Skip to content

auth: use object nameAlg for implicit PCR sessions - #3597

Open
chench246 wants to merge 1 commit into
tpm2-software:masterfrom
chench246:master
Open

chench246 wants to merge 1 commit into
tpm2-software:masterfrom
chench246:master

Conversation

@chench246

@chench246 chench246 commented Jul 21, 2026 •

Copy link
Copy Markdown

Problem

Implicit pcr: authorization creates its policy session before the authorized object is loaded. The session therefore uses the default hash algorithm and fails with TPM_RC_POLICY_FAIL when the object policy uses a non-default nameAlg.

Solution

Defer only implicit pcr: authorization until the object ESYS handle is available, then use the object nameAlg as the policy-session hash. Keep the existing fallback for invalid or non-hash name algorithms.

Other authorization forms are unchanged, including explicitly created sessions passed through session:.

Tests

  • Unit tests for object nameAlg selection and fallback behavior
  • swtpm integration test with a SHA-384 object policy and SHA-256 PCR bank
  • Explicit SHA-384 startauthsession path remains successful
  • Implicit pcr:sha256:... succeeds without a new CLI parameter

@chench246

Copy link
Copy Markdown
Author

Hi maintainers, a gentle ping on this PR. Could someone take a look when you have time? Please let me know if any changes or additional tests are needed. Thanks!

@chench246

Copy link
Copy Markdown
Author

@AndreasFuchsTPM

Copy link
Copy Markdown
Member

If I remember correctly, the session must always use the hash alg defined as nameAlg for the object being accessed.

So instead of getting this from a CLI parameter, it should be retrieved from the object being accessed.

P.S. Sorry it took so long

@chench246 chench246 changed the title auth: support policy session hash in PCR authorization auth: use object nameAlg for implicit PCR sessions Jul 31, 2026
@chench246

Copy link
Copy Markdown
Author

If I remember correctly, the session must always use the hash alg defined as nameAlg for the object being accessed.

So instead of getting this from a CLI parameter, it should be retrieved from the object being accessed.

P.S. Sorry it took so long

Updated the PR to derive the implicit PCR policy session hash from the accessed object's nameAlg, as suggested. The proposed @ CLI syntax has been removed.

The implementation now defers only pcr: authorization until the object ESYS handle is available, then uses the object's nameAlg when creating the implicit policy session. Other authorization forms remain unchanged, including an explicitly created policy session passed through session:.

The GitHub Actions runs are currently waiting for approval. Could you please take another look?

@moritzbuhl moritzbuhl self-assigned this Aug 26, 2026

@moritzbuhl moritzbuhl left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will look into this myself and get this in.

Comment thread lib/object.c Outdated
tool_rc rc = tool_rc_success;
if (do_auth) {
bool defer_pcr_auth = do_auth && !is_restricted_pswd_session && auth &&
!strncmp(auth, "pcr:", sizeof("pcr:") - 1);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PCR_PREFIX and PCR_PREFIX_LEN

Comment thread lib/tpm2_auth_util.c
tool_rc tpm2_auth_util_from_optarg(ESYS_CONTEXT *ectx, const char *password,
tpm2_session **session, bool is_restricted) {

password = password ? password : "";

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this smells

Comment thread lib/tpm2_auth_util.c
const char *password, tpm2_session **session, bool is_restricted,
ESYS_TR auth_handle) {

password = password ? password : "";

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this smells too

Comment thread test/integration/tests/unseal.sh Outdated
tpm2 flushcontext -Q -t

rm $file_unseal_key_pub $file_unseal_key_priv $file_unseal_key_name \
$file_unseal_key_ctx

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

indentation is wrong

Comment thread test/integration/tests/unseal.sh Outdated

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

indentation is wrong here too.

Implicit PCR authorization created its policy session before the
authorization object was loaded, so the session used the default hash
algorithm. Authorization then failed when the object policy used a
non-default nameAlg, although an explicit policy session with the
matching hash worked.

Defer only pcr: authorization until the object ESYS handle is
available, then use the object nameAlg as the implicit policy session
hash. Preserve the existing fallback for an invalid or non-hash
nameAlg. Leave other authorization forms and explicitly created
sessions unchanged.

Add unit coverage for nameAlg selection and fallback behavior, plus
swtpm integration coverage for implicit and explicit PCR authorization.

Signed-off-by: chench246 <chench246@hotmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants