Skip to content

Boot hardening: rollback floor skipped without TPM, memory map truncated at 1024 entries #426

Description

@eKisNonos

Two boot-time hardening gaps found in the trusted path.

Anti-rollback silently degrades to non-monotonic when there is no TPM. check_rollback (boot/crypto/rollback/check.rs:64) only enforces the TPM NV floor "if let Some(floor) = read_floor(...)". With no EFI_TCG2, read_floor returns None (tpm_nv/floor.rs:44) and the entire floor gate is skipped, so rollback protection falls back to the in-image version state, which is not hardware-monotonic. On a Standard build with firmware TPM off, a signed-but-old kernel can be replayed. In signature-requiring modes, "TPM present but floor unreadable" should be treated distinctly from "no TPM," and consider failing closed when signatures are required.

Firmware memory map is silently truncated at 1024 entries. copy_memory_map (handoff/jump/mmap.rs:32) breaks at MAX_MMAP_ENTRIES=1024 with no error. A heavily fragmented real-firmware map (many ACPI NVS/reserved/MMIO runs, common on laptops) can exceed that, and the kernel then inherits a truncated map and may treat firmware-reserved RAM as free. OVMF's map is small so this never shows in QEMU. Size the buffer from the actual map_size returned pre-exit, or fail closed on overflow instead of break.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions