mini_trunks: add size checks to HmacKeyAppend

BUG=b:197007454
TEST=fuzzer + pinweaver_client selftest

Change-Id: I7c4e5c377d1f5c0092ab8f5dcad3a3b3012f3252
Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform/pinweaver/+/3101711
Tested-by: Andrey Pronin <[email protected]>
Auto-Submit: Andrey Pronin <[email protected]>
Commit-Queue: Yi Chou <[email protected]>
Reviewed-by: Yi Chou <[email protected]>
1 file changed
tree: 3e7b8bfb952f5efc1dcf217ebbd0a1e01374ca9c
  1. eal/
  2. fuzzer/
  3. BUILD
  4. BUILD.gn
  5. DIR_METADATA
  6. LICENSE
  7. OWNERS
  8. pinweaver.c
  9. pinweaver.h
  10. pinweaver_eal.h
  11. pinweaver_types.h
  12. PRESUBMIT.cfg
  13. README.md
README.md

Common PinWeaver Code

This directory contains reference PinWeaver code that can be used across implementation platforms.

It consists of:

  • PinWeaver reference code:
    • pinweaver.h - PinWeaver embedded API definition
    • pinweaver.c - implementation
    • pinweaver_eal.h - API for Environment Abstraction Layer (EAL) used by PinWeaver
      • note that some types used in this API are platform-specific and are defined in eal/**/pinweaver_eal_types.h
    • pinweaver_types.h - header that is shared by PinWeaver implementation and PinWeaver clients that call it through platform-specific interface.
  • Environment Abstraction Layer (EAL) implementations - in eal/ folder
    • eal/cr50 - implementation for cr50
      • pinweaver_eal_types.h - cr50-specific EAL API types
      • pinweaver_eal.c - cr50 implementation of EAL
    • eal/tpm_storage - implementation for platforms that use TPM as PinWeaver data storage
      • pinweaver_eal_types.h - TPM-storage-specific EAL API types
      • pinweaver_eal_tpm.h - additional EAL functions required by TPM storage
      • pinweaver_eal_linux.c - implementation of non-storage EAL methods for Linux case
      • tpm_storage_stubs.c - empty implementation of storage EAL methods
      • tpm_storage.c - implementation of storage EAL methods on top of TSS
      • mini_trunks/ - mini-TSS (TPM client software stack) used by TPM storage implementation
        • created from trunks TSS used by ChromeOS reduced to the minimal required set of TPM commands and ported from C++ to C
        • relies on pinweaver_eal.h + pinweaver_eal_tpm.h EAL methods
        • TSS API is defined in tss.h + *authorization_delegate.h

A platform implementation that uses TPM storage EAL option needs to implement all EAL methods implemented in pinweaver_eal_linux.c (or use it as-is, if Linux compatible).