From 07ea6c365cf16c850fd342ea431c552dbbae9b93 Mon Sep 17 00:00:00 2001 From: EnumDev Date: Sat, 13 Jun 2026 20:01:28 +0300 Subject: [PATCH] Switch to new package format --- pkg.info => info.yml | 4 +- source.sh => recipe.sh | 3 +- source-files/fix-tests.patch | 82 ++++++++++++++++++++++++++++++++++++ 3 files changed, 87 insertions(+), 2 deletions(-) rename pkg.info => info.yml (92%) rename source.sh => recipe.sh (92%) create mode 100644 source-files/fix-tests.patch diff --git a/pkg.info b/info.yml similarity index 92% rename from pkg.info rename to info.yml index 6dcf5ec..17e89af 100644 --- a/pkg.info +++ b/info.yml @@ -1,9 +1,11 @@ name: swtpm description: Libtpms-based TPM emulator with socket, character device, and Linux CUSE interface version: 0.10.1 -revision: 1 +revision: 2 url: https://github.com/stefanberger/swtpm license: BSD-3-Clause +maintainers: + - enumdev@enumerated.dev architecture: any type: source depends: diff --git a/source.sh b/recipe.sh similarity index 92% rename from source.sh rename to recipe.sh index 20b0066..23bdb3d 100644 --- a/source.sh +++ b/recipe.sh @@ -1,4 +1,4 @@ -# This is the source.sh script. It is executed by BPM in a temporary directory when compiling a source package +# This is the recipe.sh script. It is executed by BPM in a temporary directory when compiling a source package # BPM Expects the source code to be extracted into the automatically created 'source' directory which can be accessed using $BPM_SOURCE # BPM Expects the output files to be present in the automatically created 'output' directory which can be accessed using $BPM_OUTPUT @@ -6,6 +6,7 @@ # This function is used for putting downloaded files to the correct location or applying patches prepare() { cd "$BPM_SOURCE" + patch -Np1 -i "$BPM_WORKDIR"/fix-tests.patch # Remove usage of /usr/bin/env to avoid PATH manipulation attacks sed -i 's/env //' samples/swtpm-create-tpmca samples/swtpm-create-user-config-files.in diff --git a/source-files/fix-tests.patch b/source-files/fix-tests.patch new file mode 100644 index 0000000..ecd610c --- /dev/null +++ b/source-files/fix-tests.patch @@ -0,0 +1,82 @@ +From 4da66c66f92438443e66b67555673c9cb898b0ae Mon Sep 17 00:00:00 2001 +From: Stefan Berger +Date: Mon, 12 May 2025 18:25:48 -0400 +Subject: [PATCH] tests: Retry NVWrite command after 0x922 return code and inc + lockout counter + +When returncode 0x922 is received from NVWrite then retry the command so +that it gets the expected error code from failing to provide a password. +When checking the lockout counter, increase the numbers now. + +Patched versions of libtpms may not return 0x922 anymore, so write the code +that it can test both cases. + +Signed-off-by: Stefan Berger +--- + tests/_test_tpm2_avoid_da_lockout | 22 ++++++++++++++++------ + 1 file changed, 16 insertions(+), 6 deletions(-) + +diff --git a/tests/_test_tpm2_avoid_da_lockout b/tests/_test_tpm2_avoid_da_lockout +index e4f0121a9..fc26a8cf6 100755 +--- a/tests/_test_tpm2_avoid_da_lockout ++++ b/tests/_test_tpm2_avoid_da_lockout +@@ -53,6 +53,11 @@ fi + cmd='\x80\x02\x00\x00\x00\x24\x00\x00\x01\x37\x01\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x09\x40\x00\x00\x09\x00\x00\x00\x00\x00\x00\x01\x41\x00\x00' + RES=$(swtpm_cmd_tx "${SWTPM_INTERFACE}" ${cmd}) + exp=' 80 01 00 00 00 0a 00 00 09 22' ++if [ "$RES" == "$exp" ]; then ++ # 0x922 : retry command ++ RES=$(swtpm_cmd_tx "${SWTPM_INTERFACE}" ${cmd}) ++fi ++exp=' 80 01 00 00 00 0a 00 00 09 8e' + if [ "$RES" != "$exp" ]; then + echo "Error: Did not get expected result from TPM2_NV_Write" + echo "expected: $exp" +@@ -63,9 +68,9 @@ fi + # The TPM_PT_LOCKOUT_COUNTER must be 0 now: tssgetcapability -cap 6 -pr 0x20e -pc 1 + cmd='\x80\x01\x00\x00\x00\x16\x00\x00\x01\x7a\x00\x00\x00\x06\x00\x00\x02\x0e\x00\x00\x00\x01' + RES=$(swtpm_cmd_tx "${SWTPM_INTERFACE}" ${cmd}) +-exp=' 80 01 00 00 00 1b 00 00 00 00 01 00 00 00 06 00 00 00 01 00 00 02 0e 00 00 00 00' ++exp=' 80 01 00 00 00 1b 00 00 00 00 01 00 00 00 06 00 00 00 01 00 00 02 0e 00 00 00 01' + if [ "$RES" != "$exp" ]; then +- echo "Error: Did not get expected result from TPM2_GetCapability(TPM_PT_LOCKOUT_COUNTER)" ++ echo "Error: Did not get expected result from 1st TPM2_GetCapability(TPM_PT_LOCKOUT_COUNTER)" + echo "expected: $exp" + echo "received: $RES" + exit 1 +@@ -92,9 +97,9 @@ fi + # Without swtpm sending TPM2_Shutdown, it would be '1' now + cmd='\x80\x01\x00\x00\x00\x16\x00\x00\x01\x7a\x00\x00\x00\x06\x00\x00\x02\x0e\x00\x00\x00\x01' + RES=$(swtpm_cmd_tx "${SWTPM_INTERFACE}" ${cmd}) +-exp=' 80 01 00 00 00 1b 00 00 00 00 01 00 00 00 06 00 00 00 01 00 00 02 0e 00 00 00 00' ++exp=' 80 01 00 00 00 1b 00 00 00 00 01 00 00 00 06 00 00 00 01 00 00 02 0e 00 00 00 01' + if [ "$RES" != "$exp" ]; then +- echo "Error: Did not get expected result from TPM2_GetCapability(TPM_PT_LOCKOUT_COUNTER)" ++ echo "Error: Did not get expected result from 2nd TPM2_GetCapability(TPM_PT_LOCKOUT_COUNTER)" + echo "expected: $exp" + echo "received: $RES" + exit 1 +@@ -104,6 +109,11 @@ fi + cmd='\x80\x02\x00\x00\x00\x24\x00\x00\x01\x37\x01\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x09\x40\x00\x00\x09\x00\x00\x00\x00\x00\x00\x01\x41\x00\x00' + RES=$(swtpm_cmd_tx "${SWTPM_INTERFACE}" ${cmd}) + exp=' 80 01 00 00 00 0a 00 00 09 22' ++if [ "$RES" == "$exp" ]; then ++ # 0x922 : retry command ++ RES=$(swtpm_cmd_tx "${SWTPM_INTERFACE}" ${cmd}) ++fi ++exp=' 80 01 00 00 00 0a 00 00 09 8e' + if [ "$RES" != "$exp" ]; then + echo "Error: Did not get expected result from TPM2_NV_Write" + echo "expected: $exp" +@@ -136,9 +146,9 @@ fi + # Without swtpm sending TPM2_Shutdown, it would be '2' now + cmd='\x80\x01\x00\x00\x00\x16\x00\x00\x01\x7a\x00\x00\x00\x06\x00\x00\x02\x0e\x00\x00\x00\x01' + RES=$(swtpm_cmd_tx "${SWTPM_INTERFACE}" ${cmd}) +-exp=' 80 01 00 00 00 1b 00 00 00 00 01 00 00 00 06 00 00 00 01 00 00 02 0e 00 00 00 00' ++exp=' 80 01 00 00 00 1b 00 00 00 00 01 00 00 00 06 00 00 00 01 00 00 02 0e 00 00 00 02' + if [ "$RES" != "$exp" ]; then +- echo "Error: Did not get expected result from TPM2_GetCapability(TPM_PT_LOCKOUT_COUNTER)" ++ echo "Error: Did not get expected result from 3rd TPM2_GetCapability(TPM_PT_LOCKOUT_COUNTER)" + echo "expected: $exp" + echo "received: $RES" + exit 1