diff --git a/.clang-format b/.clang-format new file mode 100644 index 00000000..50c51ce6 --- /dev/null +++ b/.clang-format @@ -0,0 +1,104 @@ +--- +# Current recommendation is to use only clang-format 19.1.1 (Visual Studio) +# or 19.1.4 (debian). +# clang-format 19.1.1 is available in Visual Studio 2022 (Developer Command Prompt v17.13.6) +# clang-format 19.1.4 is available in Debian 12.10 (sudo apt install clang-19) +# +# Both of these versions handle PPIndent consistently, though differently +# from older versions. +Language: Cpp +BasedOnStyle: Microsoft +AccessModifierOffset: -4 +# AlwaysBreak & BlockIndent are buggy +# AlwaysBreak: https://github.com/llvm/llvm-project/issues/57241 +# BlockIndent: https://github.com/llvm/llvm-project/issues/57250 +# Align is widely the default and seems to work more reasonably. +AlignAfterOpenBracket: Align +AlignConsecutiveMacros: Consecutive +AlignConsecutiveAssignments: AcrossEmptyLines +AlignConsecutiveBitFields: AcrossEmptyLines +AlignConsecutiveDeclarations: AcrossEmptyLines +AlignEscapedNewlines: Left +AlignOperands: Align +BreakBeforeBinaryOperators: NonAssignment +# style Microsoft is actually for C# but TPM code base historically uses ~80 chars +ColumnLimit: 86 +# don't break after return types, though clang-format seems to have some issues +# with this and still breaks after TPM_RC and some other types. +# open issue with LLVM, no confirmation or workaround identified yet. +AlwaysBreakAfterDefinitionReturnType: None +AlwaysBreakAfterReturnType: None +# we prefer one parameter per line since many parameters have comments +# and binpacking will create extra inconsistency +BinPackArguments: false +BinPackParameters: false +# Microsft standard C/C++ braces +BreakBeforeBraces: Allman +IncludeBlocks: Preserve +IndentCaseLabels: true +IndentCaseBlocks: false +IndentGotoLabels: false +# Before hash can misalign comments when IndentWidth and PPIndentWidth differ. +IndentPPDirectives: AfterHash +IndentWidth: 4 +PPIndentWidth: 2 +# resist line-length excursions +PenaltyExcessCharacter: 100000 +# prefer not to break after '='' and '(' for function calls +# can still happen based on length of components +PenaltyBreakAssignment: 10 +PenaltyBreakBeforeFirstCallParameter: 1000 +# prefer to break a string constant rather than wrap the entire set of +# array brackets and equal sign. If this is too high, can produce this: +# const char somereallylongvariablename +# [] = "...." +# which is really weird. +PenaltyBreakString: 10 +PenaltyBreakOpenParenthesis: 1 +# really dislike breaking after bare return type, wastes vertical space. +PenaltyReturnTypeOnItsOwnLine: 100000000 +# FOO* bar, not FOO *bar +PointerAlignment: Left +# don't touch comments that might have MD tables or other +# complex snippets +ReflowComments: false +# don't sort includes because we can't be sure includes are order-agnostic. +SortIncludes: false +SpaceAroundPointerQualifiers: Default +SpacesBeforeTrailingComments: 2 +SpacesInConditionalStatement: false +# current code is inconsistent, but a simple search for "if (" and "if(" +# shows false to be most consistent with existing TPM code by +# about 2-to-1 +SpaceBeforeParens: false +StatementMacros: + - _Acquires_exclusive_lock_ + - _Acquires_lock_ + - _Function_class_ + - _IRQL_requires_ + - _Must_inspect_result_ + - _No_competing_thread_ + - _Post_same_lock_ + - _Post_writable_byte_size_ + - _Pre_satisfies_ + - _Releases_lock_ + - _Requires_exclusive_lock_held_ + - _Requires_lock_held_ + - _Requires_lock_not_held_ + - _Requires_shared_lock_held_ + - _Ret_maybenull_ + - _Success_ + - _Use_decl_annotations_ + - "DLPENTRY\n" +TabWidth: 4 +TypenameMacros: + - BN_STRUCT_DEF +DeriveLineEnding: false +UseCRLF: false +UseTab: Never +WhitespaceSensitiveMacros: + - STRINGIZE + - LIB_QUOTE + - LIB_INCLUDE2 + - PROFILE_QUOTE +... diff --git a/src/tpm2/BackwardsCompatibility.h b/src/tpm2/BackwardsCompatibility.h index 0f7e6a1f..043ad7a5 100644 --- a/src/tpm2/BackwardsCompatibility.h +++ b/src/tpm2/BackwardsCompatibility.h @@ -8,9 +8,11 @@ #include "compiler.h" typedef UINT8 SEED_COMPAT_LEVEL; -enum { - SEED_COMPAT_LEVEL_ORIGINAL = 0, /* original TPM 2 code up to rev155 */ - SEED_COMPAT_LEVEL_RSA_PRIME_ADJUST_FIX = 1, /* RsaAdjustPrimeCandidate was fixed */ +enum +{ + SEED_COMPAT_LEVEL_ORIGINAL = 0, /* original TPM 2 code up to rev155 */ + SEED_COMPAT_LEVEL_RSA_PRIME_ADJUST_FIX = + 1, /* RsaAdjustPrimeCandidate was fixed */ SEED_COMPAT_LEVEL_LAST = SEED_COMPAT_LEVEL_RSA_PRIME_ADJUST_FIX }; diff --git a/src/tpm2/BackwardsCompatibilityBitArray.c b/src/tpm2/BackwardsCompatibilityBitArray.c index fa7db9eb..70d4edf4 100644 --- a/src/tpm2/BackwardsCompatibilityBitArray.c +++ b/src/tpm2/BackwardsCompatibilityBitArray.c @@ -11,11 +11,11 @@ * A bit in the PERSISTEN_DATA.auditCommands array corresponds to the index in * this array where the command code can be found. */ -static const struct { +static const struct +{ TPM_CC cc; -#define ENTRY(CC, INDEX) \ - [INDEX] = { .cc = CC } +#define ENTRY(CC, INDEX) [INDEX] = {.cc = CC} } CCToCompressedListIndex[] = { ENTRY(TPM_CC_NV_UndefineSpaceSpecial, 0), @@ -144,35 +144,38 @@ static const struct { * to an