From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from NAM02-SN1-obe.outbound.protection.outlook.com (NAM02-SN1-obe.outbound.protection.outlook.com [40.107.96.104]) by mx.groups.io with SMTP id smtpd.web08.25747.1628790753385251809 for ; Thu, 12 Aug 2021 10:52:34 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@microsoft.com header.s=selector2 header.b=NKYMVAkw; spf=pass (domain: microsoft.com, ip: 40.107.96.104, mailfrom: bret.barkelew@microsoft.com) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=cxrLCmXWdi0LYkxGyYxEtB93JYnh7gvM4yPzoNI8Kp77DF8nKKxwwX3sFC4VfKb8asls4Eib1mT3kbJYTvkuor2X8gvPMGd8ibgKclmaYrGdeyFSvC0OOrxlVV2qMUCJ08I21Fp3BJKTKbm8FpI5xtZLHA48YtwXGaV+KJxX/bqgxe9RDna2m+Djq2rTWdxK6gwT/2Zkz7WCa7SqvYot/jwheIbMjo7A7+72qMEqKfEONUEVAo0Al7Xxs4Kg1igdJlUCCtEzaz1m49n9jUhhH1kfpeBPdUvcs4WOX07V124RxC18jVam6JcUHS3sVF2Z2richF/eh6uWIVAKbd8Nsg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=WW89LEw82n0dW6iYfXIR7Lfg08hoKRcPzMa4SH9H3hY=; b=QMlvtbWRFoeEdYFewe2nIOBeCo4jxOmBf4FHLMYGv4xqVOetSDh0l9iQd24AVQTR0J0PMk4Yv7AtTE1PlX3C926cc/516Gh4Bc7mTZ1CA9ok5NKkb63FXQ1AN9Wdn5s/M0neFMU1jt3Vi77UJso5D1bn0q42jir1KBifcjzTxEBut9UH8T/Yo5oxwor9xClf0nr3apAEjOfRMFy4L6nT0OB/gnAbktFmaDBn2zfNXr1W45tRrMAvZ1Sk2MJq/Wh86hslDAoLsTswsoJnx+tb6v1POT4ZMRAmCijBpwlWCHfOB4QfzIsvHCw2OE6pscLax/tdZIvuis2LHHeeDnF8rw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=microsoft.com; dmarc=pass action=none header.from=microsoft.com; dkim=pass header.d=microsoft.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=WW89LEw82n0dW6iYfXIR7Lfg08hoKRcPzMa4SH9H3hY=; b=NKYMVAkwS+S/9YPp4H0aM4GwJluweFzLfdD8sW7ABtJB82w4ZHDMgEBMGq5YyYQXOQPi4SMvQn4Wi4Ye233SyIdgcwGIrwpEG+c2jJ/JCMPavi6XIq6uQvgsuOzRFMDlTexUlV9WH31y924ln84lWXqGNNl4aZ25hoY+FsoSoH4= Received: from MW4PR21MB1907.namprd21.prod.outlook.com (2603:10b6:303:71::8) by MWHPR21MB1600.namprd21.prod.outlook.com (2603:10b6:300:90::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4436.4; Thu, 12 Aug 2021 17:52:29 +0000 Received: from MW4PR21MB1907.namprd21.prod.outlook.com ([fe80::203b:4b22:735f:bdc2]) by MW4PR21MB1907.namprd21.prod.outlook.com ([fe80::203b:4b22:735f:bdc2%9]) with mapi id 15.20.4436.011; Thu, 12 Aug 2021 17:52:28 +0000 From: "Bret Barkelew" To: "devel@edk2.groups.io" , "bret@corthon.com" CC: "Yao, Jiewen" , Jian J Wang , Qi Zhang , Rahul Kumar Subject: Re: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Library: Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib Thread-Topic: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Library: Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib Thread-Index: AQHXhWwbbT7kW1JgJUKHOEoZ3Z5qO6tb0LjCgAe8VzuACzjTU4ABdOMp Date: Thu, 12 Aug 2021 17:52:28 +0000 Message-ID: References: <20210730175517.2445-1-brbarkel@microsoft.com> <1696A3E2DE5C4DCB.1941@groups.io> <169A57BB10BEC566.13770@groups.io> In-Reply-To: <169A57BB10BEC566.13770@groups.io> Accept-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=True;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2021-07-30T18:07:39.2266129Z;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ContentBits=0;MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Method=Standard authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=microsoft.com; x-ms-publictraffictype: Email x-ms-office365-filtering-correlation-id: 3ad0af6c-d6c3-4880-ea7d-08d95db9f3c8 x-ms-traffictypediagnostic: MWHPR21MB1600: x-ld-processed: 72f988bf-86f1-41af-91ab-2d7cd011db47,ExtAddr x-microsoft-antispam-prvs: x-ms-oob-tlc-oobclassifiers: OLM:5797; x-ms-exchange-senderadcheck: 1 x-ms-exchange-antispam-relay: 0 x-microsoft-antispam: BCL:0; x-microsoft-antispam-message-info: p0LOEl5+sfw8P0n7jLVDCPn/2e8tx/gmLrgyrmtpYLMI/r/3V+eJwB6lL65gvzWWOHevFGh9SRekseF77WU1OrGZRSXhidC55JQaOA6rVz0Aatf7tm7sPEDf7oZ08T3kcajr1e2c0Or/gVc0Lqa/TxzaXFxZtGdIMqWMc/OHOlHHGgfzjgfPQUgESnmw839vmWNEoaT8PDBZNeIOhqaOPWDHP5X+PZESJ8b27X7GBW3Ia2WCqj0UXxcu1dk5RoQVdamnuqMnGyk6H6AVML6k4uWfg2eyF2QFPWXb2HnD1CuSvfKZtdcG0cbN3Euzsxohk2cuBR5SkKxxp0Yh9xC0hh9a1i0p3UHLpyFN9kIxG/DbJge6CkVbkv7wwiFaYbOGboeqoCzoov51aZlmsPLfVofQ/2TPWDmrYzrq2OG4dXfkJvnjrUZjZt3x0Rb5ELhGgvNtGXoDF6bEicZhYkvBNiMDIXyPdS3xo0yGKGDitVjSAF2p+0MVIl5L1GJNO51MIuM7EpvtW0cJ+xrcdPPJXY/1Kkdm7zt2qY8oU9NFc4k0k7QEKGooUvkEpElLtrDstD710Ix7M3whEmtOdwNqZEsViQgSqXGBnXuZJ8hMX5WPtdPlloX8aDwCM78PtNSVJ/2tQjDaLuE+IwoZNijf1dxKTTYNiCK31eu5BO1bUdX48nKkRa2rLJsnEYZ9ets+M6BaYrApCBTG7fwoZ5VQz1LVn1HyznEV1SSQEdw3izzrV2yjYCpDLLP9dNIRnHlMRGlczxc9Ua46trJwIJFU8aWEUEUfQeWJ4aHIHYsEuNE= x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:MW4PR21MB1907.namprd21.prod.outlook.com;PTR:;CAT:NONE;SFS:(6029001)(4636009)(366004)(316002)(6506007)(8990500004)(33656002)(53546011)(8936002)(4326008)(82950400001)(82960400001)(8676002)(7696005)(2906002)(52536014)(71200400001)(83380400001)(10290500003)(15650500001)(26005)(66946007)(38100700002)(54906003)(9686003)(110136005)(76236003)(19627235002)(122000001)(76116006)(166002)(30864003)(86362001)(186003)(966005)(66446008)(38070700005)(5660300002)(508600001)(66476007)(66556008)(64756008)(55016002);DIR:OUT;SFP:1102; x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?Windows-1252?Q?2pdGnCyqSIPu4ieKsxdUsPVNh2mndi22JpN8VPc74RQmUg9sTiZk2+tm?= =?Windows-1252?Q?bSn5UOA33Nr5jrsLkVr6M4DdTbD9C2PUODXIOT7MFCvxtgMMoEqLeMJe?= =?Windows-1252?Q?Jg5+VZJdZ4MK+3x3MGcb8+DXXSXokhtb9JTFA7g1Wbl4GEpG8b4uNuvv?= =?Windows-1252?Q?9/O4cJB4eMDcoYJLWZWrzKgsExdQhwDgH2Zi1h0doNnhJG5jxGmwCvTq?= =?Windows-1252?Q?wn7o8i931RRr/fVD2nTJAZiwUgCmFozJ1ueuPlDUli8Ayee+qvbJNnv4?= =?Windows-1252?Q?KFRaBj0k2jvc+JvPzLqkb8f6IG797e75oadHPKZ3XxGjYPGXe8gr1Dwi?= =?Windows-1252?Q?ZPACicvwM+8/X5h+G9ZHdrOrE+703CiuCqfHaTFkAOJMraJk9ROMx2tz?= =?Windows-1252?Q?SUftN9D5pyluox2BWwcgYeP+WfSAim97wXB5556yEukDyfGQBtySMuKP?= =?Windows-1252?Q?ZpCz5yp8QKJwJaEQ7L3VPeOlmuKygD1Q3CupBRE2i53B8MrKdIjHUVVp?= =?Windows-1252?Q?1D05WIQTnVi4K+hUM0zFgS1wZpGVfh3iAjZmJZ91FEaMmcFCZTKscO6M?= =?Windows-1252?Q?HmP01bERv4zVNDupbRiAbbuFrpyblDELfU97lFnYD1q5xlj6HgNvIpfH?= =?Windows-1252?Q?EkI5641bYxEwFFMh+29n+XU3MUvssSi9ln23BIU4mKXVGFnvluiywlZS?= =?Windows-1252?Q?pz+eoTDR5rbb9/hiKPa+n9pxyZ35Bz4WmaE5KZKFkL5y/Q5bqpFemls8?= =?Windows-1252?Q?sKo6V0dtpHvIPvEZB1FgTDQLcKy9sjtPVbd8ueI7vyJjkPxv0n2aT/60?= =?Windows-1252?Q?k91M9eJWdY+i+VTkVWSLwe34Wic6Q0vneUGRPbUj6p3Jof12k0Jd61+s?= =?Windows-1252?Q?4YWEcMPJSrRf8W2YDc1oDjONGIy85nY2EJA2N8S4QFHnFuamD4MU8ir1?= =?Windows-1252?Q?9YHohLZKXiaj9uCwqFs3sHPs5Pf0h4cyvnWxLafDQ3xAUO2ArLKGL1Ji?= =?Windows-1252?Q?Bihkrsy5VKizE4tZ+2dIpBAlUyNfpTtOwxYoppynfH3buAgFDtWhFTcV?= =?Windows-1252?Q?5b3xl1Mg49GspwaIHdgrgGOvgSbUjdXDBt4i4QC4gP523Glo82j6h0aj?= =?Windows-1252?Q?mhyF4cXTE2z9uNNHRPvOgyw044wi6kyQS+vORGPTNOQNW5N7JV/tsbZ6?= =?Windows-1252?Q?AoiwzBN93Tyhp01vO2Yo68WSHeg995mbj15sUSDOjWJA3KN0MIICVxAK?= =?Windows-1252?Q?gaTigodqM+avVZnbfVgokeXpwlQLP+u5SY+rs+hVP6BLrCsgeKGwojC3?= =?Windows-1252?Q?u9lTVRLH1HiS48CpDo/v9QCudbe3Ovj5TPgWExUijgzI/6T+R23yNmg0?= =?Windows-1252?Q?PRhmHCff/279gdYSASyaXZkXd1T2ql+rW5Zxq1D/V9lJyjHuk5JLi1QC?= =?Windows-1252?Q?O7oWfJsalL45LEVtZtEF/g=3D=3D?= x-ms-exchange-transport-forked: True MIME-Version: 1.0 X-OriginatorOrg: microsoft.