Skip to content

Commit bc20b84

Browse files
uglyoldbobFirstyear
authored andcommitted
Update documentation
Update bundled documentation and include macos support Signed-off-by: William Brown <william@blackhats.net.au>
1 parent 0074cdc commit bc20b84

File tree

3 files changed

+92
-16
lines changed

3 files changed

+92
-16
lines changed

tss-esapi-sys/Cargo.toml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ cfg-if = "1.0.0"
2222
semver = "1.0.7"
2323

2424
[target.'cfg(windows)'.build-dependencies]
25-
msbuild = { git = "https://github.com/uglyoldbob/msbuild.git", optional = true }
25+
msbuild = { version = "0.1.0", optional = true }
2626
winreg = {version = "0.52", optional = true }
2727

2828
[features]

tss-esapi-sys/README.md

Lines changed: 51 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -13,12 +13,12 @@ interface to Rust to [TSS](https://github.com/tpm2-software/tpm2-tss).
1313

1414
This crate exposes an interface for the TSS Enhanced System API and thus
1515
links to libraries that expose this interface. In order to allow proper use
16-
of the ESAPI, this FFI layer includes bindings to TCTI and MU headers, and
16+
of the ESAPI, this FFI layer includes bindings to TCTI and MU headers, and
1717
must therefore link to all of them at build time.
1818

1919
The paths to the libraries are discovered using `pkg-config` - make sure they
20-
are discoverable in this way on your system. Our build script looks for
21-
`tss2-esys`, `tss2-tctildr` and `tss2-mu`. A minimum version of `3.2.2` is
20+
are discoverable in this way on your system. Our build script looks for
21+
`tss2-esys`, `tss2-tctildr` and `tss2-mu`. A minimum version of `3.2.2` is
2222
required for all of them.
2323

2424
Having installed the open-source implementation libraries at `/usr/local/lib` (by default), it
@@ -41,9 +41,56 @@ available, feel free to raise a Pull Request to add it or to use build-time
4141
generation of bindings. All the committed bindings **MUST** be generated from
4242
the library version found under the `vendor` submodule.
4343

44+
## Bundling TPM-TSS
45+
46+
tpm-tss is used by this library to communicate with TPMs. If this library
47+
is not available on your system you may optionally bundle (vendor) tpm-tss
48+
during builds. tpm-tss can be provided from a local source path with the
49+
environment variable `TPM_TSS_SOURCE_PATH` or it will be retrieved from
50+
github during the build.
51+
52+
To enable this feature:
53+
54+
```bash
55+
cargo build --features=bundled
56+
```
57+
58+
```bash
59+
TPM_TSS_SOURCE_PATH=/path/to/tpm-tss cargo build --features=bundled
60+
```
61+
62+
If using this feature from an external project
63+
64+
```
65+
tss-esapi-sys = { version = "...", features = "bundled" }
66+
```
67+
68+
## Windows
69+
70+
Compiling for windows requires a bit of setup to work with the bundled feature.
71+
72+
* Openssl must be installed to a non-standard location at C:\OpenSSL-v11-Win64
73+
* Visual studio 2017 must be installed with the Clang/C2 experimental component,
74+
and windows sdk 10.0.17134.0.
75+
76+
## MacOS
77+
78+
Compiling on MacOS requires the bundling feature. This requires dependencies
79+
from brew.
80+
81+
```bashbre
82+
brew install autoconf autoconf-archive automake json-c libtool m4 pkg-config
83+
```
84+
85+
Optionally you may require these libraries for certain classes of TPM transport
86+
87+
```
88+
brew install libftdi
89+
```
90+
4491
## Cross compiling
4592

46-
Cross-compilation can be done as long as you have on your build system the TSS
93+
Cross-compilation can be done as long as you have on your build system the TSS
4794
libraries compiled for your target system of choice. We rely on `pkg-config` to
4895
identify the libraries which we link against. Installing `tpm2-tss` does yield
4996
`.pc` files which can be used for this purpose, but depending on the exact build

tss-esapi-sys/build.rs

Lines changed: 40 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -43,6 +43,7 @@ pub mod target {
4343
match (target.architecture, target.operating_system) {
4444
(Architecture::Arm(_), OperatingSystem::Linux)
4545
| (Architecture::Aarch64(_), OperatingSystem::Linux)
46+
| (Architecture::Aarch64(_), OperatingSystem::Darwin)
4647
| (Architecture::X86_64, OperatingSystem::Darwin)
4748
| (Architecture::X86_64, OperatingSystem::Linux) => {}
4849
(arch, os) => {
@@ -77,15 +78,20 @@ pub mod tpm2_tss {
7778
}
7879

