Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
87 changes: 87 additions & 0 deletions .github/workflows/win-swtpm-test.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,87 @@
name: Windows swtpm Transport Test

on:
push:
branches: [ 'master', 'main', 'release/**' ]
pull_request:
branches: [ '*' ]
types: [opened, synchronize, reopened, ready_for_review]
repository_dispatch:
types: [nightly-trigger]

concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

jobs:
# The Visual Studio job in win-test.yml never compiles the socket
# transport, so nothing on Windows exercised it and it had drifted to the
# point of not working at all. The firmware TPM is software, so a runner
# with no TPM can still drive the transport end to end.
swtpm:
if: github.event_name != 'pull_request' || github.event.pull_request.draft == false

runs-on: windows-latest
timeout-minutes: 45

defaults:
run:
shell: msys2 {0}

steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4

- name: Setup MSYS2
uses: msys2/setup-msys2@v2
with:
msystem: MINGW64
update: true
install: git make autoconf automake libtool
pacboy: toolchain:p

- name: Build wolfSSL
run: |
set -e
git clone --quiet --depth 1 -b master \
https://github.com/wolfSSL/wolfssl.git
cd wolfssl
./autogen.sh
# The Windows certificate store is what drags in crypt32 and is not
# wanted here. Winsock is: wolfio really does call recv().
./configure --prefix="$PWD/../wolfssl-inst" --enable-wolftpm \
--enable-pkcallbacks --enable-keygen \
--disable-sys-ca-certs \
CFLAGS="-DWC_RSA_NO_PADDING" LIBS="-lws2_32"
make
make install

- name: Build wolfTPM
run: |
set -e
./autogen.sh
./configure --enable-fwtpm --enable-swtpm \
--with-wolfcrypt="$PWD/wolfssl-inst" LIBS="-lws2_32"
# wolfTPM's own unit tests use POSIX setenv, which MinGW does not
# have, so a bare `make` stops before reaching these.
make src/fwtpm/fwtpm_server.exe examples/wrap/caps.exe

- name: Talk to the firmware TPM over the socket transport
run: |
set -e
./src/fwtpm/fwtpm_server.exe --port 2321 --platform-port 2322 \
> fwtpm.log 2>&1 &
sleep 5
cat fwtpm.log
# Reading capabilities needs the whole path to work: the handle has
# to survive being stored, Winsock has to be started, and a command
# has to go out and a response come back. Each of those has been
# broken on Windows.
./examples/wrap/caps.exe | tee caps.log
grep -q "Mfg WOLF" caps.log

- name: Collect logs on failure
if: failure()
run: |
tail -40 fwtpm.log 2>/dev/null || true
tail -40 caps.log 2>/dev/null || true
4 changes: 2 additions & 2 deletions examples/tls/tls_client.c
Original file line number Diff line number Diff line change
Expand Up @@ -169,8 +169,8 @@ int TPM2_TLS_ClientArgs(void* userCtx, int argc, char *argv[])
/* initialize variables */
XMEMSET(&storageKey, 0, sizeof(storageKey));
XMEMSET(&sockIoCtx, 0, sizeof(sockIoCtx));
sockIoCtx.fd = -1;
sockIoCtx.listenFd = -1;
sockIoCtx.fd = SOCKET_INVALID;
sockIoCtx.listenFd = SOCKET_INVALID;
XMEMSET(&tpmCtx, 0, sizeof(tpmCtx));
#ifndef NO_RSA
XMEMSET(&rsaKey, 0, sizeof(rsaKey));
Expand Down
14 changes: 7 additions & 7 deletions examples/tls/tls_common.h
Original file line number Diff line number Diff line change
Expand Up @@ -228,7 +228,7 @@ static inline int SetupSocketAndListen(SockIoCbCtx* sockIoCtx, word32 port)
/* Create a socket that uses an Internet IPv4 address,
* Sets the socket to be stream based (TCP),
* 0 means choose the default protocol. */
if ((sockIoCtx->listenFd = socket(AF_INET, SOCK_STREAM, 0)) == -1) {
if ((sockIoCtx->listenFd = socket(AF_INET, SOCK_STREAM, 0)) == SOCKET_INVALID) {
printf("ERROR: failed to create the socket\n");
return -1;
}
Expand Down Expand Up @@ -270,7 +270,7 @@ static inline int SocketWaitClient(SockIoCbCtx* sockIoCtx)
struct sockaddr_in clientAddr;
XSOCKLENT size = sizeof(clientAddr);

if ((connd = accept(sockIoCtx->listenFd, (struct sockaddr*)&clientAddr, &size)) == -1) {
if ((connd = accept(sockIoCtx->listenFd, (struct sockaddr*)&clientAddr, &size)) == SOCKET_INVALID) {
printf("ERROR: failed to accept the connection\n\n");
return -1;
}
Expand Down Expand Up @@ -307,7 +307,7 @@ static inline int SetupSocketAndConnect(SockIoCbCtx* sockIoCtx, const char* host
/* Create a socket that uses an Internet IPv4 address,
* Sets the socket to be stream based (TCP),
* 0 means choose the default protocol. */
if ((sockIoCtx->fd = socket(AF_INET, SOCK_STREAM, 0)) == -1) {
if ((sockIoCtx->fd = socket(AF_INET, SOCK_STREAM, 0)) == SOCKET_INVALID) {
printf("ERROR: failed to create the socket\n");
return -1;
}
Expand Down Expand Up @@ -350,13 +350,13 @@ static inline int SocketWaitData(SockIoCbCtx* sockIoCtx, int timeout_sec)

