swtpm/tests/_test_tpm2_setbuffersize
Stefan Berger ea49575290 tests: Test failure to init TPM 2 with 5kb buffer and default-v2 profile
Add a test case that starts the TPM 2 with the default-v2 profile which
enables ML-KEM and ML-DSA and check that the TPM 2 cannot be initialized
when the buffer size is set to 5kb and that it can be initialized once
the buffer size is at 8kb.

Signed-off-by: Stefan Berger <stefanb@linux.ibm.com>
2026-06-12 18:39:33 +00:00

201 lines
5.7 KiB
Bash
Executable File

#!/bin/bash
# For the license, see the LICENSE file in the root directory.
#set -x
ROOT=${abs_top_builddir:-$(pwd)/..}
TESTDIR=${abs_top_testdir:-$(dirname "$0")}
VTPM_NAME="vtpm-test-tpm2-setbuffersize"
SWTPM_DEV_NAME="/dev/${VTPM_NAME}"
TPM_PATH="$(mktemp -d)" || exit 1
STATE_FILE=$TPM_PATH/tpm2-00.permall
OUTFILE=$TPM_PATH/output
VOLATILE_STATE_FILE=$TPM_PATH/tpm2-00.volatilestate
SWTPM_CMD_UNIX_PATH=${TPM_PATH}/unix-cmd.sock
SWTPM_CTRL_UNIX_PATH=${TPM_PATH}/unix-ctrl.sock
SWTPM_INTERFACE=${SWTPM_INTERFACE:-cuse}
function cleanup()
{
pid=${SWTPM_PID}
if [ -n "$pid" ]; then
kill_quiet -9 "$pid"
fi
rm -rf "$TPM_PATH"
}
trap "cleanup" EXIT
source "${TESTDIR}/common"
[ "${SWTPM_INTERFACE}" == cuse ] && source "${TESTDIR}/test_cuse"
rm -f "$STATE_FILE" "$VOLATILE_STATE_FILE" 2>/dev/null
TPM_PATH=$TPM_PATH run_swtpm "${SWTPM_INTERFACE}" --tpm2
if ! kill_quiet -0 "${SWTPM_PID}"; then
echo "Error: ${SWTPM_INTERFACE} TPM did not start."
exit 1
fi
# Check the buffer size
if ! run_swtpm_ioctl "${SWTPM_INTERFACE}" -b 0 > "${OUTFILE}"; then
echo "Error: Could not get the buffersize of the ${SWTPM_INTERFACE} TPM."
exit 1
fi
cat "${OUTFILE}"
if ! grep "TPM buffersize" "${OUTFILE}" | grep -q 4096; then
echo "Error: The TPM buffersize of the ${SWTPM_INTERFACE} TPM is not 4096."
exit 1
fi
# set the buffer size -- it's not going to change but command must not fail
if ! run_swtpm_ioctl "${SWTPM_INTERFACE}" -b 4000 > "${OUTFILE}"; then
echo "Error: Could not set the buffersize of the ${SWTPM_INTERFACE} TPM."
exit 1
fi
cat "${OUTFILE}"
if ! grep "TPM buffersize" "${OUTFILE}" | grep -q 4000; then
echo "Error: Could not set the buffersize of the ${SWTPM_INTERFACE} TPM to 4000."
exit 1
fi
# Init the TPM
if ! run_swtpm_ioctl "${SWTPM_INTERFACE}" -i; then
echo "Error: Could not initialize the ${SWTPM_INTERFACE} TPM."
exit 1
fi
if ! kill_quiet -0 "${SWTPM_PID}" 2>/dev/null; then
echo "Error: ${SWTPM_INTERFACE} TPM not running anymore after INIT."
exit 1
fi
# Set the buffer size -- should fail
if ERR="$(run_swtpm_ioctl "${SWTPM_INTERFACE}" -b 4096 2>&1)"; then
echo "Error: Could set the buffersize while the ${SWTPM_INTERFACE} TPM is running."
exit 1
fi
exp="TPM result from PTM_SET_BUFFERSIZE: 0xa"
if [ "$ERR" != "$exp" ]; then
echo "Error: Unexpected error message"
echo "Received: $ERR"
echo "Expected: $exp"
exit 1
fi
# Startup the TPM2
RES=$(swtpm_cmd_tx "${SWTPM_INTERFACE}" '\x80\x01\x00\x00\x00\x0c\x00\x00\x01\x44\x00\x00')
exp=' 80 01 00 00 00 0a 00 00 00 00'
if [ "$RES" != "$exp" ]; then
echo "Error: Did not get expected result from TPM2_Startup(SU_Clear)"
echo "expected: $exp"
