From patchwork Sun May 14 07:23:46 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Kuppuswamy Sathyanarayanan X-Patchwork-Id: 93652 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:a59:b0ea:0:b0:3b6:4342:cba0 with SMTP id b10csp6170878vqo; Sun, 14 May 2023 00:48:23 -0700 (PDT) X-Google-Smtp-Source: ACHHUZ7dvKOhnQdGQIrpHEpWTviVOMaV/wdwWKb1CXff+3eIG9BnsozsVjN7oBpvwBWFv4a0MC3d X-Received: by 2002:a17:902:ecc3:b0:1aa:f818:7a24 with SMTP id a3-20020a170902ecc300b001aaf8187a24mr39125286plh.1.1684050503437; Sun, 14 May 2023 00:48:23 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1684050503; cv=none; d=google.com; s=arc-20160816; b=TC6/LRUT4VSE+hpbgl4D4Vo86flaZNE+7QUNy65sXP66QFteAXjZ/yDBQlQdziivE6 rC243W9qoOAmgO3l14hTKemBE6wE0SnE1fnAksoyzs8lwwyJAf+/FBd910dWXzbOvezf 41EC/rmUhBjCaF/NBYxgomRTCdDG3LH6yYTZ0Tc3/S+buXQOABUKtSwrrxZgTQZUK4ij 2u2q2rthUudmAtZOf+RLv1qokYtWTSmbQEXom31ZxV0VxPezVg6ymfe07xj+0YdUBvSU A9xJDlkUXOEnA3yh4auDCbkUsFa9a8ViWmhYqLXHrawDctJPYDQlzPDg9U65mEdSoK6y kxHA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :dkim-signature; bh=15XeGeRWnoq8+Obi4Ut4R1g9u+nLh2dX8WlbBFucTqg=; b=WzQmQ5+Flb6Xu2TXNtmwE9u8w/qGattPHXf80QzCNqM0DSFZgjihnB4Yfysze5d+6v lHUl2x1bqPFL1lmWOsS4ARw/GrjKoJnihrexRi3pHwEVQPSEUYAsehzTbnfKqFcC21gI ZhjMu1FqqVTxdT0H0mhc/ZYNWwmWt5yc+p98O2lT4L70huqfxWp7w4qnWfWTJi38mbQF VbcfLMtysATbM/DnpwN3X9mEN4DsLZpYU3X0VQs0AE6codOW+cX8M8ePSfwVe4xcOHJt FJToO5AGkRmGCOxX/mHT0eaXAsmXW4fiL2HK8em2bui/fS1PARO0srY3C48MJu5SAOov 22eg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@intel.com header.s=Intel header.b=h9v+sgHC; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=intel.com Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id h8-20020a170902680800b001ab06ae9edfsi12162018plk.551.2023.05.14.00.48.00; Sun, 14 May 2023 00:48:23 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@intel.com header.s=Intel header.b=h9v+sgHC; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=intel.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231916AbjENHYP (ORCPT + 99 others); Sun, 14 May 2023 03:24:15 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:50706 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S230153AbjENHYF (ORCPT ); Sun, 14 May 2023 03:24:05 -0400 Received: from mga03.intel.com (mga03.intel.com [134.134.136.65]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 9A57A19A6; Sun, 14 May 2023 00:24:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1684049043; x=1715585043; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=It7+hrDdGgiW/UhfIn901YFgwWvU46GKYQaeQEUbiLs=; b=h9v+sgHChp1Bx4TwGddAecbs07iEyColAND8XBl2OB48g+hI8JMyOCLU yNaliiPNpJ+1OSqLqgLpVNo0SokOJ/AIeXASiLV6iSBMLlpiLoYNukYqn Djjmb9uKc1Y+Tcu00XHHfeEQHFYJqvc+ytV/91wO2dzLobIjsDgbJIMV5 GQdzqey0yfGZTTUcHC8rWInDddg7QHBAc7izmedZZOxc+CMhMTcdxTLuY gYabF8MxiaZ1tELqH1oek5UTCFUPUG8nKapNarnKEGCVwCm5ihdFMz3T3 NfrURUe3TGWrna5LCj2ulbs5RpVFLh3gSgwZKwO0rRS2vT9qek6zgk9I2 g==; X-IronPort-AV: E=McAfee;i="6600,9927,10709"; a="354167306" X-IronPort-AV: E=Sophos;i="5.99,273,1677571200"; d="scan'208";a="354167306" Received: from orsmga008.jf.intel.com ([10.7.209.65]) by orsmga103.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 14 May 2023 00:24:01 -0700 X-ExtLoop1: 1 X-IronPort-AV: E=McAfee;i="6600,9927,10709"; a="731262953" X-IronPort-AV: E=Sophos;i="5.99,273,1677571200"; d="scan'208";a="731262953" Received: from mply-mobl1.amr.corp.intel.com (HELO skuppusw-desk1.amr.corp.intel.com) ([10.212.130.17]) by orsmga008-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 14 May 2023 00:24:01 -0700 From: Kuppuswamy Sathyanarayanan To: Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, Shuah Khan , Jonathan Corbet Cc: "H . Peter Anvin" , Kuppuswamy Sathyanarayanan , "Kirill A . Shutemov" , Tony Luck , Wander Lairson Costa , Erdem Aktas , Dionna Amalie Glaze , Chong Cai , Qinkun Bao , Guorui Yu , Du Fan , linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, linux-doc@vger.kernel.org Subject: [PATCH v3 3/3] selftests/tdx: Test GetQuote TDX attestation feature Date: Sun, 14 May 2023 00:23:46 -0700 Message-Id: <972e1d5c5ec53e2757fb17a586558c5385e987dd.1684048511.git.sathyanarayanan.kuppuswamy@linux.intel.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Status: No, score=-4.3 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_EF,RCVD_IN_DNSWL_MED,SPF_HELO_NONE, SPF_NONE,T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= X-GMAIL-THRID: =?utf-8?q?1765854940525387492?= X-GMAIL-MSGID: =?utf-8?q?1765854940525387492?= In TDX guest, the second stage of the attestation process is Quote generation. This process is required to convert the locally generated TDREPORT into a remotely verifiable Quote. It involves sending the TDREPORT data to a Quoting Enclave (QE) which will verify the integrity of the TDREPORT and sign it with an attestation key. Intel's TDX attestation driver exposes TDX_CMD_GET_QUOTE IOCTL to allow the user agent to get the TD Quote. Add a kernel selftest module to verify the Quote generation feature. TD Quote generation involves following steps: * Get the TDREPORT data using TDX_CMD_GET_REPORT IOCTL. * Embed the TDREPORT data in quote buffer and request for quote generation via TDX_CMD_GET_QUOTE IOCTL request. * Upon completion of the GetQuote request, check for non zero value in the status field of Quote header to make sure the generated quote is valid. Reviewed-by: Tony Luck Reviewed-by: Andi Kleen Reviewed-by: Shuah Khan Reviewed-by: Mika Westerberg Reviewed-by: Erdem Aktas Acked-by: Kirill A. Shutemov Signed-off-by: Kuppuswamy Sathyanarayanan --- Changes since v2: * Adapted to struct tdx_quote_hdr -> struct tdx_quote_buf rename. tools/testing/selftests/tdx/tdx_guest_test.c | 65 ++++++++++++++++++-- 1 file changed, 59 insertions(+), 6 deletions(-) diff --git a/tools/testing/selftests/tdx/tdx_guest_test.c b/tools/testing/selftests/tdx/tdx_guest_test.c index 81d8cb88ea1a..0b4b4293b9cb 100644 --- a/tools/testing/selftests/tdx/tdx_guest_test.c +++ b/tools/testing/selftests/tdx/tdx_guest_test.c @@ -18,6 +18,7 @@ #define TDX_GUEST_DEVNAME "/dev/tdx_guest" #define HEX_DUMP_SIZE 8 #define DEBUG 0 +#define QUOTE_SIZE 8192 /** * struct tdreport_type - Type header of TDREPORT_STRUCT. @@ -128,21 +129,29 @@ static void print_array_hex(const char *title, const char *prefix_str, printf("\n"); } +/* Helper function to get TDREPORT */ +long get_tdreport0(int devfd, struct tdx_report_req *req) +{ + int i; + + /* Generate sample report data */ + for (i = 0; i < TDX_REPORTDATA_LEN; i++) + req->reportdata[i] = i; + + return ioctl(devfd, TDX_CMD_GET_REPORT0, req); +} + TEST(verify_report) { struct tdx_report_req req; struct tdreport *tdreport; - int devfd, i; + int devfd; devfd = open(TDX_GUEST_DEVNAME, O_RDWR | O_SYNC); ASSERT_LT(0, devfd); - /* Generate sample report data */ - for (i = 0; i < TDX_REPORTDATA_LEN; i++) - req.reportdata[i] = i; - /* Get TDREPORT */ - ASSERT_EQ(0, ioctl(devfd, TDX_CMD_GET_REPORT0, &req)); + ASSERT_EQ(0, get_tdreport0(devfd, &req)); if (DEBUG) { print_array_hex("\n\t\tTDX report data\n", "", @@ -160,4 +169,48 @@ TEST(verify_report) ASSERT_EQ(0, close(devfd)); } +TEST(verify_quote) +{ + struct tdx_quote_buf *quote_buf; + struct tdx_report_req rep_req; + struct tdx_quote_req req; + __u64 quote_buf_size; + int devfd; + + /* Open attestation device */ + devfd = open(TDX_GUEST_DEVNAME, O_RDWR | O_SYNC); + + ASSERT_LT(0, devfd); + + /* Add size for quote header */ + quote_buf_size = sizeof(*quote_buf) + QUOTE_SIZE; + + /* Allocate quote buffer */ + quote_buf = (struct tdx_quote_buf *)malloc(quote_buf_size); + ASSERT_NE(NULL, quote_buf); + + /* Initialize GetQuote header */ + quote_buf->version = 1; + quote_buf->status = GET_QUOTE_SUCCESS; + quote_buf->in_len = TDX_REPORT_LEN; + quote_buf->out_len = 0; + + /* Get TDREPORT data */ + ASSERT_EQ(0, get_tdreport0(devfd, &rep_req)); + + /* Fill GetQuote request */ + memcpy(quote_buf->data, rep_req.tdreport, TDX_REPORT_LEN); + req.buf = (__u64)quote_buf; + req.len = quote_buf_size; + + ASSERT_EQ(0, ioctl(devfd, TDX_CMD_GET_QUOTE, &req)); + + /* Check whether GetQuote request is successful */ + EXPECT_EQ(0, quote_buf->status); + + free(quote_buf); + + ASSERT_EQ(0, close(devfd)); +} + TEST_HARNESS_MAIN