xref: /aosp_15_r20/external/vboot_reference/tests/vb2_secdata_kernel_tests.c (revision 8617a60d3594060b7ecbd21bc622a7c14f3cf2bc)
1 /* Copyright 2015 The ChromiumOS Authors
2  * Use of this source code is governed by a BSD-style license that can be
3  * found in the LICENSE file.
4  *
5  * Tests for kernel secure storage library.
6  */
7 
8 #include "2api.h"
9 #include "2common.h"
10 #include "2crc8.h"
11 #include "2misc.h"
12 #include "2secdata.h"
13 #include "2secdata_struct.h"
14 #include "2sysincludes.h"
15 #include "common/tests.h"
16 
17 static uint8_t workbuf[VB2_FIRMWARE_WORKBUF_RECOMMENDED_SIZE]
18 	__attribute__((aligned(VB2_WORKBUF_ALIGN)));
19 static struct vb2_context *ctx;
20 static struct vb2_shared_data *sd;
21 static struct vb2_secdata_kernel_v0 *sec02;
22 static struct vb2_secdata_kernel_v1 *sec10;
23 
reset_common_data(void)24 static void reset_common_data(void)
25 {
26 	memset(workbuf, 0xaa, sizeof(workbuf));
27 	TEST_SUCC(vb2api_init(workbuf, sizeof(workbuf), &ctx),
28 		  "vb2api_init failed");
29 
30 	sd = vb2_get_sd(ctx);
31 
32 	/* Most tests assume we have passed fw_phase1() */
33 	sd->status |= VB2_SD_STATUS_RECOVERY_DECIDED;
34 
35 	sec02 = (struct vb2_secdata_kernel_v0 *)ctx->secdata_kernel;
36 	sec10 = (struct vb2_secdata_kernel_v1 *)ctx->secdata_kernel;
37 }
38 
test_init(struct vb2_shared_data * s,int init,const char * why)39 static void test_init(struct vb2_shared_data *s, int init, const char *why)
40 {
41 	if (init)
42 		TEST_NEQ(s->status & VB2_SD_STATUS_SECDATA_KERNEL_INIT, 0, why);
43 	else
44 		TEST_EQ(s->status & VB2_SD_STATUS_SECDATA_KERNEL_INIT, 0, why);
45 }
46 
test_changed(struct vb2_context * c,int changed,const char * why)47 static void test_changed(struct vb2_context *c, int changed, const char *why)
48 {
49 	if (changed)
50 		TEST_NEQ(c->flags & VB2_CONTEXT_SECDATA_KERNEL_CHANGED, 0, why);
51 	else
52 		TEST_EQ(c->flags & VB2_CONTEXT_SECDATA_KERNEL_CHANGED, 0, why);
53 
54 	c->flags &= ~VB2_CONTEXT_SECDATA_KERNEL_CHANGED;
55 }
56 
57 /*
58  * Version-independent tests
59  */
secdata_kernel_test(void)60 static void secdata_kernel_test(void)
61 {
62 	uint8_t size;
63 
64 	reset_common_data();
65 
66 	/* Blank data is invalid */
67 	size = VB2_SECDATA_KERNEL_MIN_SIZE;
68 	memset(&ctx->secdata_kernel, 0xa6, size);
69 	TEST_EQ(vb2api_secdata_kernel_check(ctx, &size),
70 		VB2_ERROR_SECDATA_KERNEL_VERSION, "Check blank bad version");
71 	TEST_EQ(vb2_secdata_kernel_init(ctx),
72 		VB2_ERROR_SECDATA_KERNEL_VERSION, "Init blank bad version");
73 	test_init(sd, 0, "Init set SD status");
74 
75 	/* Ensure zeroed buffers are invalid */
76 	size = VB2_SECDATA_KERNEL_MIN_SIZE;
77 	memset(&ctx->secdata_kernel, 0, size);
78 	TEST_EQ(vb2api_secdata_kernel_check(ctx, &size),
79 		VB2_ERROR_SECDATA_KERNEL_VERSION, "Check zero bad version");
80 	TEST_EQ(vb2_secdata_kernel_init(ctx),
81 		VB2_ERROR_SECDATA_KERNEL_VERSION, "Init zero incomplete");
82 	test_init(sd, 0, "Init set SD status");
83 
84 	/* Read data less than minimum size */
85 	size = VB2_SECDATA_KERNEL_MIN_SIZE - 1;
86 	TEST_EQ(vb2api_secdata_kernel_check(ctx, &size),
87 		VB2_ERROR_SECDATA_KERNEL_INCOMPLETE, "Check incomplete");
88 	TEST_EQ(size, VB2_SECDATA_KERNEL_MIN_SIZE, "Return minimum size");
89 }
90 
secdata_kernel_test_v10(void)91 static void secdata_kernel_test_v10(void)
92 {
93 	uint8_t size;
94 
95 	reset_common_data();
96 
97 	/* Create good data */
98 	size = VB2_SECDATA_KERNEL_SIZE_V10;
99 	TEST_EQ(vb2api_secdata_kernel_create(ctx),
100 		VB2_SECDATA_KERNEL_SIZE_V10, "Create v1.0");
101 	TEST_SUCC(vb2api_secdata_kernel_check(ctx, &size), "Check created CRC");
102 	TEST_SUCC(vb2_secdata_kernel_init(ctx), "Init created CRC");
103 	test_init(sd, 1, "Init set SD status");
104 	test_changed(ctx, 1, "Create changes data");
105 
106 	/* Check excessive data */
107 	size = VB2_SECDATA_KERNEL_SIZE_V10 + 1;
108 	TEST_SUCC(vb2api_secdata_kernel_check(ctx, &size),
109 		  "Check large v1.0 data");
110 	TEST_EQ(size, VB2_SECDATA_KERNEL_SIZE_V10, "Return expected size");
111 
112 	/* Check incomplete data */
113 	size = VB2_SECDATA_KERNEL_SIZE_V10 - 1;
114 	vb2api_secdata_kernel_create(ctx);
115 	TEST_EQ(vb2api_secdata_kernel_check(ctx, &size),
116 		VB2_ERROR_SECDATA_KERNEL_INCOMPLETE, "Check incomplete");
117 	TEST_EQ(size, VB2_SECDATA_KERNEL_SIZE_V10, "Return expected size");
118 
119 	reset_common_data();
120 
121 	/* Bad version */
122 	size = VB2_SECDATA_KERNEL_SIZE_V10;
123 	vb2api_secdata_kernel_create(ctx);
124 	sec10->struct_version -= 1;
125 	TEST_EQ(vb2api_secdata_kernel_check(ctx, &size),
126 		VB2_ERROR_SECDATA_KERNEL_VERSION, "Check invalid version");
127 	TEST_EQ(vb2_secdata_kernel_init(ctx),
128 		VB2_ERROR_SECDATA_KERNEL_VERSION, "Init invalid version");
129 	test_init(sd, 0, "Init set SD status");
130 
131 	/* Higher minor version */
132 	vb2api_secdata_kernel_create(ctx);
133 	sec10->struct_version += 1;
134 	TEST_SUCC(vb2api_secdata_kernel_check(ctx, &size), "Check v1.1 data");
135 	TEST_SUCC(vb2_secdata_kernel_init(ctx), "Init v1.1 data");
136 	test_init(sd, 1, "Init set SD status");
137 
138 	reset_common_data();
139 
140 	/* Higher major version */
141 	vb2api_secdata_kernel_create(ctx);
142 	sec10->struct_version += 0x10;
143 	TEST_EQ(vb2api_secdata_kernel_check(ctx, &size),
144 		VB2_ERROR_SECDATA_KERNEL_VERSION, "Check v2.0 data");
145 	TEST_EQ(vb2_secdata_kernel_init(ctx),
146 		VB2_ERROR_SECDATA_KERNEL_VERSION, "Init v2.0 data");
147 	test_init(sd, 0, "Init set SD status");
148 
149 	reset_common_data();
150 
151 	/* Corrupt data */
152 	size = VB2_SECDATA_KERNEL_SIZE_V10;
153 	vb2api_secdata_kernel_create(ctx);
154 	sec10->kernel_versions++;
155 	TEST_EQ(vb2api_secdata_kernel_check(ctx, &size),
