Skip to content

Bound fwTPM PCR capability response parsing - #615

Merged
dgarske merged 2 commits into
wolfSSL:masterfrom
aidangarske:coverity-913848-fwtpm-pcr-bounds
Sep 29, 2026
Merged

dgarske merged 2 commits into
wolfSSL:masterfrom
aidangarske:coverity-913848-fwtpm-pcr-bounds

Conversation

@aidangarske

Copy link
Copy Markdown
Member
  • Coverity CID 913848 flagged response controlled loop bounds in the fwTPM test helper.
  • Validate the response length before reading the fixed fields.
  • Bound the bank count and PCR selection size before iterating.
  • Return an error for truncated or malformed capability data.
  • Add regression cases for valid and malformed responses.

@aidangarske aidangarske self-assigned this Sep 28, 2026
Copilot AI balanced review requested due to automatic review settings September 28, 2026 21:44

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.

Copilot review overview

Review effort: Lite
Findings: 2 Medium severity

Open (2)
What changed in this PR

This PR hardens fwTPM PCR capability response parsing by adding explicit bounds checks before iterating over response-controlled fields, and introduces regression tests for valid and malformed responses.

Changes:

  • Split PCR bank detection into a response parser (fwtpm_parse_bank_allocated) plus a command wrapper (fwtpm_bank_allocated).
  • Add defensive validation for response size, bank count, and PCR selection size before parsing.
  • Add a new unit test to cover valid and malformed PCR capability responses.
File Description
tests/​fwtpm_unit_tests.c Adds a bounded parser for TPM_CAP_PCRS responses and regression tests for malformed/truncated data.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread tests/fwtpm_unit_tests.c Outdated
Comment thread tests/fwtpm_unit_tests.c Outdated
@dgarske
dgarske merged commit 65e352e into wolfSSL:master Sep 29, 2026
265 of 269 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants