Make wolfTPM's SPDM core the wolfSPDM stack, with the standard requester and PQC on top - #34
Open
aidangarske wants to merge 27 commits into
Open
aidangarske wants to merge 27 commits into
aidangarske wants to merge 27 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
wolfSPDM and wolfTPM's
src/spdmhad diverged into two SPDM stacks. This branch makes wolfTPM's core, the one that is maintained, reviewed and validated on silicon, into wolfSPDM. The standard DMTF requester features frommainare then ported onto it behind compile-time switches.What you get:
WOLFSPDM_PROFILE_TPMbuilds exactly what wolfTPM needs. The context is about 9.5 KB and no standard-requester symbols are exported.A later wolfTPM PR replaces its
src/spdmwithlib/wolfSPDMas a submodule.Closes #10.
Layout
cdd1221imports wolfTPM's core as of wolfTPM0f639565. It is one mechanical commit, with renames only.Each commit after that ports one
mainfeature, or fixes something found in review.Standalone builds turn every feature on. You can turn features off with:
WOLFSPDM_NO_CERT,NO_MEAS,NO_CHALLENGE,NO_HEARTBEAT,NO_KEY_UPDATE,NO_CHUNK,NO_APP_DATA,NO_MLDSA,NO_MLKEM,LEAN--disable-mldsa,--disable-mlkem,--disable-app-dataML-DSA and ML-KEM follow wolfSSL's
WOLFSSL_HAVE_MLDSAandWOLFSSL_HAVE_MLKEM.PQC
wolfSPDM_SetKeyExchangePrefwolfSPDM_SetRequesterSessionIdwolfSPDM_GetVersion_NegotiatedwolfSPDM_ValidateCertChainAPI and ABI changes vs
mainWOLFSPDM_E_MEAS_NOT_VERIFIED→E_MEASUREMENTWOLFSPDM_E_MEAS_SIG_FAIL→E_BAD_SIGNATUREWOLFSPDM_E_MEAS_NOT_VERIFIEDstill compiles but is never returned (-1000): it used to be a soft success, and aliasing it to a real error would let oldrc != E_MEAS_NOT_VERIFIEDchecks accept malformed responses.WOLFSPDM_E_MEAS_SIG_FAILstays as an alias ofE_BAD_SIGNATURE.libwolfspdmnow sets-version-info 1:0:0, so the shared library soname marks the ABI change.rxSzis the buffer size on input and the received size on output, and must never exceed the buffer size.SendDatacalls the callback send-only:rxBufNULL and*rxSz0.ReceiveDatacalls it receive-only:txBufNULL andtxSz0.SendData/ReceiveDatamessage starts with its own MCTP message type (for example 0x01 for PLDM, never 0x05). An SPDM ERROR received in place of data returnsWOLFSPDM_E_PEER_ERROR.GetMeasurementBlock. It accepts NULL output buffers and reports the size it needs withWOLFSPDM_E_BUFFER_SMALL.wolfSPDM_KeyExchangerefuses to send without a trusted responder key (ValidateCertChainorSetResponderPubKeyfirst).wolfSPDM_Finishruns only in the KEY_EX state.wolfSPDM_SecuredExchangeaccepts handshake-state requests only for the TCG binding (GIVE_PUB).wolfspdm/options.hunless the library itself is being built (BUILDING_WOLFSPDM), so an application with its ownconfig.hstill sees the right feature switches.WOLFSPDM_DEBUGbuilds;wolfSPDM_SetDebugdoes nothing otherwise.NO_WOLFSPDM_MEASandNO_WOLFSPDM_CHALLENGEstill work; they map toWOLFSPDM_NO_MEASandWOLFSPDM_NO_CHALLENGE.WOLFSPDM_CTX_STATIC_SIZEdepends on the build:WOLFSPDM_CTX_STATIC_SIZEMeasured
sizeofon arm64 is about 19 KB, 24 KB and 59 KB respectively.Security fixes found in review
These were found in security review of the branch. Several are also present in wolfTPM
mastertoday, and wolfTPM picks them up with the submodule switch.Requester
Responder
Known limitation, documented in
spdm_responder.h: the responder does not authenticate the requester. GIVE_PUB is recorded but not verified.Review findings not taken
WOLFSPDM_PROFILE_TPM.test_spdm.cremovedspdm_demoand the spdm-emu CI.constParameterCallbacksuppressionstrlen(and, on the next pass, should not)WOLFSPDM_IO_CB; listed under API changes above.spdm_types.h(unusedSPDM_CAP_*, measurement value types, socket constants)Testing
CI. All workflows are green:
Local. A strict build matrix of 27 configurations passes, covering:
Lab.
master0f63956with this wolfSPDM (14 configs)Not tested here. The Nuvoton NPCT75x and Nations NS350 silicon bench runs before the wolfTPM switch-over PR, not before this PR.
Follow-ups tracked as issues
WOLFSPDM_LOCAL, Add a CMake build for wolfSPDM and SPDM support in wolfTPM CMake and Zephyr #27 CMake and Zephyr, Update wolfTPM packaging for the wolfSPDM submodule #28 wolfTPM packaging--get-pubkey, Print wolfSPDM error names in spdm_ctrl instead of unknown error number #20 error names, Skip the SPDM session info check on TPMs that reject the capability #21 session info capability