Repository navigation
[keymgr_dpe, sw] Support metadata register in various driver - #31356
rroth-lowrisc wants to merge 5 commits into
Conversation
ba60964 to
fad7df1
Compare
gautschimi
left a comment
There was a problem hiding this comment.
Only minor comments. What is the reason for having two versions of keymgr_dpe.c/h?
fad7df1 to
fd10c1b
Compare
75f56fa to
77f45d8
Compare
gautschimi
left a comment
There was a problem hiding this comment.
Thanks for this PR. Looks mostly good. only minor comments:
- unittests
There are no unit tests, and some new code has no callers.
dif_keymgr_dpe_unittest.cc and silicon_creator/lib/drivers/keymgr_dpe_unittest.cc both exist, but neither gets a test for the new functions.
keymgr_dpe_testutils_check_metadata() and the cryptolib keymgr_dpe_get_metadata() aren't called anywhere in this PR. Is there already a followup PR that uses them? Even if not, it's mostly debug functionality. so probably not required.
- bazel deps
keymgr_dpe_functest may be missing a Bazel dependency. It now includes silicon_creator/lib/manifest.h and manifest_def.h, but the PR doesn't touch sw/device/silicon_creator/lib/drivers/BUILD.
It probably builds because ottf_main pulls in test_framework_manifest_def indirectly.
Adding a direct dependency on //sw/device/silicon_creator/lib:manifest would be cleaner.
- Nit: the types differ between layers.
The DIF uses uint32_t for boot_stage and valid.
The cryptolib uses a bool plus its own enum.
silicon_creator uses its own enum with uint32_t valid.
Could we just define this boot_stage enum once? Aligns with an earlier comment of mine.
I don't fully understand why we have two versions of keymgr_dpe.c/h @nasahlpa is that intended?
Thanks for the review @gautschimi
|
77f45d8 to
8486540
Compare
gautschimi
left a comment
There was a problem hiding this comment.
Cool! Thanks for the additional unittests, clarifications and the enum alignment.
All my comments have been addressed. Approving this PR.
8486540 to
4cf558e
Compare
andrea-caforio
left a comment
There was a problem hiding this comment.
Thanks @rroth-lowrisc. Some questions and remarks from my side.
| ptrdiff_t offset_low = (ptrdiff_t)(KEYMGR_DPE_METADATA_LOW_0_REG_OFFSET + | ||
| slot * sizeof(uint32_t)); | ||
| ptrdiff_t offset_high = (ptrdiff_t)(KEYMGR_DPE_METADATA_HIGH_0_REG_OFFSET + | ||
| slot * sizeof(uint32_t)); | ||
|
|
||
| metadata->max_key_version = | ||
| mmio_region_read32(keymgr_dpe->base_addr, offset_low); |
There was a problem hiding this comment.
Why can't you do it like in the driver function to get the register addresses?
There was a problem hiding this comment.
I removed the intermediate variables offset_low and offset_high. However, the dif doesn't have access to the abs_mmio_read32() function which uses an absolute uint32_t address.
| * Checks that a keymgr_dpe HW slot holds a valid DPE context with the expected | ||
| * maximum key version, boot stage and slot policy. | ||
| */ | ||
| rom_error_t sc_keymgr_dpe_check_metadata( |
There was a problem hiding this comment.
Bit of a redundant function to be honest. If you really need a test then do the verification step by in the test itself.
There was a problem hiding this comment.
This function is actually the main feature. The goal of this feature is to verify if a derivation was properly done by checking all the metadata after the derivation.
IMO it doesn't make sense to implement this function multiple times.
One example for this function can be seen in #31357. I'm verifying if the derivation in the ROM code was successfully (bcf6bca).
…tadata Read the max key version, validity, boot stage and policy of one slot. Signed-off-by: Raphael Roth <rroth@lowrisc.org>
Check that a slot holds a valid DPE context with the expected max key version, boot stage and policy, to confirm a derivation happened. Signed-off-by: Raphael Roth <rroth@lowrisc.org>
Add `sc_keymgr_dpe_get_metadata()` and `sc_keymgr_dpe_check_metadata()`, both hardened against FI on the slot index and the checked fields. Signed-off-by: Raphael Roth <rroth@lowrisc.org>
Verify the DPE context after each advance operation with `sc_keymgr_dpe_boot_stage_check()`. This ensures that the derivation was done correctly. Signed-off-by: Raphael Roth <rroth@lowrisc.org>
Read the max key version, validity, boot stage and policy of one slot. Out-of-range slots return `OTCRYPTO_BAD_ARGS` behind a hardened check. Signed-off-by: Raphael Roth <rroth@lowrisc.org>
4cf558e to
adfbe42
Compare
|
Thanks @andrea-caforio for the review I changed the code accordingly and answered your questions |
andrea-caforio
left a comment
There was a problem hiding this comment.
Thanks @rroth-lowrisc.
This PR introduces the required driver modification for #31228. It implements the read metadata functionality in
silicon_creator/cryptolib/diflibraries. To test the feature thekeymgr_dpe_functestis extended to verify theboot_stageof the derived DPE context.This PR depends on:
Only the last 5 commits are relevant for this PR.