]> git.ipfire.org Git - thirdparty/systemd.git/commit
tpm2: move policy building out of policy session creation 26357/head
authorDan Streetman <ddstreet@ieee.org>
Wed, 7 Dec 2022 16:23:59 +0000 (11:23 -0500)
committerDan Streetman <ddstreet@ieee.org>
Fri, 5 May 2023 22:34:46 +0000 (18:34 -0400)
commit2cd9d57548b0dadd52523df486d33aa4cf7c3b84
tree9bae43346cdb32bb8e7e0af7e67cd1a3629c3b3a
parente976445d035e21afec2f64a7c825be5df1f664a0
tpm2: move policy building out of policy session creation

This retains the use of policy sessions instead of trial sessions
in most cases, based on the code comment that some TPMs do not
implement trial sessions correctly. However, it's likely that the
issue was not the TPMs, but our code's incorrect use of PolicyPCR
inside a trial session; we are not providing expected PCR values
with our call to PolicyPCR inside a trial session, but the spec
indicates that in a trial session, the TPM *may* return error if
the expected PCR value(s) are not provided. That may have been the
source of the original confusion about trial sessions.

More details:
https://github.com/systemd/systemd/pull/26357#pullrequestreview-1409983694

Also, future commits will replace the use of trial sessions with
policy calculations, which avoids the problem entirely.
src/shared/tpm2-util.c