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: MW4PR21MB1907.namprd21.prod.outlook.com X-MS-Exchange-CrossTenant-Network-Message-Id: 3ad0af6c-d6c3-4880-ea7d-08d95db9f3c8 X-MS-Exchange-CrossTenant-originalarrivaltime: 12 Aug 2021 17:52:28.8386 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47 X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: ea+tufniYHj+dbZl80r2p40wcq7T9cNLyn8YIAjaw0NzWdtjh07VTAKp4dNxYbHiGKudtbi6G1bYS70V6a5Lww== X-MS-Exchange-Transport-CrossTenantHeadersStamped: MWHPR21MB1600 Content-Language: en-US Content-Type: multipart/alternative; boundary="_000_MW4PR21MB19077710B3F5CEE8C0435F25EFF99MW4PR21MB1907namp_" --_000_MW4PR21MB19077710B3F5CEE8C0435F25EFF99MW4PR21MB1907namp_ Content-Type: text/plain; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable Thoughts? - Bret ________________________________ From: devel@edk2.groups.io on behalf of Bret Barkele= w via groups.io Sent: Wednesday, August 11, 2021 12:37:52 PM To: devel@edk2.groups.io ; bret@corthon.com Cc: Yao, Jiewen ; Jian J Wang = ; Qi Zhang ; Rahul Kumar Subject: Re: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Library: Ad= d Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib Thoughts? - Bret ________________________________ From: devel@edk2.groups.io on behalf of Bret Barkele= w via groups.io Sent: Wednesday, August 4, 2021 9:32:32 AM To: devel@edk2.groups.io ; bret@corthon.com Cc: Yao, Jiewen ; Jian J Wang = ; Qi Zhang ; Rahul Kumar Subject: Re: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Library: Ad= d Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib Poking this one. 1. It=92s a easy review with small, obvious code change. 2. I need some answers on =93when is it okay to violate ECC/PatchCheck, = if the new code matches the style of the existing code. Should I endeavor t= o pass the PatchCheck and ECCCheck with this patch only, and leave it in co= nflict with the rest of the file? Thanks! - Bret From: Bret Barkelew via groups.io Sent: Friday, July 30, 2021 11:08 AM To: devel@edk2.groups.io; bret@corthon.com Cc: Yao, Jiewen; Jian J Wang; Qi Zhang; Rahul Kumar Subject: Re: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Library: Ad= d Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib Note, even though this keeps with the style of the rest of the file, it bre= aks ECC: SecurityPkg/Library: Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib by co= rthon =B7 Pull Request #1848 =B7 tianocore/edk2 (github.com) PROGRESS - --Running SecurityPkg: EccCheck Test NO-TARGET -- ERROR - ERROR - ERROR - EFI coding style error ERROR - *Error code: 8001 ERROR - *Only capital letters are allowed to be used for #define declaratio= ns ERROR - *file: //home/vsts/work/1/s/SecurityPkg/Library/Tpm2CommandLib/Tpm2= NVStorage.c ERROR - *Line number: 27 ERROR - *The #define name [RC_NV_UndefineSpaceSpecial_nvIndex] does no Thoughts? - Bret From: Bret Barkelew via groups.io Sent: Friday, July 30, 2021 10:55 AM To: devel@edk2.groups.io Cc: Yao, Jiewen; Jian J Wang; Qi Zhang; Rahul Kumar Subject: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Library: Add Tp= m2NvUndefineSpaceSpecial to Tpm2CommandLib Used to provision and maintain certain HW-defined NV spaces. REF: https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fbu= gzilla.tianocore.org%2Fshow_bug.cgi%3Fid%3D2994&data=3D04%7C01%7CBret.B= arkelew%40microsoft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141= af91ab2d7cd011db47%7C1%7C0%7C637632645397602953%7CUnknown%7CTWFpbGZsb3d8eyJ= WIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&= sdata=3Ds96M3RvxMOY831Vfr1nt%2Fz1h3cyb6jU9eFzvjKO7Dtc%3D&reserved=3D0 Signed-off-by: Bret Barkelew Cc: Jiewen Yao Cc: Jian J Wang Cc: Qi Zhang Cc: Rahul Kumar --- SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c | 122 +++++++++++++++++= +++ SecurityPkg/Include/Library/Tpm2CommandLib.h | 22 ++++ 2 files changed, 144 insertions(+) diff --git a/SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c b/SecurityP= kg/Library/Tpm2CommandLib/Tpm2NVStorage.c index 87572de20164..7931fade9190 100644 --- a/SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c +++ b/SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c @@ -24,6 +24,8 @@ SPDX-License-Identifier: BSD-2-Clause-Patent #define RC_NV_UndefineSpace_authHandle (TPM_RC_H + TPM_RC_1) #define RC_NV_UndefineSpace_nvIndex (TPM_RC_H + TPM_RC_2) +#define RC_NV_UndefineSpaceSpecial_nvIndex (TPM_RC_H + TPM_RC_1) + #define RC_NV_Read_authHandle (TPM_RC_H + TPM_RC_1) #define RC_NV_Read_nvIndex (TPM_RC_H + TPM_RC_2) #define RC_NV_Read_size (TPM_RC_P + TPM_RC_1) @@ -74,6 +76,20 @@ typedef struct { TPMS_AUTH_RESPONSE AuthSession; } TPM2_NV_UNDEFINESPACE_RESPONSE; +typedef struct { + TPM2_COMMAND_HEADER Header; + TPMI_RH_NV_INDEX NvIndex; + TPMI_RH_PLATFORM Platform; + UINT32 AuthSessionSize; + TPMS_AUTH_COMMAND AuthSession; +} TPM2_NV_UNDEFINESPACESPECIAL_COMMAND; + +typedef struct { + TPM2_RESPONSE_HEADER Header; + UINT32 AuthSessionSize; + TPMS_AUTH_RESPONSE AuthSession; +} TPM2_NV_UNDEFINESPACESPECIAL_RESPONSE; + typedef struct { TPM2_COMMAND_HEADER Header; TPMI_RH_NV_AUTH AuthHandle; @@ -506,6 +522,112 @@ Done: return Status; } +/** + This command removes an index from the TPM. + + @param[in] NvIndex The NV Index. + @param[in] IndexAuthSession Auth session context for the Index auth/= policy + @param[in] PlatAuthSession Auth session context for the Platform au= th/policy + + @retval EFI_SUCCESS Operation completed successfully. + @retval EFI_NOT_FOUND The command was returned successfully, b= ut NvIndex is not found. + @retval EFI_UNSUPPORTED Selected NvIndex does not support deleti= on through this call. + @retval EFI_SECURITY_VIOLATION Deletion is not authorized by current po= licy session. + @retval EFI_INVALID_PARAMETER The command was unsuccessful. + @retval EFI_DEVICE_ERROR The command was unsuccessful. +**/ +EFI_STATUS +EFIAPI +Tpm2NvUndefineSpaceSpecial ( + IN TPMI_RH_NV_INDEX NvIndex, + IN TPMS_AUTH_COMMAND *IndexAuthSession OPTIONAL, + IN TPMS_AUTH_COMMAND *PlatAuthSession OPTIONAL + ) +{ + EFI_STATUS Status; + TPM2_NV_UNDEFINESPACESPECIAL_COMMAND SendBuffer; + TPM2_NV_UNDEFINESPACESPECIAL_RESPONSE RecvBuffer; + UINT32 SendBufferSize; + UINT32 RecvBufferSize; + UINT8 *Buffer; + UINT32 IndexAuthSize, PlatAuthSize; + TPM_RC ResponseCode; + + // + // Construct command + // + SendBuffer.Header.tag =3D SwapBytes16(TPM_ST_SESSIONS); + SendBuffer.Header.commandCode =3D SwapBytes32(TPM_CC_NV_UndefineSpaceSpe= cial); + + SendBuffer.NvIndex =3D SwapBytes32 (NvIndex); + SendBuffer.Platform =3D SwapBytes32 (TPM_RH_PLATFORM); + + // + // Marshall the Auth Sessions for the two handles. + Buffer =3D (UINT8 *)&SendBuffer.AuthSession; + // IndexAuthSession + IndexAuthSize =3D CopyAuthSessionCommand (IndexAuthSession, Buffer); + Buffer +=3D IndexAuthSize; + // PlatAuthSession + PlatAuthSize =3D CopyAuthSessionCommand (PlatAuthSession, Buffer); + Buffer +=3D PlatAuthSize; + // AuthSessionSize + SendBuffer.AuthSessionSize =3D SwapBytes32(IndexAuthSize + PlatAuthSize)= ; + + // Update total command size. + SendBufferSize =3D (UINT32)(Buffer - (UINT8 *)&SendBuffer); + SendBuffer.Header.paramSize =3D SwapBytes32 (SendBufferSize); + + // + // send Tpm command + // + RecvBufferSize =3D sizeof (RecvBuffer); + Status =3D Tpm2SubmitCommand (SendBufferSize, (UINT8 *)&SendBuffer, &Rec= vBufferSize, (UINT8 *)&RecvBuffer); + if (EFI_ERROR (Status)) { + goto Done; + } + + if (RecvBufferSize < sizeof (TPM2_RESPONSE_HEADER)) { + DEBUG ((EFI_D_ERROR, "Tpm2NvUndefineSpaceSpecial - RecvBufferSize Erro= r - %x\n", RecvBufferSize)); + Status =3D EFI_DEVICE_ERROR; + goto Done; + } + + ResponseCode =3D SwapBytes32(RecvBuffer.Header.responseCode); + if (ResponseCode !