mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-08 04:42:04 -04:00
hwkm: fail on last byte corruption
When the last byte of an incoming keyblob is corrupted for an UNWRAP_IMPORT operation, HWKM does not fail as it is considered a noop. However, we must fail as it will classify as a corrupted keyblob. Change-Id: Ia9f74d150163139f879287e9ffcc82277d76685a Signed-off-by: Gaurav Kashyap <gaurkash@codeaurora.org>
This commit is contained in:
parent
bd0cb90137
commit
bbb443fcbf
1 changed files with 13 additions and 0 deletions
|
|
@ -505,6 +505,19 @@ static int qti_handle_key_unwrap_import(const struct hwkm_cmd *cmd_in,
|
|||
return -EINVAL;
|
||||
}
|
||||
|
||||
/*
|
||||
* Unwrap in HWKM does not do an integrity check for the last byte
|
||||
* (68th byte) as it is a noop. However, we need to make sure no
|
||||
* part of the keyblob provided was tampered with, even though it
|
||||
* is a noop. Adding an explicit check for the last byte before
|
||||
* providing to unwrap command.
|
||||
*/
|
||||
if ((cmd_in->unwrap.wkb[EXPECTED_UNWRAP_KEY_SIZE - 1]) != 0x00) {
|
||||
pr_err("%s: Last byte corrupted, expecting zero value\n",
|
||||
__func__);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
memcpy(cmd, &operation, OPERATION_INFO_LENGTH);
|
||||
memcpy(cmd + COMMAND_WRAPPED_KEY_IDX, cmd_in->unwrap.wkb,
|
||||
cmd_in->unwrap.sz);
|
||||
|
|
|
|||
Loading…
Reference in a new issue