7980
impl Installation {
81+
/// Return an optional list of clang arguments that are platform specific
82+
#[cfg(feature = "bundled")]
8083
fn platform_args() -> Option<Vec<String>> {
8184
cfg_if::cfg_if! {
8285
if #[cfg(windows)] {
8386
let mut clang_args: Vec<String> = Vec::new();
8487
let hklm = winreg::RegKey::predef(winreg::enums::HKEY_LOCAL_MACHINE);
88+
// Find the windows sdk path from the windows registry
8589
let sdk_entry = hklm.open_subkey("SOFTWARE\\WOW6432Node\\Microsoft\\Microsoft SDKs\\Windows\\v10.0").unwrap();
90+
// add relevant paths to get to the windows 10.0.17134.0 sdk, which tpm2-tss uses on windows.
8691
let installation_path: String = sdk_entry.get_value("InstallationFolder").unwrap();
8792
let ip_pb = PathBuf::from(installation_path).join("Include");
8893
let windows_sdk = ip_pb.join("10.0.17134.0");
94+
// Add paths required for bindgen to find all required headers
8995
clang_args.push(format!("-I{}", windows_sdk.join("ucrt").display()));
9096
clang_args.push(format!("-I{}", windows_sdk.join("um").display()));
9197
clang_args.push(format!("-I{}", windows_sdk.join("shared").display()));
@@ -125,32 +131,56 @@ pub mod tpm2_tss {
125131
repo_path
126132
}
127133

128-
#[cfg(feature = "bundled")]
134+
#[cfg(all(feature = "bundled",not(windows)))]
129135
fn compile_with_autotools(p: PathBuf) -> PathBuf {
130136
let output1 = std::process::Command::new("./bootstrap")
131137
.current_dir(&p)
132138
.output()
133139
.expect("bootstrap script failed");
134140
let status = output1.status;
135141
if !status.success() {
136-
panic!("bootstrap script failed with {}:\n{:?}", status, output1);
142+
panic!("{:?}/bootstrap script failed with {}:\n{:?}", p, status, output1);
137143
}
138144

139145
let mut config = autotools::Config::new(p);
140-
config.fast_build(true).reconf("-ivf").build()
146+
config
147+
// Force configuration of the autotools env
148+
.reconf("-fiv")
149+
// skip ./configure if no parameter changes are made
150+
.fast_build(true)
151+
.enable("esys", None)
152+
// Disable fapi as we only use esys
153+
.disable("fapi", None)
154+
.disable("fapi-async-tests", None)
155+
// Disable integration tests
156+
.disable("integration", None)
157+
// Don't allow weak crypto
158+
.disable("weakcrypto", None)
159+
.build()
141160
}
142161

143162
#[cfg(feature = "bundled")]
144163
/// Uses a bundled build for an installation
145164
pub fn bundled() -> Self {
146165
use std::io::Write;
147166
let out_path = std::env::var("OUT_DIR").expect("No output directory given");
148-
let source_path = Self::fetch_source(
149-
out_path,
150-
"tpm2-tss",
151-
"https://github.com/tpm2-software/tpm2-tss.git",
152-
MINIMUM_VERSION,
153-
);
167+
let source_path = if let Ok(tpm_tss_source) = std::env::var("TPM_TSS_SOURCE_PATH") {
168+
eprintln!("using local tpm2-tss from {}", tpm_tss_source);
169+
let Ok(source_path) = PathBuf::from(tpm_tss_source).canonicalize() else {
170+
panic!("Unable to canonicalize tpm2-tss source path. Does the source path exist?");
171+
};
172+
173+
source_path
174+
} else {
175+
eprintln!("using remote tpm2-tss from https://github.com/tpm2-software/tpm2-tss.git");
176+
Self::fetch_source(
177+
out_path,
178+
"tpm2-tss",
179+
"https://github.com/tpm2-software/tpm2-tss.git",
180+
MINIMUM_VERSION,
181+
)
182+
};
183+
154184
let version_file_name = source_path.join("VERSION");
155185
let mut version_file = std::fs::File::create(version_file_name)
156186
.expect("Unable to create version file for tpm2-tss");
@@ -332,7 +362,7 @@ pub mod tpm2_tss {
332362
let build_string = match profile.as_str() {
333363
"debug" => "Debug",
334364
"release" => "Release",
335-
_ => panic!("Unknown cargo profile:"),
365+
_ => panic!("Unknown cargo profile: {}", profile),
336366
};
337367
let mut source_path = self
338368
.tss2_esys
@@ -342,7 +372,6 @@ pub mod tpm2_tss {
342372
source_path.pop();
343373
source_path.pop();
344374
source_path.pop();
345-
println!("Source path is {}", source_path.display());
346375
println!(
347376
"cargo:rustc-link-search=dylib={}",
348377
source_path.join("x64").join(build_string).display()

0 commit comments

Comments
 (0)