Repository navigation
Reject storage keys in fwTPM decrypt commands and bind split param-enc sessions - #622
Conversation
aidangarske
commented
Oct 5, 2026
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #622
Scan targets checked: wolftpm-src, wolftpm-bugs
Coverage: 3 of 6 in-scope changed file(s) opened by the reviewer; not opened: tests/fwtpm_unit_tests.c, tests/unit_tests.c, wolftpm/tpm2_param_enc.h
Fenrir result: Approved ✅
No new issues found in the changed files.
Advisory only — this automated result does not count as a GitHub approval.
Review tier: Lite
There was a problem hiding this comment.
Note
Copilot was unable to run its full agentic suite in this review.
Copilot review overview
Review effort: Lite
Findings: 1
Open (4)
RspSessOffsetcomputes the start of the response auth area incorrectly forTPM_ST_SESSIONS… · NewdecAuthHandle/encAuthHandledefault to0, which is not a valid TPM handle value (and is… · New PassingNULLas the key pointer towc_HmacSetKey(..., keySz=0)can be rejected on some… · New The comment contradicts the test behavior below: the test expectsTPM_RC_BAD_AUTHwhen the auth… · New
What changed in this PR
This PR improves TPM 2.0 parameter encryption behavior when authorization and parameter-encryption are split across multiple sessions, and adds firmware-TPM (FWTPM) validation plus additional key-usage restrictions.
Changes:
- Add extended HMAC calculation API to include additional session nonces in the first session’s HMAC (per TPM 2.0 Part 1 §19.6.5).
- Update host-side command/response processing to (a) encrypt before cpHash/HMAC and (b) defer response decryption until after rpHash/HMAC verification for all sessions.
- Add unit tests for split param-encryption sessions, FWTPM session-selection rules, session binding behavior, and rejecting “storage” keys for raw decrypt/key-agreement primitives.
| File | Description |
|---|---|
| wolftpm/tpm2_param_enc.h | Exposes TPM2_CalcHmac_ex for HMAC computation that can include extra session nonces. |
| src/tpm2_param_enc.c | Implements TPM2_CalcHmac_ex and keeps TPM2_CalcHmac as a wrapper for backward compatibility. |
| src/tpm2.c | Adjusts command/response session processing to correctly handle split param-encryption sessions and verification/decryption ordering. |
| src/fwtpm/fwtpm_command.c | Updates FWTPM session HMAC computation to bind decrypt/encrypt session nonces and adds restricted-key checks for decrypt primitives. |
| tests/unit_tests.c | Adds a runtime TPM wrapper test covering policy auth + separate AES-CFB parameter-encryption session. |
| tests/fwtpm_unit_tests.c | Adds FWTPM unit tests for param-encryption session attribute selection, auth binding, and decrypt primitive restrictions. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

