[tpm2] Making porting ESAPI/SAPI to constrained environments easier
Roberts, William C <william.c.roberts at intel.com> Wed, 08 Jun 2022 18:25:51 +0000
| Newsgroups | dev.linux.lists.tpm2 |
|---|---|
| Message-ID | <SN6PR11MB343760C742C8E92EC5404955B8A49@SN6PR11MB3437.namprd11.prod.outlook.com> |
Hi folks, I have been working on some commits to make SAPI and ESAPI easier to port to constrained environments. The first is run-time settable crypto backend for ESAPI. You can remove any linker dependencies and set your own crypto for whatever that env needs. - https://github.com/tpm2-software/tpm2-tss/pull/2365 The next is build time selectable functionality ala kconfig. You just tell it was SYS/ESYS commands you want, and it knows what to generate: - https://github.com/tpm2-software/tpm2-tss/pull/2369 That commit is pretty early still, but for instance if you enable an Esys function it knows you need W Esys_ functions, X sTSS2_Sys_ functions and Y TSS2_MU_ functions and sets up defines for them. I still need to "ifdef" ESAPI and MU, but SAPI is all done. The configuration engine takes a YAML file of a list of functions and uses ctags/cflow to analyze the source for leaf dependencies. I'd love comments. Thanks, Bill
attachment.htm
(text/html, 4.5 KB)
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
Hi folks,<br>
<br>
I have been working on some commits to make SAPI and ESAPI easier to port to constrained environments.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
<br>
The first is run-time settable crypto backend for ESAPI. You can remove any linker dependencies and set your own crypto</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
for whatever that env needs.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
- <a href="https://github.com/tpm2-software/tpm2-tss/pull/2365" id="LPNoLPOWALinkPreview">https://github.com/tpm2-software/tpm2-tss/pull/2365</a></div>
<div class="_Entity _EType_OWALinkPreview _EId_OWALinkPreview _EReadonly_1"></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
The next is build time selectable functionality ala kconfig. You just tell it was SYS/ESYS commands you want, and it knows what to generate:<br>
- <a href="https://github.com/tpm2-software/tpm2-tss/pull/2369" id="LPNoLPOWALinkPreview_1">https://github.com/tpm2-software/tpm2-tss/pull/2369</a>
<div class="_Entity _EType_OWALinkPreview _EId_OWALinkPreview_1 _EReadonly_1"></div>
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
<span style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;">That commit is pretty early still, but for instance if you enable an Esys function it knows you need W Esys_ functions, X sTSS2_Sys_ functions and Y TSS2_MU_
functions and sets up defines for them. I still need to "ifdef" ESAPI and MU, but SAPI is all done.</span><br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
<span style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;"><br>
</span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
<span style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;">The configuration engine takes a YAML file of a list of functions and uses ctags/cflow to analyze the source for leaf dependencies.</span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
<span style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;"><br>
</span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
<span style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;">I'd love comments.</span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
<span style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;"><br>
</span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
<span style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;">Thanks,</span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
<span style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;">Bill</span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
<span style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;"><br>
</span></div>
</body>
</html>