From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from NAM11-CO1-obe.outbound.protection.outlook.com (NAM11-CO1-obe.outbound.protection.outlook.com [40.107.220.97]) by mx.groups.io with SMTP id smtpd.web10.32092.1628824941426732683 for ; Thu, 12 Aug 2021 20:22:21 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@microsoft.com header.s=selector2 header.b=C6GHtWs0; spf=pass (domain: microsoft.com, ip: 40.107.220.97, mailfrom: bret.barkelew@microsoft.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=g8MUmO73BoWZipw+GtRBLuJoJ0VSkHc81TO70nbHOEFSIf1HHjh14CkK6uEYJSUTKyURNHARvkIQX/UYkqogtkpa4Sunzt1psJZn7K0cWcd0zTXuiNaaXD6MHhoOTaAcsgJHZvSB2WEyUYVBiQmIBcpLE7p+cTOJiaoFDkwfFJ/cpvSygX+9yVCqY3GVqKMF55SVOJLSOMQ+BbBf3Je5laXrCxU/jLx5zbKgJEeHycSUfCBE6UDCvb024OlTxhFgB2I8jkEKCAQ2eW+TVWXw6dldgnOPvqvzKHom4EhQ6uDo2cTy0itvvqeLhl4MoI4LrJtA+3Pdl71J9BO6UOYUzg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=hzT90O3lNdbVM/J32olwqCcWGdPE7PSz+HeVAu0+YlI=; b=Gw7uIZLocyPPHPwmqRGlCWbLO61ewU9xzieIM89KL18uuXBHZPkrY+gdtWkZLizl/avu7Rdp7F4eTwByWxTq30RWV+kO2KY+wt0OWeFmfg0cvRHqFcCfN9XfauAgOPk/1+xmk8YFPgZaiezdspxGkiY1wPrElIfqpe0XABnNLDZ8/kb20rlmVecv2Hazs82eO1BWJvWM1cz07mwpyrSSBsK3HEgYhqK4Wrpw/SPnOLd9W4LUAaw3MlezUUhhSsdRCTUYcNXWxUECWGWkUD9Dn9I2FRlVONKweMXENd2VxSpjQ10JKHRrqtuHJzk4tK8T7PCxUytYiJp9sJq6c+H60w== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=microsoft.com; dmarc=pass action=none header.from=microsoft.com; dkim=pass header.d=microsoft.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=hzT90O3lNdbVM/J32olwqCcWGdPE7PSz+HeVAu0+YlI=; b=C6GHtWs0pvEdADPtggc6Bp7dAvqnzvpQXKFlnrAHCDU/5nOksPzsackYaR6faGj/HPj4V1WKGLdoctznHtYrO/Vdmc9m7s0fUnjcREq58Ae6RyHxrvVoIKUlh0lQx3y8+NVMhZ89dcETtLEGq71LONXp8dOskuyuIVVwajbFYwM= Received: from MW4PR21MB1907.namprd21.prod.outlook.com (2603:10b6:303:71::8) by MW4PR21MB1889.namprd21.prod.outlook.com (2603:10b6:303:77::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4436.4; Fri, 13 Aug 2021 03:22:18 +0000 Received: from MW4PR21MB1907.namprd21.prod.outlook.com ([fe80::203b:4b22:735f:bdc2]) by MW4PR21MB1907.namprd21.prod.outlook.com ([fe80::203b:4b22:735f:bdc2%9]) with mapi id 15.20.4436.011; Fri, 13 Aug 2021 03:22:18 +0000 From: "Bret Barkelew" To: "Yao, Jiewen" , "devel@edk2.groups.io" , "gaoliming@byosoft.com.cn" , "bret@corthon.com" , "Kinney, Michael D" CC: "Wang, Jian J" , "Zhang, Qi1" , "Kumar, Rahul1" Subject: Re: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Library: Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib Thread-Topic: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Library: Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib Thread-Index: AQHXhWwbbT7kW1JgJUKHOEoZ3Z5qO6tb0LjCgAe8VzuACzjTU4ABdOMpgABcFrCAAAmOAIAAFI+AgAANPwCAAAPCkIAAE/ck Date: Fri, 13 Aug 2021 03:22:18 +0000 Message-ID: References: <20210730175517.2445-1-brbarkel@microsoft.com> <1696A3E2DE5C4DCB.1941@groups.io> <169A57BB10BEC566.13770@groups.io> <013f01d78fe3$cb33b270$619b1750$@byosoft.com.cn> <169ABCD073787695.13770@groups.io> In-Reply-To: Accept-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=True;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2021-08-13T03:22:05.3297335Z;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ContentBits=0;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Method=Standard authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=microsoft.com; x-ms-publictraffictype: Email x-ms-office365-filtering-correlation-id: 90e67d0b-1810-41af-b17c-08d95e098e6c x-ms-traffictypediagnostic: MW4PR21MB1889: x-ld-processed: 72f988bf-86f1-41af-91ab-2d7cd011db47,ExtAddr x-microsoft-antispam-prvs: x-ms-oob-tlc-oobclassifiers: OLM:9508; x-ms-exchange-senderadcheck: 1 x-ms-exchange-antispam-relay: 0 x-microsoft-antispam: BCL:0; x-microsoft-antispam-message-info: gQZ4TpFTdDIpkIBWpp+jPIFXq/dLNX3dQxScfT9XR/xpQSggcaFdN/RtsBK6lvpSzVX0M3LgAa9cFgWBzG75nBHqeDu4DXG/G219WfM7BQXGHJbU3t13PYJonRTYPNVb9ucpEg0v49ONJeVYzkzIPEYyfbEJtApFrxu1k472EFXDdzqZP2JK+jpGYuqYx/a5ax7fOVdnJkdTCm4eAUM3l9IvwXrgXOMunZmQiO81aqnJHA5XzuS3D/JA1oX7r6y7k0zg73W1aKZi2gC8yPLHINVgZJgWHVtDCs74RmOWYHe4LHNLc3QyjRDsXyXCWyPP2Rf6MydtgDOf6IbU9u3c3PGbYB54/2e2igQIZaYfHyBhasu5jNNpkqlfZv2XVNiyMKGl6z7JQOIqTpuGbYnfDW0Z6vaUYR/mG6YclwSlzOMpUhl8fMLQipIAXmK7ILXbn+K7Cc4cevNMsPZzUJ33Z2ErKZet2qrNEnuEZkxqAPkLDeTTYAgie8deIbCi7+DK/B+rdH4BJt4fMGHUp5LJKvpQcFjo9EODwt5S4ExdLmI4CT2cSBBqpPT5kQeQEOV44dXvyddpF16InkPszVB08I4HafeQp+cCTJeGvCa0I4ew+EmSvjF38s+eGQmSGAjobQlQEhcss3NgUXAS+n3FLXo94MIjKEqYdKDGWEb3fr8cm9U3AHLX0fX7UYm1iSQO4K2fWv5/f8w9PpNTuxMluXP0Dpaz/CvlOQA50qeBma7+LYFVCvMPdSVjrhah6AKSaV2DkrkBfgyakPU6MIAFEc+EvXrZnVhloVce8JAoPqA= x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:MW4PR21MB1907.namprd21.prod.outlook.com;PTR:;CAT:NONE;SFS:(6029001)(4636009)(366004)(53546011)(6506007)(166002)(8936002)(7696005)(83380400001)(8676002)(76236003)(186003)(82950400001)(82960400001)(38070700005)(19627235002)(86362001)(2906002)(30864003)(4326008)(5660300002)(110136005)(91956017)(76116006)(8990500004)(316002)(10290500003)(55016002)(33656002)(966005)(66946007)(54906003)(508600001)(15650500001)(9686003)(38100700002)(122000001)(52536014)(71200400001)(66476007)(66556008)(64756008)(66446008);DIR:OUT;SFP:1102; x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?Windows-1252?Q?VnB/RV6jdeRzM0GYLxWJR7YXkjqh1VS12YsmZqyJjSas3EV0qH+9nVSD?= =?Windows-1252?Q?ZRTjFAdwVi7DhLQx5MajzVAgFNzdZ6ZFRcT07tkGCcPpEFWTfvFTG2av?= =?Windows-1252?Q?oxyY3YKtVaj6ebKc4XwcmY3cf76szKNVYk6GYDv1ZDjjtRFAvJ0d94ux?= =?Windows-1252?Q?wXDNnwq/hcU1MK6m/+PIsgqw9SXjfDc83DZbeEpkj/y9BQTZFLyRF9Ln?= =?Windows-1252?Q?XEihtTxAn/jq4LuXTvNe00RFSYVBQqCm6i0uslTRJ7EyBSdtoBs+JoBj?= =?Windows-1252?Q?5gCS44xTmgsYJpTf2XQs2UNQhGW0RRiN07BWERFodV2NxOjhSrXrGR+N?= =?Windows-1252?Q?b4WPcjDWD/7DSDK2+UGMsuOxH6htRHOE0AUkkZyuZUmpJxDkZqMwoS7m?= =?Windows-1252?Q?FC8BQnAdUU6usP+d0FDiWRNHrJyIJuPpzop4oMiuX/8Ob6VxhxQIyjne?= =?Windows-1252?Q?aT82QStrXMZUfyCq+Grd496hr1aAwBKuGsTo+S8DLVeTj+ZTWXDzK4dM?= =?Windows-1252?Q?pruXVJ/SH876z/Ynz88Prbd5KAXBQKjsI2iAjn9E7CMwjw9aAaqVdmIU?= =?Windows-1252?Q?jyIt0UAwmRr2bg4/fhXZVeJEqT4w0lE1wVwM7lSWJwFIP5NEpzHMJJwq?= =?Windows-1252?Q?UWbhCQJZpSsps0s6Bw3qPg6V7mQu4ZlGRueuaqmv/7UOexFyXq6X6cU7?= =?Windows-1252?Q?4xZgQ+PibNjDmfr2pgAw9X+Sar6A0x3nd+LvyI8w7HW6B6Rte57f4qwD?= =?Windows-1252?Q?V5sfG3xcyZ/4kg44tLPW9TBX1namlB0cG4Y1ziVf2iJsHrFkVkyGvowj?= =?Windows-1252?Q?SV2T7xpWdeWIFMkX1IDivq9J2h0GVMAxZ88UcmDQxqB/xh5b49fZGukV?= =?Windows-1252?Q?k/aX/khcmBWikTf4in6PrdgJGvWVSaVm/+QCgFngEyR/eAfTeGOaTSJG?= =?Windows-1252?Q?dWHK1SECOMY6NNqIBQGRqh+sgWvYH6DFPiat1ktDeWJ3ruHdUufKwr9r?= =?Windows-1252?Q?W4MxO57WIxmb0fg1uzxxBLqCxbAVn+JWLzu/dmqoJdZjnmfI/KGE84/u?= =?Windows-1252?Q?7s1ZMgbmoHIgmig04DYKL2dz68QUO2fEKnuyJUBsFerFxqDU6PC2hlab?= =?Windows-1252?Q?Bzgqa7x0EUvQAB+E0Qegxufh3zyGx3SjdYRBPBaBWrsg3L6no52+L891?= =?Windows-1252?Q?MomtVvxOMt5XxbAgaYC64E1R9XM+O/UIEaamGr2djuKE8t8ODsV8DFnO?= =?Windows-1252?Q?KR6F3FvAijBUNwmwjZhKkEqtyM0pZugZ2rSsp9x5kZVzrCGiAWCODdCp?= =?Windows-1252?Q?BS1bZ6knz46MtZAE7tYCqEjrxsL3pFPn85/YCb4FnHQqI766supBBBYR?= =?Windows-1252?Q?tabhlFB7+W9oTRvGp+Q4mme0bZiNEGyN4EGLArlA2EkIeR+ZEXjTCrgx?= =?Windows-1252?Q?MG9w1nN13bxVwvhT2YfnVw=3D=3D?= x-ms-exchange-transport-forked: True MIME-Version: 1.0 X-OriginatorOrg: microsoft.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: MW4PR21MB1907.namprd21.prod.outlook.com X-MS-Exchange-CrossTenant-Network-Message-Id: 90e67d0b-1810-41af-b17c-08d95e098e6c X-MS-Exchange-CrossTenant-originalarrivaltime: 13 Aug 2021 03:22:18.4968 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47 X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: nz4OEV9MjRsZIYwv/iu3FjKYsucjsZAADR6Jn45mDOC2XDkmNZLbvxR2qQv4qU3RymH3cANY/8I4sALHk/QuIQ== X-MS-Exchange-Transport-CrossTenantHeadersStamped: MW4PR21MB1889 Content-Language: en-US Content-Type: multipart/alternative; boundary="_000_MW4PR21MB19074B8BEBB9A7E9550535F6EFFA9MW4PR21MB1907namp_" --_000_MW4PR21MB19074B8BEBB9A7E9550535F6EFFA9MW4PR21MB1907namp_ Content-Type: text/plain; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable Thanks, Jiewen! I=92ll make those changes! - Bret ________________________________ From: Yao, Jiewen Sent: Thursday, August 12, 2021 7:47:04 PM To: devel@edk2.groups.io ; Yao, Jiewen ; gaoliming@byosoft.com.cn ; Bret Barkele= w ; bret@corthon.com ; Kinne= y, Michael D Cc: Wang, Jian J ; Zhang, Qi1 ;= Kumar, Rahul1 Subject: RE: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Library: Ad= d Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib Hi Bret Since it took much long time to get ECC feedback than I expected, I would g= ive feedback on code while we are waiting. 1) Please confirm how you test the code, such as Microsoft platform ? 2) Please remove =93+} // Tpm2NvUndefineSpaceSpecial()=94 at the end of the= function. We do not use that style in other code. 3) Please copy the definition from TPM spec =93This command allows removal = of a platform-created NV Index that has TPMA_NV_POLICY_DELETE SET=94 to the= function header description. The current one =93This command removes an in= dex from the TPM.=94 is for TPM2_NV_UndefineSpace instead of TPM2_NV_Undefi= neSpaceSpecial. Since above comment does not impact any function, I would like to give RB. With about change, reviewed-by: Jiewen Yao Thank you Yao Jiewen From: Bret Barkelew via groups.io Sent: Friday, July 30, 2021 11:08 AM To: devel@edk2.groups.io; bret@corthon.com Cc: Yao, Jiewen; Jian J Wang; Qi Zhang; Rahul Kumar Subject: Re: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Library: Ad= d Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib Note, even though this keeps with the style of the rest of the file, it bre= aks ECC: SecurityPkg/Library: Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib by co= rthon =B7 Pull Request #1848 =B7 tianocore/edk2 (github.com) PROGRESS - --Running SecurityPkg: EccCheck Test NO-TARGET -- ERROR - ERROR - ERROR - EFI coding style error ERROR - *Error code: 8001 ERROR - *Only capital letters are allowed to be used for #define declaratio= ns ERROR - *file: //home/vsts/work/1/s/SecurityPkg/Library/Tpm2CommandLib/Tpm2= NVStorage.c ERROR - *Line number: 27 ERROR - *The #define name [RC_NV_UndefineSpaceSpecial_nvIndex] does no Thoughts? - Bret From: Bret Barkelew via groups.io Sent: Friday, July 30, 2021 10:55 AM To: devel@edk2.groups.io Cc: Yao, Jiewen; Jian J Wang; Qi Zhang; Rahul Kumar Subject: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Library: Add Tp= m2NvUndefineSpaceSpecial to Tpm2CommandLib Used to provision and maintain certain HW-defined NV spaces. REF: https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fbu= gzilla.tianocore.org%2Fshow_bug.cgi%3Fid%3D2994&data=3D04%7C01%7CBret.B= arkelew%40microsoft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141= af91ab2d7cd011db47%7C1%7C0%7C637632645397602953%7CUnknown%7CTWFpbGZsb3d8eyJ= WIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&= sdata=3Ds96M3RvxMOY831Vfr1nt%2Fz1h3cyb6jU9eFzvjKO7Dtc%3D&reserved=3D0 Signed-off-by: Bret Barkelew > Cc: Jiewen Yao > Cc: Jian J Wang > Cc: Qi Zhang > Cc: Rahul Kumar > --- SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c | 122 +++++++++++++++++= +++ SecurityPkg/Include/Library/Tpm2CommandLib.h | 22 ++++ 2 files changed, 144 insertions(+) diff --git a/SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c b/SecurityP= kg/Library/Tpm2CommandLib/Tpm2NVStorage.c index 87572de20164..7931fade9190 100644 --- a/SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c +++ b/SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c @@ -24,6 +24,8 @@ SPDX-License-Identifier: BSD-2-Clause-Patent #define RC_NV_UndefineSpace_authHandle (TPM_RC_H + TPM_RC_1) #define RC_NV_UndefineSpace_nvIndex (TPM_RC_H + TPM_RC_2) +#define RC_NV_UndefineSpaceSpecial_nvIndex (TPM_RC_H + TPM_RC_1) + #define RC_NV_Read_authHandle (TPM_RC_H + TPM_RC_1) #define RC_NV_Read_nvIndex (TPM_RC_H + TPM_RC_2) #define RC_NV_Read_size (TPM_RC_P + TPM_RC_1) @@ -74,6 +76,20 @@ typedef struct { TPMS_AUTH_RESPONSE AuthSession; } TPM2_NV_UNDEFINESPACE_RESPONSE; +typedef struct { + TPM2_COMMAND_HEADER Header; + TPMI_RH_NV_INDEX NvIndex; + TPMI_RH_PLATFORM Platform; + UINT32 AuthSessionSize; + TPMS_AUTH_COMMAND AuthSession; +} TPM2_NV_UNDEFINESPACESPECIAL_COMMAND; + +typedef struct { + TPM2_RESPONSE_HEADER Header; + UINT32 AuthSessionSize; + TPMS_AUTH_RESPONSE AuthSession; +} TPM2_NV_UNDEFINESPACESPECIAL_RESPONSE; + typedef struct { TPM2_COMMAND_HEADER Header; TPMI_RH_NV_AUTH AuthHandle; @@ -506,6 +522,112 @@ Done: return Status; } +/** + This command removes an index from the TPM. + + @param[in] NvIndex The NV Index. + @param[in] IndexAuthSession Auth session context for the Index auth/= policy + @param[in] PlatAuthSession Auth session context for the Platform au= th/policy + + @retval EFI_SUCCESS Operation completed successfully. + @retval EFI_NOT_FOUND The command was returned successfully, b= ut NvIndex is not found. + @retval EFI_UNSUPPORTED Selected NvIndex does not support deleti= on through this call. + @retval EFI_SECURITY_VIOLATION Deletion is not authorized by current po= licy session. + @retval EFI_INVALID_PARAMETER The command was unsuccessful. + @retval EFI_DEVICE_ERROR The command was unsuccessful. +**/ +EFI_STATUS +EFIAPI +Tpm2NvUndefineSpaceSpecial ( + IN TPMI_RH_NV_INDEX NvIndex, + IN TPMS_AUTH_COMMAND *IndexAuthSession OPTIONAL, + IN TPMS_AUTH_COMMAND *PlatAuthSession OPTIONAL + ) +{ + EFI_STATUS Status; + TPM2_NV_UNDEFINESPACESPECIAL_COMMAND SendBuffer; + TPM2_NV_UNDEFINESPACESPECIAL_RESPONSE RecvBuffer; + UINT32 SendBufferSize; + UINT32 RecvBufferSize; + UINT8 *Buffer; + UINT32 IndexAuthSize, PlatAuthSize; + TPM_RC ResponseCode; + + // + // Construct command + // + SendBuffer.Header.tag =3D SwapBytes16(TPM_ST_SESSIONS); + SendBuffer.Header.commandCode =3D SwapBytes32(TPM_CC_NV_UndefineSpaceSpe= cial); + + SendBuffer.NvIndex =3D SwapBytes32 (NvIndex); + SendBuffer.Platform =3D SwapBytes32 (TPM_RH_PLATFORM); + + // + // Marshall the Auth Sessions for the two handles. + Buffer =3D (UINT8 *)&SendBuffer.AuthSession; + // IndexAuthSession + IndexAuthSize =3D CopyAuthSessionCommand (IndexAuthSession, Buffer); + Buffer +=3D IndexAuthSize; + // PlatAuthSession + PlatAuthSize =3D CopyAuthSessionCommand (PlatAuthSession, Buffer); + Buffer +=3D PlatAuthSize; + // AuthSessionSize + SendBuffer.AuthSessionSize =3D SwapBytes32(IndexAuthSize + PlatAuthSize)= ; + + // Update total command size. + SendBufferSize =3D (UINT32)(Buffer - (UINT8 *)&SendBuffer); + SendBuffer.Header.paramSize =3D SwapBytes32 (SendBufferSize); + + // + // send Tpm command + // + RecvBufferSize =3D sizeof (RecvBuffer); + Status =3D Tpm2SubmitCommand (SendBufferSize, (UINT8 *)&SendBuffer, &Rec= vBufferSize, (UINT8 *)&RecvBuffer); + if (EFI_ERROR (Status)) { + goto Done; + } + + if (RecvBufferSize < sizeof (TPM2_RESPONSE_HEADER)) { + DEBUG ((EFI_D_ERROR, "Tpm2NvUndefineSpaceSpecial - RecvBufferSize Erro= r - %x\n", RecvBufferSize)); + Status =3D EFI_DEVICE_ERROR; + goto Done; + } + + ResponseCode =3D SwapBytes32(RecvBuffer.Header.responseCode); + if (ResponseCode !=3D TPM_RC_SUCCESS) { + DEBUG ((EFI_D_ERROR, "Tpm2NvUndefineSpaceSpecial - responseCode - %x\n= ", SwapBytes32(RecvBuffer.Header.responseCode))); + } + switch (ResponseCode) { + case TPM_RC_SUCCESS: + // return data + break; + case TPM_RC_ATTRIBUTES: + case TPM_RC_ATTRIBUTES + RC_NV_UndefineSpaceSpecial_nvIndex: + Status =3D EFI_UNSUPPORTED; + break; + case TPM_RC_NV_AUTHORIZATION: + Status =3D EFI_SECURITY_VIOLATION; + break; + case TPM_RC_HANDLE + RC_NV_UndefineSpaceSpecial_nvIndex: // TPM_RC_NV_DE= FINED: + Status =3D EFI_NOT_FOUND; + break; + case TPM_RC_VALUE + RC_NV_UndefineSpace_nvIndex: + Status =3D EFI_INVALID_PARAMETER; + break; + default: + Status =3D EFI_DEVICE_ERROR; + break; + } + +Done: + // + // Clear AuthSession Content + // + ZeroMem (&SendBuffer, sizeof(SendBuffer)); + ZeroMem (&RecvBuffer, sizeof(RecvBuffer)); + return Status; +} // Tpm2NvUndefineSpaceSpecial() + /** This command reads a value from an area in NV memory previously defined = by TPM2_NV_DefineSpace(). diff --git a/SecurityPkg/Include/Library/Tpm2CommandLib.h b/SecurityPkg/Inc= lude/Library/Tpm2CommandLib.h index ee8eb622951c..8d7b4998d98d 100644 --- a/SecurityPkg/Include/Library/Tpm2CommandLib.h +++ b/SecurityPkg/Include/Library/Tpm2CommandLib.h @@ -364,6 +364,28 @@ Tpm2NvUndefineSpace ( IN TPMS_AUTH_COMMAND *AuthSession OPTIONAL ); +/** + This command removes an index from the TPM. + + @param[in] NvIndex The NV Index. + @param[in] IndexAuthSession Auth session context for the Index auth/= policy + @param[in] PlatAuthSession Auth session context for the Platform au= th/policy + + @retval EFI_SUCCESS Operation completed successfully. + @retval EFI_NOT_FOUND The command was returned successfully, b= ut NvIndex is not found. + @retval EFI_UNSUPPORTED Selected NvIndex does not support deleti= on through this call. + @retval EFI_SECURITY_VIOLATION Deletion is not authorized by current po= licy session. + @retval EFI_INVALID_PARAMETER The command was unsuccessful. + @retval EFI_DEVICE_ERROR The command was unsuccessful. +**/ +EFI_STATUS +EFIAPI +Tpm2NvUndefineSpaceSpecial ( + IN TPMI_RH_NV_INDEX NvIndex, + IN TPMS_AUTH_COMMAND *IndexAuthSession OPTIONAL, + IN TPMS_AUTH_COMMAND *PlatAuthSession OPTIONAL + ); + /** This command reads a value from an area in NV memory previously defined = by TPM2_NV_DefineSpace(). -- 2.31.1.windows.1 -=3D-=3D-=3D-=3D-=3D-=3D Groups.io Links: You receive all messages sent to this group. View/Reply Online (#78450): https://nam06.safelinks.protection.outlook.com/= ?url=3Dhttps%3A%2F%2Fedk2.groups.io%2Fg%2Fdevel%2Fmessage%2F78450&data= =3D04%7C01%7CBret.Barkelew%40microsoft.com%7Cb7ae3c62047c48fc85d908d953833c= a0%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637632645397612922%7CUnknow= n%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI= 6Mn0%3D%7C1000&sdata=3DCWxLwgp73z2XQEa%2FN77gsCwRF73xha0RZCKwcFTlrRE%3D= &reserved=3D0 Mute This Topic: https://nam06.safelinks.protection.outlook.com/?url=3Dhttp= s%3A%2F%2Fgroups.io%2Fmt%2F84555713%2F1822150&data=3D04%7C01%7CBret.Bar= kelew%40microsoft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141af= 91ab2d7cd011db47%7C1%7C0%7C637632645397612922%7CUnknown%7CTWFpbGZsb3d8eyJWI= joiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sd= ata=3DIWQ6E4yP0ECt3oYLYQa%2BnddGfcQEDMgfASlcxRuda%2BQ%3D&reserved=3D0 Group Owner: devel+owner@edk2.groups.io Unsubscribe: https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A= %2F%2Fedk2.groups.io%2Fg%2Fdevel%2Funsub&data=3D04%7C01%7CBret.Barkelew= %40microsoft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141af91ab2= d7cd011db47%7C1%7C0%7C637632645397612922%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC= 4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata= =3Dqor4Y5FZEH8ch0AEmWDbe97FIQk4V1qx7IURcTHzjAU%3D&reserved=3D0 [brbarkel@microsoft.com] -=3D-=3D-=3D-=3D-=3D-=3D --_000_MW4PR21MB19074B8BEBB9A7E9550535F6EFFA9MW4PR21MB1907namp_ Content-Type: text/html; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable
Thanks, Jiewen! I=92ll make those changes!

- Bret

From: Yao, Jiewen <jiewe= n.yao@intel.com>
Sent: Thursday, August 12, 2021 7:47:04 PM
To: devel@edk2.groups.io <devel@edk2.groups.io>; Yao, Jiewen &= lt;jiewen.yao@intel.com>; gaoliming@byosoft.com.cn <gaoliming@byosoft= .com.cn>; Bret Barkelew <Bret.Barkelew@microsoft.com>; bret@cortho= n.com <bret@corthon.com>; Kinney, Michael D <michael.d.kinney@inte= l.com>
Cc: Wang, Jian J <jian.j.wang@intel.com>; Zhang, Qi1 <qi1.z= hang@intel.com>; Kumar, Rahul1 <rahul1.kumar@intel.com>
Subject: RE: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Libr= ary: Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib
 

Hi Bret

Since it took much long time to get ECC feedback t= han I expected, I would give feedback on code while we are waiting.

 

1) Please confirm how you test the code, such as M= icrosoft platform ?

2) Please remove =93+} // Tpm2NvUndefineSpaceSpeci= al()=94 at the end of the function. We do not use that style in other code.=

3) Please copy the definition from TPM spec =93This command al= lows removal of a platform-created NV Index that has TPMA_NV_POLICY_DELETE<= /span> SET=94 to the function header d= escription. The current one =93This command removes an index from the TPM.= =94 is for TPM= 2_NV_UndefineSpace instead of TPM2_NV_UndefineSpaceSpecial.

 

Since above comment does not impact any function, I w= ould like to give RB.

 

With about change, reviewed-by: Jiewen Yao <Jiewen= .yao@intel.com>

 

Thank you

Yao Jiewen

 

From: Bret Barkelew via groups.io
Sent: Friday, July 30, 2021 11:08 AM
To: devel@edk2.groups.io= ; bret@corthon.com
Cc: Yao, Jiewen; Jian J Wang; Qi Zhang; Rahul Kumar
Subject: Re: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Libr= ary: Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib

 

Note, even though this keeps with the style of t= he rest of the file, it breaks ECC:

SecurityPkg/Library: Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib by corthon =B7 Pull Reque= st #1848 =B7 tianocore/edk2 (github.com)

 

PROGRESS - --Running SecurityPkg: EccCheck Test NO-TARGET --

ERROR -

ERROR -

ERROR - EFI coding style error

ERROR - *Error code: 8001

ERROR - *Only capital letters are allowed to be used for #define declar= ations

ERROR - *file: //home/vsts/work/1/s/SecurityPkg/Library/Tpm2CommandLib/= Tpm2NVStorage.c

ERROR - *Line number: 27

ERROR - *The #define name [RC_NV_UndefineSpaceSpecial_nvIndex] does no<= /span>

 

Thoughts?

 

- Bret

 

From: Bret Barkelew via groups.io
Sent: Friday, July 30, 2021 10:55 AM
To: devel@edk2.groups.io=
Cc: Yao, Jiewen; Jian J Wang; Qi Zhang; Rahul Kumar
Subject: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Library:= Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib

 

Used to provision= and maintain certain HW-defined NV spaces.

REF: https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fbugzill= a.tianocore.org%2Fshow_bug.cgi%3Fid%3D2994&amp;data=3D04%7C01%7CBret.Ba= rkelew%40microsoft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141a= f91ab2d7cd011db47%7C1%7C0%7C637632645397602953%7CUnknown%7CTWFpbGZsb3d8eyJW= IjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&a= mp;sdata=3Ds96M3RvxMOY831Vfr1nt%2Fz1h3cyb6jU9eFzvjKO7Dtc%3D&amp;reserve= d=3D0

Signed-off-by: Bret Barkelew <bret.barkelew@microsoft.com>
Cc: Jiewen Yao <jiewen.yao@intel= .com>
Cc: Jian J Wang <jian.j.wang@in= tel.com>
Cc: Qi Zhang <qi1.zhang@intel.com= >
Cc: Rahul Kumar <rahul1.kumar@= intel.com>
---
 SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c | 122 ++++++++++++= ++++++++
 SecurityPkg/Include/Library/Tpm2CommandLib.h    &= nbsp;  |  22 ++++
 2 files changed, 144 insertions(+)

diff --git a/SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c b/SecurityP= kg/Library/Tpm2CommandLib/Tpm2NVStorage.c
index 87572de20164..7931fade9190 100644
--- a/SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c
+++ b/SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c
@@ -24,6 +24,8 @@ SPDX-License-Identifier: BSD-2-Clause-Patent
 #define RC_NV_UndefineSpace_authHandle      = (TPM_RC_H + TPM_RC_1)

 #define RC_NV_UndefineSpace_nvIndex     &nbs= p;   (TPM_RC_H + TPM_RC_2)

 

+#define RC_NV_UndefineSpaceSpecial_nvIndex  (TPM_RC_H + TPM_RC_1)

+

 #define RC_NV_Read_authHandle      &nbs= p;        (TPM_RC_H + TPM_RC_1)

 #define RC_NV_Read_nvIndex       &= nbsp;          (TPM_RC_H + TPM= _RC_2)