=3D TPM_RC_SUCCESS) { + DEBUG ((EFI_D_ERROR, "Tpm2NvUndefineSpaceSpecial - responseCode - %x\n= ", SwapBytes32(RecvBuffer.Header.responseCode))); + } + switch (ResponseCode) { + case TPM_RC_SUCCESS: + // return data + break; + case TPM_RC_ATTRIBUTES: + case TPM_RC_ATTRIBUTES + RC_NV_UndefineSpaceSpecial_nvIndex: + Status =3D EFI_UNSUPPORTED; + break; + case TPM_RC_NV_AUTHORIZATION: + Status =3D EFI_SECURITY_VIOLATION; + break; + case TPM_RC_HANDLE + RC_NV_UndefineSpaceSpecial_nvIndex: // TPM_RC_NV_DE= FINED: + Status =3D EFI_NOT_FOUND; + break; + case TPM_RC_VALUE + RC_NV_UndefineSpace_nvIndex: + Status =3D EFI_INVALID_PARAMETER; + break; + default: + Status =3D EFI_DEVICE_ERROR; + break; + } + +Done: + // + // Clear AuthSession Content + // + ZeroMem (&SendBuffer, sizeof(SendBuffer)); + ZeroMem (&RecvBuffer, sizeof(RecvBuffer)); + return Status; +} // Tpm2NvUndefineSpaceSpecial() + /** This command reads a value from an area in NV memory previously defined = by TPM2_NV_DefineSpace(). diff --git a/SecurityPkg/Include/Library/Tpm2CommandLib.h b/SecurityPkg/Inc= lude/Library/Tpm2CommandLib.h index ee8eb622951c..8d7b4998d98d 100644 --- a/SecurityPkg/Include/Library/Tpm2CommandLib.h +++ b/SecurityPkg/Include/Library/Tpm2CommandLib.h @@ -364,6 +364,28 @@ Tpm2NvUndefineSpace ( IN TPMS_AUTH_COMMAND *AuthSession OPTIONAL ); +/** + This command removes an index from the TPM. + + @param[in] NvIndex The NV Index. + @param[in] IndexAuthSession Auth session context for the Index auth/= policy + @param[in] PlatAuthSession Auth session context for the Platform au= th/policy + + @retval EFI_SUCCESS Operation completed successfully. + @retval EFI_NOT_FOUND The command was returned successfully, b= ut NvIndex is not found. + @retval EFI_UNSUPPORTED Selected NvIndex does not support deleti= on through this call. + @retval EFI_SECURITY_VIOLATION Deletion is not authorized by current po= licy session. + @retval EFI_INVALID_PARAMETER The command was unsuccessful. + @retval EFI_DEVICE_ERROR The command was unsuccessful. +**/ +EFI_STATUS +EFIAPI +Tpm2NvUndefineSpaceSpecial ( + IN TPMI_RH_NV_INDEX NvIndex, + IN TPMS_AUTH_COMMAND *IndexAuthSession OPTIONAL, + IN TPMS_AUTH_COMMAND *PlatAuthSession OPTIONAL + ); + /** This command reads a value from an area in NV memory previously defined = by TPM2_NV_DefineSpace(). -- 2.31.1.windows.1 -=3D-=3D-=3D-=3D-=3D-=3D Groups.io Links: You receive all messages sent to this group. View/Reply Online (#78450): https://nam06.safelinks.protection.outlook.com/= ?url=3Dhttps%3A%2F%2Fedk2.groups.io%2Fg%2Fdevel%2Fmessage%2F78450&data= =3D04%7C01%7CBret.Barkelew%40microsoft.com%7Cb7ae3c62047c48fc85d908d953833c= a0%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637632645397612922%7CUnknow= n%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI= 6Mn0%3D%7C1000&sdata=3DCWxLwgp73z2XQEa%2FN77gsCwRF73xha0RZCKwcFTlrRE%3D= &reserved=3D0 Mute This Topic: https://nam06.safelinks.protection.outlook.com/?url=3Dhttp= s%3A%2F%2Fgroups.io%2Fmt%2F84555713%2F1822150&data=3D04%7C01%7CBret.Bar= kelew%40microsoft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141af= 91ab2d7cd011db47%7C1%7C0%7C637632645397612922%7CUnknown%7CTWFpbGZsb3d8eyJWI= joiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sd= ata=3DIWQ6E4yP0ECt3oYLYQa%2BnddGfcQEDMgfASlcxRuda%2BQ%3D&reserved=3D0 Group Owner: devel+owner@edk2.groups.io Unsubscribe: https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A= %2F%2Fedk2.groups.io%2Fg%2Fdevel%2Funsub&data=3D04%7C01%7CBret.Barkelew= %40microsoft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141af91ab2= d7cd011db47%7C1%7C0%7C637632645397612922%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC= 4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata= =3Dqor4Y5FZEH8ch0AEmWDbe97FIQk4V1qx7IURcTHzjAU%3D&reserved=3D0 [brbarkel@microsoft.com] -=3D-=3D-=3D-=3D-=3D-=3D --_000_MW4PR21MB19077710B3F5CEE8C0435F25EFF99MW4PR21MB1907namp_ Content-Type: text/html; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable

Thoughts?

 

- Bret

 


From: devel@edk2.groups.io = <devel@edk2.groups.io> on behalf of Bret Barkelew via groups.io <b= ret.barkelew=3Dmicrosoft.com@groups.io>
Sent: Wednesday, August 11, 2021 12:37:52 PM
To: devel@edk2.groups.io <devel@edk2.groups.io>; bret@corthon.= com <bret@corthon.com>
Cc: Yao, Jiewen <jiewen.yao@intel.com>; Jian J Wang <jian.j= .wang@intel.com>; Qi Zhang <qi1.zhang@intel.com>; Rahul Kumar <= rahul1.kumar@intel.com>
Subject: Re: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Libr= ary: Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib
 

Thoughts?

 

- Bret

 


From: devel@edk2.groups.i= o <devel@edk2.groups.io> on behalf of Bret Barkelew via groups.io <= ;bret.barkelew=3Dmicrosoft.com@groups.io>
Sent: Wednesday, August 4, 2021 9:32:32 AM
To: devel@edk2.groups.io <devel@edk2.groups.io>; bret@corthon.= com <bret@corthon.com>
Cc: Yao, Jiewen <jiewen.yao@intel.com>; Jian J Wang <jian.j= .wang@intel.com>; Qi Zhang <qi1.zhang@intel.com>; Rahul Kumar <= rahul1.kumar@intel.com>
Subject: Re: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Libr= ary: Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib
 

Poking this one.

 

  1. It=92s a easy = review with small, obvious code change.
  2. I need some answers on =93when is it okay to = violate ECC/PatchCheck, if the new code matches the style of the existing c= ode. Should I endeavor to pass the PatchCheck and ECCCheck with this patch = only, and leave it in conflict with the rest of the file?

 

Thanks!

 

- Bret

 

From: = Bret Barkelew vi= a groups.io
Sent: Friday, July 30, 2021 11:08 AM
To: devel@edk2.groups.io= ; bret@corthon.com
Cc: Yao, Jiewen; Jian J Wang; Qi Zhang; Rahul Kumar
Subject: Re: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Libr= ary: Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib

 

Note, even though this keeps with the style of t= he rest of the file, it breaks ECC:

Securi= tyPkg/Library: Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib by corthon =B7 Pull Reque= st #1848 =B7 tianocore/edk2 (github.com)

 

PROGRESS - --Running SecurityPkg: EccCheck Test NO-TARGET --

ERROR -

ERROR -

ERROR - EFI coding style error

ERROR - *Error code: 8001

ERROR - *Only capital letters are allowed to be used for #define declar= ations

ERROR - *file: //home/vsts/work/1/s/SecurityPkg/Library/Tpm2CommandLib/= Tpm2NVStorage.c

ERROR - *Line number: 27

ERROR - *The #define name [RC_NV_UndefineSpaceSpecial_nvIndex] does no<= /span>

 

Thoughts?

 

- Bret

 

From: Bret Barkelew via groups.io
Sent: Friday, July 30, 2021 10:55 AM
To: devel@edk2.groups.io=
Cc: Yao, Jiewen; Jian J Wang; Qi Zhang; Rahul Kumar
Subject: [EXTERNAL] [edk2-devel] [PATCH v1 1/1] SecurityPkg/Library:= Add Tpm2NvUndefineSpaceSpecial to Tpm2CommandLib

 

Used to provision= and maintain certain HW-defined NV spaces.

REF: https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fbugzill= a.tianocore.org%2Fshow_bug.cgi%3Fid%3D2994&amp;data=3D04%7C01%7CBret.Ba= rkelew%40microsoft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141a= f91ab2d7cd011db47%7C1%7C0%7C637632645397602953%7CUnknown%7CTWFpbGZsb3d8eyJW= IjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&a= mp;sdata=3Ds96M3RvxMOY831Vfr1nt%2Fz1h3cyb6jU9eFzvjKO7Dtc%3D&amp;reserve= d=3D0

Signed-off-by: Bret Barkelew <bret.barkelew@microsoft.com>
Cc: Jiewen Yao <jiewen.yao@intel.com>
Cc: Jian J Wang <jian.j.wang@intel.com>
Cc: Qi Zhang <qi1.zhang@intel.com>
Cc: Rahul Kumar <rahul1.kumar@intel.com>
---
 SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c | 122 ++++++++++++= ++++++++
 SecurityPkg/Include/Library/Tpm2CommandLib.h    &= nbsp;  |  22 ++++
 2 files changed, 144 insertions(+)

diff --git a/SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c b/SecurityP= kg/Library/Tpm2CommandLib/Tpm2NVStorage.c
index 87572de20164..7931fade9190 100644
--- a/SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c
+++ b/SecurityPkg/Library/Tpm2CommandLib/Tpm2NVStorage.c
@@ -24,6 +24,8 @@ SPDX-License-Identifier: BSD-2-Clause-Patent
 #define RC_NV_UndefineSpace_authHandle      = (TPM_RC_H + TPM_RC_1)

 #define RC_NV_UndefineSpace_nvIndex     &nbs= p;   (TPM_RC_H + TPM_RC_2)

 

+#define RC_NV_UndefineSpaceSpecial_nvIndex  (TPM_RC_H + TPM_RC_1)

+

 #define RC_NV_Read_authHandle      &nbs= p;        (TPM_RC_H + TPM_RC_1)

 #define RC_NV_Read_nvIndex       &= nbsp;          (TPM_RC_H + TPM= _RC_2)

 #define RC_NV_Read_size       &nbs= p;             = (TPM_RC_P + TPM_RC_1)

