PCR extend operation. However, if there is no mapping between TPM algorithm ID and crypto ID, the crypto_id field in chip->allocated_banks remains set to zero (the array is allocated and initialized with kcalloc() in tpm2_get_pcr_allocation()). Zero should not be used as value for unknown mappings, as it is a valid crypto ID (HASH_ALGO_MD4). This patch initializes crypto_id to HASH_ALGO__LAST. Signed-off-by: Roberto Sassu <roberto.sassu@huawei.com> --- drivers/char/tpm/tpm2-cmd.c | 2 ++ 1 file changed, 2 insertions(+)