From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from NAM12-MW2-obe.outbound.protection.outlook.com (NAM12-MW2-obe.outbound.protection.outlook.com [40.107.244.116]) by mx.groups.io with SMTP id smtpd.web09.12520.1628710675602077330 for ; Wed, 11 Aug 2021 12:37:56 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@microsoft.com header.s=selector2 header.b=fT+4ho3h; spf=pass (domain: microsoft.com, ip: 40.107.244.116, mailfrom: bret.barkelew@microsoft.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=S7lRFs7R75hpn4RhKRiOonjD12bv4hBjYb2wMmR72PSnmNqoTP9rjhxLRdPWTy7zCKuoS/4wgiQqranqE0927FKVo1jicVUpxGULJ2M40ABM9aVwqeWGbYEivH/3HNtUbx8Bt3/yLzm4eL7fGJn93umTtUe+A7n3ohKINflaHov84FyXQh1ZOD4yJRx3BGufXY6R7qgL/o3VnI4a4fiEgW6SrMFMZN2xnskKEx7t4SIzvl9PVDbg7LOIEhlG/k7qKO6j7BrcshfFzhLiTgLVhL9zSH+JGjOY7rkrLBR6RrOJ0c0CR5CfF4CfnN4hHwb8f1zgkYEIFeAEI1rbDwHr1A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=XWw59xeCs7EL/PZKwnOcxG8PQkl8AuNED7tTwLp8j7M=; b=ZdIJRvERkrcZMh/Jhgo0R+M4pzdffZOHDQpLNfI8enkufi5ASlFglte6bj+EIv6Cguf8O64/qJSwuutvwheIEyRrW20I+iKOLVkpNItwYbmOcu6tjKtgQXB6ZDZPvCzk/GPMe6dBFnGERuHyVMywld6qQ0K7LixZ8TVi8vLEILSmML1jeDgQm/6Dtuj7iE2GLYVN0u+X2wr5YXuJqprDuwl8+RqHFhOJy909Bd1qLHJQSuyB+j5K8ndNZO0nJSXxUbmlvXHsDzDSndG+FHKAXXL0HG9vCFLSTrKrD5Oh33Xki/TyETShWqIXRCM/E/l7o2AOR1keXqv97UeKHgV/sA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=microsoft.com; dmarc=pass action=none header.from=microsoft.com; dkim=pass header.d=microsoft.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=XWw59xeCs7EL/PZKwnOcxG8PQkl8AuNED7tTwLp8j7M=; b=fT+4ho3hct5UjQZ7NDgsbmDudR5RGevH6n7bwzJcQT6/+qLTqRZTFz4hPGip0V185Bqc2LKDCN65fXPXr00etwv0bzVcc4l6ScMQwEP0Soz1+qLqCCPevfAzgyMLz7prxceLOYK3U8L88Jpupx6h8h6/m08gcxgGvYvMTKyI0X0= Received: from MW4PR21MB1907.namprd21.prod.outlook.com (2603:10b6:303:71::8) by MWHPR21MB0143.namprd21.prod.outlook.com (2603:10b6:300:78::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4436.2; Wed, 11 Aug 2021 19:37:53 +0000 Received: from MW4PR21MB1907.namprd21.prod.outlook.com ([fe80::203b:4b22:735f:bdc2]) by MW4PR21MB1907.namprd21.prod.outlook.com ([fe80::203b:4b22:735f:bdc2%9]) with mapi id 15.20.4436.009; Wed, 11 Aug 2021 19:37:52 +0000 From: "Bret Barkelew" To: "devel@edk2.groups.io" , "bret@corthon.com" CC: "Yao, Jiewen" , Jian J Wang , Qi Zhang , Rahul Kumar Subject: Re: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Library: Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib Thread-Topic: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Library: Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib Thread-Index: AQHXhWwbbT7kW1JgJUKHOEoZ3Z5qO6tb0LjCgAe8VzuACzjTUw== Date: Wed, 11 Aug 2021 19:37:52 +0000 Message-ID: References: <20210730175517.2445-1-brbarkel@microsoft.com> <1696A3E2DE5C4DCB.1941@groups.io> In-Reply-To: Accept-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=True;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2021-07-30T18:07:39.2266129Z;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ContentBits=0;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Method=Standard authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=microsoft.com; x-ms-publictraffictype: Email x-ms-office365-filtering-correlation-id: 35f89f40-f95d-4485-bf94-08d95cff82c4 x-ms-traffictypediagnostic: MWHPR21MB0143: x-ld-processed: 72f988bf-86f1-41af-91ab-2d7cd011db47,ExtAddr x-microsoft-antispam-prvs: x-ms-oob-tlc-oobclassifiers: OLM:5797; x-ms-exchange-senderadcheck: 1 x-ms-exchange-antispam-relay: 0 x-microsoft-antispam: BCL:0; x-microsoft-antispam-message-info: EWs/8yHF6tjq64h6705kn6epd4xLhAA7HFKuzCU2PZ6cO9jo7nLXpLQqg6plzHaw6EdMGwCdrRl79LIruZxaMcfYY9Lepon5Bb2+/FHBnZIxPYSrXDYcNv/QRm7DOKpKEIuv5ML7pHtxTmTDohSS0/GiRIWBFca+I0uCnuKlVSoAtnsfj2Mtgw5DSINuq7Xi7Rn9/l6uJpRBBfCzSYLC1rTfIpAjdJPdcO3mPfp4MvHJyqGCofEXlQHnI2rQPbXb43ebWdGSg/KSiPSvXmgzBhOOYeQTUBNzhds2gSzduEYIDCnr46hCswSwuC53ovqHUd972vXG5avkkhjG2MabGxBplCx7Ku63PaA79nCd+q6snNCZKMscIja5tZ2f0VsHMTotwwCuDwvOJIH7WAXLd+KRzbDEYMZQMy1T5sUcPkF8ioQP4d9hTnwNlnHGlRxrhFw7M2/5KH/WHwO1wyAnfqwN6fXc3adMlvxFTNTJkUeuCWMJPXnWHUmlkBTbPLg4IYErSOUp4F73JBph3RZrVcYusY0PKqDlQeGtxg+JZ3MQ8c/INbIjmaWO8jM6KIKA8jiqeeu7AYHQL+au83R0qT8Thqg+3e2w3HGAEPZX/xE46whOgoMhauWp285rVYkgEZoN6xkT5Dby+dPBEKIjCeDgTy8j8G61jNcHcgi25Xuo7k0mFK0F83ZuyE59hwPngBL6cbmw+P+L7L9KcXyW/xwo2DlgfLPeGQHcwwHjw2Ahnr4r87VXgtTAbhyL/DxmLXDsD0kzdeSnqbeZ8qpGhYXBFTWZpvPis3N26MAGZLQ= x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:MW4PR21MB1907.namprd21.prod.outlook.com;PTR:;CAT:NONE;SFS:(6029001)(4636009)(366004)(508600001)(122000001)(33656002)(76236003)(6506007)(10290500003)(53546011)(83380400001)(5660300002)(38100700002)(82950400001)(82960400001)(110136005)(186003)(30864003)(2906002)(166002)(71200400001)(52536014)(4326008)(7696005)(38070700005)(26005)(66446008)(9686003)(55016002)(8990500004)(19627235002)(76116006)(316002)(66946007)(8676002)(8936002)(66476007)(86362001)(64756008)(966005)(66556008)(15650500001)(54906003);DIR:OUT;SFP:1102; x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?Windows-1252?Q?gPdYmkfsWB8OAfOvKT7hnEGxvP0tbv2QVEKNFqzb56p8DYbH0nPe4q1W?= =?Windows-1252?Q?5v1a/nZLD3WUFsPvkULzKfeDYsVms57fUblh9tcr364kTqxiCTqlYz2n?= =?Windows-1252?Q?Zi+sseKZQW++sEZp+05ykZvJDIFAP5L40vL5AN+5JJS72Trj8E2pRpu8?= =?Windows-1252?Q?tIRuIrdnQYYVC6yDFtQbALNfLPYeh9jerCuEDszJjX7eFJkW+8YHg8hS?= =?Windows-1252?Q?JpGW2N9g+SFK/wcNVuR4xfF3on5vPnn+ftTI2K718UU5UAujYhxcllI3?= =?Windows-1252?Q?RVoWcKG80nYCGQtSEjL/3lbjDtysz5wxVRMYELnSftJNGhfp6sXO/dY6?= =?Windows-1252?Q?pO3S5hY+Gv2bMlLEBZk7oTuT3q0P3rt75deW/e2ntA1OFS2gzdrzLimj?= =?Windows-1252?Q?UB2R8E731LR0GRKaSqsNsV8NnuGEdbMlT4IMalRtOk2omMRFLNzbQAPq?= =?Windows-1252?Q?Ki3v5nAqG0f0uHGnoCCM9GmjcKFtw/qiQQA3hrzW/h4tKZVGBow0TySD?= =?Windows-1252?Q?KuxLfXyEOFl8wo6VFoHjCwU2izRyQWvq9Fdfw9kGHZfVw/M4x0dkYSMo?= =?Windows-1252?Q?oYXd/Ucv6m3E6k+7Jb9FmtOvprj/fCfR2YiXq29+8pnbUMfqKYjM6mqx?= =?Windows-1252?Q?pyxqpQpVNPTw7DWjAe3lLgl0mY8zmGY/HDoA1dKd0HNAZF9Bsx8RrUB/?= =?Windows-1252?Q?dYy6R7lSrtHDVTfKYxXRa1AOjyodAEIt4wBC+nxtuN9omtk958G2RCAT?= =?Windows-1252?Q?0v3AiCLLGqpqjbQ/jFpZEFS52OwG21pg9G9rkFc0z/xs9tCrSCt3xKAU?= =?Windows-1252?Q?Jj3uMaVy+NoS0k9isFxw1ghlCaE0+gPHfV/uE2ILWphSh2+rOspFS0ZU?= =?Windows-1252?Q?i+N7wt/22x56AJobyIwZ/MVDggUj6C6BWfpZTO4n5kd3mtdGo/b3wwsg?= =?Windows-1252?Q?DpwIMVrQqKg6WwV7Mcz3hg0MLKj+Zg8OMXnFDxIT9CpYAUXCWfxL3yjj?= =?Windows-1252?Q?ZcYnTgDr6rhdds9EW9y5C7XHe0p1y9wZsFOdpxP6ILMIgzbLFTRzJxaN?= =?Windows-1252?Q?m0xrGIDswXoVdi9J5OmI3ZtKJIuvJIgX/ahe7Je5trQXPAdkgLX+myOz?= =?Windows-1252?Q?0Z18hji1CMeiaSNzzkofRkptJpIt2fEfl3DoqLUF1owgLxWJANwFN/BO?= =?Windows-1252?Q?D8q6KFSyaKLZMzEQJrvAj2kTOkLFogRzIUzU2Sy5ABT3Z5ltnAr1bg4o?= =?Windows-1252?Q?EqUd0fVt2wy0XWHIDxGDUrlvDbkkBEsZB+WXtuj/vaKkAWosZnCneTZy?= =?Windows-1252?Q?X4ooHJ2nJi9fJ9stJNkhHGSjXNifR8U08kEiWfZZf3l0Lp3w90oWX0x4?= =?Windows-1252?Q?Tq8W3kTTtG/rOJo+n3U0wEMIXMoTX0F7ds0qfAnVsItwOuNawLbeOyWt?= =?Windows-1252?Q?ouWiqvU27RshHRCOJ97i2g=3D=3D?= x-ms-exchange-transport-forked: True MIME-Version: 1.0 X-OriginatorOrg: microsoft.