156 		VB2_ERROR_SECDATA_KERNEL_CRC, "Check invalid CRC");
157 	TEST_EQ(vb2_secdata_kernel_init(ctx),
158 		VB2_ERROR_SECDATA_KERNEL_CRC, "Init invalid CRC");
159 	test_init(sd, 0, "Init set SD status");
160 }
161 
secdata_kernel_test_v02(void)162 static void secdata_kernel_test_v02(void)
163 {
164 	uint8_t size;
165 
166 	reset_common_data();
167 
168 	/* Create good data */
169 	size = VB2_SECDATA_KERNEL_SIZE_V02;
170 	TEST_EQ(vb2api_secdata_kernel_create_v0(ctx), size, "Create v0.2");
171 	TEST_SUCC(vb2api_secdata_kernel_check(ctx, &size), "Check v0.2");
172 	TEST_SUCC(vb2_secdata_kernel_init(ctx), "Init created CRC");
173 	test_init(sd, 1, "Init set SD status");
174 
175 	/* Check excessive data */
176 	size = VB2_SECDATA_KERNEL_SIZE_V02 + 1;
177 	TEST_SUCC(vb2api_secdata_kernel_check(ctx, &size),
178 		  "Check large v0.2 data");
179 	TEST_EQ(size, VB2_SECDATA_KERNEL_SIZE_V02, "Return expected size");
180 
181 	/* Check incomplete data */
182 	size = VB2_SECDATA_KERNEL_SIZE_V02 - 1;
183 	TEST_EQ(vb2api_secdata_kernel_check(ctx, &size),
184 		VB2_ERROR_SECDATA_KERNEL_INCOMPLETE, "Check small v0.2 data");
185 	TEST_EQ(size, VB2_SECDATA_KERNEL_SIZE_V02, "Return expected size");
186 	reset_common_data();
187 
188 	/* Corrupt data */
189 	vb2api_secdata_kernel_create_v0(ctx);
190 	sec02->kernel_versions++;
191 	TEST_EQ(vb2api_secdata_kernel_check(ctx, &size),
192 		VB2_ERROR_SECDATA_KERNEL_CRC, "Check invalid CRC");
193 	TEST_EQ(vb2_secdata_kernel_init(ctx),
194 		VB2_ERROR_SECDATA_KERNEL_CRC, "Init invalid CRC");
195 }
196 
secdata_kernel_access_test_v10(void)197 static void secdata_kernel_access_test_v10(void)
198 {
199 	uint32_t v = 1;
200 	const uint8_t *p;
201 	uint8_t ec_hash[VB2_SHA256_DIGEST_SIZE];
202 
203 	reset_common_data();
204 
205 	/* Read/write versions */
206 	vb2api_secdata_kernel_create(ctx);
207 	vb2_secdata_kernel_init(ctx);
208 	ctx->flags = 0;
209 	v = vb2_secdata_kernel_get(ctx, VB2_SECDATA_KERNEL_VERSIONS);
210 	TEST_EQ(v, 0, "Versions created 0");
211 	test_changed(ctx, 0, "Get doesn't change data");
212 	vb2_secdata_kernel_set(ctx, VB2_SECDATA_KERNEL_VERSIONS, 0x123456ff);
213 	test_changed(ctx, 1, "Set changes data");
214 	vb2_secdata_kernel_set(ctx, VB2_SECDATA_KERNEL_VERSIONS, 0x123456ff);
215 	test_changed(ctx, 0, "Set again doesn't change data");
216 	v = vb2_secdata_kernel_get(ctx, VB2_SECDATA_KERNEL_VERSIONS);
217 	TEST_EQ(v, 0x123456ff, "Versions changed");
218 
219 	/* Read/write flags */
220 	vb2api_secdata_kernel_create(ctx);
221 	vb2_secdata_kernel_init(ctx);
222 	ctx->flags = 0;
223 	v = vb2_secdata_kernel_get(ctx, VB2_SECDATA_KERNEL_FLAGS);
224 	TEST_EQ(v, 0, "Flags created 0");
225 	test_changed(ctx, 0, "Get doesn't change data");
226 	vb2_secdata_kernel_set(ctx, VB2_SECDATA_KERNEL_FLAGS, 0x12);
227 	test_changed(ctx, 1, "Set changes data");
228 	vb2_secdata_kernel_set(ctx, VB2_SECDATA_KERNEL_FLAGS, 0x12);
229 	test_changed(ctx, 0, "Set again doesn't change data");
230 	v = vb2_secdata_kernel_get(ctx, VB2_SECDATA_KERNEL_FLAGS);
231 	TEST_EQ(v, 0x12, "Flags changed");
232 	TEST_ABORT(vb2_secdata_kernel_set(ctx, VB2_SECDATA_KERNEL_FLAGS, 0x100),
233 		   "Bad flags");
234 
235 	/* Invalid field fails */
236 	TEST_ABORT(vb2_secdata_kernel_get(ctx, -1), "Get invalid");
237 	TEST_ABORT(vb2_secdata_kernel_set(ctx, -1, 456), "Set invalid");
238 	test_changed(ctx, 0, "Set invalid field doesn't change data");
239 
240 	/* Read/write uninitialized data fails */
241 	sd->status &= ~VB2_SD_STATUS_SECDATA_KERNEL_INIT;
242 	TEST_ABORT(vb2_secdata_kernel_get(ctx, VB2_SECDATA_KERNEL_VERSIONS),
243 		   "Get uninitialized");
244 	test_changed(ctx, 0, "Get uninitialized doesn't change data");
245 	TEST_ABORT(vb2_secdata_kernel_set(ctx, VB2_SECDATA_KERNEL_VERSIONS,
246 					  0x123456ff),
247 		   "Set uninitialized");
248 	test_changed(ctx, 0, "Set uninitialized doesn't change data");
249 
250 	/* Read/write uninitialized in recovery mode */
251 	ctx->flags |= VB2_CONTEXT_RECOVERY_MODE;
252 	TEST_EQ(vb2_secdata_kernel_get(ctx, VB2_SECDATA_KERNEL_VERSIONS), 0,
253 		"Get uninitialized (recmode)");
254 	test_changed(ctx, 0, "Get uninitialized (recmode) doesn't change data");
255 	vb2_secdata_kernel_set(ctx, VB2_SECDATA_KERNEL_VERSIONS,
256 				 0x123456ff);
257 	test_changed(ctx, 0, "Set uninitialized (recmode) doesn't change data");
258 
259 	/* Read/write early in fw_phase1 */
260 	ctx->flags &= ~VB2_CONTEXT_RECOVERY_MODE;
261 	sd->status &= ~VB2_SD_STATUS_RECOVERY_DECIDED;
262 	TEST_EQ(vb2_secdata_kernel_get(ctx, VB2_SECDATA_KERNEL_VERSIONS), 0,
263 		"Get uninitialized (phase1)");
264 	test_changed(ctx, 0, "Get uninitialized (phase1) doesn't change data");
265 	vb2_secdata_kernel_set(ctx, VB2_SECDATA_KERNEL_VERSIONS,
266 				 0x123456ff);
267 	test_changed(ctx, 0, "Set uninitialized (phase1) doesn't change data");
268 
269 	/* Test EC hash set */
270 	reset_common_data();
271 	vb2api_secdata_kernel_create(ctx);
272 	vb2_secdata_kernel_init(ctx);
273 	memset(ec_hash, 0xaa, sizeof(ec_hash));
274 	vb2_secdata_kernel_set_ec_hash(ctx, ec_hash);
275 	TEST_EQ(memcmp(ec_hash, sec10->ec_hash, sizeof(ec_hash)), 0,
276 		       "Check EC hash");
277 	test_changed(ctx, 1, "Set EC hash changes data");
278 
279 	sec10->struct_version = VB2_SECDATA_KERNEL_VERSION_V02;
280 	TEST_ABORT(vb2_secdata_kernel_set_ec_hash(ctx, ec_hash),
281 		   "Can't set EC hash for v0.2");
282 	test_changed(ctx, 0, "Failing to set EC hash doesn't change data");
283 	sec10->struct_version = VB2_SECDATA_KERNEL_VERSION_V10;
284 
285 	sd->status &= ~VB2_SD_STATUS_SECDATA_KERNEL_INIT;
286 	TEST_ABORT(vb2_secdata_kernel_set_ec_hash(ctx, ec_hash),
287 		   "Can't set EC hash before init");
