tpm2-software / tpm2-openssl

OpenSSL Provider for TPM2 integration
BSD 3-Clause "New" or "Revised" License
82 stars 36 forks source link

Tests are failing on ubuntu 24.04 #119

Open lmussier opened 1 month ago

lmussier commented 1 month ago

Hi,

Pretty sure it is not directly linked to the provider. I'm willing to run the container tests like described in the doc

Podman 4.9.3 Ubuntu 24.04 tpm2-openssl @ commit be35c35ace48647bb73ae5028db7e8caaccd038d (head of master)

And get the following error :

lmussier@lmussier-VMware:~/workspace/tpm2-openssl$ podman run -it --name tpm2-openssl-1 -v "$(pwd):/build:Z" --rm --userns=keep-id \
       "localhost/tpm2-openssl-build-$TEST_CONTAINER" /bin/bash
lmussier@24c3d07ce4a4:/$ /build/test/run-with-simulator
configure.ac:69: warning: AC_C_BIGENDIAN should be used with AC_CONFIG_HEADERS
Makefile.am:134: warning: AM_DISTCHECK_CONFIGURE_FLAGS was already defined in condition AUTOCONF_CODE_COVERAGE_2019_01_06 and CODE_COVERAGE_ENABLED, which is included in condition TRUE ...
aminclude_static.am:100: ... 'AM_DISTCHECK_CONFIGURE_FLAGS' previously defined here
Makefile.am:34:   'aminclude_static.am' included from here
checking for a BSD-compatible install... /usr/bin/install -c
checking whether build environment is sane... yes
checking for a race-free mkdir -p... /usr/bin/mkdir -p
checking for gawk... no
checking for mawk... mawk
checking whether make sets $(MAKE)... yes
checking whether make supports nested variables... yes
checking whether make supports nested variables... (cached) yes
checking whether to build with code coverage support... no
checking build system type... x86_64-pc-linux-gnu
checking host system type... x86_64-pc-linux-gnu
checking whether to enable debugging... info
checking for gcc... gcc
checking whether the C compiler works... yes
checking for C compiler default output file name... a.out
checking for suffix of executables... 
checking whether we are cross compiling... no
checking for suffix of object files... o
checking whether the compiler supports GNU C... yes
checking whether gcc accepts -g... yes
checking for gcc option to enable C11 features... none needed
checking whether gcc understands -c and -o together... yes
checking whether make supports the include directive... yes (GNU style)
checking dependency style of gcc... gcc3
checking for stdio.h... yes
checking for stdlib.h... yes
checking for string.h... yes
checking for inttypes.h... yes
checking for stdint.h... yes
checking for strings.h... yes
checking for sys/stat.h... yes
checking for sys/types.h... yes
checking for unistd.h... yes
checking whether byte ordering is bigendian... no
checking how to print strings... printf
checking for a sed that does not truncate output... /usr/bin/sed
checking for grep that handles long lines and -e... /usr/bin/grep
checking for egrep... /usr/bin/grep -E
checking for fgrep... /usr/bin/grep -F
checking for ld used by gcc... /usr/bin/ld
checking if the linker (/usr/bin/ld) is GNU ld... yes
checking for BSD- or MS-compatible name lister (nm)... /usr/bin/nm -B
checking the name lister (/usr/bin/nm -B) interface... BSD nm
checking whether ln -s works... yes
checking the maximum length of command line arguments... 1572864
checking how to convert x86_64-pc-linux-gnu file names to x86_64-pc-linux-gnu format... func_convert_file_noop
checking how to convert x86_64-pc-linux-gnu file names to toolchain format... func_convert_file_noop
checking for /usr/bin/ld option to reload object files... -r
checking for objdump... objdump
checking how to recognize dependent libraries... pass_all
checking for dlltool... no
checking how to associate runtime and link libraries... printf %s\n
checking for ar... ar
checking for archiver @FILE support... @
checking for strip... strip
checking for ranlib... ranlib
checking command to parse /usr/bin/nm -B output from gcc object... ok
checking for sysroot... no
checking for a working dd... /usr/bin/dd
checking how to truncate binary pipes... /usr/bin/dd bs=4096 count=1
checking for mt... no
checking if : is a manifest tool... no
checking for dlfcn.h... yes
checking for objdir... .libs
checking if gcc supports -fno-rtti -fno-exceptions... no
checking for gcc option to produce PIC... -fPIC -DPIC
checking if gcc PIC flag -fPIC -DPIC works... yes
checking if gcc static flag -static works... yes
checking if gcc supports -c -o file.o... yes
checking if gcc supports -c -o file.o... (cached) yes
checking whether the gcc linker (/usr/bin/ld -m elf_x86_64) supports shared libraries... yes
checking whether -lc should be explicitly linked in... no
checking dynamic linker characteristics... GNU/Linux ld.so
checking how to hardcode library paths into programs... immediate
checking whether stripping libraries is possible... yes
checking if libtool supports shared libraries... yes
checking whether to build shared libraries... yes
checking whether to build static libraries... no
checking for pkg-config... /usr/bin/pkg-config
checking pkg-config is at least version 0.25... yes
checking for libcrypto >= 3.0.0... yes
checking for tss2-esys >= 3.2.0... yes
checking for tss2-tctildr... yes
checking for tss2-rc >= 3.2.0... yes
checking for library containing cbrt... -lm
checking that generated files are newer than configure... done
configure: creating ./config.status
config.status: creating Makefile
config.status: executing depfiles commands
config.status: executing libtool commands
  CC       src/tpm2_la-tpm2-provider.lo
  CC       src/tpm2_la-tpm2-provider-core.lo
  CC       src/tpm2_la-tpm2-provider-types.lo
  CC       src/tpm2_la-tpm2-provider-x509.lo
  CC       src/tpm2_la-tpm2-provider-rand.lo
  CC       src/tpm2_la-tpm2-provider-pkey.lo
  CC       src/tpm2_la-tpm2-provider-store-handle.lo
  CC       src/tpm2_la-tpm2-provider-decoder-der.lo
  CC       src/tpm2_la-tpm2-provider-decoder-tss2.lo
  CC       src/tpm2_la-tpm2-provider-encoder.lo
  CC       src/tpm2_la-tpm2-provider-keymgmt-rsa.lo
  CC       src/tpm2_la-tpm2-provider-keymgmt-ec.lo
  CC       src/tpm2_la-tpm2-provider-keyexch.lo
  CC       src/tpm2_la-tpm2-provider-asymcipher-rsa.lo
  CC       src/tpm2_la-tpm2-provider-digest.lo
  CC       src/tpm2_la-tpm2-provider-signature.lo
  CC       src/tpm2_la-tpm2-provider-cipher.lo
  CCLD     tpm2.la
---> starting dbus daemon
---> starting swtpm simulator
swtpm: SWTPM_NVRAM_Lock_Lockfile: Could not open lockfile: Permission denied
swtpm: Error: Could not initialize libtpms.
Error: Port conflict? Cleaning up PID: 5536
Starting tpm2 simulator failed (swtpm)

For the context I'm comming from here https://github.com/stefanberger/swtpm/discussions/866, the goal is to be able emulate a tpm inside a container the smothest way possible. These tests sound promising :)

Is there a new thing to do on 24.04 to be able to run these tests?

joholl commented 1 month ago

Could this be related to https://github.com/stefanberger/swtpm/issues/763?

afreof commented 1 month ago

Quickly tested this on a Fedora 40 host using an Ubuntu 24.04 container. This works. To make it reproducible I added one more commit to my pull request: https://github.com/tpm2-software/tpm2-openssl/pull/122