s390x: add "IBM Secure Execution for Linux" support
authorNikita Dubrovskii <nikita@linux.ibm.com>
Wed, 17 Nov 2021 12:10:20 +0000 (13:10 +0100)
committerNikita Dubrovskii <nikita@linux.ibm.com>
Fri, 11 Feb 2022 08:00:38 +0000 (09:00 +0100)
If system contains ibm-z-hostkey (fetched during ignition), than
ostree generates 'sd-boot' image and reboots into Secure Execution

Signed-off-by: Nikita Dubrovskii <nikita@linux.ibm.com>
src/libostree/ostree-bootloader-zipl.c
src/libostree/ostree-bootloader-zipl.h
src/libostree/ostree-bootloader.c
src/libostree/ostree-bootloader.h
src/libostree/ostree-sysroot-deploy.c

index a7078aeaff07391f81e1d395129703404569eb1b..7358671bfb079dc37071cb1093e26b1eceb1ffc4 100644 (file)
 
 #include "ostree-sysroot-private.h"
 #include "ostree-bootloader-zipl.h"
+#include "ostree-deployment-private.h"
 #include "otutil.h"
-
+#include <systemd/sd-journal.h>
 #include <string.h>
 
+#define SECURE_EXECUTION_BOOT_IMAGE     "/boot/sd-boot"
+#define SECURE_EXECUTION_HOSTKEY_PATH   "/etc/se-hostkeys/"
+#define SECURE_EXECUTION_HOSTKEY_PREFIX "ibm-z-hostkey"
+
 /* This is specific to zipl today, but in the future we could also
  * use it for the grub2-mkconfig case.
  */
@@ -78,8 +83,163 @@ _ostree_bootloader_zipl_write_config (OstreeBootloader  *bootloader,
   return TRUE;
 }
 
