[PATCH 2/3][SRU][E] efi/tpm: don't traverse an event log with no events

Seth Forshee seth.forshee at canonical.com
Sat Sep 28 15:46:57 UTC 2019

From: Peter Jones <pjones at redhat.com>

BugLink: https://bugs.launchpad.net/bugs/1845454

When there are no entries to put into the final event log, some machines
will return the template they would have populated anyway.  In this case
the nr_events field is 0, but the rest of the log is just garbage.

This patch stops us from trying to iterate the table with
__calc_tpm2_event_size() when the number of events in the table is 0.

Fixes: c46f3405692d ("tpm: Reserve the TPM final events table")
Cc: linux-efi at vger.kernel.org
Cc: linux-integrity at vger.kernel.org
Cc: stable at vger.kernel.org
Signed-off-by: Peter Jones <pjones at redhat.com>
Tested-by: Lyude Paul <lyude at redhat.com>
Reviewed-by: Jarkko Sakkinen <jarkko.sakkinen at linux.intel.com>
Acked-by: Matthew Garrett <mjg59 at google.com>
Acked-by: Ard Biesheuvel <ard.biesheuvel at linaro.org>
Signed-off-by: Jarkko Sakkinen <jarkko.sakkinen at linux.intel.com>
Signed-off-by: Ard Biesheuvel <ard.biesheuvel at linaro.org>
(cherry picked from commit 1f112c0544b1a6bb49bbf4f7457a7d4bb0d304b6
Signed-off-by: Seth Forshee <seth.forshee at canonical.com>
 drivers/firmware/efi/tpm.c | 15 ++++++++++-----
 1 file changed, 10 insertions(+), 5 deletions(-)

diff --git a/drivers/firmware/efi/tpm.c b/drivers/firmware/efi/tpm.c
index 1d3f5ca3eaaf..b9ae5c6f9b9c 100644
--- a/drivers/firmware/efi/tpm.c
+++ b/drivers/firmware/efi/tpm.c
@@ -75,11 +75,16 @@ int __init efi_tpm_eventlog_init(void)
 		goto out;
-	tbl_size = tpm2_calc_event_log_size((void *)efi.tpm_final_log
-					    + sizeof(final_tbl->version)
-					    + sizeof(final_tbl->nr_events),
-					    final_tbl->nr_events,
-					    log_tbl->log);
+	tbl_size = 0;
+	if (final_tbl->nr_events != 0) {
+		void *events = (void *)efi.tpm_final_log
+				+ sizeof(final_tbl->version)
+				+ sizeof(final_tbl->nr_events);
+		tbl_size = tpm2_calc_event_log_size(events,
+						    final_tbl->nr_events,
+						    log_tbl->log);
+	}
 	memblock_reserve((unsigned long)final_tbl,
 			 tbl_size + sizeof(*final_tbl));
 	early_memunmap(final_tbl, sizeof(*final_tbl));

More information about the kernel-team mailing list