Changelog for
libtss2-tcti-mssim0-2.4.5-150300.3.3.1.x86_64.rpm :
* Tue Aug 09 2022 matthias.gerstnerAATTsuse.com- add 0001-tcti-device-partial-may-be-used-uninitialized.patch: fix missing zero initialization of a header data field that could lead to data corruption if the TPM does not support partial read (bsc#1202172).
* Thu Jan 28 2021 matthias.gerstnerAATTsuse.com- drop 0001-esys-Fix-HMAC-generation-for-policy-sessions.patch: now contained in upstream tarball- update to upstream version 2.4.5 (jsc#SLE-17366): - changes in version 2.3.2:
* Fix unit tests on S390 architectures
* Fixed HMAC generation for policy sessions - changes in version 2.3.3:
* Fixed mixing salted and unsalted sessions in the same ESAPI context
* Removed use of VLAs from TPML marshal code
* Added check for object node before calling compute_session_value function
* Fixed auth calculation in Esys_StartAuthSession called with optional parameters
* Fixed compute_encrypted_salt error handling in Esys_StartAuthSession
* Fixed exported symbols map for libtss2-mu - changes in version 2.4.0:
* Added a new Feature API (FAPI) implementation
* Added Esys_TRSess_GetAuthRequired() ESAPI function
* Added Esys_TR_GetTpmHandle() SAPI function
* Added Esys_GetSysContext() SAPI function
* Added the with-sanitizer configure option
* Added CI for FreeBSD
* Changed MSSIM TCTI to be async capable
* Removed TCTI loaders from ESYS dependencies in pkg-config
* Changed getPollHandles to allow num_handles query
* Improved CI builds
* Converted builds to docker builds
* Number of fixes and improvements in the test code
* Changed tcti-device in non-async mode to allways block
* Fixed hmac calculation for tpm2_clear command in ESAPI
* Fixed mixing salted and unsalted sessions in the same ESAPI context
* Removed use of VLAs from TPML marshal code
* Fixed setting C++ compiler for non-fuzzing builds at configure
* Fixed setting the name of session objects
* Fixed page alignment errors in Sys_Get/SetAuths functions
* Fixed potential buffer overflow in tcti_mssim_receive
* Fixed invalid memory alloc failure in Tss2_TctiLdr_Initialize
* Fixed list of exported symbols map for libtss2-mu
* Fixed resource name calculation in Esys_CreateLoaded
* Fixed keysize of ECC curve TPM2_ECC_NISTP224
* Fixed segmentation fault in tctildr if name_conf was too big
* Fixed memory leak in tctildr-tcti tests
* Fixed HMAC generation for policy sessions
* Added check for object node before calling compute_session_value function
* Fixed auth calculation in Esys_StartAuthSession called with optional parameters
* Fixed compute_encrypted_salt error handling in Esys_StartAuthSession
* Fixed exported symbols map for libtss2-mu
* Remove duplicate ESYS entries from map file
* Removed the private implementation of strndup from tctildr - changes in version 2.4.1:
* Fixed systemd-sysusers/-tmpfiles creation without systemd
* Removed expired coverity token from travis.yaml
* Fixed uninitialized context of FAPI command Fapi_ChangeAuth issue
* Fixed handling of tcti pointer in Esys_Initialize
* Fixed usages of EC routines deprecated in OSSL 1.2 and greater
* Fixed FAPI handling of TPMs without stored certificates - changes in version 2.4.2:
* Fixed duoble json_object_put call in event log processing.
* Fixed memory leaks on error paths in FAPI
* Fixed setting of FAPI app data.
* Fixed size check for Fapi_Encrypt.
* Fixed computation of PCR logs and PCR digest of PCR logs.
* Improved comments for FAPI authentication.
* Fixed segfault and leaks in FAPI
* Fixed Fapi_GetCertificate for objects which are not of type key
* Fixed hierarchy usage in Fapi_Provision
* Fixed ESYS Shared secret calculation
* Fixed doxygen warnings for FAPI docs
* Fixed copying of primary template during key loading.
* Fixed some wrong format directives in debug statements.
* Fixed usage of hierarchy and authentication in Fapi_GetCertificate und Fapi_Delete
* Fixed unallocated return buffers which may have lead to segfaults in tooling
* Fixed usage of persistent handles.
* Fixed computation of the size of a PCR selection (Fixes #1737).
* Fixed missing hierarchy authentication for Fapi_Delete.
* Fixed uninitialized context of FAPI command Fapi_ChangeAuth.
* Fixed computation of random value for objects used for sealing.
* Fixed return code for event parsing errors.
* Fixed NV index and path handling in NV creation.
* Fixed path checking for keys.
* Fixed Fapi_GetInfo function.
* Fixed path usage in Fapi_Import.
* Fixed invalid settings of default flags for keys creation.
* Fixed handle usage in Fapi_ChangeAuth
* Enabled all PCR registers for SHA256 bank in the distribution profiles.
* Added some checks to Fapi_Provisioning to avoid nasty failure states
* Added a check to prevent overwrite or delete FAPI storage objects and directories
* Remove obsolete test fapi-key-create-policy-password-sign.int.c
* Checked hierarchy needed for EvictControl for deleting objects in FAPI.
* Checked event log file before calling the TPM in Fapi_PcrExtend.
* Adapted integration tests to SRK delete checking.
* Improved presentation of Fapi_GetInfo.
* Silenced expected errors from Esys_TestParams
* Added man pages for FAPI json config files
* Added a check that prevents deleting default directories
* Added a check if primary keys already exist for Fapi_Provision
* Added tests for derived persistent keys.
* Added test policy PCR with PCR register 8.
* Added check for deleting of the SRK.
* Added test for sealing a random value.
* Added content of the config file to FAPI Info.
* Added a check for valid pathnames in keystore module.
* Removed unecassary code from Fapi_ExportKey
* Removed obsolete LIBDL_LDFLAGS and replace it with LIBADD_DL
* Removed superfluous policies/pol_password.json file - changes in version 2.4.3:
* Fix CVE-2020-24455 FAPI PolicyPCR not instatiating correctly Note that all TPM object created with a PolicyPCR with the currentPcrs and currentPcrsAndBank options have been created with an incorrect policy that ommits PCR checks. All these objects have to be recreated!
* Fix bug in FAPI NV creation with custom index values
* Cleanup of leftover sessions in error cases in FAPI
* Better error messages in several FAPI errors
* Add checks to FAPI policy paths
* Add checks if FAPI is correctly provisioned
* Fix execution of FAPI policies in some cases
* Allow 0x prefixes for TPMU_HA in JSON encoding - changes in version 2.4.4:
* FAPI: Fix policy searching, when a policyRef was provided
* FAPI: Accept EK-Certs without CRL dist point
* FAPI: Fix memleak in policy execution
* FAPI: Fix setting of the system flag of NV objects This will let NV object metadata be created system-wide always instead of locally in the user. Existing metadata will remain in the user directory. It can be moved to the corresponding systemstore manually if needed.
* FAPI: Set the written flag of NV objects in FAPI PolicyNV commands
* FAPI: Fix deleting of policy files.
* FAPI: Fix wrong file loading during object search.
* Fapi: Fix memory leak
* Fapi: Fix potential NULL-Dereference
* Fapi: Remove superfluous NULL check - changes in version 2.4.5:
* Fix Regression in Fapi_List
* Fix memory leak in policy calculation
* Thu Jan 16 2020 matthias.gerstnerAATTsuse.com- 0001-esys-Fix-HMAC-generation-for-policy-sessions.patch: fix problems with policy sessions that don\'t include an TPM2_PolicyAuthValue (bsc#1160736). This bug was fixed upstream in a minor release 2.3.2.