array where the indices do NOT correspond to a COMPRESSED_LIST. */ TPM_RC -ConvertFromCompressedBitArray(BYTE *inAuditCommands, - size_t inAuditCommandsLen, - BYTE *outAuditCommands, - size_t outAuditCommandsLen) +ConvertFromCompressedBitArray(BYTE* inAuditCommands, + size_t inAuditCommandsLen, + BYTE* outAuditCommands, + size_t outAuditCommandsLen) { size_t max_bit = MIN(inAuditCommandsLen * 8, ARRAY_SIZE(CCToCompressedListIndex)); - size_t bit = 0; + size_t bit = 0; MemorySet(outAuditCommands, 0, outAuditCommandsLen); - while (bit < max_bit) { - BYTE bits = inAuditCommands[bit >> 3]; - BYTE mask = 1; - size_t lbit = bit; + while(bit < max_bit) + { + BYTE bits = inAuditCommands[bit >> 3]; + BYTE mask = 1; + size_t lbit = bit; - while (bits != 0 && lbit < max_bit) { - if ((bits & mask) != 0) { - TPM_CC cc = CCToCompressedListIndex[lbit].cc; - COMMAND_INDEX idx = cc - TPM_CC_NV_UndefineSpaceSpecial; + while(bits != 0 && lbit < max_bit) + { + if((bits & mask) != 0) + { + TPM_CC cc = CCToCompressedListIndex[lbit].cc; + COMMAND_INDEX idx = cc - TPM_CC_NV_UndefineSpaceSpecial; - assert(idx != UNIMPLEMENTED_COMMAND_INDEX); + assert(idx != UNIMPLEMENTED_COMMAND_INDEX); - SetBit(idx, outAuditCommands, outAuditCommandsLen); - bits ^= mask; /* unset bit */ - } - mask <<= 1; - lbit++; - } - bit += 8; + SetBit(idx, outAuditCommands, outAuditCommandsLen); + bits ^= mask; /* unset bit */ + } + mask <<= 1; + lbit++; + } + bit += 8; } return TPM_RC_SUCCESS; @@ -183,19 +186,25 @@ static size_t FindCCInCompressedListIndexArray(TPM_CC cc) size_t e_index = ARRAY_SIZE(CCToCompressedListIndex) - 1; size_t s_index = 0; - while (true) { + while(true) + { size_t index = (e_index + s_index) >> 1; - if (cc == CCToCompressedListIndex[index].cc) { + if(cc == CCToCompressedListIndex[index].cc) + { return index; } - if (e_index == s_index) { + if(e_index == s_index) + { break; } - if (cc < CCToCompressedListIndex[index].cc) { + if(cc < CCToCompressedListIndex[index].cc) + { e_index = index; - } else { - if (s_index != index) + } + else + { + if(s_index != index) s_index = index; else s_index++; @@ -209,34 +218,37 @@ static size_t FindCCInCompressedListIndexArray(TPM_CC cc) * from an array where the indices do NOT correspond to a COMPRESSED_LIST. */ TPM_RC -ConvertToCompressedBitArray(BYTE *inAuditCommands, - size_t inAuditCommandsLen, - BYTE *outAuditCommands, - size_t outAuditCommandsLen) +ConvertToCompressedBitArray(BYTE* inAuditCommands, + size_t inAuditCommandsLen, + BYTE* outAuditCommands, + size_t outAuditCommandsLen) { size_t max_idx = inAuditCommandsLen * 8; - size_t idx = 0; + size_t idx = 0; MemorySet(outAuditCommands, 0, outAuditCommandsLen); - while (idx < max_idx) { - BYTE bits = inAuditCommands[idx >> 3]; - BYTE mask = 1; - size_t lidx = idx; + while(idx < max_idx) + { + BYTE bits = inAuditCommands[idx >> 3]; + BYTE mask = 1; + size_t lidx = idx; - /* handle bits set in one byte in the loop */ - while (bits != 0 && lidx < max_idx) { - if ((bits & mask) != 0) { - TPM_CC cc = lidx + TPM_CC_NV_UndefineSpaceSpecial; - size_t bit = FindCCInCompressedListIndexArray(cc); + /* handle bits set in one byte in the loop */ + while(bits != 0 && lidx < max_idx) + { + if((bits & mask) != 0) + { + TPM_CC cc = lidx + TPM_CC_NV_UndefineSpaceSpecial; + size_t bit = FindCCInCompressedListIndexArray(cc); - SetBit(bit, outAuditCommands, outAuditCommandsLen); - bits ^= mask; /* unset bit */ - } - mask <<= 1; - lidx++; - } - idx += 8; + SetBit(bit, outAuditCommands, outAuditCommandsLen); + bits ^= mask; /* unset bit */ + } + mask <<= 1; + lidx++; + } + idx += 8; } return TPM_RC_SUCCESS; diff --git a/src/tpm2/BackwardsCompatibilityBitArray.h b/src/tpm2/BackwardsCompatibilityBitArray.h index 55e00aa3..6241dd97 100644 --- a/src/tpm2/BackwardsCompatibilityBitArray.h +++ b/src/tpm2/BackwardsCompatibilityBitArray.h @@ -9,15 +9,15 @@ #include TPM_RC -ConvertFromCompressedBitArray(BYTE *inAuditCommands, - size_t inAuditCommandsLen, - BYTE *outAuditCommands, - size_t outAuditCommandsLen); +ConvertFromCompressedBitArray(BYTE* inAuditCommands, + size_t inAuditCommandsLen, + BYTE* outAuditCommands, + size_t outAuditCommandsLen); TPM_RC -ConvertToCompressedBitArray(BYTE *inAuditCommands, - size_t inAuditCommandsLen, - BYTE *outAuditCommands, - size_t outAuditCommandsLen); +ConvertToCompressedBitArray(BYTE* inAuditCommands, + size_t inAuditCommandsLen, + BYTE* outAuditCommands, + size_t outAuditCommandsLen); #endif diff --git a/src/tpm2/BackwardsCompatibilityObject.c b/src/tpm2/BackwardsCompatibilityObject.c index 988771a4..ade973e9 100644 --- a/src/tpm2/BackwardsCompatibilityObject.c +++ b/src/tpm2/BackwardsCompatibilityObject.c @@ -30,61 +30,70 @@ MUST_BE(sizeof(TPMU_PUBLIC_PARMS) == 20); * in some data structures for architectures where the compiler does not pad * automatically as expected (m68k). */ -typedef union { - struct { - UINT16 size; - BYTE buffer[2048/8]; - } t; - TPM2B b; +typedef union +{ + struct + { + UINT16 size; + BYTE buffer[2048 / 8]; + } t; + TPM2B b; } RSA2048_TPM2B_PUBLIC_KEY_RSA; -MUST_BE(sizeof(RSA2048_TPM2B_PUBLIC_KEY_RSA) == 2 + 2048/8); +MUST_BE(sizeof(RSA2048_TPM2B_PUBLIC_KEY_RSA) == 2 + 2048 / 