Commit Graph

314 Commits (1d8ea0cfd2df6188701f6fd8c0aba9ad3bc1b743)

Author SHA1 Message Date
David Garske 5f3a6af5af
Merge pull request #595 from aidangarske/coverity-913517-tainted-child-blobs
Bound fwTPM child blob sizes before copying from the response
2026-09-10 10:42:16 -07:00
Aidan Garske bc33d44169 Bound fwTPM child blob sizes before copying from the response 2026-09-09 09:29:42 -07:00
Aidan Garske e6a99705f3 F-12706 - Enforce TPM response header minimum and inclusive size bound 2026-09-09 09:19:01 -07:00
David Garske 8646904212
Merge pull request #592 from aidangarske/pq-attestation-fix
Support ML-KEM credential activation and ML-DSA quotes in fwTPM
2026-09-08 10:40:01 -07:00
David Garske 17f1230449
Merge pull request #593 from aidangarske/fenrir-fixes-12712-13524-13525-13526-13527
Make fwTPM state changes transactional and harden PolicyPCR and private-blob wrapping
2026-09-08 10:37:00 -07:00
Aidan Garske c9e652988b F-13526 - Bind wrapped fwTPM private blobs to their public area 2026-09-07 18:45:08 -07:00
Aidan Garske a27662a4c2 F-13527 - Use a fresh IV for every wrapped fwTPM private blob 2026-09-07 18:45:08 -07:00
Aidan Garske fc23e93ced F-13525 - Invalidate PCR policy sessions when a PCR changes 2026-09-07 18:45:08 -07:00
Aidan Garske e9716101b2 Support ML-KEM credential activation and ML-DSA quotes in fwTPM 2026-09-07 18:44:02 -07:00
Aidan Garske 11917addc0 F-13524 - Verify the PolicyPCR digest against live PCR values 2026-09-07 18:06:08 -07:00
Aidan Garske 9bb9e2f8f7 F-12712 - Roll back fwTPM state when the NV journal write fails 2026-09-07 18:06:08 -07:00
Aidan Garske aed309c03c Resolve six outstanding Coverity findings 2026-09-07 10:50:31 -07:00
Aidan Garske 18d9ead84f Keep fixed fwTPM TIS semaphore names and protocol version 2026-09-02 14:14:59 -07:00
Aidan Garske a7b1aa6c3b Inline fwTPM TIS atomics and semaphore name helpers 2026-09-02 14:14:59 -07:00
Aidan Garske ab1bdb3602 F-12738 - Reject truncated signing sequence buffers 2026-09-02 14:14:59 -07:00
Aidan Garske 95696b36ef F-12736 - Authenticate fwTPM shared-memory endpoints 2026-09-02 14:14:58 -07:00
Aidan Garske 5e3cbd2241 F-12735 - Pin the SPDM responder identity 2026-09-02 14:14:58 -07:00
Aidan Garske 3507da0429 F-12710 - Advertise supported ECC curves 2026-09-02 14:14:28 -07:00
Aidan Garske 17c6926f80 F-12709 - Order handle capability pages numerically 2026-09-02 14:14:28 -07:00
Aidan Garske 657cfa499f F-12708 - Report live ReadClock counters 2026-09-02 14:14:28 -07:00
Aidan Garske de67c482d5
Merge pull request #586 from dgarske/st33_fu_ordinal
Select ST33 field upgrade commands from the TPM command set
2026-09-02 13:42:42 -07:00
David Garske fe7167a6a9 Peer review feedback (thanks Aidan) 2026-09-02 11:54:59 -07:00
David Garske 00591ba28c
Merge pull request #584 from aidangarske/fenrir-fixes-11898-11920-11921-11925-11927
Fix TCG v185 complaince issues for fwtpm and spdm
2026-09-02 07:44:05 -07:00
David Garske 50dfdcec95 Cover the ST33 command set probe in unit tests 2026-08-31 10:26:12 -07:00
David Garske ca34684225 Select ST33 field upgrade commands from the TPM command set (ZD 22193) 2026-08-27 13:29:29 -07:00