static inline void CloseAndCleanupSocket(SockIoCbCtx* sockIoCtx)
{
if (sockIoCtx->fd != -1) {
if (sockIoCtx->fd != SOCKET_INVALID) {
CloseSocket(sockIoCtx->fd);
sockIoCtx->fd = -1;
sockIoCtx->fd = SOCKET_INVALID;
}
if (sockIoCtx->listenFd != -1) {
if (sockIoCtx->listenFd != SOCKET_INVALID) {
CloseSocket(sockIoCtx->listenFd);
sockIoCtx->listenFd = -1;
sockIoCtx->listenFd = SOCKET_INVALID;
}
}
#else
Expand Down
4 changes: 2 additions & 2 deletions examples/tls/tls_server.c
Original file line number Diff line number Diff line change
Expand Up @@ -202,8 +202,8 @@ int TPM2_TLS_ServerArgs(void* userCtx, int argc, char *argv[])
/* initialize variables */
XMEMSET(&storageKey, 0, sizeof(storageKey));
XMEMSET(&sockIoCtx, 0, sizeof(sockIoCtx));
sockIoCtx.fd = -1;
sockIoCtx.listenFd = -1;
sockIoCtx.fd = SOCKET_INVALID;
sockIoCtx.listenFd = SOCKET_INVALID;
XMEMSET(&tpmCtx, 0, sizeof(tpmCtx));
#ifndef NO_RSA
XMEMSET(&rsaKey, 0, sizeof(rsaKey));
Expand Down
14 changes: 8 additions & 6 deletions src/fwtpm/fwtpm_io.c
Original file line number Diff line number Diff line change
Expand Up @@ -219,7 +219,7 @@ static int BuildErrorResponse(byte* rspBuf, UINT16 tag, TPM_RC rc)
}

/* --- Platform port handler --- */
static int HandlePlatformCommand(FWTPM_CTX* ctx, int clientFd)
static int HandlePlatformCommand(FWTPM_CTX* ctx, SOCKET_T clientFd)
{
int rc;
UINT32 cmd;
Expand Down Expand Up @@ -319,7 +319,7 @@ static int HandlePlatformCommand(FWTPM_CTX* ctx, int clientFd)
}

/* --- Handle mssim signal on command port --- */
static int HandleMssimSignal(FWTPM_CTX* ctx, int clientFd, UINT32 tssCmd)
static int HandleMssimSignal(FWTPM_CTX* ctx, SOCKET_T clientFd, UINT32 tssCmd)
{
UINT32 netVal;
/* State-mutating signals (POWER_OFF/RESET) are rejected before reaching
Expand All @@ -335,7 +335,7 @@ static int HandleMssimSignal(FWTPM_CTX* ctx, int clientFd, UINT32 tssCmd)

/* --- Process and send TPM command response --- */
static int DispatchAndRespond(FWTPM_CTX* ctx, UINT32 cmdSize, int locality,
int clientFd, int isSwtpm)
SOCKET_T clientFd, int isSwtpm)
{
int rc;
int rspSize = 0;
Expand Down Expand Up @@ -445,7 +445,7 @@ static int IsMssimSignal(UINT32 cmd)
/* --- Command port handler (auto-detects mssim vs swtpm protocol) ---
* mssim: first 4 bytes are a small protocol command (1-21)
* swtpm: first 4 bytes are raw TPM header (tag 0x8001/0x8002 + size) */
static int HandleCommandConnection(FWTPM_CTX* ctx, int clientFd)
static int HandleCommandConnection(FWTPM_CTX* ctx, SOCKET_T clientFd)
{
int rc;
UINT32 firstWord;
Expand Down Expand Up @@ -670,7 +670,7 @@ int FWTPM_IO_ServerLoop(FWTPM_CTX* ctx)
#ifndef WOLFTPM_FWTPM_TIS
int rc = TPM_RC_SUCCESS;
fd_set readFds;
int maxFd;
SOCKET_T maxFd;
SOCKET_T cmdFds[FWTPM_MAX_COMMAND_CLIENTS];
SOCKET_T platFd = FWTPM_INVALID_FD; /* active platform client fd */
struct timeval tv;
Expand Down Expand Up @@ -737,7 +737,9 @@ int FWTPM_IO_ServerLoop(FWTPM_CTX* ctx)

tv.tv_sec = 30;
tv.tv_usec = 0;
selRc = select(maxFd + 1, &readFds, NULL, NULL, &tv);
/* Windows ignores the first argument and its SOCKET does not fit an
* int; everywhere else it is the descriptor bound and does. */
selRc = select((int)(maxFd + 1), &readFds, NULL, NULL, &tv);
if (selRc < 0) {
#ifdef _WIN32
if (WSAGetLastError() == WSAEINTR) continue;
Expand Down
Loading
Loading