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: MW4PR21MB1907.namprd21.prod.outlook.com X-MS-Exchange-CrossTenant-Network-Message-Id: 35f89f40-f95d-4485-bf94-08d95cff82c4 X-MS-Exchange-CrossTenant-originalarrivaltime: 11 Aug 2021 19:37:52.8779 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47 X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: SDBMuzRkQlah4HJAYuEUkZNQyyuGGEWFLPQm3IQwwUOQpVwoPFjRGMYSSDUm6TBQoxxxncx//9bsyAN2yNFabg== X-MS-Exchange-Transport-CrossTenantHeadersStamped: MWHPR21MB0143 Content-Language: en-US Content-Type: multipart/alternative; boundary="_000_MW4PR21MB19076E259F582957CB1685F2EFF89MW4PR21MB1907namp_" --_000_MW4PR21MB19076E259F582957CB1685F2EFF89MW4PR21MB1907namp_ Content-Type: text/plain; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable Thoughts? - Bret ________________________________ From: devel@edk2.groups.io on behalf of Bret Barkele= w via groups.io Sent: Wednesday, August 4, 2021 9:32:32 AM To: devel@edk2.groups.io ; bret@corthon.com Cc: Yao, Jiewen ; Jian J Wang = ; Qi Zhang ; Rahul Kumar Subject: Re: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Library: Ad= d Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib Poking this one. 1. It=92s a easy review with small, obvious code change. 2. I need some answers on =93when is it okay to violate ECC/PatchCheck, = if the new code matches the style of the existing code. Should I endeavor t= o pass the PatchCheck and ECCCheck with this patch only, and leave it in co= nflict with the rest of the file? Thanks! - Bret From: Bret Barkelew via groups.io Sent: Friday, July 30, 2021 11:08 AM To: devel@edk2.groups.io; bret@corthon.com Cc: Yao, Jiewen; Jian J Wang; Qi Zhang; Rahul Kumar Subject: Re: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Library: Ad= d Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib Note, even though this keeps with the style of the rest of the file, it bre= aks ECC: SecurityPkg/Library: Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib by co= rthon =B7 Pull Request #1848 =B7 tianocore/edk2 (github.com) PROGRESS - --Running SecurityPkg: EccCheck Test NO-TARGET -- ERROR - ERROR - ERROR - EFI coding style error ERROR - *Error code: 8001 ERROR - *Only capital letters are allowed to be used for #define declaratio= ns ERROR - *file: //home/vsts/work/1/s/SecurityPkg/Library/Tpm2CommandLib/Tpm2= NVStorage.c ERROR - *Line number: 27 ERROR - *The #define name [RC_NV_UndefineSpaceSpecial_nvIndex] does no Thoughts? - Bret From: Bret Barkelew via groups.io Sent: Friday, July 30, 2021 10:55 AM To: devel@edk2.groups.io Cc: Yao, Jiewen; Jian J Wang; Qi Zhang; Rahul Kumar Subject: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Library: Add Tp= m2NvUndefineSpaceSpecial to Tpm2CommandLib Used to provision and maintain certain HW-defined NV spaces. REF: https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fbu= gzilla.tianocore.org%2Fshow_bug.cgi%3Fid%3D2994&data=3D04%7C01%7CBret.B= arkelew%40microsoft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141= af91ab2d7cd011db47%7C1%7C0%7C637632645397602953%7CUnknown%7CTWFpbGZsb3d8eyJ= WIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&= sdata=3Ds96M3RvxMOY831Vfr1nt%2Fz1h3cyb6jU9eFzvjKO7Dtc%3D&reserved=3D0 Signed-off-by: Bret Barkelew Cc: Jiewen Yao Cc: Jian J Wang Cc: Qi Zhang Cc: Rahul Kumar --- SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c | 122 +++++++++++++++++= +++ SecurityPkg/Include/Library/Tpm2CommandLib.h | 22 ++++ 2 files changed, 144 insertions(+) diff --git a/SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c b/SecurityP= kg/Library/Tpm2CommandLib/Tpm2NVStorage.c index 87572de20164..7931fade9190 100644 --- a/SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c +++ b/SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c @@ -24,6 +24,8 @@ SPDX-License-Identifier: BSD-2-Clause-Patent #define RC_NV_UndefineSpace_authHandle (TPM_RC_H + TPM_RC_1) #define RC_NV_UndefineSpace_nvIndex (TPM_RC_H + TPM_RC_2) +#define RC_NV_UndefineSpaceSpecial_nvIndex (TPM_RC_H + TPM_RC_1) + #define RC_NV_Read_authHandle (TPM_RC_H + TPM_RC_1) #define RC_NV_Read_nvIndex (TPM_RC_H + TPM_RC_2) #define RC_NV_Read_size (TPM_RC_P + TPM_RC_1) @@ -74,6 +76,20 @@ typedef struct { TPMS_AUTH_RESPONSE AuthSession; } TPM2_NV_UNDEFINESPACE_RESPONSE; +typedef struct { + TPM2_COMMAND_HEADER Header; + TPMI_RH_NV_INDEX NvIndex; + TPMI_RH_PLATFORM Platform; + UINT32 AuthSessionSize; + TPMS_AUTH_COMMAND AuthSession; +} TPM2_NV_UNDEFINESPACESPECIAL_COMMAND; + +typedef struct { + TPM2_RESPONSE_HEADER Header; + UINT32 AuthSessionSize; + TPMS_AUTH_RESPONSE AuthSession; +} TPM2_NV_UNDEFINESPACESPECIAL_RESPONSE; + typedef struct { TPM2_COMMAND_HEADER Header; TPMI_RH_NV_AUTH AuthHandle; @@ -506,6 +522,112 @@ Done: return Status; } +/** + This command removes an index from the TPM. + + @param[in] NvIndex The NV Index. + @param[in] IndexAuthSession Auth session context for the Index auth/= policy + @param[in] PlatAuthSession Auth session context for the Platform au= th/policy + + @retval EFI_SUCCESS Operation completed successfully. + @retval EFI_NOT_FOUND The command was returned successfully, b= ut NvIndex is not found. + @retval EFI_UNSUPPORTED Selected NvIndex does not support deleti= on through this call. + @retval EFI_SECURITY_VIOLATION Deletion is not authorized by current po= licy session. + @retval EFI_INVALID_PARAMETER The command was unsuccessful. + @retval EFI_DEVICE_ERROR The command was unsuccessful. +**/ +EFI_STATUS +EFIAPI +Tpm2NvUndefineSpaceSpecial ( + IN TPMI_RH_NV_INDEX NvIndex, + IN TPMS_AUTH_COMMAND *IndexAuthSession OPTIONAL, + IN TPMS_AUTH_COMMAND *PlatAuthSession OPTIONAL + ) +{ + EFI_STATUS Status; + TPM2_NV_UNDEFINESPACESPECIAL_COMMAND SendBuffer; + TPM2_NV_UNDEFINESPACESPECIAL_RESPONSE RecvBuffer; + UINT32 SendBufferSize; + UINT32 RecvBufferSize; + UINT8 *Buffer; + UINT32 IndexAuthSize, PlatAuthSize; + TPM_RC ResponseCode; + + // + // Construct command + // + SendBuffer.Header.tag =3D SwapBytes16(TPM_ST_SESSIONS); + SendBuffer.Header.commandCode =3D SwapBytes32(TPM_CC_NV_UndefineSpaceSpe= cial); + + SendBuffer.NvIndex =3D SwapBytes32 (NvIndex); + SendBuffer.Platform =3D SwapBytes32 (TPM_RH_PLATFORM); + + // + // Marshall the Auth Sessions for the two handles. + Buffer =3D (UINT8 *)&SendBuffer.AuthSession; + // IndexAuthSession + IndexAuthSize =3D CopyAuthSessionCommand (IndexAuthSession, Buffer); + Buffer +=3D IndexAuthSize; + // PlatAuthSession + PlatAuthSize =3D CopyAuthSessionCommand (PlatAuthSession, Buffer); + Buffer +=3D PlatAuthSize; + // AuthSessionSize + SendBuffer.AuthSessionSize =3D SwapBytes32(IndexAuthSize + PlatAuthSize)= ; + + // Update total command size. + SendBufferSize =3D (UINT32)(Buffer - (UINT8 *)&SendBuffer); + SendBuffer.Header.paramSize =3D SwapBytes32 (SendBufferSize); + + // + // send Tpm command + // + RecvBufferSize =3D sizeof (RecvBuffer); + Status =3D Tpm2SubmitCommand (SendBufferSize, (UINT8 *)&SendBuffer, &Rec= vBufferSize, (UINT8 *)&RecvBuffer); + if (EFI_ERROR (Status)) { + goto Done; + } + + if (RecvBufferSize < sizeof (TPM2_RESPONSE_HEADER)) { + DEBUG ((EFI_D_ERROR, "Tpm2NvUndefineSpaceSpecial - RecvBufferSize Erro= r - %x\n", RecvBufferSize)); + Status =3D EFI_DEVICE_ERROR; + goto Done; + } + + ResponseCode =3D SwapBytes32(RecvBuffer.Header.responseCode); + if (ResponseCode !