+static gboolean
+_ostree_secure_execution_get_keys (GPtrArray **keys,
+                                   GCancellable *cancellable,
+                                   GError **error)
+{
+  g_auto (GLnxDirFdIterator) it = { 0,};
+  if ( !glnx_dirfd_iterator_init_at (-1, SECURE_EXECUTION_HOSTKEY_PATH, TRUE, &it, error))
+    return glnx_prefix_error (error, "s390x SE: looking for SE keys");
+
+  g_autoptr(GPtrArray) ret_keys = g_ptr_array_new_with_free_func (g_free);
+  while (TRUE)
+    {
+      struct dirent *dent = NULL;
+      if (!glnx_dirfd_iterator_next_dent (&it, &dent, cancellable, error))
+        return FALSE;
+
+      if (!dent)
+        break;
+
+      if (g_str_has_prefix (dent->d_name, SECURE_EXECUTION_HOSTKEY_PREFIX))
+        g_ptr_array_add (ret_keys, g_build_filename (SECURE_EXECUTION_HOSTKEY_PATH, dent->d_name, NULL));
+    }
+
+  *keys = g_steal_pointer (&ret_keys);
+  return TRUE;
+}
+
+static gboolean
+_ostree_secure_execution_get_bls_config (OstreeBootloaderZipl *self,
+                                         int bootversion,
+                                         gchar **vmlinuz,
+                                         gchar **initramfs,
+                                         gchar **options,
+                                         GCancellable *cancellable,
+                                         GError **error)
+{
+  g_autoptr (GPtrArray) configs = NULL;
+  if ( !_ostree_sysroot_read_boot_loader_configs (self->sysroot, bootversion, &configs, cancellable, error))
+    return glnx_prefix_error (error, "s390x SE: loading bls configs");
+
+  if (!configs || configs->len == 0)
+    return glnx_throw (error, "s390x SE: no bls config");
+
+  OstreeBootconfigParser *parser = (OstreeBootconfigParser *) g_ptr_array_index (configs, 0);
+  const gchar *val = NULL;
+
+  val = ostree_bootconfig_parser_get (parser, "linux");
+  if (!val)
+    return glnx_throw (error, "s390x SE: no \"linux\" key in bootloader config");
+  *vmlinuz = g_build_filename ("/boot", val, NULL);
+
+  val = ostree_bootconfig_parser_get (parser, "initrd");
+  if (!val)
+    return glnx_throw (error, "s390x SE: no \"initrd\" key in bootloader config");
+  *initramfs = g_build_filename ("/boot", val, NULL);
+
+  val = ostree_bootconfig_parser_get (parser, "options");
+  if (!val)
+    return glnx_throw (error, "s390x SE: no \"options\" key in bootloader config");
+  *options = g_strdup(val);
+
+  return TRUE;
+}
+
+static gboolean
+_ostree_secure_execution_generate_sdboot (gchar *vmlinuz,
+                                          gchar *initramfs,
+                                          gchar *options,
+                                          GPtrArray *keys,
+                                          GError **error)
+{
+  g_assert (vmlinuz && initramfs && options && keys && keys->len);
+  sd_journal_print(LOG_INFO, "s390x SE: kernel: %s", vmlinuz);
+  sd_journal_print(LOG_INFO, "s390x SE: initrd: %s", initramfs);
+  sd_journal_print(LOG_INFO, "s390x SE: kargs: %s", options);
+
+  pid_t self = getpid();
+
+  // Store kernel options to temp file, so `genprotimg` can later embed it
+  g_auto(GLnxTmpfile) cmdline = { 0, };
+  if (!glnx_open_anonymous_tmpfile (O_RDWR | O_CLOEXEC, &cmdline, error))
+    return glnx_prefix_error(error, "s390x SE: opening cmdline file");
+  if (glnx_loop_write (cmdline.fd, options, strlen (options)) < 0)
+    return glnx_throw_errno_prefix (error, "s390x SE: writting cmdline file");
+  g_autofree gchar *cmdline_filename = g_strdup_printf ("/proc/%d/fd/%d", self, cmdline.fd);
+
+  g_autoptr(GPtrArray) argv = g_ptr_array_new ();
+  g_ptr_array_add (argv, "genprotimg");
+  g_ptr_array_add (argv, "-i");
+  g_ptr_array_add (argv, vmlinuz);
+  g_ptr_array_add (argv, "-r");
+  g_ptr_array_add (argv, initramfs);
+  g_ptr_array_add (argv, "-p");
+  g_ptr_array_add (argv, cmdline_filename);
+  for (guint i = 0; i < keys->len; ++i)
+    {
+      gchar *key = g_ptr_array_index (keys, i);
+      g_ptr_array_add (argv, "-k");
+      g_ptr_array_add (argv, key);
+      sd_journal_print(LOG_INFO, "s390x SE: key[%d]: %s", i + 1, key);
+    }
+  g_ptr_array_add (argv, "--no-verify");
+  g_ptr_array_add (argv, "-o");
+  g_ptr_array_add (argv, SECURE_EXECUTION_BOOT_IMAGE);
+  g_ptr_array_add (argv, NULL);
+
+  gint status = 0;
+  if (!g_spawn_sync (NULL, (char**)argv->pdata, NULL, G_SPAWN_SEARCH_PATH,
+                       NULL, NULL, NULL, NULL, &status, error))
+    return glnx_prefix_error(error, "s390x SE: spawning genprotimg");
+
+  if (!g_spawn_check_exit_status (status, error))
+    return glnx_prefix_error(error, "s390x SE: `genprotimg` failed");
+
+  sd_journal_print(LOG_INFO, "s390x SE: `%s` generated", SECURE_EXECUTION_BOOT_IMAGE);
+  return TRUE;
+}
+
+static gboolean
+_ostree_secure_execution_call_zipl (GError **error)
+{
+  int status = 0;
+  const char *const zipl_argv[] = {"zipl", "-V", "-t", "/boot", "-i", SECURE_EXECUTION_BOOT_IMAGE, NULL};
+  if (!g_spawn_sync (NULL, (char**)zipl_argv, NULL, G_SPAWN_SEARCH_PATH,
+                       NULL, NULL, NULL, NULL, &status, error))
+    return glnx_prefix_error(error, "s390x SE: spawning zipl");
+
+  if (!g_spawn_check_exit_status (status, error))
+    return glnx_prefix_error(error, "s390x SE: `zipl` failed");
+
+  sd_journal_print(LOG_INFO, "s390x SE: `sd-boot` zipled");
+  return TRUE;
+}
+
+static gboolean
+_ostree_secure_execution_enable (OstreeBootloaderZipl *self,
+                                 int bootversion,
+                                 GPtrArray *keys,
+                                 GCancellable *cancellable,
+                                 GError **error)
+{
+  g_autofree gchar* vmlinuz = NULL;
+  g_autofree gchar* initramfs = NULL;
+  g_autofree gchar* options = NULL;
+
+  gboolean rc =
+      _ostree_secure_execution_get_bls_config (self, bootversion, &vmlinuz, &initramfs, &options, cancellable, error) &&
+      _ostree_secure_execution_generate_sdboot (vmlinuz, initramfs, options, keys, error) &&
+      _ostree_secure_execution_call_zipl (error);
+
+  return rc;
+}
+
+
 static gboolean
 _ostree_bootloader_zipl_post_bls_sync (OstreeBootloader  *bootloader,
+                                       int bootversion,
                                        GCancellable  *cancellable,
                                        GError       **error)
 {
@@ -97,6 +257,14 @@ _ostree_bootloader_zipl_post_bls_sync (OstreeBootloader  *bootloader,
   if (errno == ENOENT)
     return TRUE;
 
