From nobody Sat May 18 15:08:28 2024 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) client-ip=66.175.222.108; envelope-from=bounce+27952+103661+1787277+3901457@groups.io; helo=mail02.groups.io; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) smtp.mailfrom=bounce+27952+103661+1787277+3901457@groups.io; dmarc=fail(p=none dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1682526259; cv=none; d=zohomail.com; s=zohoarc; b=D/G2YdeDk2M2+yToz9RubJIUeRziFMg/AYoKdbkxEARyi6eNLff5uDfAJW1Pr6Zgeeo18alIeZlrqMlrzs0Rr9KOfHQP7W4KODLPGizHjjQbcyS37OVa3drnpdkyPwEFAd0ImjuuNB/l8GQPlqBp2TK2c0Ls3+wyRsNT2WbNta0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1682526259; h=Content-Type:Content-Transfer-Encoding:Cc:Date:From:In-Reply-To:List-Subscribe:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:References:Sender:Subject:To; bh=SBfxL2f9JSOS0Lv3/zFfAtvRv/Tv9UEB38CkPiasLpE=; b=V8xmCKH2T5eqqI2wCmSWgm500o/7m4fKzLJ5R2mU+ANi//Qqi0GbwFhw2BA4p6ncejxlCQAJHZyDyOpBd62f0sgqHMsocIhFSQiEg84JKnRk83X0g8m9WUNhX3j5/JyjF81zHL1qm/Mktcwj5/fdRoir+gQU3PRjzuwu3JlnDqA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) smtp.mailfrom=bounce+27952+103661+1787277+3901457@groups.io; dmarc=fail header.from= (p=none dis=none) Received: from mail02.groups.io (mail02.groups.io [66.175.222.108]) by mx.zohomail.com with SMTPS id 1682526259703367.6682189928888; Wed, 26 Apr 2023 09:24:19 -0700 (PDT) Return-Path: X-Received: by 127.0.0.2 with SMTP id gxM9YY1788612xAWoU1xyhjp; Wed, 26 Apr 2023 09:24:19 -0700 X-Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by mx.groups.io with SMTP id smtpd.web10.351.1682526258299005709 for ; Wed, 26 Apr 2023 09:24:18 -0700 X-Received: from mimecast-mx02.redhat.com (mimecast-mx02.redhat.com [66.187.233.88]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id us-mta-251-68boEypaNG60VU2FPSzXow-1; Wed, 26 Apr 2023 12:24:13 -0400 X-MC-Unique: 68boEypaNG60VU2FPSzXow-1 X-Received: from smtp.corp.redhat.com (int-mx10.intmail.prod.int.rdu2.redhat.com [10.11.54.10]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx02.redhat.com (Postfix) with ESMTPS id A4BE0A0F385; Wed, 26 Apr 2023 16:24:08 +0000 (UTC) X-Received: from sirius.home.kraxel.org (unknown [10.39.195.158]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 61C66492B03; Wed, 26 Apr 2023 16:24:07 +0000 (UTC) X-Received: by sirius.home.kraxel.org (Postfix, from userid 1000) id 93D891800634; Wed, 26 Apr 2023 18:24:05 +0200 (CEST) From: "Gerd Hoffmann" To: devel@edk2.groups.io Cc: Jian J Wang , Pawel Polawski , Oliver Steffen , Jiewen Yao , Gerd Hoffmann Subject: [edk2-devel] [PATCH 1/2] SecurityPkg: add TIS sanity check (tpm2) Date: Wed, 26 Apr 2023 18:24:04 +0200 Message-Id: <20230426162405.653953-2-kraxel@redhat.com> In-Reply-To: <20230426162405.653953-1-kraxel@redhat.com> References: <20230426162405.653953-1-kraxel@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.1 on 10.11.54.10 X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Precedence: Bulk List-Unsubscribe: List-Subscribe: List-Help: Sender: devel@edk2.groups.io List-Id: Mailing-List: list devel@edk2.groups.io; contact devel+owner@edk2.groups.io Reply-To: devel@edk2.groups.io,kraxel@redhat.com X-Gm-Message-State: u0nOv47yn8ZIcU5QJ5r96oEqx1787277AA= Content-Transfer-Encoding: quoted-printable DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=groups.io; q=dns/txt; s=20140610; t=1682526259; bh=eux0Dqn7S+oY0B01CJOir0y41fLLPggLtgRfe9Gm0kk=; h=Cc:Content-Type:Date:From:Reply-To:Subject:To; b=YRc0rKRxVvcIBTWY+DRw++pStID4Hw9mIfDeO7KaRWPHkrYu0S+PLS2qM3b0h7uKiWP BcNQG+mgx3IHbGnS3d3Lwi+0ScLLOvzFxBhwdKQgeWg7VVc1LCUJmiQKT2+vEfbkwrP98 rj4KKI07Y5V8I9heiOE3k1HjLit+/gtECR4= X-ZohoMail-DKIM: pass (identity @groups.io) X-ZM-MESSAGEID: 1682526260306100001 Content-Type: text/plain; charset="utf-8"; x-default="true" The code blindly assumes a TIS interface is present in case both CRB and FIFO checks fail. Check the InterfaceType for TIS instead and only return Tpm2PtpInterfaceTis in case it matches, Tpm2PtpInterfaceMax otherwise. Signed-off-by: Gerd Hoffmann Reviewed-by: Jiewen Yao --- SecurityPkg/Library/Tpm2DeviceLibDTpm/Tpm2Ptp.c | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/SecurityPkg/Library/Tpm2DeviceLibDTpm/Tpm2Ptp.c b/SecurityPkg/= Library/Tpm2DeviceLibDTpm/Tpm2Ptp.c index 1f9ac5ab5a30..eac9f0e29941 100644 --- a/SecurityPkg/Library/Tpm2DeviceLibDTpm/Tpm2Ptp.c +++ b/SecurityPkg/Library/Tpm2DeviceLibDTpm/Tpm2Ptp.c @@ -464,7 +464,11 @@ Tpm2GetPtpInterface ( return Tpm2PtpInterfaceFifo; } =20 - return Tpm2PtpInterfaceTis; + if (InterfaceId.Bits.InterfaceType =3D=3D PTP_INTERFACE_IDENTIFIER_INTER= FACE_TYPE_TIS) { + return Tpm2PtpInterfaceTis; + } + + return Tpm2PtpInterfaceMax; } =20 /** --=20 2.40.0 -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#103661): https://edk2.groups.io/g/devel/message/103661 Mute This Topic: https://groups.io/mt/98518597/1787277 Group Owner: devel+owner@edk2.groups.io Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org] -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- From nobody Sat May 18 15:08:28 2024 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) client-ip=66.175.222.108; envelope-from=bounce+27952+103662+1787277+3901457@groups.io; helo=mail02.groups.io; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) smtp.mailfrom=bounce+27952+103662+1787277+3901457@groups.io; dmarc=fail(p=none dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1682526266; cv=none; d=zohomail.com; s=zohoarc; b=GkmGe+/YtMgf1FfTwqUH+W51X8ZKXrWazKdbZ1fN4NTvqxa95NA9AvDXn9J9hD0ngSQFiWPZQRi8I3bSFB5+LrHVrQuXjvARRTG3y8Y2TEr+VFGBdcW4G02uVvnUkJqireUn00girLiLF3ykKkjzJ3Rv67LQIlejqfVNe/Nphfw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1682526266; h=Content-Type:Content-Transfer-Encoding:Cc:Date:From:In-Reply-To:List-Subscribe:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:References:Sender:Subject:To; bh=Tjf2gZehgZAH7CQAHZlkk4ZgFP90a2Pn6xLhjnBGgLs=; b=e1F9G8iflQ47+1YI8icyNkVaeWoyBvNg8ivx2Q6WueNf/2S0ssyq9JBlCvOhtp9tSpPac/wqIyMWLMlwTyxcpUqvWicJ/TyLFy+zfKP+jl6cM+Pfd5XzHO69llcG5YNkUI8ZN0BS9hiQ1qG6m3lN6C/XKFOW3b6docTzKokFtRo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) smtp.mailfrom=bounce+27952+103662+1787277+3901457@groups.io; dmarc=fail header.from= (p=none dis=none) Received: from mail02.groups.io (mail02.groups.io [66.175.222.108]) by mx.zohomail.com with SMTPS id 1682526266152879.8858825368284; Wed, 26 Apr 2023 09:24:26 -0700 (PDT) Return-Path: X-Received: by 127.0.0.2 with SMTP id Bko4YY1788612xa0sd5lSpVA; Wed, 26 Apr 2023 09:24:25 -0700 X-Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by mx.groups.io with SMTP id smtpd.web10.359.1682526265179436575 for ; Wed, 26 Apr 2023 09:24:25 -0700 X-Received: from mimecast-mx02.redhat.com (mimecast-mx02.redhat.com [66.187.233.88]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id us-mta-213-dmkk8ftnOy-h88_GJ_oZ_A-1; Wed, 26 Apr 2023 12:24:18 -0400 X-MC-Unique: dmkk8ftnOy-h88_GJ_oZ_A-1 X-Received: from smtp.corp.redhat.com (int-mx02.intmail.prod.int.rdu2.redhat.com [10.11.54.2]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx02.redhat.com (Postfix) with ESMTPS id 605DB855422; Wed, 26 Apr 2023 16:24:12 +0000 (UTC) X-Received: from sirius.home.kraxel.org (unknown [10.39.195.158]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 1E1DA40C6E67; Wed, 26 Apr 2023 16:24:12 +0000 (UTC) X-Received: by sirius.home.kraxel.org (Postfix, from userid 1000) id 994EA1800635; Wed, 26 Apr 2023 18:24:05 +0200 (CEST) From: "Gerd Hoffmann" To: devel@edk2.groups.io Cc: Jian J Wang , Pawel Polawski , Oliver Steffen , Jiewen Yao , Gerd Hoffmann Subject: [edk2-devel] [PATCH 2/2] SecurityPkg: add TIS sanity check (tpm12) Date: Wed, 26 Apr 2023 18:24:05 +0200 Message-Id: <20230426162405.653953-3-kraxel@redhat.com> In-Reply-To: <20230426162405.653953-1-kraxel@redhat.com> References: <20230426162405.653953-1-kraxel@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.1 on 10.11.54.2 X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Precedence: Bulk List-Unsubscribe: List-Subscribe: List-Help: Sender: devel@edk2.groups.io List-Id: Mailing-List: list devel@edk2.groups.io; contact devel+owner@edk2.groups.io Reply-To: devel@edk2.groups.io,kraxel@redhat.com X-Gm-Message-State: 9alPhdJWwE5d2HXQaxiuqvBUx1787277AA= Content-Transfer-Encoding: quoted-printable DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=groups.io; q=dns/txt; s=20140610; t=1682526265; bh=McGKgLP7XuDJi/EDIb2Bo5fb0eYdY5Zx+v4wTKrcoK4=; h=Cc:Content-Type:Date:From:Reply-To:Subject:To; b=batMYrwuHXLvh/jIuULt6Q6g15RD8rnZRLIYFQkK+EJvt3Nqg2HwWYg5XfxmFgF4Csk vWn5PSHYZqY41E7qb97kssfDDwZi5TIXDSlIq+uQaSYmgJ4OZ9OFgVLec3HcNR2CWm/vX loTDDMLcjNVtjQ3mwTXVihWoFRhb1qXR3ac= X-ZohoMail-DKIM: pass (identity @groups.io) X-ZM-MESSAGEID: 1682526267352100005 Content-Type: text/plain; charset="utf-8"; x-default="true" The code blindly assumes a TIS interface is present in case both CRB and FIFO checks fail. Check the InterfaceType for TIS instead and only return PtpInterfaceTis in case it matches, PtpInterfaceMax otherwise. Signed-off-by: Gerd Hoffmann Reviewed-by: Jiewen Yao --- SecurityPkg/Library/Tpm12DeviceLibDTpm/Tpm12Tis.c | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/SecurityPkg/Library/Tpm12DeviceLibDTpm/Tpm12Tis.c b/SecurityPk= g/Library/Tpm12DeviceLibDTpm/Tpm12Tis.c index 51f43591287a..d2b79a274084 100644 --- a/SecurityPkg/Library/Tpm12DeviceLibDTpm/Tpm12Tis.c +++ b/SecurityPkg/Library/Tpm12DeviceLibDTpm/Tpm12Tis.c @@ -91,7 +91,11 @@ Tpm12GetPtpInterface ( return PtpInterfaceFifo; } =20 - return PtpInterfaceTis; + if (InterfaceId.Bits.InterfaceType =3D=3D PTP_INTERFACE_IDENTIFIER_INTER= FACE_TYPE_TIS) { + return PtpInterfaceTis; + } + + return PtpInterfaceMax; } =20 /** --=20 2.40.0 -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#103662): https://edk2.groups.io/g/devel/message/103662 Mute This Topic: https://groups.io/mt/98518602/1787277 Group Owner: devel+owner@edk2.groups.io Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org] -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-