70 lines
2.0 KiB
C
70 lines
2.0 KiB
C
/*
|
|
* VAS_EBOOT -- GRand Unified Bootloader
|
|
* Copyright (C) 2024 SUSE LLC
|
|
* Copyright (C) 2024 Free Software Foundation, Inc.
|
|
*
|
|
* VAS_EBOOT is free software: you can redistribute it and/or modify
|
|
* it under the terms of the GNU General Public License as published by
|
|
* the Free Software Foundation, either version 3 of the License, or
|
|
* (at your option) any later version.
|
|
*
|
|
* VAS_EBOOT is distributed in the hope that it will be useful,
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
* GNU General Public License for more details.
|
|
*
|
|
* You should have received a copy of the GNU General Public License
|
|
* along with VAS_EBOOT. If not, see <http://www.gnu.org/licenses/>.
|
|
*/
|
|
|
|
#include <VasEBoot/mm.h>
|
|
#include <VasEBoot/emu/misc.h>
|
|
|
|
#include <tss2_buffer.h>
|
|
#include <tss2_structs.h>
|
|
#include <tpm2_cmd.h>
|
|
#include <tcg2.h>
|
|
|
|
VasEBoot_err_t
|
|
VasEBoot_tcg2_get_max_output_size (VasEBoot_size_t *size)
|
|
{
|
|
if (size == NULL)
|
|
return VAS_EBOOT_ERR_BAD_ARGUMENT;
|
|
|
|
*size = VAS_EBOOT_TPM2_BUFFER_CAPACITY;
|
|
|
|
return VAS_EBOOT_ERR_NONE;
|
|
}
|
|
|
|
VasEBoot_err_t
|
|
VasEBoot_tcg2_submit_command (VasEBoot_size_t input_size, VasEBoot_uint8_t *input,
|
|
VasEBoot_size_t output_size, VasEBoot_uint8_t *output)
|
|
{
|
|
if (VasEBoot_util_tpm_write (input, input_size) != input_size)
|
|
return VAS_EBOOT_ERR_BAD_DEVICE;
|
|
|
|
if (VasEBoot_util_tpm_read (output, output_size) < sizeof (TPM_RESPONSE_HEADER_t))
|
|
return VAS_EBOOT_ERR_BAD_DEVICE;
|
|
|
|
return VAS_EBOOT_ERR_NONE;
|
|
}
|
|
|
|
VasEBoot_err_t
|
|
VasEBoot_tcg2_cap_pcr (VasEBoot_uint8_t pcr)
|
|
{
|
|
TPMS_AUTH_COMMAND_t authCmd = {
|
|
.sessionHandle = TPM_RS_PW,
|
|
};
|
|
TPM2B_EVENT_t data = {
|
|
.size = 4,
|
|
};
|
|
TPM_RC_t rc;
|
|
|
|
/* Submit an EV_SEPARATOR event, i.e. an event with 4 zero-bytes */
|
|
rc = VasEBoot_tpm2_pcr_event (pcr, &authCmd, &data, NULL, NULL);
|
|
if (rc != TPM_RC_SUCCESS)
|
|
return VasEBoot_error (VAS_EBOOT_ERR_BAD_DEVICE, N_("cannot cap PCR %u"), pcr);
|
|
|
|
return VAS_EBOOT_ERR_NONE;
|
|
}
|