+  /* Try with Secure Execution */
+  g_autoptr(GPtrArray) keys = NULL;
+  if (!_ostree_secure_execution_get_keys (&keys, cancellable, error))
+    return FALSE;
+  if (keys && keys->len)
+    return _ostree_secure_execution_enable (self, bootversion, keys, cancellable, error);
+
+  /* Fallback to non-SE setup */
   const char *const zipl_argv[] = {"zipl", NULL};
   int estatus;
   if (!g_spawn_sync (NULL, (char**)zipl_argv, NULL, G_SPAWN_SEARCH_PATH,
index 3584feb228f5bd00c9f127a522f31817734c33cc..e3f0b2b32c5c000e361d5637e685a4757138b8bf 100644 (file)
@@ -30,5 +30,4 @@ typedef struct _OstreeBootloaderZipl OstreeBootloaderZipl;
 GType _ostree_bootloader_zipl_get_type (void) G_GNUC_CONST;
 
 OstreeBootloaderZipl * _ostree_bootloader_zipl_new (OstreeSysroot *sysroot);
-
 G_END_DECLS
index f221b6081c6b0a035845c5137f32d2e7c4658bf5..785fd233965fda2c2be28622546cfc4cd66a52a4 100644 (file)
@@ -65,13 +65,14 @@ _ostree_bootloader_write_config (OstreeBootloader  *self,
 
 gboolean
 _ostree_bootloader_post_bls_sync (OstreeBootloader  *self,
+                                  int bootversion,
                                   GCancellable  *cancellable,
                                   GError       **error)
 {
   g_return_val_if_fail (OSTREE_IS_BOOTLOADER (self), FALSE);
 
   if (OSTREE_BOOTLOADER_GET_IFACE (self)->post_bls_sync)
-    return OSTREE_BOOTLOADER_GET_IFACE (self)->post_bls_sync (self, cancellable, error);
+    return OSTREE_BOOTLOADER_GET_IFACE (self)->post_bls_sync (self, bootversion, cancellable, error);
 
   return TRUE;
 }
index 6e0f6f88ecdc547e0f6b2fadb9650a7bd661ed8a..ca1b453eba9fd324b2e0652a1d8e791496b48486 100644 (file)
@@ -46,6 +46,7 @@ struct _OstreeBootloaderInterface
                                                    GCancellable  *cancellable,
                                                    GError       **error);
   gboolean             (* post_bls_sync)          (OstreeBootloader  *self,
+                                                   int bootversion,
                                                    GCancellable  *cancellable,
                                                    GError       **error);
   gboolean             (* is_atomic)              (OstreeBootloader  *self);
@@ -68,6 +69,7 @@ gboolean _ostree_bootloader_write_config (OstreeBootloader  *self,
                                           GError       **error);
 
 gboolean _ostree_bootloader_post_bls_sync (OstreeBootloader  *self,
+                                           int bootversion,
                                            GCancellable  *cancellable,
                                            GError       **error);
 
index c4ae86d545d34f9111d709f3224964ef67f45ebc..c1e19db3c22a680de22f83807e85485f01991799 100644 (file)
@@ -2097,7 +2097,7 @@ swap_bootloader (OstreeSysroot  *sysroot,
    **/
   if (bootloader)
     {
-      if (!_ostree_bootloader_post_bls_sync (bootloader, cancellable, error))
+      if (!_ostree_bootloader_post_bls_sync (bootloader, new_bootversion, cancellable, error))
         return FALSE;
     }