From bf25cda14eb09116a1d92bfcb291968618caa6cb Mon Sep 17 00:00:00 2001 From: Matthew Garrett Date: Thu, 13 Oct 2016 13:55:26 -0700 Subject: [PATCH] Make TPM errors less fatal Handle TPM errors, and stop trying to use the TPM once we hit one. --- grub-core/kern/dl.c | 1 + grub-core/kern/i386/pc/tpm.c | 21 +++++++++++++++++---- grub-core/lib/cmdline.c | 1 + grub-core/loader/i386/efi/linux.c | 2 ++ grub-core/loader/i386/linux.c | 1 + grub-core/loader/i386/multiboot_mbi.c | 1 + grub-core/loader/i386/pc/linux.c | 1 + grub-core/loader/linux.c | 2 ++ grub-core/loader/multiboot.c | 1 + grub-core/loader/multiboot_mbi2.c | 1 + grub-core/script/execute.c | 1 + 11 files changed, 29 insertions(+), 4 deletions(-) diff --git a/grub-core/kern/dl.c b/grub-core/kern/dl.c index 7c76d3097..2fdd40e8c 100644 --- a/grub-core/kern/dl.c +++ b/grub-core/kern/dl.c @@ -725,6 +725,7 @@ grub_dl_load_file (const char *filename) grub_file_close (file); grub_tpm_measure(core, size, GRUB_BINARY_PCR, "grub_module", filename); + grub_print_error(); mod = grub_dl_load_core (core, size); grub_free (core); diff --git a/grub-core/kern/i386/pc/tpm.c b/grub-core/kern/i386/pc/tpm.c index 8c6c1e6ec..f6f264aff 100644 --- a/grub-core/kern/i386/pc/tpm.c +++ b/grub-core/kern/i386/pc/tpm.c @@ -7,21 +7,28 @@ #define TCPA_MAGIC 0x41504354 +static int tpm_presence = -1; + int tpm_present(void); int tpm_present(void) { struct grub_bios_int_registers regs; + if (tpm_presence != -1) + return tpm_presence; + regs.flags = GRUB_CPU_INT_FLAGS_DEFAULT; regs.eax = 0xbb00; regs.ebx = TCPA_MAGIC; grub_bios_interrupt (0x1a, ®s); if (regs.eax == 0) - return 1; + tpm_presence = 1; + else + tpm_presence = 0; - return 0; + return tpm_presence; } grub_err_t @@ -49,7 +56,10 @@ grub_tpm_execute(PassThroughToTPM_InputParamBlock *inbuf, grub_bios_interrupt (0x1a, ®s); if (regs.eax) - return grub_error (GRUB_ERR_IO, N_("TPM error %x\n"), regs.eax); + { + tpm_presence = 0; + return grub_error (GRUB_ERR_IO, N_("TPM error %x, disabling TPM"), regs.eax); + } return 0; } @@ -126,7 +136,10 @@ grub_tpm_log_event(unsigned char *buf, grub_size_t size, grub_uint8_t pcr, grub_free(event); if (regs.eax) - return grub_error (GRUB_ERR_IO, N_("TPM error %x\n"), regs.eax); + { + tpm_presence = 0; + return grub_error (GRUB_ERR_IO, N_("TPM error %x, disabling TPM"), regs.eax); + } return 0; } diff --git a/grub-core/lib/cmdline.c b/grub-core/lib/cmdline.c index 3791f3aa9..f090ea20d 100644 --- a/grub-core/lib/cmdline.c +++ b/grub-core/lib/cmdline.c @@ -107,6 +107,7 @@ int grub_create_loader_cmdline (int argc, char *argv[], char *buf, grub_tpm_measure ((void *)orig, grub_strlen (orig), GRUB_ASCII_PCR, "grub_kernel_cmdline", orig); + grub_print_error(); return i; } diff --git a/grub-core/loader/i386/efi/linux.c b/grub-core/loader/i386/efi/linux.c index e89d466f6..e572d2351 100644 --- a/grub-core/loader/i386/efi/linux.c +++ b/grub-core/loader/i386/efi/linux.c @@ -170,6 +170,7 @@ grub_cmd_initrd (grub_command_t cmd __attribute__ ((unused)), goto fail; } grub_tpm_measure (ptr, cursize, GRUB_BINARY_PCR, "grub_linuxefi", "Initrd"); + grub_print_error(); ptr += cursize; grub_memset (ptr, 0, ALIGN_UP_OVERHEAD (cursize, 4)); ptr += ALIGN_UP_OVERHEAD (cursize, 4); @@ -226,6 +227,7 @@ grub_cmd_linux (grub_command_t cmd __attribute__ ((unused)), } grub_tpm_measure (kernel, filelen, GRUB_BINARY_PCR, "grub_linuxefi", "Kernel"); + grub_print_error(); if (! grub_linuxefi_secure_validate (kernel, filelen)) { diff --git a/grub-core/loader/i386/linux.c b/grub-core/loader/i386/linux.c index 52769419f..7f92c363a 100644 --- a/grub-core/loader/i386/linux.c +++ b/grub-core/loader/i386/linux.c @@ -719,6 +719,7 @@ grub_cmd_linux (grub_command_t cmd __attribute__ ((unused)), } grub_tpm_measure (kernel, len, GRUB_BINARY_PCR, "grub_linux", "Kernel"); + grub_print_error(); grub_memcpy (&lh, kernel, sizeof (lh)); diff --git a/grub-core/loader/i386/multiboot_mbi.c b/grub-core/loader/i386/multiboot_mbi.c index efaa66ce4..92daef053 100644 --- a/grub-core/loader/i386/multiboot_mbi.c +++ b/grub-core/loader/i386/multiboot_mbi.c @@ -166,6 +166,7 @@ grub_multiboot_load (grub_file_t file, const char *filename) } grub_tpm_measure((unsigned char*)buffer, len, GRUB_BINARY_PCR, "grub_multiboot", filename); + grub_print_error(); header = find_header (buffer, len); diff --git a/grub-core/loader/i386/pc/linux.c b/grub-core/loader/i386/pc/linux.c index b9dd80bb3..a20c66346 100644 --- a/grub-core/loader/i386/pc/linux.c +++ b/grub-core/loader/i386/pc/linux.c @@ -162,6 +162,7 @@ grub_cmd_linux (grub_command_t cmd __attribute__ ((unused)), } grub_tpm_measure (kernel, len, GRUB_BINARY_PCR, "grub_linux16", "Kernel"); + grub_print_error(); grub_memcpy (&lh, kernel, sizeof (lh)); kernel_offset = sizeof (lh); diff --git a/grub-core/loader/linux.c b/grub-core/loader/linux.c index 78c41e334..c2c7cfcd0 100644 --- a/grub-core/loader/linux.c +++ b/grub-core/loader/linux.c @@ -290,6 +290,8 @@ grub_initrd_load (struct grub_linux_initrd_context *initrd_ctx, return grub_errno; } grub_tpm_measure (ptr, cursize, GRUB_BINARY_PCR, "grub_initrd", "Initrd"); + grub_print_error(); + ptr += cursize; } if (newc) diff --git a/grub-core/loader/multiboot.c b/grub-core/loader/multiboot.c index 05cd51154..e85623899 100644 --- a/grub-core/loader/multiboot.c +++ b/grub-core/loader/multiboot.c @@ -386,6 +386,7 @@ grub_cmd_module (grub_command_t cmd __attribute__ ((unused)), grub_file_close (file); grub_tpm_measure (module, size, GRUB_BINARY_PCR, "grub_multiboot", argv[0]); + grub_print_error(); return GRUB_ERR_NONE; } diff --git a/grub-core/loader/multiboot_mbi2.c b/grub-core/loader/multiboot_mbi2.c index 91f842bf7..501842815 100644 --- a/grub-core/loader/multiboot_mbi2.c +++ b/grub-core/loader/multiboot_mbi2.c @@ -128,6 +128,7 @@ grub_multiboot_load (grub_file_t file, const char *filename) COMPILE_TIME_ASSERT (MULTIBOOT_HEADER_ALIGN % 4 == 0); grub_tpm_measure ((unsigned char *)buffer, len, GRUB_BINARY_PCR, "grub_multiboot", filename); + grub_print_error(); header = find_header (buffer, len); diff --git a/grub-core/script/execute.c b/grub-core/script/execute.c index 4852f1b59..bcca91e08 100644 --- a/grub-core/script/execute.c +++ b/grub-core/script/execute.c @@ -963,6 +963,7 @@ grub_script_execute_cmdline (struct grub_script_cmd *cmd) cmdstring[cmdlen-1]= '\0'; grub_tpm_measure ((unsigned char *)cmdstring, cmdlen, GRUB_ASCII_PCR, "grub_cmd", cmdstring); + grub_print_error(); grub_free(cmdstring); invert = 0; argc = argv.argc - 1;