=3D TPM_RC_SUCCESS) { + DEBUG ((EFI_D_ERROR, "Tpm2NvUndefineSpaceSpecial - responseCode - %x\n= ", SwapBytes32(RecvBuffer.Header.responseCode))); + } + switch (ResponseCode) { + case TPM_RC_SUCCESS: + // return data + break; + case TPM_RC_ATTRIBUTES: + case TPM_RC_ATTRIBUTES + RC_NV_UndefineSpaceSpecial_nvIndex: + Status =3D EFI_UNSUPPORTED; + break; + case TPM_RC_NV_AUTHORIZATION: + Status =3D EFI_SECURITY_VIOLATION; + break; + case TPM_RC_HANDLE + RC_NV_UndefineSpaceSpecial_nvIndex: // TPM_RC_NV_DE= FINED: + Status =3D EFI_NOT_FOUND; + break; + case TPM_RC_VALUE + RC_NV_UndefineSpace_nvIndex: + Status =3D EFI_INVALID_PARAMETER; + break; + default: + Status =3D EFI_DEVICE_ERROR; + break; + } + +Done: + // + // Clear AuthSession Content + // + ZeroMem (&SendBuffer, sizeof(SendBuffer)); + ZeroMem (&RecvBuffer, sizeof(RecvBuffer)); + return Status; +} // Tpm2NvUndefineSpaceSpecial() + /** This command reads a value from an area in NV memory previously defined = by TPM2_NV_DefineSpace(). diff --git a/SecurityPkg/Include/Library/Tpm2CommandLib.h b/SecurityPkg/Inc= lude/Library/Tpm2CommandLib.h index ee8eb622951c..8d7b4998d98d 100644 --- a/SecurityPkg/Include/Library/Tpm2CommandLib.h +++ b/SecurityPkg/Include/Library/Tpm2CommandLib.h @@ -364,6 +364,28 @@ Tpm2NvUndefineSpace ( IN TPMS_AUTH_COMMAND *AuthSession OPTIONAL ); +/** + This command removes an index from the TPM. + + @param[in] NvIndex The NV Index. + @param[in] IndexAuthSession Auth session context for the Index auth/= policy + @param[in] PlatAuthSession Auth session context for the Platform au= th/policy + + @retval EFI_SUCCESS Operation completed successfully. + @retval EFI_NOT_FOUND The command was returned successfully, b= ut NvIndex is not found. + @retval EFI_UNSUPPORTED Selected NvIndex does not support deleti= on through this call. + @retval EFI_SECURITY_VIOLATION Deletion is not authorized by current po= licy session. + @retval EFI_INVALID_PARAMETER The command was unsuccessful. + @retval EFI_DEVICE_ERROR The command was unsuccessful. +**/ +EFI_STATUS +EFIAPI +Tpm2NvUndefineSpaceSpecial ( + IN TPMI_RH_NV_INDEX NvIndex, + IN TPMS_AUTH_COMMAND *IndexAuthSession OPTIONAL, + IN TPMS_AUTH_COMMAND *PlatAuthSession OPTIONAL + ); + /** This command reads a value from an area in NV memory previously defined = by TPM2_NV_DefineSpace(). -- 2.31.1.windows.1 -=3D-=3D-=3D-=3D-=3D-=3D Groups.io Links: You receive all messages sent to this group. View/Reply Online (#78450): https://nam06.safelinks.protection.outlook.com/= ?url=3Dhttps%3A%2F%2Fedk2.groups.io%2Fg%2Fdevel%2Fmessage%2F78450&data= =3D04%7C01%7CBret.Barkelew%40microsoft.com%7Cb7ae3c62047c48fc85d908d953833c= a0%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637632645397612922%7CUnknow= n%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI= 6Mn0%3D%7C1000&sdata=3DCWxLwgp73z2XQEa%2FN77gsCwRF73xha0RZCKwcFTlrRE%3D= &reserved=3D0 Mute This Topic: https://nam06.safelinks.protection.outlook.com/?url=3Dhttp= s%3A%2F%2Fgroups.io%2Fmt%2F84555713%2F1822150&data=3D04%7C01%7CBret.Bar= kelew%40microsoft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141af= 91ab2d7cd011db47%7C1%7C0%7C637632645397612922%7CUnknown%7CTWFpbGZsb3d8eyJWI= joiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sd= ata=3DIWQ6E4yP0ECt3oYLYQa%2BnddGfcQEDMgfASlcxRuda%2BQ%3D&reserved=3D0 Group Owner: devel+owner@edk2.groups.io Unsubscribe: https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A= %2F%2Fedk2.groups.io%2Fg%2Fdevel%2Funsub&data=3D04%7C01%7CBret.Barkelew= %40microsoft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141af91ab2= d7cd011db47%7C1%7C0%7C637632645397612922%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC= 4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata= =3Dqor4Y5FZEH8ch0AEmWDbe97FIQk4V1qx7IURcTHzjAU%3D&reserved=3D0 [brbarkel@microsoft.com] -=3D-=3D-=3D-=3D-=3D-=3D --_000_MW4PR21MB19076E259F582957CB1685F2EFF89MW4PR21MB1907namp_ Content-Type: text/html; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable

Thoughts?

 

- Bret

 


From: devel@edk2.groups.io = <devel@edk2.groups.io> on behalf of Bret Barkelew via groups.io <b= ret.barkelew=3Dmicrosoft.com@groups.io>
Sent: Wednesday, August 4, 2021 9:32:32 AM
To: devel@edk2.groups.io <devel@edk2.groups.io>; bret@corthon.= com <bret@corthon.com>
Cc: Yao, Jiewen <jiewen.yao@intel.com>; Jian J Wang <jian.j= .wang@intel.com>; Qi Zhang <qi1.zhang@intel.com>; Rahul Kumar <= rahul1.kumar@intel.com>
Subject: Re: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Libr= ary: Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib
 

Poking this one.

 

  1. It=92s a easy re= view with small, obvious code change.
  2. I need some answers on =93when is it okay to viol= ate ECC/PatchCheck, if the new code matches the style of the existing code.= Should I endeavor to pass the PatchCheck and ECCCheck with this patch only= , and leave it in conflict with the rest of the file?

 

Thanks!

 

- Bret

 

From: Bret Barkelew via = groups.io
Sent: Friday, July 30, 2021 11:08 AM
To: devel@edk2.groups.io= ; bret@corthon.com
Cc: Yao, Jiewen; Jian J Wang; Qi Zhang; Rahul Kumar
Subject: Re: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Libr= ary: Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib

 

Note, even though this keeps with the style of the= rest of the file, it breaks ECC:

SecurityPkg/Library: Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib by corthon =B7 Pull Reque= st #1848 =B7 tianocore/edk2 (github.com)

 

= PROGRESS - --Running SecurityPkg: EccCheck Test NO-TARGET --

= ERROR -

= ERROR -

= ERROR - EFI coding style error

= ERROR - *Error code: 8001

= ERROR - *Only capital letters are allowed to be used for #define declaratio= ns

= ERROR - *file: //home/vsts/work/1/s/SecurityPkg/Library/Tpm2CommandLib/Tpm2= NVStorage.c

= ERROR - *Line number: 27

= ERROR - *The #define name [RC_NV_UndefineSpaceSpecial_nvIndex] does no

 

Thoughts?

 

- Bret

 

From: Bret Barkelew via groups.io
Sent: Friday, July 30, 2021 10:55 AM
To: devel@edk2.groups.io=
Cc: Yao, Jiewen; Jian J Wang; Qi Zhang; Rahul Kumar
Subject: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Library:= Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib

 

Used to provision a= nd maintain certain HW-defined NV spaces.

REF: https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fbugzill= a.tianocore.org%2Fshow_bug.cgi%3Fid%3D2994&amp;data=3D04%7C01%7CBret.Ba= rkelew%40microsoft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141a= f91ab2d7cd011db47%7C1%7C0%7C637632645397602953%7CUnknown%7CTWFpbGZsb3d8eyJW= IjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&a= mp;sdata=3Ds96M3RvxMOY831Vfr1nt%2Fz1h3cyb6jU9eFzvjKO7Dtc%3D&amp;reserve= d=3D0

Signed-off-by: Bret Barkelew <bret.barkelew@microsoft.com>
Cc: Jiewen Yao <jiewen.yao@intel.com>
Cc: Jian J Wang <jian.j.wang@intel.com>
Cc: Qi Zhang <qi1.zhang@intel.com>
Cc: Rahul Kumar <rahul1.kumar@intel.com>
---
 SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c | 122 ++++++++++++= ++++++++
 SecurityPkg/Include/Library/Tpm2CommandLib.h    &= nbsp;  |  22 ++++
 2 files changed, 144 insertions(+)

diff --git a/SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c b/SecurityP= kg/Library/Tpm2CommandLib/Tpm2NVStorage.c
index 87572de20164..7931fade9190 100644
--- a/SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c
+++ b/SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c
@@ -24,6 +24,8 @@ SPDX-License-Identifier: BSD-2-Clause-Patent
 #define RC_NV_UndefineSpace_authHandle      = (TPM_RC_H + TPM_RC_1)

 #define RC_NV_UndefineSpace_nvIndex     &nbs= p;   (TPM_RC_H + TPM_RC_2)

 

+#define RC_NV_UndefineSpaceSpecial_nvIndex  (TPM_RC_H + TPM_RC_1)

+

 #define RC_NV_Read_authHandle      &nbs= p;        (TPM_RC_H + TPM_RC_1)

 #define RC_NV_Read_nvIndex       &= nbsp;          (TPM_RC_H + TPM= _RC_2)

 #define RC_NV_Read_size       &nbs= p;             = (TPM_RC_P + TPM_RC_1)

@@ -74,6 +76,20 @@ typedef struct {
   TPMS_AUTH_RESPONSE       &n= bsp; AuthSession;

 } TPM2_NV_UNDEFINESPACE_RESPONSE;

 

+typedef struct {

+  TPM2_COMMAND_HEADER       Header;

+  TPMI_RH_NV_INDEX        &nb= sp; NvIndex;