* Wed Dec 11 2019 matthias.gerstnerAATTsuse.com- update to upstream version 2.3.0 (dependency for jsc#SLE-9515): - changes in version 2.3.0: - tss2-tctildr: A new library that helps with tcti initialization Recommend to use this in place of custom tcti loading code now ! - tss2-rc: A new library that provides textual representations for return codes - Option to disable NIST-deprecated crypto (--disable-weak-crypto) - Support Esys_TR_FromTPMPublic on sessions (for use in Esys_FlushContext) - map-files with correct symbol lists for tss2-sys and tss2-esys This may lead to unresolved symbols in linked applications - Support to call Tss2_Sys_Execute repeatedly on certain errors - Reduced RAM consumption in Esys due to Tss2_Sys_Execute change - Automated session attribution clearing for esys (decrypt and encrypt) per cmd - Removed libtss2-mu from \"Requires\" field of libtss2-esys.pc Needs to be added explicitely now - All fixes from 2.2.1, 2.2.2 and 2.2.3 - Fixed SPDX License Identifiers - Fixed Null-pointer problems in tcti-tbs - Fixed Default locality for tcti-mssim set to LOC_0 - Fixed coverity and valgrind leaks detected in test programs (not library code)
* Fri Aug 23 2019 matthias.gerstnerAATTsuse.com- update to upstream version 2.2.3: - changes in version 2.2.3:
* Fix computation of session name
* Fixed PolicyPassword handling of session Attributes
* Fixed windows build from dist ball
* Fixed default tcti configure option
* Fixed nonce size calculation in ESYS sessions - changes in version 2.2.2:
* Fixed wrong encryption flag in EncryptDecrypt
* Fixing openssl engine invocation
* Fri Apr 26 2019 mvetterAATTsuse.com- bsc#1130588: Require shadow instead of old pwdutils
* Wed Mar 06 2019 matthias.gerstnerAATTsuse.com- update to upstream version 2.2.1: - changes from version 2.2.0: - Fixed leak of hkey on success in iesys_cryptossl_hmac_start - Fixed NULL ptr issues in Esys_HMAC_Start, Esys_HierarchyChangeAuth and Esys_NV_ChangeAuth - Fixed NULL ptr issue in sequenceHandleNode - Fixed NULL ptr auth handling in Esys_TR_SetAuth - Fixed NULL auth handling in iesys_compute_session_value - Fixed marshaling of TPM2Bs with sub types. - Fixed NULL ptr session handling in Esys_TRSess_SetAttributes - Fixed the way size of the hmac value of a session without authorization - Added missing MU functions for TPM2_NT type - Added missing MU functions for TPMA_ID_OBJECT type - Added missing type TPM2_NT into tss2_tpm2_types.h - Fixed wrong typename _ID_OBJECT in tss2_tpm2_types.h - Fixed build breakage when --with-maxloglevel is not \'trace\' - Fixed build breakage in generated configure script when CFLAGS is set - Fixed configure scritp ERROR_IF_NO_PROG macro - Changed TPM2B type unmarshal to use sizeof of the dest buffer instead of dest - Fixed unmarshaling of the TPM2B type with invalid size - Removed dead code defect detected by coverity from Esys_TRSess_GetNonceTPM - Added support for QNX build - Added support for partial reads in device TCTI - changes from version 2.1.1: - Fixed leak of hkey on success in iesys_cryptossl_hmac_start - Fixed NULL ptr issues in Esys_HMAC_Start, Esys_HierarchyChangeAuth and Esys_NV_ChangeAuth - Fixed NULL ptr issue in sequenceHandleNode - Fixed NULL ptr auth handling in Esys_TR_SetAuth - Fixed NULL auth handling in iesys_compute_session_value - Fixed marshaling of TPM2Bs with sub types. - Fixed NULL ptr session handling in Esys_TRSess_SetAttributes - Fixed the way size of the hmac value of a session without authorization - Added missing MU functions for TPM2_NT type - Added missing MU functions for TPMA_ID_OBJECT type - Added missing type TPM2_NT into tss2_tpm2_types.h - Fixed wrong typename _ID_OBJECT in tss2_tpm2_types.h - Fixed build breakage when --with-maxloglevel is not \'trace\' - Fixed build breakage in generated configure script when CFLAGS is set - Fixed configure scritp ERROR_IF_NO_PROG macro - Changed TPM2B type unmarshal to use sizeof of the dest buffer instead of dest - Fixed unmarshaling of the TPM2B type with invalid size - Removed dead code defect detected by coverity from Esys_TRSess_GetNonceTPM - changes from version 2.1.0: - Fixed handling of the default TCTI - Changed logging to be ISO-C99 compatible - Fixed leak of dlopen handle - Fixed logging of a response header tag in Tss2_Sys_Execute - Fixed marshaling of TPM2B parameters in SAPI commands - Fixed unnecessary warning in Esys_Startup - Fixed warnings in doxygen documentation - Added Esys_Free wrapper function for systems using different C runtime libraries - Added Windows TBS TCTI - Added non-blocking mode of operation in tcti-device - Added tests for Esys_HMAC and Esys_Hash - Enabled integration tests on physical TPM device - Added openssl libcrypto backend - Added Doxygen documentation to integration tests - Refactored SetDecryptParam - Enabled OpenSSL crypto backend by default - changes from 2.0.2: - Fixed NULL ptr issues in Esys_HMAC_Start, Esys_HierarchyChangeAuth and Esys_NV_ChangeAuth - Fixed NULL ptr issue in sequenceHandleNode - Fixed NULL ptr auth handling in Esys_TR_SetAuth - Fixed NULL auth handling in iesys_compute_session_value - Fixed marshaling of TPM2Bs with sub types. - Fixed NULL ptr session handling in Esys_TRSess_SetAttributes - Fixed the way size of the hmac value of a session without authorization - Added missing MU functions for TPM2_NT type - Added missing MU functions for TPMA_ID_OBJECT type - Added missing type TPM2_NT into tss2_tpm2_types.h - Fixed wrong typename _ID_OBJECT in tss2_tpm2_types.h - Fixed build breakage when --with-maxloglevel is not \'trace\' - Fixed build breakage in generated configure script when CFLAGS is set - Fixed configure scritp ERROR_IF_NO_PROG macro - Changed TPM2B type unmarshal to use sizeof of the dest buffer instead of dest - Fixed unmarshaling of the TPM2B type with invalid size - Removed dead code defect detected by coverity from Esys_TRSess_GetNonceTPM- introduce _service file for syncing with upstream tags
* Wed Sep 26 2018 matthias.gerstnerAATTsuse.com- update to upstream version 2.0.1 (FATE#324477): - Fixed problems with doxygan failing make distcheck - Fixed conversion of gcrypt mpi numbers to binary data - Fixed an error in parsing socket address in MSSIM TCTI - Fixed compilation error with --disable-tcti-mssim - Added initialization function for gcrypt to suppress warning - Fixed invalid type base type while marshaling TPMI_ECC_CURVE in Tss2_Sys_ECC_Parameters - Fixed invalid RSA encryption with exponent equal to 0 - Fixed checking of return codes in ESAPI commands - Added checks for programs required by the test harness AATT configure time - Fixed warning on TPM2_RC_INITIALIZE rc after a Startup in Esys_Startup - Checked for 1.2 TPM type response - Changed constants values in esys header file to unsigned
* Tue Sep 18 2018 matthias.gerstnerAATTsuse.com- also process udev triggers for tpmrm subsystem, otherwise /dev/tpmrm0 isn\'t properly updated (at least on SLES-12-SP4)
* Thu Jul 05 2018 matthias.gerstnerAATTsuse.com- added all librares to baselibs.conf to satisfy 32-bit dependencies of esys0 and sys0
* Tue Jul 03 2018 matthias.gerstnerAATTsuse.com- Explicitly require udev to fix missing ownership for /usr/lib/udev.
* Fri Jun 29 2018 matthias.gerstnerAATTsuse.com- update to new major version 2.0.0: - version_fix.patch: removed, we\'re now using the distribution tarballs where this problem shouldn\'t happen - this update introduces an incompatible ABI to the previous version. all libraries have been renamed so there is not really a relation to the old version any more. - upstream changelog: [#]# [2.0.0] - 2018-06-20 [#]## Added - Implementation of the Marshal/Unmarshal library (libtss2-mu) - Implementation of the Enhanced System API (libtss2-esys aka ESAPI) - New implemetation of the TPM Command Transmission Interface (TCTI) for: - communication with Linux TPM2 device driver: libtss2-tcti-device - communication with Microsoft software simulator: libtss2-tcti-mssim - New directory layout (API break) - Updated documentation with new doxygen and updated man pages - Support for Windows build with Visual Studio and clang, currently limited to libtss2-mu and libtss2-sys - Implementation of the new Attached Component (AC) commands - Implementation of the new TPM2_PolicyAuthorizeNV command - Implementation of the new TPM2_CreateLoaded command - Implementation of the new TPM2_PolicyTemplate command - Addition of _Complete functions to all TPM commands - New logging framework - Added const qualifiers to API input pointers (API break) - Cleaned up headers and remove implementation.h and tpm2.h (API break) [#]## Changed - Converted all cpp files to c, removed dependency on C++ compiler. - Cleaned out a number of marshaling functions from the SAPI code. - Update Linux / Unix OS detection to use non-obsolete macros. - Changed TCTI macros to CamelCase (API break) - Changed TPMA_types to unsigned int with defines instead of bitfield structs (API/ABI break) - Changed Get/SetCmd/RspAuths to new parameter types (API/ABI break) - Fixed order of parameters in AC commands: Input command authorizations now come after the input handles, but still before the command parameters. [#]## Removed - Removed all sysapi/sysapi_utils/
*arshal_TPM
*.c files [#]## Fixed - Updated invalid number of handles in TPM2_PolicyNvWritten and TPM2_TestParms - Updated PlatformCommand function from libtss2-tcti-mssim to no longer send CANCEL_OFF before every command. - Expanded TPM2B macros and removed TPM2B_TYPE1 and TPM2B_TYPE2 macros - Fixed wrong return type for Tss2_Sys_Finalize (API break). [#]# [1.4.0] - 2018-03-02 [#]## Added - Attached Component commands from the last public review spec. [#]## Fixed - Essential files missing from release tarballs are now included. - Version string generation has been moved from configure.ac to the bootstrap script. It is now stored in a file named `VERSION` that is shipped in the release tarball. - We\'ve stopped shipping the built man page for InitSocketTcti.3 and now ship the source.
