libcrypta master: SRCREV bump 41f6a791e8..7ed2546ceb
Alina Sbirlea (1):
Align command_buf in TctiSetLocality to ec_request_tpm_control.
Nicholas Noonarby (5):
Install crypto_types.h header
Reorganize libcrypta to separate google3 and native meson.builds
Prepare meson.build for migrating rules relevant to google3 meson.build
fix(havend): include <fmt/ranges.h> for fmt::join
Implement HavendEcCommandService in libcrypta.
gBMC Team (81):
fix(crypta): initialize stack memory in InsertProtoBytes
Fix 12 ClangTidyLegacy findings: * inclusion of forwarding header 'util/task/status_macros.h'; use 'third_party/gloop/util/status/status_macros.h' instead. For more info, see go/clang_tidy/checks/google3-legacy-forwarding-headers (6 times) * inclusion of forwarding header 'base/file_toc.h'; use 'third_party/gloop/base/file_toc.h' instead. For more info, see go/clang_tidy/checks/google3-legacy-forwarding-headers (3 times) * inclusion of forwarding header 'util/random/acmrandom.h'; use 'third_party/gloop/util/random/acmrandom.h' instead. For more info, see go/clang_tidy/checks/google3-legacy-forwarding-headers (2 times) * inclusion of forwarding header 'util/task/status.h'; use 'third_party/gloop/util/status/status.h' instead. For more info, see go/clang_tidy/checks/google3-legacy-forwarding-headers
fix(crypta): Add early bounds checks before std::equal to prevent OOB reads
Remove MBM capping from TPM event log
fix(crypta): Fix authPolicy bypass and stack buffer overflow in SealData
Fix 1 ClangTidyLegacy finding: * inclusion of forwarding header 'util/task/status_macros.h'; use 'third_party/gloop/util/status/status_macros.h' instead. For more info, see go/clang_tidy/checks/google3-legacy-forwarding-headers
Project import generated by Copybara.
Add bounds checking for PCR index in PopulatePcrBanks.
Add a check for minimum TPM response size in Haven TCTI.
Add meson.build and update copybara to export files to a google3 subdirectory.
Implements the build-firmware, build-payload, and inspect logic for the mauv tool.
Update response size in Haven TCTI Receive.
Fix DoS via unregulated vector::resize in TctiTransmit
Fix 3 ClangTidyLegacy findings: * inclusion of forwarding header 'util/task/status_macros.h'; use 'third_party/gloop/util/status/status_macros.h' instead. For more info, see go/clang_tidy/checks/google3-legacy-forwarding-headers (2 times) * inclusion of forwarding header 'util/task/status_builder.h'; use 'third_party/gloop/util/status/status_builder.h' instead. For more info, see go/clang_tidy/checks/google3-legacy-forwarding-headers
Fix uninitialized stack memory leak in DPE client.
Modernize Tpm2ClientBuilder API and add CreateAndAcquire helpers
Change representation for command code of `EC_PRV_CMD_HAVEN_TPM`
Fix 1 ClangTidyLegacy finding: * inclusion of forwarding header 'util/task/status_macros.h'; use 'third_party/gloop/util/status/status_macros.h' instead. For more info, see go/clang_tidy/checks/google3-legacy-forwarding-headers
Fix 1 IncludeCleaner finding: * Used header "security/crypta/tpm/client/tpm2_client_builder.h" is not included directly
Fix TPM transient handle leak in `TpmHandle` move assignment
[Upkeep] Remove obsolete TODOs in crypta_portable_blob_key_fetcher.h
Removed the obsolete TODO.
Add ForwardTpmCommand to the TPM2 Client API
Install all exported headers in libcrypta.
Remove deprecated functions in Tpm2ClientBuilder
Align crypta_export copy.bara.sky transforms with securityd
Add ForwardTpmCommand function to ProdIdV3RotEnv
Fix 1 IncludeCleaner finding: * Used header "third_party/absl/container/flat_hash_map.h" is not included directly
mldsa_perso: Implement loading of ML-DSA public key into flash
Initialize (zeroize) TPM2B structures that are allocated on the stack to avoid leaking information from the stack when the content of the structures is copied to the caller.
Fix DpeStatus ToString formatting in C++ client
Reserve EC_PRV_CMD_UNIQUE_CHIP_ID host command.
Add raw TPM2 marshal/unmarshal helpers to tpm2_marshal.
Migrate legacy util/task/status.h C++ includes to gloop in Crypta.
Add SetLocality to ProdIdV3RotEnvInterface
Implement SetLocality in ProdIdV3RotEnv
[Upkeep] Migrate legacy util/task/status_macros.h C++ includes to gloop in Crypta
Refactor TPM attestation proto and implementation for compatibility
Add DpeClientArbiter to guard DpeClient usage in ProdIdV3RotEnv.