 #define RC_NV_Read_size       &nbs= p;             = (TPM_RC_P + TPM_RC_1)

@@ -74,6 +76,20 @@ typedef struct {
   TPMS_AUTH_RESPONSE       &n= bsp; AuthSession;

 } TPM2_NV_UNDEFINESPACE_RESPONSE;

 

+typedef struct {

+  TPM2_COMMAND_HEADER       Header;

+  TPMI_RH_NV_INDEX        &nb= sp; NvIndex;

+  TPMI_RH_PLATFORM        &nb= sp; Platform;

+  UINT32          &= nbsp;         AuthSessionSize;

+  TPMS_AUTH_COMMAND         A= uthSession;

+} TPM2_NV_UNDEFINESPACESPECIAL_COMMAND;

+

+typedef struct {

+  TPM2_RESPONSE_HEADER       Header;
+  UINT32          &= nbsp;          AuthSessionSize= ;

+  TPMS_AUTH_RESPONSE         = AuthSession;

+} TPM2_NV_UNDEFINESPACESPECIAL_RESPONSE;

+

 typedef struct {

   TPM2_COMMAND_HEADER       Header= ;

   TPMI_RH_NV_AUTH        = ;   AuthHandle;

@@ -506,6 +522,112 @@ Done:
   return Status;

 }

 

+/**

+  This command removes an index from the TPM.

+

+  @param[in]  NvIndex       &= nbsp;     The NV Index.

+  @param[in]  IndexAuthSession    Auth session co= ntext for the Index auth/policy

+  @param[in]  PlatAuthSession     Auth sessi= on context for the Platform auth/policy

+

+  @retval EFI_SUCCESS        =      Operation completed successfully.

+  @retval EFI_NOT_FOUND       &nbs= p;   The command was returned successfully, but NvIndex is not fo= und.

+  @retval EFI_UNSUPPORTED       &n= bsp; Selected NvIndex does not support deletion through this call.

+  @retval EFI_SECURITY_VIOLATION  Deletion is not authorized by = current policy session.

+  @retval EFI_INVALID_PARAMETER   The command was unsuccess= ful.

+  @retval EFI_DEVICE_ERROR        = The command was unsuccessful.

+**/

+EFI_STATUS

+EFIAPI

+Tpm2NvUndefineSpaceSpecial (

+  IN      TPMI_RH_NV_INDEX   =        NvIndex,

+  IN      TPMS_AUTH_COMMAND   = ;      *IndexAuthSession OPTIONAL,

+  IN      TPMS_AUTH_COMMAND   = ;      *PlatAuthSession OPTIONAL

+  )

+{

+  EFI_STATUS         &nb= sp;            =         Status;

+  TPM2_NV_UNDEFINESPACESPECIAL_COMMAND    SendBuffer;<= br>
+  TPM2_NV_UNDEFINESPACESPECIAL_RESPONSE   RecvBuffer;

+  UINT32          &= nbsp;           &nbs= p;           SendBufferSi= ze;

+  UINT32          &= nbsp;           &nbs= p;           RecvBufferSi= ze;

+  UINT8          &n= bsp;            = ;            *Buffer= ;

+  UINT32          &= nbsp;           &nbs= p;           IndexAuthSiz= e, PlatAuthSize;

+  TPM_RC          &= nbsp;           &nbs= p;           ResponseCode= ;

+

+  //

+  // Construct command

+  //

+  SendBuffer.Header.tag =3D SwapBytes16(TPM_ST_SESSIONS);

+  SendBuffer.Header.commandCode =3D SwapBytes32(TPM_CC_NV_UndefineSpa= ceSpecial);

+

+  SendBuffer.NvIndex =3D SwapBytes32 (NvIndex);

+  SendBuffer.Platform =3D SwapBytes32 (TPM_RH_PLATFORM);

+

+  //

+  // Marshall the Auth Sessions for the two handles.

+  Buffer =3D (UINT8 *)&SendBuffer.AuthSession;

+  // IndexAuthSession

+  IndexAuthSize =3D CopyAuthSessionCommand (IndexAuthSession, Buffer)= ;

+  Buffer +=3D IndexAuthSize;

+  // PlatAuthSession

+  PlatAuthSize =3D CopyAuthSessionCommand (PlatAuthSession, Buffer);<= br>
+  Buffer +=3D PlatAuthSize;

+  // AuthSessionSize

+  SendBuffer.AuthSessionSize =3D SwapBytes32(IndexAuthSize + PlatAuth= Size);

+

+  // Update total command size.

+  SendBufferSize =3D (UINT32)(Buffer - (UINT8 *)&SendBuffer);

+  SendBuffer.Header.paramSize =3D SwapBytes32 (SendBufferSize);

+

+  //

+  // send Tpm command

+  //

+  RecvBufferSize =3D sizeof (RecvBuffer);

+  Status =3D Tpm2SubmitCommand (SendBufferSize, (UINT8 *)&SendBuf= fer, &RecvBufferSize, (UINT8 *)&RecvBuffer);

+  if (EFI_ERROR (Status)) {

+    goto Done;

+  }

+

+  if (RecvBufferSize < sizeof (TPM2_RESPONSE_HEADER)) {

+    DEBUG ((EFI_D_ERROR, "Tpm2NvUndefineSpaceSpecial -= RecvBufferSize Error - %x\n", RecvBufferSize));

+    Status =3D EFI_DEVICE_ERROR;

+    goto Done;