Aidan Garske dde9925d45 F-11926 - Enforce ADMIN authorization policy 2026-08-25 16:22:05 -07:00
David Garske 23a328ff87 Fix ST33 generation 1 manifest size and refuse oversized commands (ZD 22193) 2026-08-25 16:02:53 -07:00
Aidan Garske c483e43061 F-11927 - Match NV access to authorization method 2026-08-25 15:48:38 -07:00
Aidan Garske 6ee27ccdfe F-11921 - Reject unsupported limited primaries 2026-08-25 15:48:38 -07:00
Aidan Garske 64003cbdd3 F-11920 - Gate advertised PQC algorithms by support 2026-08-25 15:48:38 -07:00
Aidan Garske 98070a6796 F-9209 - Stream Pure ML-DSA sequence hashing 2026-08-22 00:45:51 -07:00
Aidan Garske cb009766b1 F-9208 - Exempt sequence authorization from DA lockout 2026-08-22 00:20:06 -07:00
Aidan Garske 18066a9402 F-9203 - Bind sequence tickets to raw messages 2026-08-21 15:59:27 -07:00
Eric Blankenhorn 68deab3ca6
Merge pull request #581 from aidangarske/coverity-fixes-912593-912594-911493
Harden PCR policy bounds checks
2026-08-21 07:50:17 -05:00
Aidan Garske 2882b72b9d Handle ClearControl NV save failures 2026-08-19 20:01:38 -07:00
Aidan Garske f3360c5d11 Address additional PolicyPCRMake review findings 2026-08-19 14:43:26 -07:00
Aidan Garske 6331325e9e Address PolicyPCRMake review findings 2026-08-19 14:09:25 -07:00
Aidan Garske b1c4c03028 Address fwTPM review findings 2026-08-19 13:53:15 -07:00
Aidan Garske 7d50ca1eef Harden PCR policy bounds checks 2026-08-19 12:41:15 -07:00
Aidan Garske ec250336b8 F-10831 - Bind verified-ticket HMAC to the context integrity hash 2026-08-19 11:59:40 -07:00
Aidan Garske bd94568b89 F-10830 - Advertise FlushContext with zero command handles 2026-08-19 11:59:31 -07:00
Aidan Garske 373a22f517 F-10829 - Set TPMA_CC flushed bit for SequenceComplete commands 2026-08-19 11:59:05 -07:00
Aidan Garske 1aaded0a31
Merge pull request #576 from dgarske/jetson_orin_ftpm
Add support for the NVIDIA Jetson Orin OP-TEE firmware TPM
2026-08-18 16:50:54 -07:00
David Garske a5a400bd0b Add support for the NVIDIA Jetson Orin OP-TEE firmware TPM 2026-08-18 14:03:58 -07:00
Aidan Garske 4354f2012a F-10826 - Validate v1.85 ML templates in TPM2_CreateLoaded 2026-08-18 12:12:07 -07:00
Aidan Garske fa57c838eb F-10825 - Validate ML public areas and key sizes in TPM2_LoadExternal 2026-08-18 11:09:48 -07:00
Aidan Garske fbbfabd02e
Merge pull request #574 from dgarske/fwtpm_finer_gating
Add finer per-command-group gating macros in fTPM
2026-08-17 13:03:37 -07:00
David Garske 20dae36517 fwTPM: add finer per-command-group gating macros 2026-08-17 12:14:10 -07:00
David Garske 2b8e41caf1 Add caller-supplied policy authorization for TPM firmware upgrade
Lets a deployment gate the TPM firmware-update start command behind its own
platform hierarchy policy instead of the vendor default. Previously wolfTPM
always managed that authorization internally: on Infineon it installed and
satisfied a PolicyCommandCode(TPM_CC_FieldUpgradeStartVendor) policy on the
platform primary policy, and on ST33 it used password authorization with an
empty platform password. Both assume default platform auth, which a hardened
deployment will not have.

New _ex entry points take an already-satisfied session:
  wolfTPM2_FirmwareUpgradeHash_ex()
  wolfTPM2_FirmwareUpgrade_ex()
  wolfTPM2_FirmwareUpgradeRecover_ex()
Passing NULL for startSession keeps the existing library-managed behavior, so
the original functions are unchanged wrappers and existing code is unaffected.
With a session supplied, Infineon no longer overwrites the platform primary
policy (the caller provisions it) and ST33 uses the session in place of
TPM_RS_PW.

Supporting wrappers:
  wolfTPM2_PolicyOR()               satisfy a session with a compound OR
  wolfTPM2_PolicyCommandCodeMake()  offline PolicyCommandCode digest
  wolfTPM2_IsAlgSupported()         report whether the TPM implements an alg
PolicyOR is hash-agnostic (each branch carries its own size), so SHA2-256
through SHA2-512 policy branches all work. It requires at least two branches
per TPM 2.0 Part 3 Sec.23.6 and validates each branch size against the digest
buffer. PolicyCommandCodeMake takes digestSz as in/out - input is the output
buffer capacity and BUFFER_E is returned when it is too small, checked before
the buffer is written. IsAlgSupported reports through an out-parameter and
returns TPM_RC, so a capability-query failure cannot be misread as
"supported"; it sets the out-parameter to 0 on every error path.

Session contract: the vendor FieldUpgradeStart commands are hand-marshalled
with an authorization area carrying only the session handle - empty
nonceCaller, zero attributes, empty HMAC. That is correct only for an
unsalted, unbound policy session with no auth value, so the _ex path validates
the caller session up front and rejects anything needing a computed session
HMAC or parameter encryption (PolicyAuthValue/PolicyPassword, attached auth
value, bind, salt, encrypt/decrypt/audit attributes, or a non-policy handle).
Validation runs before any TPM traffic. On a successful start the TPM consumes
the session and the library sets handle.hndl to TPM_RH_NULL; this is now
documented, including that it is not zero and that wolfTPM2_UnloadHandle
no-ops on it.

Examples: ifx_fw_update and st33_fw_update gain --policy, --policyor and
--policytest, backed by a shared examples/firmware/firmware_policy.c. The
--policytest mode is a non-destructive self-test that checks the TPM's running
policy digest against an offline computation at SHA2-256/384/512, skipping any
hash the TPM does not implement or the local wolfCrypt build was not compiled
with (a build mismatch is a skip, not a failure). The provisioned PolicyOR
carries a PolicyCommandCode(TPM_CC_SetPrimaryPolicy) branch so the policy can
authorize its own removal, and cleanup is gated on a FirmwarePolicyCtx that
records what was actually provisioned, so an early failure cannot clear a
policy the deployment installed itself. A failed rollback is reported but
never overwrites the upgrade error that explains the run, and is skipped once
the start has succeeded (the TPM has reset into upgrade mode and will not
service SetPrimaryPolicy).

Because TPM 2.0 offers no way to read a hierarchy authPolicy back, the example
cannot detect or restore one it replaces, so provisioning prints an explicit
warning naming that. The policy modes are also refused where the session could
never be used: any Infineon operational mode other than normal (recovery and
finalize skip the start entirely), and on ST33 when the TPM is already in
firmware-upgrade mode - previously the flags were silently ignored there,
which is the authorization downgrade they exist to prevent. Rollback normally uses platform password
authorization, which an installed authPolicy does not disable (TPM 2.0 Part 1
Sec.19.7); this was confirmed on ST33KTPM2X, SLB9670 and SLB9673 parts.

The firmware examples now require wolfCrypt in their feature guards. They
drive wolfTPM2_FirmwareUpgrade_ex, which hashes the manifest with SHA-384 and
only exists with wolfCrypt, so --enable-firmware with --disable-wolfcrypt
previously failed to compile.

Also converts examples/nvram/extend.c to the new PolicyCommandCodeMake
capacity contract.

Tests: argument validation and known-answer vectors for the new wrappers,
short-buffer and canary coverage for PolicyCommandCodeMake, caller-session
rejection for every unsupported session shape plus an accepted session,
simulator-backed success paths for PolicyOR and IsAlgSupported, and a
regression test that a platform authPolicy remains clearable with password
authorization while a non-matching policy session is refused.
2026-08-13 11:18:25 -07:00
David Garske 46d2d337a4
Merge pull request #563 from aidangarske/fenrir-fixes-7606-7610
Reuse transport connections and reduce NV write and hash cache overhead
2026-08-11 15:30:00 -07:00