Update platforms/gbmc/crypta_export Copybara config to use standardized external header include paths
Cache DPE leaf public key and certificates in ProdIdV3RotEnv.
Automated g4 rollback of changelist 949674133.
Fix buffer size and alignment in GenVersionedCak.
Update Tpm2ClientBuilder to use GetEcCommandServicePlatformCandidates
Add overload GetOrCreateClient that accepts a list of cache keys
Validate coordinate sizes in PubKeyToTss and return absl::Status.
Update GetOrCreateClient that accepts single key to use overload
Migrate ABSL_ARRAYSIZE() to std::size() where possible
Migrate deprecated HexStringToBytes C++ function calls to Abseil.
Add PerformRtm to Tpm2Client
Rename absl::Cleanup variables in tpm2_client.cc to be more descriptive.
Fix platforms/gbmc/crypta_export Copybara config to rewrite tpm_types proto include
Add ResetDrtmPcrs to ProdIdV3RotEnvInterface
Evict unhealthy TPM clients from the registry.
Fix Copybara transformations in crypta_export for arbiter and haven proto headers
Remediate security findings in TCTI and Marshaling.
Remove Tpm2Client::PcrExtend in favor of PcrEvent
Reorganize and document methods in Tpm2Client.
Improve error messages and debugging context in TPM client and attestation flows.
[Crypta] Document CryptaClient method preconditions.
Remove [REDACTED] BIOS ABI incompatibility warning from DPE error messages.
Fix securityd build.
Enable automatic self-healing in ProdIdV3RotEnv when Tpm2Client becomes unhealthy.
Use more specific TSS2 TCTI return codes in haven_tcti.cc.
Reserve HostCommand enum.
Release TPM lock before acquiring DPE lock in GetProdIdV3Info and CapMbmPcr.
Decouple TPM and DPE lock acquisition in policy calculation and key/sealing flows.
Add RoT-mediated I2C device update session host commands and stubs.
Reserve host command for notify target boot.
Fix 1 IncludeCleaner findings:
Fix field comment for key rotation payload key and hash chunks
Fix 7 ClangTidyReadability findings: * function 'operator[]' has inline specifier but is implicitly inlined. For more info, see go/clang_tidy/checks/readability-redundant-inline-specifier (2 times) * function 'size' has inline specifier but is implicitly inlined. For more info, see go/clang_tidy/checks/readability-redundant-inline-specifier * function 'begin' has inline specifier but is implicitly inlined. For more info, see go/clang_tidy/checks/readability-redundant-inline-specifier * function 'empty' has inline specifier but is implicitly inlined. For more info, see go/clang_tidy/checks/readability-redundant-inline-specifier * function 'end' has inline specifier but is implicitly inlined. For more info, see go/clang_tidy/checks/readability-redundant-inline-specifier * function 'operator==' has inline specifier but is implicitly inlined. For more info, see go/clang_tidy/checks/readability-redundant-inline-specifier
Refactor GetCounterDefiningIfNeeded to use a named struct and improve NV index initialization.
Migrate security::crypta SHA*_lite implementations to DigestView().
Rename NOTIFY_TARGET_BOOT host command to PET_TARGET_WATCHDOG
Propagate EC command errors through Haven TCTI and TPM client layers.
libcrypta: Add Nanopb proto generation and dependencies to exported meson.build
Fix 13 ViewTypeMigrations findings: * This is a change required to migrate proto string accessors to return absl::string_view instead of const std::string&. See go/proto-string-view-accessors-cpp-lsc for more details. (8 times) * This is a change required to migrate function parameters to absl::Span from const std::vector (3 times) * This is a change required to migrate function parameters to absl::string_view from const std::string& (2 times)
Migrate MerkleDamgaard override in security/crypta/tpm to string_view Update
platforms/gbmc/crypta_export: fix header includes and compile 14 Crypta sources into libcrypta.
Automated g4 rollback of changelist 989691908.
Fusion-Link: fusion2 N/A
Tested: N/A
Google-Bug-Id: b/396407868
Change-Id: I3e36ca181483f814581ee14a0dce2bdd3f8ee9e5
Signed-off-by: Jessica Ambrosio <jeambrosio@google.com>
diff --git a/recipes-google/libcrypta/libcrypta_git.bb b/recipes-google/libcrypta/libcrypta_git.bb
index 7190e22..57ed3aa 100644
--- a/recipes-google/libcrypta/libcrypta_git.bb
+++ b/recipes-google/libcrypta/libcrypta_git.bb
@@ -27,7 +27,7 @@
S = "${WORKDIR}/git"
SRC_URI = "git://gbmc-private.googlesource.com/libcrypta;protocol=https;branch=master"
-SRCREV = "41f6a791e8990b7a417214892fde2f77d3a18ea5"
+SRCREV = "7ed2546ceb0e312d072f5166445fe27b35461c59"
# Disable unit tests
PACKAGECONFIG ??= ""