Skip to content

efi: implement platform-agnostic arm64 host security checks - #566

Open
alexclewontin wants to merge 2 commits into
alexclewontin/check-host-security-unpin-amd64from
alexclewontin/check-host-security-arm64
Open

alexclewontin wants to merge 2 commits into
alexclewontin/check-host-security-unpin-amd64from
alexclewontin/check-host-security-arm64

Conversation

@alexclewontin

Copy link
Copy Markdown
Member

This PR adds a framework for host security checks on arm64 platforms. It moves #564 to the stack.

It adds a generic framework to check host security on ARM64. Very few truly cross-platform APIs were found to be applicable to that ecosystem, but we can use the backing driver for the TPM to prove that a given TPM is a fTPM: if it is using the OP-TEE fTPM driver we can be sure that it is an fTPM. This is not conclusive (absence of that driver doesn't prove that a TPM is a dTPM), but it is a common reference implementation for the ARM ecosystem, so worth including.

Comment thread efi/preinstall/check_host_security.go Outdated
Comment thread efi/preinstall/checks_fixture_test.go Outdated
Comment thread efi/preinstall/checks_fixture_test.go Outdated
)

func init() {
RegisterARM64TestPlatform(exampleARM64CPUManufacturer, exampleARM64CPUVersion)

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please add a comment about what is the purpose of this, and why this is done here.

Wouldn't it be more explicit to have this done in the setup of one of the test suites instead?

return func() { runtimeGOARCH = orig }
}

func RegisterARM64TestPlatform(cpuManufacturer, cpuVersion string) {

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please add a description of this function.


eventLogPath = "/sys/kernel/security/tpm0/binary_bios_measurements" // Path of the TCG event log for the default TPM, in binary form

dmiProcessorInfoPath = "/sys/firmware/dmi/entries/4-0/raw"

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Does "4" means type 4?
Does "0" means processor 0? Do we make any assumption there (eg: that other CPUs are the same as CPU 0...)
Please document these.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Documented

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We do indeed assume that CPUs are all homogenous

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

ARM CI fails because the required TPM simulator snap is unavailable for arm64.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Adds ARM64 host-security infrastructure, including SMBIOS CPU identification and OP-TEE fTPM detection.

Changes:

  • Adds ARM64 environment abstractions and SMBIOS parsing.
  • Adds ARM64 host-security, TPM checks, and tests.
  • Expands CI to ARM64 runners.
File summaries
File Description
internal/efitest/hostenv.go Adds mock ARM64 environments.
internal/efi/env.go Defines ARM64 host interfaces and errors.
internal/efi/default_env.go Implements SMBIOS CPU identification.
internal/efi/default_env_test.go Tests ARM64 environment behavior.
efi/preinstall/export_test.go Exposes ARM64 test helpers.
efi/preinstall/checks_fixture_test.go Adds ARM64 integration fixtures.
efi/preinstall/check_tpm.go Detects OP-TEE firmware TPMs.
efi/preinstall/check_tpm_test.go Tests ARM64 TPM classification.
efi/preinstall/check_host_security.go Adds ARM64 security-check dispatch.
efi/preinstall/check_host_security_test.go Tests ARM64 security checks.
.github/workflows/test.yaml Adds ARM64 CI runners.
Review details
  • Files reviewed: 11/11 changed files
  • Comments generated: 2
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

matrix:
runner:
- ubuntu-24.04
- ubuntu-24.04-arm
Comment thread internal/efi/env.go

// ErrNotARM64Host is returned from HostEnvironment.ARM64 on environments that
// are not ARM64.
ErrNotARM64Host = errors.New("not a ARM64 host")
matrix:
runner:
- ubuntu-24.04
- ubuntu-24.04-arm

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are these run in parallel or sequentially?
Running them sequentially would double the testing time, which is already a lot. In that case, consider only running minimal tests on arm64.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

They will run in parallel, on separate runners

@alexclewontin
alexclewontin force-pushed the alexclewontin/check-host-security-arm64 branch from 4ec0a33 to 9eabe8c Compare September 25, 2026 16:37
@alexclewontin
alexclewontin force-pushed the alexclewontin/check-host-security-arm64 branch from 9eabe8c to bf5cb23 Compare September 25, 2026 16:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants