From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751224AbdE3Hgi (ORCPT ); Tue, 30 May 2017 03:36:38 -0400 Received: from lhrrgout.huawei.com ([194.213.3.17]:27805 "EHLO lhrrgout.huawei.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751129AbdE3Hgf (ORCPT ); Tue, 30 May 2017 03:36:35 -0400 Subject: Re: [Linux-ima-devel] [PATCH v2 4/5] keys, trusted: modify arguments of tpm_pcr_extend() To: Mimi Zohar , References: <20170505142152.29795-1-roberto.sassu@huawei.com> <20170505142152.29795-5-roberto.sassu@huawei.com> <1496115337.3841.485.camel@linux.vnet.ibm.com> CC: , , , From: Roberto Sassu Message-ID: Date: Tue, 30 May 2017 09:36:13 +0200 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.7.1 MIME-Version: 1.0 In-Reply-To: <1496115337.3841.485.camel@linux.vnet.ibm.com> Content-Type: text/plain; charset="utf-8"; format=flowed Content-Transfer-Encoding: 7bit X-Originating-IP: [10.220.96.113] X-CFilter-Loop: Reflected X-Mirapoint-Virus-RAPID-Raw: score=unknown(0), refid=str=0001.0A020204.592D20F4.0125,ss=1,re=0.000,recu=0.000,reip=0.000,cl=1,cld=1,fgs=0, ip=0.0.0.0, so=2013-06-18 04:22:30, dmn=2013-03-21 17:37:32 X-Mirapoint-Loop-Id: 6aac35932fb7e08a26227a6afbd3baf1 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 5/30/2017 5:35 AM, Mimi Zohar wrote: > On Fri, 2017-05-05 at 16:21 +0200, Roberto Sassu wrote: >> pcrlock() has been modified to pass the correct arguments >> to tpm_pcr_extend(): the pointer of a tpm2_digest structure containing >> a random value generated by tpm_get_random() and the size of the array (1). > > If the number of arguments is wrong, that means the patch that > introduced the change is not bi-sect safe. (This comment is > applicable to patch 5/5 too.) Jarkko (the TPM driver maintainer) asked me to not introduce a new function to pass multiple digests, but to modify the parameters of tpm_pcr_extend(). Roberto > > Mimi > >> Signed-off-by: Roberto Sassu >> --- >> security/keys/trusted.c | 6 +++--- >> 1 file changed, 3 insertions(+), 3 deletions(-) >> >> diff --git a/security/keys/trusted.c b/security/keys/trusted.c >> index 2ae31c5..3eb89e6 100644 >> --- a/security/keys/trusted.c >> +++ b/security/keys/trusted.c >> @@ -377,15 +377,15 @@ static int trusted_tpm_send(const u32 chip_num, unsigned char *cmd, >> */ >> static int pcrlock(const int pcrnum) >> { >> - unsigned char hash[SHA1_DIGEST_SIZE]; >> + struct tpm2_digest digestarg = {.alg_id = TPM2_ALG_SHA1}; >> int ret; >> >> if (!capable(CAP_SYS_ADMIN)) >> return -EPERM; >> - ret = tpm_get_random(TPM_ANY_NUM, hash, SHA1_DIGEST_SIZE); >> + ret = tpm_get_random(TPM_ANY_NUM, digestarg.digest, SHA1_DIGEST_SIZE); >> if (ret != SHA1_DIGEST_SIZE) >> return ret; >> - return tpm_pcr_extend(TPM_ANY_NUM, pcrnum, hash) ? -EINVAL : 0; >> + return tpm_pcr_extend(TPM_ANY_NUM, pcrnum, 1, &digestarg) ? -EINVAL : 0; >> } >> >> /* >