echo "received: $RES"
exit 1
fi
# Read the Buffer sizes; we want to see '4000' (0xfa0) in the buffer sizes now
RES=$(swtpm_cmd_tx "${SWTPM_INTERFACE}" '\x80\x01\x00\x00\x00\x16\x00\x00\x01\x7a\x00\x00\x00\x06\x00\x00\x01\x1e\x00\x00\x00\x02')
exp=' 80 01 00 00 00 23 00 00 00 00 01 00 00 00 06 00 00 00 02 00 00 01 1e 00 00 0f a0 00 00 01 1f 00 00 0f a0'
if [ "$RES" != "$exp" ]; then
echo "Error: Did not get expected result from TPM2_GetCapability()"
echo "expected: $exp"
echo "received: $RES"
exit 1
fi
if ! run_swtpm_ioctl "${SWTPM_INTERFACE}" -s; then
echo "Error: Could not shut down the ${SWTPM_INTERFACE} TPM."
exit 1
fi
if wait_process_gone "${SWTPM_PID}" 4; then
echo "Error: ${SWTPM_INTERFACE} TPM should not be running anymore."
exit 1
fi
if [ ! -e "$STATE_FILE" ]; then
echo "Error: TPM state file $STATE_FILE does not exist."
exit 1
fi
printf "Test 1: OK\n\n"
# libtpms must refuse to start with default-v2 profile and 5kb buffer size since
# ML-KEM and ML-DSA require 8kb buffer size
rm -f "$STATE_FILE" "$VOLATILE_STATE_FILE" 2>/dev/null
TPM_PATH=$TPM_PATH run_swtpm "${SWTPM_INTERFACE}" --tpm2 --profile name="default-v2"
if ! kill_quiet -0 "${SWTPM_PID}"; then
echo "Error: ${SWTPM_INTERFACE} TPM did not start."
exit 1
fi
# set the buffer size to 5kb
if ! run_swtpm_ioctl "${SWTPM_INTERFACE}" -b $((5 * 1024)) > "${OUTFILE}"; then
echo "Error: Could not set the buffersize of the ${SWTPM_INTERFACE} TPM."
exit 1
fi
cat "${OUTFILE}"
if ! grep "TPM buffersize" "${OUTFILE}" | grep -q $((5 * 1024)); then
echo "Error: Could not set the buffersize of the ${SWTPM_INTERFACE} TPM to $((5 * 1024))."
exit 1
fi
# Init the TPM -- must fail
if run_swtpm_ioctl "${SWTPM_INTERFACE}" -i; then
echo "Error: Could initialize the ${SWTPM_INTERFACE} TPM even though buffer is too small for default-v2 profile."
exit 1
fi
printf "INFO: Initialization failed as expected\n\n"
# set the buffer size to 8kb
if ! run_swtpm_ioctl "${SWTPM_INTERFACE}" -b $((8 * 1024)) > "${OUTFILE}"; then
echo "Error: Could not set the buffersize of the ${SWTPM_INTERFACE} TPM."
exit 1
fi
cat "${OUTFILE}"
if ! grep "TPM buffersize" "${OUTFILE}" | grep -q $((8 * 1024)); then
echo "Error: Could not set the buffersize of the ${SWTPM_INTERFACE} TPM to $((8 * 1024))."
exit 1
fi
# Init the TPM -- must NOT fail
if ! run_swtpm_ioctl "${SWTPM_INTERFACE}" -i; then
echo "Error: Could not initialize the ${SWTPM_INTERFACE} TPM even though buffer is 8kb (default-v2 profile)."
exit 1
fi
# Startup the TPM2
RES=$(swtpm_cmd_tx "${SWTPM_INTERFACE}" '\x80\x01\x00\x00\x00\x0c\x00\x00\x01\x44\x00\x00')
exp=' 80 01 00 00 00 0a 00 00 00 00'
if [ "$RES" != "$exp" ]; then
echo "Error: Did not get expected result from TPM2_Startup(SU_Clear)"
echo "expected: $exp"
echo "received: $RES"
exit 1
fi
printf "INFO: Successfully started TPM 2 with 8kb buffer and default-v2 profile"
if ! run_swtpm_ioctl "${SWTPM_INTERFACE}" -s; then
echo "Error: Could not shut down the ${SWTPM_INTERFACE} TPM."
exit 1
fi
if wait_process_gone "${SWTPM_PID}" 4; then
echo "Error: ${SWTPM_INTERFACE} TPM should not be running anymore."
exit 1
fi
printf "Test 2: OK\n\n"
exit 0