From patchwork Mon Oct 10 08:44:20 2016 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Stewart Smith X-Patchwork-Id: 680274 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Received: from lists.ozlabs.org (lists.ozlabs.org [103.22.144.68]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 3ssv3X1r2Dz9ryr for ; Mon, 10 Oct 2016 19:50:48 +1100 (AEDT) Received: from lists.ozlabs.org (lists.ozlabs.org [IPv6:2401:3900:2:1::3]) by lists.ozlabs.org (Postfix) with ESMTP id 3ssv3X13w4zDt2b for ; Mon, 10 Oct 2016 19:50:48 +1100 (AEDT) X-Original-To: skiboot@lists.ozlabs.org Delivered-To: skiboot@lists.ozlabs.org Received: from mx0a-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by lists.ozlabs.org (Postfix) with ESMTPS id 3sstwj3ydHzDsfl for ; Mon, 10 Oct 2016 19:44:53 +1100 (AEDT) Received: from pps.filterd (m0098420.ppops.net [127.0.0.1]) by mx0b-001b2d01.pphosted.com (8.16.0.17/8.16.0.17) with SMTP id u9A8XATj140120 for ; Mon, 10 Oct 2016 04:44:51 -0400 Received: from e18.ny.us.ibm.com (e18.ny.us.ibm.com [129.33.205.208]) by mx0b-001b2d01.pphosted.com with ESMTP id 26062emy4p-1 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=NOT) for ; Mon, 10 Oct 2016 04:44:51 -0400 Received: from localhost by e18.ny.us.ibm.com with IBM ESMTP SMTP Gateway: Authorized Use Only! Violators will be prosecuted for from ; Mon, 10 Oct 2016 04:44:50 -0400 Received: from d01dlp01.pok.ibm.com (9.56.250.166) by e18.ny.us.ibm.com (146.89.104.205) with IBM ESMTP SMTP Gateway: Authorized Use Only! Violators will be prosecuted; Mon, 10 Oct 2016 04:44:47 -0400 Received: from b01cxnp22034.gho.pok.ibm.com (b01cxnp22034.gho.pok.ibm.com [9.57.198.24]) by d01dlp01.pok.ibm.com (Postfix) with ESMTP id 0153638C8046 for ; Mon, 10 Oct 2016 04:44:47 -0400 (EDT) Received: from b01ledav004.gho.pok.ibm.com (b01ledav004.gho.pok.ibm.com [9.57.199.109]) by b01cxnp22034.gho.pok.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id u9A8ilFO3736000; Mon, 10 Oct 2016 08:44:47 GMT Received: from localhost (unknown [127.0.0.1]) by IMSVA (Postfix) with SMTP id 03E2311204B; Mon, 10 Oct 2016 04:44:47 -0400 (EDT) X-IMSS-HAND-OFF-DIRECTIVE: 127.0.0.1:10026 Received: from birb.localdomain (unknown [9.81.212.138]) by b01ledav004.gho.pok.ibm.com (Postfix) with SMTP id 80C0B112056; Mon, 10 Oct 2016 04:44:39 -0400 (EDT) Received: by birb.localdomain (Postfix, from userid 1000) id CCFB22335216; Mon, 10 Oct 2016 19:44:25 +1100 (AEDT) From: Stewart Smith To: skiboot@lists.ozlabs.org, cclaudio@linux.vnet.ibm.com Date: Mon, 10 Oct 2016 19:44:20 +1100 X-Mailer: git-send-email 2.7.4 In-Reply-To: <1476089061-15197-1-git-send-email-stewart@linux.vnet.ibm.com> References: <1476089061-15197-1-git-send-email-stewart@linux.vnet.ibm.com> X-TM-AS-GCONF: 00 X-Content-Scanned: Fidelis XPS MAILER x-cbid: 16101008-0044-0000-0000-00000169DD82 X-IBM-SpamModules-Scores: X-IBM-SpamModules-Versions: BY=3.00005885; HX=3.00000240; KW=3.00000007; PH=3.00000004; SC=3.00000186; SDB=6.00766372; UDB=6.00366537; IPR=6.00542488; BA=6.00004798; NDR=6.00000001; ZLA=6.00000005; ZF=6.00000009; ZB=6.00000000; ZP=6.00000000; ZH=6.00000000; ZU=6.00000002; MB=3.00012933; XFM=3.00000011; UTC=2016-10-10 08:44:49 X-IBM-AV-DETECTION: SAVI=unused REMOTE=unused XFE=unused x-cbparentid: 16101008-0045-0000-0000-00000596EA49 Message-Id: <1476089061-15197-40-git-send-email-stewart@linux.vnet.ibm.com> X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:, , definitions=2016-10-10_05:, , signatures=0 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 suspectscore=0 malwarescore=0 phishscore=0 adultscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1609300000 definitions=main-1610100142 Subject: [Skiboot] [PATCH 39/40] init: rework tb_measure/verify so can work on preloaded kernels X-BeenThere: skiboot@lists.ozlabs.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: Mailing list for skiboot development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Errors-To: skiboot-bounces+incoming=patchwork.ozlabs.org@lists.ozlabs.org Sender: "Skiboot" e.g. in a simulator, we could load in a STB container and verify/measure it. Signed-off-by: Stewart Smith --- core/init.c | 23 ++++++++++++++--------- 1 file changed, 14 insertions(+), 9 deletions(-) diff --git a/core/init.c b/core/init.c index 28fdf82..12fd7a7 100644 --- a/core/init.c +++ b/core/init.c @@ -334,6 +334,7 @@ static bool start_preload_kernel(void) static bool load_kernel(void) { + void* stb_container = NULL; struct elf_hdr *kh; int loaded; bool do_stb = false; @@ -377,16 +378,20 @@ static bool load_kernel(void) memcpy(NULL, old_vectors, 0x2000); } do_stb = true; + stb_container = kh; /* probably incorrect */ } else { - if (!kernel_size) + if (!kernel_size) { printf("INIT: Assuming kernel at %p\n", KERNEL_LOAD_BASE); - if (stb_is_container(KERNEL_LOAD_BASE, kernel_size)) - kh = (struct elf_hdr *) (KERNEL_LOAD_BASE + - SECURE_BOOT_HEADERS_SIZE); - else - kh = (struct elf_hdr *) (KERNEL_LOAD_BASE); - do_stb = true; + /* Hack for STB in Mambo, assume at least 4kb in mem */ + kernel_size = SECURE_BOOT_HEADERS_SIZE; + do_stb = true; + } + kh = (struct elf_hdr *) (KERNEL_LOAD_BASE); + if (stb_is_container(KERNEL_LOAD_BASE, kernel_size)) { + stb_container = kh; + kh = (struct elf_hdr *) (KERNEL_LOAD_BASE + SECURE_BOOT_HEADERS_SIZE); + } } printf("INIT: Kernel loaded, size: %zu bytes (0 = unknown preload)\n", @@ -411,9 +416,9 @@ static bool load_kernel(void) if (do_stb) { sb_verify(RESOURCE_ID_KERNEL, RESOURCE_SUBID_NONE, - kh, kernel_size); + stb_container, kernel_size + SECURE_BOOT_HEADERS_SIZE); tb_measure(RESOURCE_ID_KERNEL, RESOURCE_SUBID_NONE, - kh, kernel_size); + stb_container, kernel_size + SECURE_BOOT_HEADERS_SIZE); } /*