@@ -74,6 +76,20 @@ typedef struct {
   TPMS_AUTH_RESPONSE       &n= bsp; AuthSession;

 } TPM2_NV_UNDEFINESPACE_RESPONSE;

 

+typedef struct {

+  TPM2_COMMAND_HEADER       Header;

+  TPMI_RH_NV_INDEX        &nb= sp; NvIndex;

+  TPMI_RH_PLATFORM        &nb= sp; Platform;

+  UINT32          &= nbsp;         AuthSessionSize;

+  TPMS_AUTH_COMMAND         A= uthSession;

+} TPM2_NV_UNDEFINESPACESPECIAL_COMMAND;

+

+typedef struct {

+  TPM2_RESPONSE_HEADER       Header;
+  UINT32          &= nbsp;          AuthSessionSize= ;

+  TPMS_AUTH_RESPONSE         = AuthSession;

+} TPM2_NV_UNDEFINESPACESPECIAL_RESPONSE;

+

 typedef struct {

   TPM2_COMMAND_HEADER       Header= ;

   TPMI_RH_NV_AUTH        = ;   AuthHandle;

@@ -506,6 +522,112 @@ Done:
   return Status;

 }

 

+/**

+  This command removes an index from the TPM.

+

+  @param[in]  NvIndex       &= nbsp;     The NV Index.

+  @param[in]  IndexAuthSession    Auth session co= ntext for the Index auth/policy

+  @param[in]  PlatAuthSession     Auth sessi= on context for the Platform auth/policy

+

+  @retval EFI_SUCCESS        =      Operation completed successfully.

+  @retval EFI_NOT_FOUND       &nbs= p;   The command was returned successfully, but NvIndex is not fo= und.

+  @retval EFI_UNSUPPORTED       &n= bsp; Selected NvIndex does not support deletion through this call.

+  @retval EFI_SECURITY_VIOLATION  Deletion is not authorized by = current policy session.

+  @retval EFI_INVALID_PARAMETER   The command was unsuccess= ful.

+  @retval EFI_DEVICE_ERROR        = The command was unsuccessful.

+**/

+EFI_STATUS

+EFIAPI

+Tpm2NvUndefineSpaceSpecial (

+  IN      TPMI_RH_NV_INDEX   =        NvIndex,

+  IN      TPMS_AUTH_COMMAND   = ;      *IndexAuthSession OPTIONAL,

+  IN      TPMS_AUTH_COMMAND   = ;      *PlatAuthSession OPTIONAL

+  )

+{

+  EFI_STATUS         &nb= sp;            =         Status;

+  TPM2_NV_UNDEFINESPACESPECIAL_COMMAND    SendBuffer;<= br>
+  TPM2_NV_UNDEFINESPACESPECIAL_RESPONSE   RecvBuffer;

+  UINT32          &= nbsp;           &nbs= p;           SendBufferSi= ze;

+  UINT32          &= nbsp;           &nbs= p;           RecvBufferSi= ze;

+  UINT8          &n= bsp;            = ;            *Buffer= ;

+  UINT32          &= nbsp;           &nbs= p;           IndexAuthSiz= e, PlatAuthSize;

+  TPM_RC          &= nbsp;           &nbs= p;           ResponseCode= ;

+

+  //

+  // Construct command

+  //

+  SendBuffer.Header.tag =3D SwapBytes16(TPM_ST_SESSIONS);

+  SendBuffer.Header.commandCode =3D SwapBytes32(TPM_CC_NV_UndefineSpa= ceSpecial);

+

+  SendBuffer.NvIndex =3D SwapBytes32 (NvIndex);

+  SendBuffer.Platform =3D SwapBytes32 (TPM_RH_PLATFORM);

+

+  //

+  // Marshall the Auth Sessions for the two handles.

+  Buffer =3D (UINT8 *)&SendBuffer.AuthSession;

+  // IndexAuthSession

+  IndexAuthSize =3D CopyAuthSessionCommand (IndexAuthSession, Buffer)= ;

+  Buffer +=3D IndexAuthSize;

+  // PlatAuthSession

+  PlatAuthSize =3D CopyAuthSessionCommand (PlatAuthSession, Buffer);<= br>
+  Buffer +=3D PlatAuthSize;

+  // AuthSessionSize

+  SendBuffer.AuthSessionSize =3D SwapBytes32(IndexAuthSize + PlatAuth= Size);

+

+  // Update total command size.

+  SendBufferSize =3D (UINT32)(Buffer - (UINT8 *)&SendBuffer);

+  SendBuffer.Header.paramSize =3D SwapBytes32 (SendBufferSize);

+

+  //

+  // send Tpm command

+  //

+  RecvBufferSize =3D sizeof (RecvBuffer);

+  Status =3D Tpm2SubmitCommand (SendBufferSize, (UINT8 *)&SendBuf= fer, &RecvBufferSize, (UINT8 *)&RecvBuffer);

+  if (EFI_ERROR (Status)) {

+    goto Done;

+  }

+

+  if (RecvBufferSize < sizeof (TPM2_RESPONSE_HEADER)) {

+    DEBUG ((EFI_D_ERROR, "Tpm2NvUndefineSpaceSpecial -= RecvBufferSize Error - %x\n", RecvBufferSize));

+    Status =3D EFI_DEVICE_ERROR;

+    goto Done;

+  }

+

+  ResponseCode =3D SwapBytes32(RecvBuffer.Header.responseCode);

