Skip to content
This repository was archived by the owner on Sep 6, 2023. It is now read-only.
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -11,3 +11,4 @@ test: trust
bats tests/keyset.bats
bats tests/project.bats
bats tests/sudi.bats
bats tests/policygen.bats
4 changes: 2 additions & 2 deletions cmd/trust/policygen.go
Original file line number Diff line number Diff line change
Expand Up @@ -79,7 +79,7 @@ func doTpmPolicygen(ctx *cli.Context) error {
if err != nil {
return err
}
err = os.WriteFile(passwdOutFile, passwdPolDigest, 0400)
err = os.WriteFile(passwdOutFile, passwdPolDigest, 0644)
if err != nil {
return err
}
Expand All @@ -95,7 +95,7 @@ func doTpmPolicygen(ctx *cli.Context) error {
if err != nil {
return err
}
err = os.WriteFile(luksOutFile, luksPolDigest, 0400)
err = os.WriteFile(luksOutFile, luksPolDigest, 0644)
if err != nil {
return err
}
Expand Down
26 changes: 20 additions & 6 deletions tests/policygen.bats
Original file line number Diff line number Diff line change
Expand Up @@ -2,17 +2,31 @@ load helpers

function setup() {
common_setup
rm -rf "${BATS_TMPDIR}/passwd.out" "${BATS_TMPDIR}/luks.out"
rm -rf "${BATS_TMPDIR}/luks_policy.out" "${BATS_TMPDIR}/passwd_policy.out"
}

function teardown() {
common_teardown
rm -rf "${BATS_TMPDIR}/passwd.out" "${BATS_TMPDIR}/luks.out"
rm -rf "${BATS_TMPDIR}/luks_policy.out" "${BATS_TMPDIR}/passwd_policy.out"
}

@test "Generate a policy" {
trust tpm-policy-gen --passwd-pcr7-file sample1/pcr7-tpm.bin \
--production-pcr7-file sample1/pcr7-prod.bin \
--passwd-policy-file sample1/passwd.out \
--luks-policy-file sample1/luks.out
diff sample1/passwd.out sample1/passwd.policy
diff sample1/luks.out sample1/luks.policy
trust tpm-policy-gen --pcr7-tpm "${BATS_TEST_DIRNAME}/sample1/pcr7-tpm.bin" \
--pcr7-production "${BATS_TEST_DIRNAME}/sample1/pcr7-prod.bin" \
--passwd-policy-file "${BATS_TMPDIR}/passwd.out" \
--luks-policy-file "${BATS_TMPDIR}/luks.out" \
--policy-version 0001
diff "${BATS_TMPDIR}/passwd.out" "${BATS_TEST_DIRNAME}/sample1/passwd.policy"
diff "${BATS_TMPDIR}/luks.out" "${BATS_TEST_DIRNAME}/sample1/luks.policy"
}

@test "Generate a policy using defaults" {
current_dir=${PWD}; cd "${BATS_TMPDIR}"
trust tpm-policy-gen --pcr7-tpm "${BATS_TEST_DIRNAME}/sample1/pcr7-tpm.bin" \
--pcr7-production "${BATS_TEST_DIRNAME}/sample1/pcr7-prod.bin"
cd $current_dir
diff "${BATS_TMPDIR}/passwd_policy.out" "${BATS_TEST_DIRNAME}/sample1/passwd.policy"
diff "${BATS_TMPDIR}/luks_policy.out" "${BATS_TEST_DIRNAME}/sample1/luks.policy"
}
Binary file modified tests/sample1/luks.policy
Binary file not shown.