+  }

+

+  ResponseCode =3D SwapBytes32(RecvBuffer.Header.responseCode);

+  if (ResponseCode !=3D TPM_RC_SUCCESS) {

+    DEBUG ((EFI_D_ERROR, "Tpm2NvUndefineSpaceSpecial -= responseCode - %x\n", SwapBytes32(RecvBuffer.Header.responseCode)));<= br>
+  }

+  switch (ResponseCode) {

+  case TPM_RC_SUCCESS:

+    // return data

+    break;

+  case TPM_RC_ATTRIBUTES:

+  case TPM_RC_ATTRIBUTES + RC_NV_UndefineSpaceSpecial_nvIndex:

+    Status =3D EFI_UNSUPPORTED;

+    break;

+  case TPM_RC_NV_AUTHORIZATION:

+    Status =3D EFI_SECURITY_VIOLATION;

+    break;

+  case TPM_RC_HANDLE + RC_NV_UndefineSpaceSpecial_nvIndex: // TPM_RC_= NV_DEFINED:

+    Status =3D EFI_NOT_FOUND;

+    break;

+  case TPM_RC_VALUE + RC_NV_UndefineSpace_nvIndex:

+    Status =3D EFI_INVALID_PARAMETER;

+    break;

+  default:

+    Status =3D EFI_DEVICE_ERROR;

+    break;

+  }

+

+Done:

+  //

+  // Clear AuthSession Content

+  //

+  ZeroMem (&SendBuffer, sizeof(SendBuffer));

+  ZeroMem (&RecvBuffer, sizeof(RecvBuffer));

+  return Status;

+} // Tpm2NvUndefineSpaceSpecial()

+

 /**

   This command reads a value from an area in NV memory previousl= y defined by TPM2_NV_DefineSpace().

 

diff --git a/SecurityPkg/Include/Library/Tpm2CommandLib.h b/SecurityPkg/Inc= lude/Library/Tpm2CommandLib.h
index ee8eb622951c..8d7b4998d98d 100644
--- a/SecurityPkg/Include/Library/Tpm2CommandLib.h
+++ b/SecurityPkg/Include/Library/Tpm2CommandLib.h
@@ -364,6 +364,28 @@ Tpm2NvUndefineSpace (
   IN      TPMS_AUTH_COMMAND  =        *AuthSession OPTIONAL

   );

 

+/**

+  This command removes an index from the TPM.

+

+  @param[in]  NvIndex       &= nbsp;     The NV Index.

+  @param[in]  IndexAuthSession    Auth session co= ntext for the Index auth/policy

+  @param[in]  PlatAuthSession     Auth sessi= on context for the Platform auth/policy

+

+  @retval EFI_SUCCESS        =      Operation completed successfully.

+  @retval EFI_NOT_FOUND       &nbs= p;   The command was returned successfully, but NvIndex is not fo= und.

+  @retval EFI_UNSUPPORTED       &n= bsp; Selected NvIndex does not support deletion through this call.

+  @retval EFI_SECURITY_VIOLATION  Deletion is not authorized by = current policy session.

+  @retval EFI_INVALID_PARAMETER   The command was unsuccess= ful.

+  @retval EFI_DEVICE_ERROR        = The command was unsuccessful.

+**/

+EFI_STATUS

+EFIAPI

+Tpm2NvUndefineSpaceSpecial (

+  IN      TPMI_RH_NV_INDEX   =        NvIndex,

+  IN      TPMS_AUTH_COMMAND   = ;      *IndexAuthSession OPTIONAL,

+  IN      TPMS_AUTH_COMMAND   = ;      *PlatAuthSession OPTIONAL

+  );

+

 /**

   This command reads a value from an area in NV memory previousl= y defined by TPM2_NV_DefineSpace().

 

--
2.31.1.windows.1



-=3D-=3D-=3D-=3D-=3D-=3D
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#78450): https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fedk2.gr= oups.io%2Fg%2Fdevel%2Fmessage%2F78450&amp;data=3D04%7C01%7CBret.Barkele= w%40microsoft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141af91ab= 2d7cd011db47%7C1%7C0%7C637632645397612922%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiM= C4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sd= ata=3DCWxLwgp73z2XQEa%2FN77gsCwRF73xha0RZCKwcFTlrRE%3D&amp;reserved=3D0=
Mute This Topic: https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fgroups.= io%2Fmt%2F84555713%2F1822150&amp;data=3D04%7C01%7CBret.Barkelew%40micro= soft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141af91ab2d7cd011d= b47%7C1%7C0%7C637632645397612922%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMD= AiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=3DIWQ= 6E4yP0ECt3oYLYQa%2BnddGfcQEDMgfASlcxRuda%2BQ%3D&amp;reserved=3D0 Group Owner: devel+owner@edk2= .groups.io
Unsubscribe: https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fedk2.gr= oups.io%2Fg%2Fdevel%2Funsub&amp;data=3D04%7C01%7CBret.Barkelew%40micros= oft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141af91ab2d7cd011db= 47%7C1%7C0%7C637632645397612922%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDA= iLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=3Dqor4= Y5FZEH8ch0AEmWDbe97FIQk4V1qx7IURcTHzjAU%3D&amp;reserved=3D0 [brbarkel@microsoft.com]
-=3D-=3D-=3D-=3D-=3D-=3D

 

 

 

--_000_MW4PR21MB19074B8BEBB9A7E9550535F6EFFA9MW4PR21MB1907namp_--