+  if (ResponseCode !=3D TPM_RC_SUCCESS) {

+    DEBUG ((EFI_D_ERROR, "Tpm2NvUndefineSpaceSpecial -= responseCode - %x\n", SwapBytes32(RecvBuffer.Header.responseCode)));<= br>
+  }

+  switch (ResponseCode) {

+  case TPM_RC_SUCCESS:

+    // return data

+    break;

+  case TPM_RC_ATTRIBUTES:

+  case TPM_RC_ATTRIBUTES + RC_NV_UndefineSpaceSpecial_nvIndex:

+    Status =3D EFI_UNSUPPORTED;

+    break;

+  case TPM_RC_NV_AUTHORIZATION:

+    Status =3D EFI_SECURITY_VIOLATION;

+    break;

+  case TPM_RC_HANDLE + RC_NV_UndefineSpaceSpecial_nvIndex: // TPM_RC_= NV_DEFINED:

+    Status =3D EFI_NOT_FOUND;

+    break;

+  case TPM_RC_VALUE + RC_NV_UndefineSpace_nvIndex:

+    Status =3D EFI_INVALID_PARAMETER;

+    break;

+  default:

+    Status =3D EFI_DEVICE_ERROR;

+    break;

+  }

+

+Done:

+  //

+  // Clear AuthSession Content

+  //

+  ZeroMem (&SendBuffer, sizeof(SendBuffer));

+  ZeroMem (&RecvBuffer, sizeof(RecvBuffer));

+  return Status;

+} // Tpm2NvUndefineSpaceSpecial()

+

 /**

   This command reads a value from an area in NV memory previousl= y defined by TPM2_NV_DefineSpace().

 

diff --git a/SecurityPkg/Include/Library/Tpm2CommandLib.h b/SecurityPkg/Inc= lude/Library/Tpm2CommandLib.h
index ee8eb622951c..8d7b4998d98d 100644
--- a/SecurityPkg/Include/Library/Tpm2CommandLib.h
+++ b/SecurityPkg/Include/Library/Tpm2CommandLib.h
@@ -364,6 +364,28 @@ Tpm2NvUndefineSpace (
   IN      TPMS_AUTH_COMMAND  =        *AuthSession OPTIONAL

   );

 

+/**

+  This command removes an index from the TPM.

+

+  @param[in]  NvIndex       &= nbsp;     The NV Index.

+  @param[in]  IndexAuthSession    Auth session co= ntext for the Index auth/policy

+  @param[in]  PlatAuthSession     Auth sessi= on context for the Platform auth/policy

+

+  @retval EFI_SUCCESS        =      Operation completed successfully.

+  @retval EFI_NOT_FOUND       &nbs= p;   The command was returned successfully, but NvIndex is not fo= und.

+  @retval EFI_UNSUPPORTED       &n= bsp; Selected NvIndex does not support deletion through this call.

+  @retval EFI_SECURITY_VIOLATION  Deletion is not authorized by = current policy session.

+  @retval EFI_INVALID_PARAMETER   The command was unsuccess= ful.

+  @retval EFI_DEVICE_ERROR        = The command was unsuccessful.

+**/

+EFI_STATUS

+EFIAPI

+Tpm2NvUndefineSpaceSpecial (

+  IN      TPMI_RH_NV_INDEX   =        NvIndex,

+  IN      TPMS_AUTH_COMMAND   = ;      *IndexAuthSession OPTIONAL,

+  IN      TPMS_AUTH_COMMAND   = ;      *PlatAuthSession OPTIONAL

+  );

+

 /**

   This command reads a value from an area in NV memory previousl= y defined by TPM2_NV_DefineSpace().

 

--
2.31.1.windows.1



-=3D-=3D-=3D-=3D-=3D-=3D
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#78450): https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fedk2.gr= oups.io%2Fg%2Fdevel%2Fmessage%2F78450&amp;data=3D04%7C01%7CBret.Barkele= w%40microsoft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141af91ab= 2d7cd011db47%7C1%7C0%7C637632645397612922%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiM= C4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sd= ata=3DCWxLwgp73z2XQEa%2FN77gsCwRF73xha0RZCKwcFTlrRE%3D&amp;reserved=3D0=
Mute This Topic: https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fgroups.= io%2Fmt%2F84555713%2F1822150&amp;data=3D04%7C01%7CBret.Barkelew%40micro= soft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141af91ab2d7cd011d= b47%7C1%7C0%7C637632645397612922%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMD= AiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=3DIWQ= 6E4yP0ECt3oYLYQa%2BnddGfcQEDMgfASlcxRuda%2BQ%3D&amp;reserved=3D0 Group Owner: devel+owner@edk2.groups.io
Unsubscribe: https://nam06.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fedk2.gr= oups.io%2Fg%2Fdevel%2Funsub&amp;data=3D04%7C01%7CBret.Barkelew%40micros= oft.com%7Cb7ae3c62047c48fc85d908d953833ca0%7C72f988bf86f141af91ab2d7cd011db= 47%7C1%7C0%7C637632645397612922%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDA= iLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=3Dqor4= Y5FZEH8ch0AEmWDbe97FIQk4V1qx7IURcTHzjAU%3D&amp;reserved=3D0 [brbarkel@microsoft.com]
-=3D-=3D-=3D-=3D-=3D-=3D

 

 

--_000_MW4PR21MB19077710B3F5CEE8C0435F25EFF99MW4PR21MB1907namp_--