Skip to content

Fix to derive the wrapping key size from the parent public area - #618

Merged
aidangarske merged 1 commit into
wolfSSL:masterfrom
dgarske:sensitive_parent_pub
Oct 1, 2026
Merged

aidangarske merged 1 commit into
wolfSSL:masterfrom
dgarske:sensitive_parent_pub

Conversation

@dgarske

@dgarske dgarske commented Sep 29, 2026

Copy link
Copy Markdown
Member

Found while producing a duplication blob for a TPM that is not present, which is what wolfTPM2_SensitiveToPrivate() is exported for. Two related problems in that function.

1. A parent supplied as a public area alone failed with BAD_FUNC_ARG

SensitiveToPrivate() takes the wrapping symmetric key size from parentKey->handle.symmetric.keyBits.sym. That field is populated when the parent is a key loaded on this TPM, but not when the caller holds only the target's public area, which is exactly the offline wrapping case. symKey.size was then zero and the call failed well downstream inside TPM2_AesCfbEncrypt(), returning a bare BAD_FUNC_ARG that pointed nowhere near the cause.

The public area carries the same symmetric definition, so fall back to it when the handle has none: symDetail.sym for a TPM_ALG_SYMCIPHER parent and asymDetail.symmetric otherwise, which covers both RSA and ECC storage parents.

2. A zero length symmetric key reached the cipher

With symKey.size zero, TPM2_KDFa_ex() returns zero for a zero length request, so the rc == symKey.size check compared equal and the derivation was treated as successful. The sensitive area then went to TPM2_AesCfbEncrypt() with no key at all. That failed, but only because AES rejects a zero length key, not because anything verified one had been derived. Reject symKey.size == 0 explicitly so a wrap cannot proceed without a key.

Testing

make check passes.

Verified with a three phase import flow: export the storage root key public area, wrap a symmetric key offline with the TPM unreachable, then TPM2_Import and TPM2_Load it and confirm the TPM computed HMAC matches one computed in software from the original key. Before this change the offline wrap returned BAD_FUNC_ARG; after it the flow completes.

Run on a TPM 2.0 simulator with an RSA storage parent, and on TPM 2.0 hardware with an ECC storage parent, which exercises the asymDetail.symmetric fallback for both key types.

@dgarske dgarske self-assigned this Sep 29, 2026
Copilot AI balanced review requested due to automatic review settings September 29, 2026 18:17

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.

Copilot review overview

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

This PR fixes offline wrapping in wolfTPM2_SensitiveToPrivate() by deriving the wrapping symmetric key size from the parent public area when the parent handle metadata is absent, and by explicitly rejecting zero-length wrapping keys to avoid reaching the cipher with no key.

Changes:

  • Fallback to parentKey->pub.publicArea.parameters.*.symmetric.keyBits.sym when parentKey->handle.symmetric.keyBits.sym is unset (offline/public-area-only parent).
  • Reject outerWrap operations when the derived symmetric key size is zero.
  • Add a unit test covering public-area-only parent behavior and zero-length key refusal.
File Description
src/​tpm2_wrap.c Adds key-size fallback from parent public area and rejects zero-length outer-wrap keys
tests/​unit_tests.c Adds unit test to exercise offline wrapping with parent public area only and validates failure on missing symmetric key bits

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/tpm2_wrap.c Outdated

@aidangarske aidangarske left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nice

@aidangarske
aidangarske merged commit fe402bd into wolfSSL:master Oct 1, 2026
344 of 357 checks passed
@aidangarske
aidangarske deleted the sensitive_parent_pub branch October 1, 2026 16:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants