Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
38 changes: 35 additions & 3 deletions include/tpm.h
Original file line number Diff line number Diff line change
Expand Up @@ -40,10 +40,42 @@ extern WOLFTPM2_KEY wolftpm_srk;
#ifndef WOLFBOOT_TPM_SEAL_NV_BASE
#define WOLFBOOT_TPM_SEAL_NV_BASE 0x01400300
#endif
/* The PCR bank algorithm and its digest size must always agree. They used to
* be defined together under a single #ifndef on the algorithm, which meant
* overriding only WOLFBOOT_TPM_PCR_ALG left WOLFBOOT_TPM_PCR_DIG_SZ undefined
* - and an undefined macro is 0 to the preprocessor, so the size checks
* downstream silently changed meaning. Select the pair with one switch, and
* refuse a half-specified override.
*
* Note the algorithm cannot be tested with #if: TPM_ALG_SHA256 and friends are
* enum constants, not macros, so every #if comparison against them evaluates
* 0 == 0 and is always true. */
#if defined(WOLFBOOT_TPM_PCR_ALG) != defined(WOLFBOOT_TPM_PCR_DIG_SZ)
#error "Define both WOLFBOOT_TPM_PCR_ALG and WOLFBOOT_TPM_PCR_DIG_SZ, or neither"
#endif
#ifndef WOLFBOOT_TPM_PCR_ALG
/* Prefer SHA2-256 for PCR's, and all TPM 2.0 devices support it */
#define WOLFBOOT_TPM_PCR_ALG TPM_ALG_SHA256
#define WOLFBOOT_TPM_PCR_DIG_SZ 32
#ifdef WOLFBOOT_TPM_PCR_SHA384
/* SHA2-384 bank. Present on parts like the Infineon SLB9672, absent on
* the SLB9670 - selecting it on a part with no such bank makes every
* extend fail, which measured boot treats as fatal. */
#define WOLFBOOT_TPM_PCR_ALG TPM_ALG_SHA384
Comment on lines +57 to +61
#define WOLFBOOT_TPM_PCR_DIG_SZ 48
#else
/* Prefer SHA2-256 for PCR's, and all TPM 2.0 devices support it */
#define WOLFBOOT_TPM_PCR_ALG TPM_ALG_SHA256
#define WOLFBOOT_TPM_PCR_DIG_SZ 32
#endif
#endif

/* The measured-boot extend path hands wolfBoot_tpm2_extend() the image's own
* hash buffer and the TPM reads WOLFBOOT_TPM_PCR_DIG_SZ bytes from it, so an
* image hash narrower than the selected PCR bank would read past the buffer
* and extend the PCR with adjacent memory. Require the image hash to be at
* least as wide as the bank. */
#if defined(WOLFBOOT_MEASURED_BOOT) && \
(WOLFBOOT_SHA_DIGEST_SIZE < WOLFBOOT_TPM_PCR_DIG_SZ)
#error "measured boot: image hash is narrower than the TPM PCR bank; " \
"widen the image HASH or select a smaller WOLFBOOT_TPM_PCR_ALG"
#endif

#define WOLFBOOT_MAX_SEAL_SZ MAX_SYM_DATA
Expand Down
Loading