efi: implement platform-agnostic arm64 host security checks - #566
alexclewontin wants to merge 2 commits into
Conversation
| ) | ||
|
|
||
| func init() { | ||
| RegisterARM64TestPlatform(exampleARM64CPUManufacturer, exampleARM64CPUVersion) |
There was a problem hiding this comment.
Please add a comment about what is the purpose of this, and why this is done here.
Wouldn't it be more explicit to have this done in the setup of one of the test suites instead?
| return func() { runtimeGOARCH = orig } | ||
| } | ||
|
|
||
| func RegisterARM64TestPlatform(cpuManufacturer, cpuVersion string) { |
There was a problem hiding this comment.
Please add a description of this function.
|
|
||
| eventLogPath = "/sys/kernel/security/tpm0/binary_bios_measurements" // Path of the TCG event log for the default TPM, in binary form | ||
|
|
||
| dmiProcessorInfoPath = "/sys/firmware/dmi/entries/4-0/raw" |
There was a problem hiding this comment.
Does "4" means type 4?
Does "0" means processor 0? Do we make any assumption there (eg: that other CPUs are the same as CPU 0...)
Please document these.
There was a problem hiding this comment.
We do indeed assume that CPUs are all homogenous
f7d6868 to
8b0abfa
Compare
There was a problem hiding this comment.
🟡 Changes recommended
ARM CI fails because the required TPM simulator snap is unavailable for arm64.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Adds ARM64 host-security infrastructure, including SMBIOS CPU identification and OP-TEE fTPM detection.
Changes:
- Adds ARM64 environment abstractions and SMBIOS parsing.
- Adds ARM64 host-security, TPM checks, and tests.
- Expands CI to ARM64 runners.
File summaries
| File | Description |
|---|---|
internal/efitest/hostenv.go |
Adds mock ARM64 environments. |
internal/efi/env.go |
Defines ARM64 host interfaces and errors. |
internal/efi/default_env.go |
Implements SMBIOS CPU identification. |
internal/efi/default_env_test.go |
Tests ARM64 environment behavior. |
efi/preinstall/export_test.go |
Exposes ARM64 test helpers. |
efi/preinstall/checks_fixture_test.go |
Adds ARM64 integration fixtures. |
efi/preinstall/check_tpm.go |
Detects OP-TEE firmware TPMs. |
efi/preinstall/check_tpm_test.go |
Tests ARM64 TPM classification. |
efi/preinstall/check_host_security.go |
Adds ARM64 security-check dispatch. |
efi/preinstall/check_host_security_test.go |
Tests ARM64 security checks. |
.github/workflows/test.yaml |
Adds ARM64 CI runners. |
Review details
- Files reviewed: 11/11 changed files
- Comments generated: 2
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| matrix: | ||
| runner: | ||
| - ubuntu-24.04 | ||
| - ubuntu-24.04-arm |
|
|
||
| // ErrNotARM64Host is returned from HostEnvironment.ARM64 on environments that | ||
| // are not ARM64. | ||
| ErrNotARM64Host = errors.New("not a ARM64 host") |
8b0abfa to
4ec0a33
Compare
| matrix: | ||
| runner: | ||
| - ubuntu-24.04 | ||
| - ubuntu-24.04-arm |
There was a problem hiding this comment.
Are these run in parallel or sequentially?
Running them sequentially would double the testing time, which is already a lot. In that case, consider only running minimal tests on arm64.
There was a problem hiding this comment.
They will run in parallel, on separate runners
4ec0a33 to
9eabe8c
Compare
9eabe8c to
bf5cb23
Compare
This PR adds a framework for host security checks on arm64 platforms. It moves #564 to the stack.
It adds a generic framework to check host security on ARM64. Very few truly cross-platform APIs were found to be applicable to that ecosystem, but we can use the backing driver for the TPM to prove that a given TPM is a fTPM: if it is using the OP-TEE fTPM driver we can be sure that it is an fTPM. This is not conclusive (absence of that driver doesn't prove that a TPM is a dTPM), but it is a common reference implementation for the ARM ecosystem, so worth including.