+  TPMI_RH_PLATFORM        &nb= sp; Platform;

+  UINT32          &= nbsp;         AuthSessionSize;

+  TPMS_AUTH_COMMAND         A= uthSession;

+} TPM2_NV_UNDEFINESPACESPECIAL_COMMAND;

+

+typedef struct {

+  TPM2_RESPONSE_HEADER       Header;
+  UINT32          &= nbsp;          AuthSessionSize= ;

+  TPMS_AUTH_RESPONSE         = AuthSession;

+} TPM2_NV_UNDEFINESPACESPECIAL_RESPONSE;

+

 typedef struct {

   TPM2_COMMAND_HEADER       Header= ;

   TPMI_RH_NV_AUTH        = ;   AuthHandle;

@@ -506,6 +522,112 @@ Done:
   return Status;

 }

 

+/**

+  This command removes an index from the TPM.

+

+  @param[in]  NvIndex       &= nbsp;     The NV Index.

+  @param[in]  IndexAuthSession    Auth session co= ntext for the Index auth/policy

+  @param[in]  PlatAuthSession     Auth sessi= on context for the Platform auth/policy

+

+  @retval EFI_SUCCESS        =      Operation completed successfully.

+  @retval EFI_NOT_FOUND       &nbs= p;   The command was returned successfully, but NvIndex is not fo= und.

+  @retval EFI_UNSUPPORTED       &n= bsp; Selected NvIndex does not support deletion through this call.

+  @retval EFI_SECURITY_VIOLATION  Deletion is not authorized by = current policy session.

+  @retval EFI_INVALID_PARAMETER   The command was unsuccess= ful.

+  @retval EFI_DEVICE_ERROR        = The command was unsuccessful.

+**/

+EFI_STATUS

+EFIAPI

+Tpm2NvUndefineSpaceSpecial (

+  IN      TPMI_RH_NV_INDEX   =        NvIndex,

+  IN      TPMS_AUTH_COMMAND   = ;      *IndexAuthSession OPTIONAL,

+  IN      TPMS_AUTH_COMMAND   = ;      *PlatAuthSession OPTIONAL

+  )

+{

+  EFI_STATUS         &nb= sp;            =         Status;

+  TPM2_NV_UNDEFINESPACESPECIAL_COMMAND    SendBuffer;<= br>
+  TPM2_NV_UNDEFINESPACESPECIAL_RESPONSE   RecvBuffer;

+  UINT32          &= nbsp;           &nbs= p;           SendBufferSi= ze;

+  UINT32          &= nbsp;           &nbs= p;           RecvBufferSi= ze;

+  UINT8          &n= bsp;            = ;            *Buffer= ;

+  UINT32          &= nbsp;           &nbs= p;           IndexAuthSiz= e, PlatAuthSize;

+  TPM_RC          &= nbsp;           &nbs= p;           ResponseCode= ;

+

+  //

+  // Construct command

+  //

+  SendBuffer.Header.tag =3D SwapBytes16(TPM_ST_SESSIONS);

+  SendBuffer.Header.commandCode =3D SwapBytes32(TPM_CC_NV_UndefineSpa= ceSpecial);

+

+  SendBuffer.NvIndex =3D SwapBytes32 (NvIndex);

+  SendBuffer.Platform =3D SwapBytes32 (TPM_RH_PLATFORM);

+

+  //

+  // Marshall the Auth Sessions for the two handles.

+  Buffer =3D (UINT8 *)&SendBuffer.AuthSession;

+  // IndexAuthSession

+  IndexAuthSize =3D CopyAuthSessionCommand (IndexAuthSession, Buffer)= ;

+  Buffer +=3D IndexAuthSize;

+  // PlatAuthSession

+  PlatAuthSize =3D CopyAuthSessionCommand (PlatAuthSession, Buffer);<= br>
+  Buffer +=3D PlatAuthSize;

+  // AuthSessionSize

+  SendBuffer.AuthSessionSize =3D SwapBytes32(IndexAuthSize + PlatAuth= Size);

+

+  // Update total command size.

+  SendBufferSize =3D (UINT32)(Buffer - (UINT8 *)&SendBuffer);

+  SendBuffer.Header.paramSize =3D SwapBytes32 (SendBufferSize);

+

+  //

+  // send Tpm command

+  //

+  RecvBufferSize =3D sizeof (RecvBuffer);

+  Status =3D Tpm2SubmitCommand (SendBufferSize, (UINT8 *)&SendBuf= fer, &RecvBufferSize, (UINT8 *)&RecvBuffer);

+  if (EFI_ERROR (Status)) {

+    goto Done;

+  }

+

+  if (RecvBufferSize < sizeof (TPM2_RESPONSE_HEADER)) {

+    DEBUG ((EFI_D_ERROR, "Tpm2NvUndefineSpaceSpecial -= RecvBufferSize Error - %x\n", RecvBufferSize));

+    Status =3D EFI_DEVICE_ERROR;

+    goto Done;

+  }

+

+  ResponseCode =3D SwapBytes32(RecvBuffer.Header.responseCode);