8); -typedef union { +typedef union +{ TPM2B_DIGEST keyedHash; TPM2B_DIGEST sym; RSA2048_TPM2B_PUBLIC_KEY_RSA rsa; TPMS_ECC_POINT ecc; -// TPMS_DERIVE derive; + // TPMS_DERIVE derive; } RSA2048_TPMU_PUBLIC_ID; -MUST_BE(sizeof(RSA2048_TPMU_PUBLIC_ID) == 2 + 2048/8); +MUST_BE(sizeof(RSA2048_TPMU_PUBLIC_ID) == 2 + 2048 / 8); MUST_BE(sizeof(TPMS_ECC_POINT) == 2 * (2 + MAX_ECC_KEY_BYTES)); -typedef struct { - TPMI_ALG_PUBLIC type; - TPMI_ALG_HASH nameAlg; - TPMA_OBJECT objectAttributes; - TPM2B_DIGEST authPolicy; +typedef struct +{ + TPMI_ALG_PUBLIC type; + TPMI_ALG_HASH nameAlg; + TPMA_OBJECT objectAttributes; + TPM2B_DIGEST authPolicy; ARCH_PADDING(pad1, 2); - TPMU_PUBLIC_PARMS parameters; - RSA2048_TPMU_PUBLIC_ID unique; + TPMU_PUBLIC_PARMS parameters; + RSA2048_TPMU_PUBLIC_ID unique; ARCH_PADDING(pad2, 2); } RSA2048_TPMT_PUBLIC; MUST_BE(offsetof(RSA2048_TPMT_PUBLIC, nameAlg) == 2); MUST_BE(offsetof(RSA2048_TPMT_PUBLIC, objectAttributes) == 2 + 2); MUST_BE(offsetof(RSA2048_TPMT_PUBLIC, authPolicy) == 2 + 2 + 4); -MUST_BE(offsetof(RSA2048_TPMT_PUBLIC, parameters) == 2 + 2 + 4 + 66 + 2/*!*/); -MUST_BE(offsetof(RSA2048_TPMT_PUBLIC, unique) == 2 + 2 + 4 + 66 + 2 + 20); +MUST_BE(offsetof(RSA2048_TPMT_PUBLIC, parameters) == 2 + 2 + 4 + 66 + 2 /*!*/); +MUST_BE(offsetof(RSA2048_TPMT_PUBLIC, unique) == 2 + 2 + 4 + 66 + 2 + 20); MUST_BE(sizeof(RSA2048_TPMT_PUBLIC) == 356); -typedef union { - struct { - UINT16 size; - BYTE buffer[((2048/8)/2)*5]; - } t; - TPM2B b; +typedef union +{ + struct + { + UINT16 size; + BYTE buffer[((2048 / 8) / 2) * 5]; + } t; + TPM2B b; } RSA2048_TPM2B_PRIVATE_KEY_RSA; MUST_BE(sizeof(RSA2048_TPM2B_PRIVATE_KEY_RSA) == 642); -typedef union { - struct { - UINT16 size; - BYTE buffer[((2048/8)/2)*5]; - } t; - TPM2B b; +typedef union +{ + struct + { + UINT16 size; + BYTE buffer[((2048 / 8) / 2) * 5]; + } t; + TPM2B b; } RSA2048_TPM2B_PRIVATE_VENDOR_SPECIFIC; -typedef union { +typedef union +{ RSA2048_TPM2B_PRIVATE_KEY_RSA rsa; TPM2B_ECC_PARAMETER ecc; TPM2B_SENSITIVE_DATA bits; @@ -92,7 +101,8 @@ typedef union { RSA2048_TPM2B_PRIVATE_VENDOR_SPECIFIC any; } RSA2048_TPMU_SENSITIVE_COMPOSITE; -typedef struct { +typedef struct +{ TPMI_ALG_PUBLIC sensitiveType; TPM2B_AUTH authValue; TPM2B_DIGEST seedValue; @@ -108,17 +118,16 @@ BN_TYPE(old_prime, (2048 / 2)); typedef struct RSA2048_privateExponent { - bn_old_prime_t Q; - bn_old_prime_t dP; - bn_old_prime_t dQ; - bn_old_prime_t qInv; + bn_old_prime_t Q; + bn_old_prime_t dP; + bn_old_prime_t dQ; + bn_old_prime_t qInv; } RSA2048_privateExponent_t; -static inline void CopyFromOldPrimeT(ci_prime_t *dst, - const bn_old_prime_t *src) +static inline void CopyFromOldPrimeT(ci_prime_t* dst, const bn_old_prime_t* src) { dst->allocated = src->allocated; - dst->size = src->size; + dst->size = src->size; memcpy(dst->d, src->d, sizeof(src->d)); } @@ -128,24 +137,24 @@ typedef struct RSA2048_OBJECT { // The attributes field is required to be first followed by the publicArea. // This allows the overlay of the object structure and a sequence structure - OBJECT_ATTRIBUTES attributes; // object attributes - RSA2048_TPMT_PUBLIC publicArea; // public area of an object - RSA2048_TPMT_SENSITIVE sensitive; // sensitive area of an object + OBJECT_ATTRIBUTES attributes; // object attributes + RSA2048_TPMT_PUBLIC publicArea; // public area of an object + RSA2048_TPMT_SENSITIVE sensitive; // sensitive area of an object RSA2048_privateExponent_t privateExponent; // Additional field for the private - TPM2B_NAME qualifiedName; // object qualified name + TPM2B_NAME qualifiedName; // object qualified name ARCH_PADDING(pad1, 2); - TPMI_DH_OBJECT evictHandle; // if the object is an evict object, + TPMI_DH_OBJECT evictHandle; // if the object is an evict object, // the original handle is kept here. // The 'working' handle will be the // handle of an object slot. - TPM2B_NAME name; // Name of the object name. Kept here + TPM2B_NAME name; // Name of the object name. Kept here // to avoid repeatedly computing it. ARCH_PADDING(pad2, 2); // libtpms added: OBJECT lies in NVRAM; to avoid that it needs different number // of bytes on 32 bit and 64 bit architectures, we need to make sure it's the // same size; simple padding at the end works here - UINT32 _pad; + UINT32 _pad; } RSA2048_OBJECT; MUST_BE(sizeof(OBJECT_ATTRIBUTES) == 4); @@ -160,97 +169,99 @@ MUST_BE(sizeof(RSA2048_OBJECT) == 1896); TPMI_RH_HIERARCHY ObjectGetHierarchyFromAttributes(OBJECT* object) { if(object->attributes.spsHierarchy) - return TPM_RH_OWNER; + return TPM_RH_OWNER; if(object->attributes.epsHierarchy) - return TPM_RH_ENDORSEMENT; + return TPM_RH_ENDORSEMENT; if(object->attributes.ppsHierarchy) - return TPM_RH_PLATFORM; + return TPM_RH_PLATFORM; return TPM_RH_NULL; } static void RSA2048_OBJECT_To_OBJECT(OBJECT* dest, const RSA2048_OBJECT* src) { - dest->attributes = src->attributes; - dest->hierarchy = ObjectGetHierarchyFromAttributes(dest); + dest->attributes = src->attributes; + dest->hierarchy = ObjectGetHierarchyFromAttributes(dest); - dest->publicArea.type = src->publicArea.type; - dest->publicArea.nameAlg = src->publicArea.nameAlg; + dest->publicArea.type = src->publicArea.type; + dest->publicArea.nameAlg = src->publicArea.nameAlg; dest->publicArea.objectAttributes = src->publicArea.objectAttributes; - dest->publicArea.authPolicy = src->publicArea.authPolicy; - dest->publicArea.parameters = src->publicArea.parameters; + dest->publicArea.authPolicy = src->publicArea.authPolicy; + dest->publicArea.parameters = src->publicArea.parameters; /* the unique part can be one or two TPM2B's */ - switch (dest->publicArea.type) { - case TPM_ALG_KEYEDHASH: - MemoryCopy2B(&dest->publicArea.unique.keyedHash.b, - &src->publicArea.unique.keyedHash.b, - sizeof(src->publicArea.unique.keyedHash.t.buffer)); - memset(&dest->privateExponent, 0, sizeof(dest->privateExponent)); - break; - case TPM_ALG_SYMCIPHER: - MemoryCopy2B(&dest->publicArea.unique.sym.b, - &src->publicArea.unique.sym.b, - sizeof(src->publicArea.unique.sym.t.buffer)); - memset(&dest->privateExponent, 0, sizeof(dest->privateExponent)); - break; - case TPM_ALG_RSA: - MemoryCopy2B(&dest->publicArea.unique.rsa.b, - &src->publicArea.unique.rsa.b, - sizeof(src->publicArea.unique.rsa.t.buffer)); + switch(dest->publicArea.type) + { + case TPM_ALG_KEYEDHASH: + MemoryCopy2B(&dest->publicArea.unique.keyedHash.b, + &src->publicArea.unique.keyedHash.b, + sizeof(src->publicArea.unique.keyedHash.t.buffer)); + memset(&dest->privateExponent, 0, sizeof(dest->privateExponent)); + break; + case TPM_ALG_SYMCIPHER: + MemoryCopy2B(&dest->publicArea.unique.sym.b, + &src->publicArea.unique.sym.b, + sizeof(src->publicArea.unique.sym.t.buffer)); + memset(&dest->privateExponent, 0, sizeof(dest->privateExponent)); + break; + case TPM_ALG_RSA: + MemoryCopy2B(&dest->publicArea.unique.rsa.b, + &src->publicArea.unique.rsa.b, + sizeof(src->publicArea.unique.rsa.t.buffer)); - CopyFromOldPrimeT(&dest->privateExponent.Q, &src->privateExponent.Q); - CopyFromOldPrimeT(&dest->privateExponent.dP, &src->privateExponent.dP); - CopyFromOldPrimeT(&dest->privateExponent.dQ, &src->privateExponent.dQ); - CopyFromOldPrimeT(&dest->privateExponent.qInv, &src->privateExponent.qInv); - break; - case TPM_ALG_ECC: - MemoryCopy2B(&dest->publicArea.unique.ecc.x.b, - &src->publicArea.unique.ecc.x.b, - sizeof(src->publicArea.unique.ecc.x.t.buffer)); - MemoryCopy2B(&dest->publicArea.unique.ecc.y.b, - &src->publicArea.unique.ecc.y.b, - sizeof(src->publicArea.unique.ecc.y.t.buffer)); - memset(&dest->privateExponent, 0, sizeof(dest->privateExponent)); - break; + CopyFromOldPrimeT(&dest->privateExponent.Q, &src->privateExponent.Q); + CopyFromOldPrimeT(&dest->privateExponent.dP, &src->privateExponent.dP); + CopyFromOldPrimeT(&dest->privateExponent.dQ, &src->privateExponent.dQ); + CopyFromOldPrimeT(&dest->privateExponent.qInv, + &src->privateExponent.qInv); + break; + case TPM_ALG_ECC: + MemoryCopy2B(&dest->publicArea.unique.ecc.x.b, + &src->publicArea.unique.ecc.x.b, + sizeof(src->publicArea.unique.ecc.x.t.buffer)); + MemoryCopy2B(&dest->publicArea.unique.ecc.y.b, + &src->publicArea.unique.ecc.y.b, + sizeof(src->publicArea.unique.ecc.y.t.buffer)); + memset(&dest->privateExponent, 0, sizeof(dest->privateExponent)); + break; } dest->sensitive.sensitiveType = src->sensitive.sensitiveType; - dest->sensitive.authValue = src->sensitive.authValue; - dest->sensitive.seedValue = src->sensitive.seedValue; + dest->sensitive.authValue = src->sensitive.authValue; + dest->sensitive.seedValue = src->sensitive.seedValue; /* The RSA2048_TPMU_SENSITIVE_COMPOSITE is always a TPM2B */ MemoryCopy2B(&dest->sensitive.sensitive.any.b, - &src->sensitive.sensitive.any.b, - sizeof(src->sensitive.sensitive.any.t.buffer)); + &src->sensitive.sensitive.any.b, + sizeof(src->sensitive.sensitive.any.t.buffer)); dest->qualifiedName = src->qualifiedName; - dest->evictHandle = src->evictHandle; - dest->name = src->name; + dest->evictHandle = src->evictHandle; + dest->name = src->name; } // Convert an RSA2048_OBJECT that was copied into buffer using MemoryCopy TPM_RC RSA2048_OBJECT_Buffer_To_OBJECT(OBJECT* newObject, BYTE* buffer, INT32 size) { - RSA2048_OBJECT oldObject; - TPM_RC rc = 0; + RSA2048_OBJECT oldObject; + TPM_RC rc = 0; // get the attributes MemoryCopy(newObject, buffer, sizeof(newObject->attributes)); - if (ObjectIsSequence(newObject)) - { - /* resuming old hash contexts is not supported */ - rc = TPM_RC_DISABLED; - } + if(ObjectIsSequence(newObject)) + { + /* resuming old hash contexts is not supported */ + rc = TPM_RC_DISABLED; + } else - { - if (size != sizeof(RSA2048_OBJECT)) - return TPM_RC_SIZE; - MemoryCopy(&oldObject, buffer, sizeof(RSA2048_OBJECT)); + { + if(size != sizeof(RSA2048_OBJECT)) + return TPM_RC_SIZE; + MemoryCopy(&oldObject, buffer, sizeof(RSA2048_OBJECT)); - /* fill the newObject with the contents of the oldObject */ - RSA2048_OBJECT_To_OBJECT(newObject, &oldObject); + /* fill the newObject with the contents of the oldObject */ + RSA2048_OBJECT_To_OBJECT(newObject, &oldObject); } return rc; @@ -258,16 +269,19 @@ RSA2048_OBJECT_Buffer_To_OBJECT(OBJECT* newObject, BYTE* buffer, INT32 size) /* The following are data structure from libtpms 0.9.x with RSA 3072 support. */ -typedef union { - struct { - UINT16 size; - BYTE buffer[3072/8]; - } t; - TPM2B b; +typedef union +{ + struct + { + UINT16 size; + BYTE buffer[3072 / 8]; + } t; + TPM2B b; } RSA3072_TPM2B_PUBLIC_KEY_RSA; -MUST_BE(sizeof(RSA3072_TPM2B_PUBLIC_KEY_RSA) == 2 + 3072/8); +MUST_BE(sizeof(RSA3072_TPM2B_PUBLIC_KEY_RSA) == 2 + 3072 / 8); -typedef union { +typedef union +{ TPM2B_DIGEST keyedHash; TPM2B_DIGEST sym; RSA3072_TPM2B_PUBLIC_KEY_RSA rsa; @@ -277,43 +291,49 @@ typedef union { MUST_BE(sizeof(TPM2B_DIGEST) == 2 + BITS_TO_BYTES(512)); MUST_BE(sizeof(TPMS_ECC_POINT) == 2 * (2 + BITS_TO_BYTES(638))); MUST_BE(sizeof(TPMS_DERIVE) == 2 * (2 + 32)); -MUST_BE(sizeof(RSA3072_TPMU_PUBLIC_ID) == 2 + 3072/8); +MUST_BE(sizeof(RSA3072_TPMU_PUBLIC_ID) == 2 + 3072 / 8); -typedef struct { - TPMI_ALG_PUBLIC type; - TPMI_ALG_HASH nameAlg; - TPMA_OBJECT objectAttributes; - TPM2B_DIGEST authPolicy; +typedef struct +{ + TPMI_ALG_PUBLIC type; + TPMI_ALG_HASH nameAlg; + TPMA_OBJECT objectAttributes; + TPM2B_DIGEST authPolicy; ARCH_PADDING(pad1, 2); - TPMU_PUBLIC_PARMS parameters; - RSA3072_TPMU_PUBLIC_ID unique; + TPMU_PUBLIC_PARMS parameters; + RSA3072_TPMU_PUBLIC_ID unique; ARCH_PADDING(pad2, 2); } RSA3072_TPMT_PUBLIC; MUST_BE(offsetof(RSA3072_TPMT_PUBLIC, nameAlg) == 2); MUST_BE(offsetof(RSA3072_TPMT_PUBLIC, objectAttributes) == 2 + 2); MUST_BE(offsetof(RSA3072_TPMT_PUBLIC, authPolicy) == 2 + 2 + 4); -MUST_BE(offsetof(RSA3072_TPMT_PUBLIC, parameters) == 2 + 2 + 4 + 66 + 2/*!*/); +MUST_BE(offsetof(RSA3072_TPMT_PUBLIC, parameters) == 2 + 2 + 4 + 66 + 2 /*!*/); MUST_BE(offsetof(RSA3072_TPMT_PUBLIC, unique) == 2 + 2 + 4 + 66 + 2 + 20); MUST_BE(sizeof(RSA3072_TPMT_PUBLIC) == 484); -typedef union { - struct { - UINT16 size; - BYTE buffer[((3072 / 8) / 2) * 5]; - } t; - TPM2B b; +typedef union +{ + struct + { + UINT16 size; + BYTE buffer[((3072 / 8) / 2) * 5]; + } t; + TPM2B b; } RSA3072_TPM2B_PRIVATE_KEY_RSA; MUST_BE(sizeof(RSA3072_TPM2B_PRIVATE_KEY_RSA) == 962); -typedef union { - struct { - UINT16 size; - BYTE buffer[((3072 / 8) / 2) * 5]; - } t; - TPM2B b; +typedef union +{ + struct + { + UINT16 size; + BYTE buffer[((3072 / 8) / 2) * 5]; + } t; + TPM2B b; } RSA3072_TPM2B_PRIVATE_VENDOR_SPECIFIC; -typedef union { +typedef union +{ RSA3072_TPM2B_PRIVATE_KEY_RSA rsa; TPM2B_ECC_PARAMETER ecc; TPM2B_SENSITIVE_DATA bits; @@ -324,11 +344,12 @@ MUST_BE(sizeof(TPM2B_ECC_PARAMETER) == 2 + BITS_TO_BYTES(638) /* BN P638 */); MUST_BE(sizeof(TPM2B_SENSITIVE_DATA) == 2 + 128); MUST_BE(sizeof(TPM2B_SYM_KEY) == 2 + BITS_TO_BYTES(256)); -typedef struct { - TPMI_ALG_PUBLIC sensitiveType; - TPM2B_AUTH authValue; - TPM2B_DIGEST seedValue; - RSA3072_TPMU_SENSITIVE_COMPOSITE sensitive; +typedef struct +{ + TPMI_ALG_PUBLIC sensitiveType; + TPM2B_AUTH authValue; + TPM2B_DIGEST seedValue; + RSA3072_TPMU_SENSITIVE_COMPOSITE sensitive; } RSA3072_TPMT_SENSITIVE; MUST_BE(sizeof(TPM2B_AUTH) == 2 + BITS_TO_BYTES(512)); MUST_BE(sizeof(TPM2B_DIGEST) == 2 + BITS_TO_BYTES(512)); @@ -338,10 +359,10 @@ BN_TYPE(rsa3072_prime, (3072 / 2)); typedef struct RSA3072_privateExponent { - bn_rsa3072_prime_t Q; - bn_rsa3072_prime_t dP; - bn_rsa3072_prime_t dQ; - bn_rsa3072_prime_t qInv; + bn_rsa3072_prime_t Q; + bn_rsa3072_prime_t dP; + bn_rsa3072_prime_t dQ; + bn_rsa3072_prime_t qInv; } RSA3072_privateExponent_t; MUST_BE(offsetof(RSA3072_privateExponent_t, dP) == 216); MUST_BE(offsetof(RSA3072_privateExponent_t, dQ) == 216 + 216); @@ -352,27 +373,27 @@ typedef struct RSA3072_OBJECT { // The attributes field is required to be first followed by the publicArea. // This allows the overlay of the object structure and a sequence structure - OBJECT_ATTRIBUTES attributes; // object attributes - RSA3072_TPMT_PUBLIC publicArea; // public area of an object - RSA3072_TPMT_SENSITIVE sensitive; // sensitive area of an object -#if 1 // libtpms added begin: keep - RSA3072_privateExponent_t privateExponent; // Additional field for the private -#endif // libtpms added end - TPM2B_NAME qualifiedName; // object qualified name + OBJECT_ATTRIBUTES attributes; // object attributes + RSA3072_TPMT_PUBLIC publicArea; // public area of an object + RSA3072_TPMT_SENSITIVE sensitive; // sensitive area of an object +#if 1 // libtpms added begin: keep + RSA3072_privateExponent_t privateExponent; // Additional field for the private +#endif // libtpms added end + TPM2B_NAME qualifiedName; // object qualified name ARCH_PADDING(pad1, 2); - TPMI_DH_OBJECT evictHandle; // if the object is an evict object, + TPMI_DH_OBJECT evictHandle; // if the object is an evict object, // the original handle is kept here. // The 'working' handle will be the // handle of an object slot. - TPM2B_NAME name; // Name of the object name. Kept here + TPM2B_NAME name; // Name of the object name. Kept here // to avoid repeatedly computing it. // libtpms added: SEED_COMPAT_LEVEL to use for deriving child keys - SEED_COMPAT_LEVEL seedCompatLevel; + SEED_COMPAT_LEVEL seedCompatLevel; // libtpms added: OBJECT lies in NVRAM; to avoid that it needs different number // of bytes on 32 bit and 64 bit architectures, we need to make sure it's the // same size; simple padding at the end works here - UINT8 _pad[3]; + UINT8 _pad[3]; ARCH_PADDING(pad2, 2); } RSA3072_OBJECT; MUST_BE(sizeof(OBJECT_ATTRIBUTES) == 4); @@ -382,149 +403,155 @@ MUST_BE(offsetof(RSA3072_OBJECT, privateExponent) == 4 + 484 + 1096); MUST_BE(offsetof(RSA3072_OBJECT, qualifiedName) == 4 + 484 + 1096 + 864); MUST_BE(offsetof(RSA3072_OBJECT, evictHandle) == 4 + 484 + 1096 + 864 + 68 + 4); MUST_BE(offsetof(RSA3072_OBJECT, name) == 4 + 484 + 1096 + 864 + 68 + 4 + 4); -MUST_BE(offsetof(RSA3072_OBJECT, seedCompatLevel) == 4 + 484 + 1096 + 864 + 68 + 4 + 4 + 70); +MUST_BE(offsetof(RSA3072_OBJECT, seedCompatLevel) + == 4 + 484 + 1096 + 864 + 68 + 4 + 4 + 70); MUST_BE(offsetof(RSA3072_OBJECT, _pad) == 4 + 484 + 1096 + 864 + 68 + 4 + 4 + 70 + 1); MUST_BE(sizeof(RSA3072_OBJECT) == 2600); -static inline void CopyFromRSA3072PrimeT(ci_prime_t* dst, - const bn_rsa3072_prime_t* src) +static inline void CopyFromRSA3072PrimeT(ci_prime_t* dst, + const bn_rsa3072_prime_t* src) { dst->allocated = src->allocated; - dst->size = src->size; + dst->size = src->size; memcpy(dst->d, src->d, sizeof(src->d)); } -static inline void CopyToRSA3072PrimeT(bn_rsa3072_prime_t* dst, - const ci_prime_t* src) +static inline void CopyToRSA3072PrimeT(bn_rsa3072_prime_t* dst, const ci_prime_t* src) { dst->allocated = src->allocated; - dst->size = src->size; + dst->size = src->size; memcpy(dst->d, src->d, sizeof(dst->d)); } static void RSA3072_OBJECT_To_OBJECT(OBJECT* dest, const RSA3072_OBJECT* src) { - dest->attributes = src->attributes; - dest->hierarchy = ObjectGetHierarchyFromAttributes(dest); + dest->attributes = src->attributes; + dest->hierarchy = ObjectGetHierarchyFromAttributes(dest); - dest->publicArea.type = src->publicArea.type; - dest->publicArea.nameAlg = src->publicArea.nameAlg; + dest->publicArea.type = src->publicArea.type; + dest->publicArea.nameAlg = src->publicArea.nameAlg; dest->publicArea.objectAttributes = src->publicArea.objectAttributes; - dest->publicArea.authPolicy = src->publicArea.authPolicy; - dest->publicArea.parameters = src->publicArea.parameters; + dest->publicArea.authPolicy = src->publicArea.authPolicy; + dest->publicArea.parameters = src->publicArea.parameters; /* the unique part can be one or two TPM2B's */ - switch (dest->publicArea.type) { - case TPM_ALG_KEYEDHASH: - MemoryCopy2B(&dest->publicArea.unique.keyedHash.b, - &src->publicArea.unique.keyedHash.b, - sizeof(src->publicArea.unique.keyedHash.t.buffer)); - memset(&dest->privateExponent, 0, sizeof(dest->privateExponent)); - break; - case TPM_ALG_SYMCIPHER: - MemoryCopy2B(&dest->publicArea.unique.sym.b, - &src->publicArea.unique.sym.b, - sizeof(src->publicArea.unique.sym.t.buffer)); - memset(&dest->privateExponent, 0, sizeof(dest->privateExponent)); - break; - case TPM_ALG_RSA: - MemoryCopy2B(&dest->publicArea.unique.rsa.b, - &src->publicArea.unique.rsa.b, - sizeof(src->publicArea.unique.rsa.t.buffer)); + switch(dest->publicArea.type) + { + case TPM_ALG_KEYEDHASH: + MemoryCopy2B(&dest->publicArea.unique.keyedHash.b, + &src->publicArea.unique.keyedHash.b, + sizeof(src->publicArea.unique.keyedHash.t.buffer)); + memset(&dest->privateExponent, 0, sizeof(dest->privateExponent)); + break; + case TPM_ALG_SYMCIPHER: + MemoryCopy2B(&dest->publicArea.unique.sym.b, + &src->publicArea.unique.sym.b, + sizeof(src->publicArea.unique.sym.t.buffer)); + memset(&dest->privateExponent, 0, sizeof(dest->privateExponent)); + break; + case TPM_ALG_RSA: + MemoryCopy2B(&dest->publicArea.unique.rsa.b, + &src->publicArea.unique.rsa.b, + sizeof(src->publicArea.unique.rsa.t.buffer)); - CopyFromRSA3072PrimeT(&dest->privateExponent.Q, &src->privateExponent.Q); - CopyFromRSA3072PrimeT(&dest->privateExponent.dP, &src->privateExponent.dP); - CopyFromRSA3072PrimeT(&dest->privateExponent.dQ, &src->privateExponent.dQ); - CopyFromRSA3072PrimeT(&dest->privateExponent.qInv, &src->privateExponent.qInv); - break; - case TPM_ALG_ECC: - MemoryCopy2B(&dest->publicArea.unique.ecc.x.b, - &src->publicArea.unique.ecc.x.b, - sizeof(src->publicArea.unique.ecc.x.t.buffer)); - MemoryCopy2B(&dest->publicArea.unique.ecc.y.b, - &src->publicArea.unique.ecc.y.b, - sizeof(src->publicArea.unique.ecc.y.t.buffer)); - memset(&dest->privateExponent, 0, sizeof(dest->privateExponent)); - break; + CopyFromRSA3072PrimeT(&dest->privateExponent.Q, &src->privateExponent.Q); + CopyFromRSA3072PrimeT(&dest->privateExponent.dP, + &src->privateExponent.dP); + CopyFromRSA3072PrimeT(&dest->privateExponent.dQ, + &src->privateExponent.dQ); + CopyFromRSA3072PrimeT(&dest->privateExponent.qInv, + &src->privateExponent.qInv); + break; + case TPM_ALG_ECC: + MemoryCopy2B(&dest->publicArea.unique.ecc.x.b, + &src->publicArea.unique.ecc.x.b, + sizeof(src->publicArea.unique.ecc.x.t.buffer)); + MemoryCopy2B(&dest->publicArea.unique.ecc.y.b, + &src->publicArea.unique.ecc.y.b, + sizeof(src->publicArea.unique.ecc.y.t.buffer)); + memset(&dest->privateExponent, 0, sizeof(dest->privateExponent)); + break; } dest->sensitive.sensitiveType = src->sensitive.sensitiveType; - dest->sensitive.authValue = src->sensitive.authValue; - dest->sensitive.seedValue = src->sensitive.seedValue; + dest->sensitive.authValue = src->sensitive.authValue; + dest->sensitive.seedValue = src->sensitive.seedValue; /* The OLD_TPMU_SENSITIVE_COMPOSITE is always a TPM2B */ MemoryCopy2B(&dest->sensitive.sensitive.any.b, - &src->sensitive.sensitive.any.b, - sizeof(src->sensitive.sensitive.any.t.buffer)); + &src->sensitive.sensitive.any.b, + sizeof(src->sensitive.sensitive.any.t.buffer)); - dest->qualifiedName = src->qualifiedName; - dest->evictHandle = src->evictHandle; - dest->name = src->name; + dest->qualifiedName = src->qualifiedName; + dest->evictHandle = src->evictHandle; + dest->name = src->name; dest->seedCompatLevel = src->seedCompatLevel; } /* Convert an OBJECT to the (smaller) RSA3072_OBJECT. */ static void OBJECT_To_RSA3072_OBJECT(RSA3072_OBJECT* dest, const OBJECT* src) { - dest->attributes = src->attributes; + dest->attributes = src->attributes; - dest->publicArea.type = src->publicArea.type; - dest->publicArea.nameAlg = src->publicArea.nameAlg; + dest->publicArea.type = src->publicArea.type; + dest->publicArea.nameAlg = src->publicArea.nameAlg; dest->publicArea.objectAttributes = src->publicArea.objectAttributes; - dest->publicArea.authPolicy = src->publicArea.authPolicy; - dest->publicArea.parameters = src->publicArea.parameters; + dest->publicArea.authPolicy = src->publicArea.authPolicy; + dest->publicArea.parameters = src->publicArea.parameters; /* the unique part can be one or two TPM2B's */ - switch (dest->publicArea.type) { - case TPM_ALG_KEYEDHASH: - MemoryCopy2B(&dest->publicArea.unique.keyedHash.b, - &src->publicArea.unique.keyedHash.b, - sizeof(dest->publicArea.unique.keyedHash.t.buffer)); - break; - case TPM_ALG_SYMCIPHER: - MemoryCopy2B(&dest->publicArea.unique.sym.b, - &src->publicArea.unique.sym.b, - sizeof(dest->publicArea.unique.sym.t.buffer)); - break; - case TPM_ALG_RSA: - MemoryCopy2B(&dest->publicArea.unique.rsa.b, - &src->publicArea.unique.rsa.b, - sizeof(dest->publicArea.unique.rsa.t.buffer)); + switch(dest->publicArea.type) + { + case TPM_ALG_KEYEDHASH: + MemoryCopy2B(&dest->publicArea.unique.keyedHash.b, + &src->publicArea.unique.keyedHash.b, + sizeof(dest->publicArea.unique.keyedHash.t.buffer)); + break; + case TPM_ALG_SYMCIPHER: + MemoryCopy2B(&dest->publicArea.unique.sym.b, + &src->publicArea.unique.sym.b, + sizeof(dest->publicArea.unique.sym.t.buffer)); + break; + case TPM_ALG_RSA: + MemoryCopy2B(&dest->publicArea.unique.rsa.b, + &src->publicArea.unique.rsa.b, + sizeof(dest->publicArea.unique.rsa.t.buffer)); - CopyToRSA3072PrimeT(&dest->privateExponent.Q, &src->privateExponent.Q); - CopyToRSA3072PrimeT(&dest->privateExponent.dP, &src->privateExponent.dP); - CopyToRSA3072PrimeT(&dest->privateExponent.dQ, &src->privateExponent.dQ); - CopyToRSA3072PrimeT(&dest->privateExponent.qInv, &src->privateExponent.qInv); - break; - case TPM_ALG_ECC: - MemoryCopy2B(&dest->publicArea.unique.ecc.x.b, - &src->publicArea.unique.ecc.x.b, - sizeof(dest->publicArea.unique.ecc.x.t.buffer)); - MemoryCopy2B(&dest->publicArea.unique.ecc.y.b, - &src->publicArea.unique.ecc.y.b, - sizeof(dest->publicArea.unique.ecc.y.t.buffer)); - break; + CopyToRSA3072PrimeT(&dest->privateExponent.Q, &src->privateExponent.Q); + CopyToRSA3072PrimeT(&dest->privateExponent.dP, &src->privateExponent.dP); + CopyToRSA3072PrimeT(&dest->privateExponent.dQ, &src->privateExponent.dQ); + CopyToRSA3072PrimeT(&dest->privateExponent.qInv, + &src->privateExponent.qInv); + break; + case TPM_ALG_ECC: + MemoryCopy2B(&dest->publicArea.unique.ecc.x.b, + &src->publicArea.unique.ecc.x.b, + sizeof(dest->publicArea.unique.ecc.x.t.buffer)); + MemoryCopy2B(&dest->publicArea.unique.ecc.y.b, + &src->publicArea.unique.ecc.y.b, + sizeof(dest->publicArea.unique.ecc.y.t.buffer)); + break; } dest->sensitive.sensitiveType = src->sensitive.sensitiveType; - dest->sensitive.authValue = src->sensitive.authValue; - dest->sensitive.seedValue = src->sensitive.seedValue; + dest->sensitive.authValue = src->sensitive.authValue; + dest->sensitive.seedValue = src->sensitive.seedValue; /* The OLD_TPMU_SENSITIVE_COMPOSITE is always a TPM2B */ MemoryCopy2B(&dest->sensitive.sensitive.any.b, - &src->sensitive.sensitive.any.b, - sizeof(dest->sensitive.sensitive.any.t.buffer)); + &src->sensitive.sensitive.any.b, + sizeof(dest->sensitive.sensitive.any.t.buffer)); - dest->qualifiedName = src->qualifiedName; - dest->evictHandle = src->evictHandle; - dest->name = src->name; + dest->qualifiedName = src->qualifiedName; + dest->evictHandle = src->evictHandle; + dest->name = src->name; dest->seedCompatLevel = src->seedCompatLevel; MemorySet(dest->_pad, 0, sizeof(dest->_pad)); } TPM_RC -RSA3072_OBJECT_Buffer_To_OBJECT(OBJECT *object, BYTE *buffer, INT32 size) +RSA3072_OBJECT_Buffer_To_OBJECT(OBJECT* object, BYTE* buffer, INT32 size) { RSA3072_OBJECT rsa3072_object; - if (size != sizeof(RSA3072_OBJECT)) - return TPM_RC_SIZE; + if(size != sizeof(RSA3072_OBJECT)) + return TPM_RC_SIZE; MemoryCopy(&rsa3072_object, buffer, size); diff --git a/src/tpm2/LibtpmsCallbacks.c b/src/tpm2/LibtpmsCallbacks.c index ea744434..3735e9cf 100644 --- a/src/tpm2/LibtpmsCallbacks.c +++ b/src/tpm2/LibtpmsCallbacks.c @@ -14,107 +14,102 @@ #include "tpm_error.h" #include "tpm_nvfilename.h" -int -libtpms_plat__NVEnable(void) +int libtpms_plat__NVEnable(void) { - unsigned char *data = NULL; - uint32_t length = 0; - struct libtpms_callbacks *cbs = TPMLIB_GetCallbacks(); - TPM_RC