288 	sd->status |= VB2_SD_STATUS_SECDATA_KERNEL_INIT;
289 
290 	/* Test EC hash get */
291 	p = vb2_secdata_kernel_get_ec_hash(ctx);
292 	TEST_PTR_EQ(p, sec10->ec_hash, "Get EC hash returns pointer");
293 	test_changed(ctx, 0, "Get EC hash doesn't change data");
294 
295 	sec10->struct_version = VB2_SECDATA_KERNEL_VERSION_V02;
296 	TEST_PTR_EQ(vb2_secdata_kernel_get_ec_hash(ctx), NULL,
297 		    "Can't get EC hash for v0.2");
298 	sec10->struct_version = VB2_SECDATA_KERNEL_VERSION_V10;
299 
300 	sd->status &= ~VB2_SD_STATUS_SECDATA_KERNEL_INIT;
301 	TEST_ABORT(vb2_secdata_kernel_get_ec_hash(ctx),
302 		   "Can't get EC hash before init");
303 	sd->status |= VB2_SD_STATUS_SECDATA_KERNEL_INIT;
304 }
305 
secdata_kernel_access_test_v02(void)306 static void secdata_kernel_access_test_v02(void)
307 {
308 	uint32_t v = 1;
309 	reset_common_data();
310 
311 	/* Read/write versions */
312 	vb2api_secdata_kernel_create_v0(ctx);
313 	vb2_secdata_kernel_init(ctx);
314 	ctx->flags = 0;
315 	v = vb2_secdata_kernel_get(ctx, VB2_SECDATA_KERNEL_VERSIONS);
316 	TEST_EQ(v, 0, "Versions created 0");
317 	test_changed(ctx, 0, "Get doesn't change data");
318 	vb2_secdata_kernel_set(ctx, VB2_SECDATA_KERNEL_VERSIONS, 0x123456ff);
319 	test_changed(ctx, 1, "Set changes data");
320 	vb2_secdata_kernel_set(ctx, VB2_SECDATA_KERNEL_VERSIONS, 0x123456ff);
321 	test_changed(ctx, 0, "Set again doesn't change data");
322 	v = vb2_secdata_kernel_get(ctx, VB2_SECDATA_KERNEL_VERSIONS);
323 	TEST_EQ(v, 0x123456ff, "Versions changed");
324 
325 	/* Read/write flags: should be no-op for v0 */
326 	TEST_EQ(vb2_secdata_kernel_get(ctx, VB2_SECDATA_KERNEL_FLAGS), 0,
327 		"Get flags");
328 	vb2_secdata_kernel_set(ctx, VB2_SECDATA_KERNEL_FLAGS, 0x1);
329 	TEST_EQ(vb2_secdata_kernel_get(ctx, VB2_SECDATA_KERNEL_FLAGS), 0,
330 		"Get flags again");
331 
332 	/* Invalid field fails */
333 	TEST_ABORT(vb2_secdata_kernel_get(ctx, -1), "Get invalid");
334 	TEST_ABORT(vb2_secdata_kernel_set(ctx, -1, 456), "Set invalid");
335 	test_changed(ctx, 0, "Set invalid field doesn't change data");
336 
337 	/* Read/write uninitialized data fails */
338 	sd->status &= ~VB2_SD_STATUS_SECDATA_KERNEL_INIT;
339 	TEST_ABORT(vb2_secdata_kernel_get(ctx, VB2_SECDATA_KERNEL_VERSIONS),
340 		   "Get uninitialized");
341 	test_changed(ctx, 0, "Get uninitialized doesn't change data");
342 	TEST_ABORT(vb2_secdata_kernel_set(ctx, VB2_SECDATA_KERNEL_VERSIONS,
343 					  0x123456ff),
344 		   "Set uninitialized");
345 	test_changed(ctx, 0, "Set uninitialized doesn't change data");
346 }
347 
main(int argc,char * argv[])348 int main(int argc, char* argv[])
349 {
350 	secdata_kernel_test();
351 	secdata_kernel_test_v10();
352 	secdata_kernel_test_v02();
353 	secdata_kernel_access_test_v10();
354 	secdata_kernel_access_test_v02();
355 
356 	return gTestSuccess ? 0 : 255;
357 }
358