+  if (ResponseCode !=3D TPM_RC_SUCCESS) {

+    DEBUG ((EFI_D_ERROR, "Tpm2NvUndefineSpaceSpecial -= responseCode - %x\n", SwapBytes32(RecvBuffer.Header.responseCode)));<= br>
+  }

+  switch (ResponseCode) {

+  case TPM_RC_SUCCESS:

+    // return data

+    break;

+  case TPM_RC_ATTRIBUTES:

+  case TPM_RC_ATTRIBUTES + RC_NV_UndefineSpaceSpecial_nvIndex:

+    Status =3D EFI_UNSUPPORTED;

+    break;

+  case TPM_RC_NV_AUTHORIZATION:

+    Status =3D EFI_SECURITY_VIOLATION;

+    break;

+  case TPM_RC_HANDLE + RC_NV_UndefineSpaceSpecial_nvIndex: // TPM_RC_= NV_DEFINED:

+    Status =3D EFI_NOT_FOUND;

+    break;

+  case TPM_RC_VALUE + RC_NV_UndefineSpace_nvIndex:

+    Status =3D EFI_INVALID_PARAMETER;

+    break;

+  default:

+    Status =3D EFI_DEVICE_ERROR;

+    break;

+  }

+

+Done:

+  //

+  // Clear AuthSession Content

+  //

+  ZeroMem (&SendBuffer, sizeof(SendBuffer));

+  ZeroMem (&RecvBuffer, sizeof(RecvBuffer));

+  return Status;

+} // Tpm2NvUndefineSpaceSpecial()

+

 /**

   This command reads a value from an area in NV memory previousl= y defined by TPM2_NV_DefineSpace().

 

diff --git a/SecurityPkg/Include/Library/Tpm2CommandLib.h b/SecurityPkg/Inc= lude/Library/Tpm2CommandLib.h
index ee8eb622951c..8d7b4998d98d 100644
--- a/SecurityPkg/Include/Library/Tpm2CommandLib.h
+++ b/SecurityPkg/Include/Library/Tpm2CommandLib.h
@@ -364,6 +364,28 @@ Tpm2NvUndefineSpace (
   IN      TPMS_AUTH_COMMAND  =        *AuthSession OPTIONAL

   );

 

+/**

+  This command removes an index from the TPM.

+

+  @param[in]  NvIndex       &= nbsp;     The NV Index.

+  @param[in]  IndexAuthSession    Auth session co= ntext for the Index auth/policy

+  @param[in]  PlatAuthSession     Auth sessi= on context for the Platform auth/policy

+

+  @retval EFI_SUCCESS        =      Operation completed successfully.

+  @retval EFI_NOT_FOUND       &nbs= p;   The command was returned successfully, but NvIndex is not fo= und.

+  @retval EFI_UNSUPPORTED       &n= bsp; Selected NvIndex does not support deletion through this call.

+  @retval EFI_SECURITY_VIOLATION  Deletion is not authorized by = current policy session.

+  @retval EFI_INVALID_PARAMETER   The command was unsuccess= ful.

+  @retval EFI_DEVICE_ERROR        = The command was unsuccessful.

+**/

+EFI_STATUS

+EFIAPI

+Tpm2NvUndefineSpaceSpecial (

+  IN      TPMI_RH_NV_INDEX   =        NvIndex,

+  IN      TPMS_AUTH_COMMAND   = ;      *IndexAuthSession OPTIONAL,

+  IN      TPMS_AUTH_COMMAND   = ;      *PlatAuthSession OPTIONAL

+  );

+

 /**

   This command reads a value from an area in NV memory previousl= y defined by TPM2_NV_DefineSpace().

 

--
2.31.1.windows.1



-=3D-=3D-=3D-=3D-=3D-=3D
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#78450): https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fedk2.gr= oups.io%2Fg%2Fdevel%2Fmessage%2F78450&amp;data=3D04%7C01%7CBret.Barkele= w%40microsoft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141af91ab= 2d7cd011db47%7C1%7C0%7C637632645397612922%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiM= C4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sd= ata=3DCWxLwgp73z2XQEa%2FN77gsCwRF73xha0RZCKwcFTlrRE%3D&amp;reserved=3D0=
Mute This Topic: https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fgroups.= io%2Fmt%2F84555713%2F1822150&amp;data=3D04%7C01%7CBret.Barkelew%40micro= soft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141af91ab2d7cd011d= b47%7C1%7C0%7C637632645397612922%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMD= AiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=3DIWQ= 6E4yP0ECt3oYLYQa%2BnddGfcQEDMgfASlcxRuda%2BQ%3D&amp;reserved=3D0 Group Owner: devel+owner@edk2.groups.io
Unsubscribe: https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fedk2.gr= oups.io%2Fg%2Fdevel%2Funsub&amp;data=3D04%7C01%7CBret.Barkelew%40micros= oft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141af91ab2d7cd011db= 47%7C1%7C0%7C637632645397612922%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDA= iLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=3Dqor4= Y5FZEH8ch0AEmWDbe97FIQk4V1qx7IURcTHzjAU%3D&amp;reserved=3D0 [brbarkel@microsoft.com]
-=3D-=3D-=3D-=3D-=3D-=3D

 

 

--_000_MW4PR21MB19076E259F582957CB1685F2EFF89MW4PR21MB1907namp_--