* Wed Mar 07 2018 matthias.gerstnerAATTsuse.com- removed leftover comment from dropped reproducable.patch
* Thu Feb 22 2018 matthias.gerstnerAATTsuse.com- update to upstream version 1.3.0: - support for reproducable builds - improved documentation / manual pages - various stability bugfixes - EncryptDecrypt2 command is now implemented- removed reproducible.patch. This is now included upstream.- added version_fix.patch to fix package config version numbers.
* Fri Sep 01 2017 matthias.gerstnerAATTsuse.com- fix the \"fix\", turns out only the unversioned symlink\'s supposed to go into - devel.
* Thu Jul 20 2017 matthias.gerstnerAATTsuse.com- no longer install the udev rule, it\'s now part of the new tpm2.0-abrmd package.- fixed a warning regarding a missing dependency of the devel package to the main package- correctly package library symlinks only in the devel package, the library itself only in the library package. Was mixed up before.
* Wed Jul 19 2017 matthias.gerstnerAATTsuse.com- removed tpm2-0-tss-configure.patch, it was just a hack, fixed by requiring autoconf-archive, see https://github.com/01org/TPM2.0-TSS/issues/227.
* Wed Jul 19 2017 matthias.gerstnerAATTsuse.com- Updated to upstream version 1.1.0 - With this version the resourcemgr daemon is dropped from this package. It is replaced by a completely new implementation found in a new package tpm2.0-abrmd. this package will only consist of the libraries any more. - Changed - tpmclient, disabled all tests that rely on the old resourcemgr. - Fixed - Fixed definition of PCR_LAST AND TRANSIENT_LAST macros. - Removed - tpmtest - resourcemgr, replacement is in new repo: https://github.com/01org/tpm2-abrmd
* Sat May 27 2017 bwiedemannAATTsuse.com- Add reproducible.patch to sort input files to make build reproducible (boo#1041090)
* Thu May 11 2017 matthias.gerstnerAATTsuse.com- create tss user account and install udev rule to fix startup of resourcemgr (bnc#1038586)
* Wed May 10 2017 mgerstnerAATTsuse.com- remove unnecessary dependency of libsapi0 to trousers. trousers has nothing to do with tpm2-tss.
* Tue Apr 11 2017 meissnerAATTsuse.com- fixed typo in resourcemgr.service (bsc#1031004)
* Thu Feb 16 2017 jengelhAATTinai.de- Remove --with-pic which is only for static libs.- Fix an improper Requires line.- Split libtcti
* from libsapi0; these are independentlty developable units.
* Wed Feb 08 2017 meissnerAATTsuse.com- Updated to 1.0 (FATE#321508) - Added - Travis-CI integration with GitHub - Unit tests for primitive (un)?marshal functions. - Example systemd unit for resourcemgr. - Allow for unit tests to be enabled selectively. - added pkg-config files for libraries - Changed - move simulator initialization code to socket TCTI init function. - socket TCTI finalize no longer frees context - rename libtss2 to libsapi - rename libtcti_device to libtcti-device - rename libtcti_socket to libtcti-socket - move $(includedir)/tss to $(includedir)/sapi - Move default compiler flags to config.site file. - Fixed - Fix run away resourcemgr threads by closing client sockets when resourcemgr recv() call returns 0. - Set MSG_NOSIGNAL for client connections to avoid SIGPIPE killing resourcemgr. - Fixes to handling of persistent objects by resourcemgr. - Removed - Semicolon from TPMA_
* macros definitions. - Windows build files. - SAPI_CLIENT macro tests. - Security - Fix buffer overflow in resourcemgr.- use sample resourcemanager.service- tpm2-0-tss-configure.patch: fix weird error.
* Thu Aug 25 2016 meissnerAATTsuse.com- Remove type=forking from service file (bsc#995554)
* Sat Aug 06 2016 meissnerAATTsuse.com- added a systemd unit service file (FATE#315631)
* Fri May 06 2016 jengelhAATTinai.de- Correct package naming to be in line with shared library guideline- Remove unused systemd build and runtime dependencies (FATE#315631)
* Fri Apr 08 2016 dimstarAATTopensuse.org- Fix rpm group of library package: libs belong, per definition, to the group \"System/Libraries\". (FATE#315631)
* Wed Feb 24 2016 meissnerAATTsuse.com- initial import of the tpm 2.0 tss stack (FATE#315631)