rc; - bool is_empty_state; + unsigned char* data = NULL; + uint32_t length = 0; + struct libtpms_callbacks* cbs = TPMLIB_GetCallbacks(); + TPM_RC rc; + bool is_empty_state; /* try to get state blob set via TPMLIB_SetState() */ GetCachedState(TPMLIB_STATE_PERMANENT, &data, &length, &is_empty_state); - if (is_empty_state) { + if(is_empty_state) + { memset(s_NV, 0, NV_MEMORY_SIZE); return 0; } - if (data == NULL && cbs->tpm_nvram_loaddata) { - uint32_t tpm_number = 0; - const char *name = TPM_PERMANENT_ALL_NAME; - TPM_RESULT ret; + if(data == NULL && cbs->tpm_nvram_loaddata) + { + uint32_t tpm_number = 0; + const char* name = TPM_PERMANENT_ALL_NAME; + TPM_RESULT ret; ret = cbs->tpm_nvram_loaddata(&data, &length, tpm_number, name); - switch (ret) { - case TPM_RETRY: - if (!cbs->tpm_nvram_storedata) { + switch(ret) + { + case TPM_RETRY: + if(!cbs->tpm_nvram_storedata) + { + return -1; + } + memset(s_NV, 0, NV_MEMORY_SIZE); + return 0; + + case TPM_SUCCESS: + /* got the data -- unmarshal them... */ + break; + + case TPM_FAIL: + default: return -1; - } - memset(s_NV, 0, NV_MEMORY_SIZE); - return 0; - - case TPM_SUCCESS: - /* got the data -- unmarshal them... */ - break; - - case TPM_FAIL: - default: - return -1; } } - if (data) { - unsigned char *buffer = data; - INT32 size = length; + if(data) + { + unsigned char* buffer = data; + INT32 size = length; - rc = PERSISTENT_ALL_Unmarshal(&buffer, &size); + rc = PERSISTENT_ALL_Unmarshal(&buffer, &size); free(data); - if (rc != TPM_RC_SUCCESS) + if(rc != TPM_RC_SUCCESS) return -1; - return 0; + return 0; } return LIBTPMS_CALLBACK_FALLTHROUGH; /* -2 */ } -int -libtpms_plat__NVDisable( - void - ) +int libtpms_plat__NVDisable(void) { - struct libtpms_callbacks *cbs = TPMLIB_GetCallbacks(); + struct libtpms_callbacks* cbs = TPMLIB_GetCallbacks(); - if (cbs->tpm_nvram_loaddata) + if(cbs->tpm_nvram_loaddata) return 0; return LIBTPMS_CALLBACK_FALLTHROUGH; /* -2 */ } -int -libtpms_plat__IsNvAvailable( - void - ) +int libtpms_plat__IsNvAvailable(void) { - struct libtpms_callbacks *cbs = TPMLIB_GetCallbacks(); + struct libtpms_callbacks* cbs = TPMLIB_GetCallbacks(); - if (cbs->tpm_nvram_loaddata && - cbs->tpm_nvram_storedata) { + if(cbs->tpm_nvram_loaddata && cbs->tpm_nvram_storedata) + { return 1; } return LIBTPMS_CALLBACK_FALLTHROUGH; /* -2 */ } -int -libtpms_plat__NvCommit( - void - ) +int libtpms_plat__NvCommit(void) { - struct libtpms_callbacks *cbs = TPMLIB_GetCallbacks(); + struct libtpms_callbacks* cbs = TPMLIB_GetCallbacks(); - if (cbs->tpm_nvram_storedata) { - uint32_t tpm_number = 0; - const char *name = TPM_PERMANENT_ALL_NAME; - TPM_RESULT ret; - BYTE *buf; - uint32_t buflen; + if(cbs->tpm_nvram_storedata) + { + uint32_t tpm_number = 0; + const char* name = TPM_PERMANENT_ALL_NAME; + TPM_RESULT ret; + BYTE* buf; + uint32_t buflen; ret = TPM2_PersistentAllStore(&buf, &buflen); - if (ret != TPM_SUCCESS) + if(ret != TPM_SUCCESS) return ret; - ret = cbs->tpm_nvram_storedata(buf, buflen, - tpm_number, name); + ret = cbs->tpm_nvram_storedata(buf, buflen, tpm_number, name); free(buf); - if (ret == TPM_SUCCESS) + if(ret == TPM_SUCCESS) return 0; return -1; @@ -122,20 +117,19 @@ libtpms_plat__NvCommit( return LIBTPMS_CALLBACK_FALLTHROUGH; /* -2 */ } -int -libtpms_plat__PhysicalPresenceAsserted( - BOOL *pp - ) +int libtpms_plat__PhysicalPresenceAsserted(BOOL* pp) { - struct libtpms_callbacks *cbs = TPMLIB_GetCallbacks(); + struct libtpms_callbacks* cbs = TPMLIB_GetCallbacks(); - if (cbs->tpm_io_getphysicalpresence) { - uint32_t tpm_number = 0; - TPM_RESULT res; + if(cbs->tpm_io_getphysicalpresence) + { + uint32_t tpm_number = 0; + TPM_RESULT res; unsigned char mypp; res = cbs->tpm_io_getphysicalpresence(&mypp, tpm_number); - if (res == TPM_SUCCESS) { + if(res == TPM_SUCCESS) + { *pp = mypp; return 0; } diff --git a/src/tpm2/LibtpmsCallbacks.h b/src/tpm2/LibtpmsCallbacks.h index d4c05a0e..210a29b9 100644 --- a/src/tpm2/LibtpmsCallbacks.h +++ b/src/tpm2/LibtpmsCallbacks.h @@ -11,6 +11,6 @@ int libtpms_plat__NVEnable(void); int libtpms_plat__NVDisable(void); int libtpms_plat__IsNvAvailable(void); int libtpms_plat__NvCommit(void); -int libtpms_plat__PhysicalPresenceAsserted(BOOL *pp); +int libtpms_plat__PhysicalPresenceAsserted(BOOL* pp); #endif /* LIBTPMS_CALLBACKS_H */ diff --git a/src/tpm2/TPMCmd/tpm/src/subsystem/Object.c b/src/tpm2/TPMCmd/tpm/src/subsystem/Object.c index ff321d29..cf1d1ac3 100644 --- a/src/tpm2/TPMCmd/tpm/src/subsystem/Object.c +++ b/src/tpm2/TPMCmd/tpm/src/subsystem/Object.c @@ -629,15 +629,17 @@ ObjectContextLoadLibtpms(BYTE *buffer, if(newObject != NULL) { rc = ANY_OBJECT_Unmarshal(newObject, &mybuf, &mysize, false); - if (rc) { - /* Attempt to load an old OBJECT that was copied out directly from - * an older version of OBJECT. - */ - rc = RSA2048_OBJECT_Buffer_To_OBJECT(newObject, buffer, size); - if (rc) { - FlushObject(*handle); - newObject = NULL; - } + if (rc) + { + /* Attempt to load an old OBJECT that was copied out directly from + * an older version of OBJECT. + */ + rc = RSA2048_OBJECT_Buffer_To_OBJECT(newObject, buffer, size); + if (rc) + { + FlushObject(*handle); + newObject = NULL; + } } } return newObject;