Skip to content

driver: Advance the eRoT's own floor when the update agent asks - #511

Merged
chrysh merged 1 commit into
OpenPRoT:ocp-global-demo-wipfrom
9elements:commit-self-floor
Oct 4, 2026
Merged

chrysh merged 1 commit into
OpenPRoT:ocp-global-demo-wipfrom
9elements:commit-self-floor

Conversation

@chrysh

@chrysh chrysh commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Rebased onto ocp-global-demo-wip now that #509 merged, and reshaped to match it: #509 landed as the free function settle_self_update, not a PlatformDriver method, so this is a free function too. One commit now, no stack note.

The counterpart to #509's hold. commit_self_svn_floor(session, floor) takes the SVN the confirmed session recorded, advances the eRoT's own floor, and closes the session. The caller runs it when the FD reports SvnCommitPending, then answers with perform_svn_commit on Ok or reject_svn_commit on Err. That is the settled policy: the floor never moves at activation, only when the update agent asks with UpdateSecurityRevision after a trial boot.

Refused unless the session is confirmed and still open, so a request with nothing behind it cannot move the floor: no image has proven itself at that SVN. Faults come back as CommitFloorError, carrying the session's or the floor's own error the way SettleError does.

Safe to repeat across the crash window between the advance and the close: advance is a no-op at or below the floor, so a request repeated after a crash finishes the close. Once the session is closed a repeat is refused, so an answer that never reached the update agent leaves its retry refused, with the floor already where it asked. Whether the caller should answer that retry with perform_svn_commit anyway is the same open question as a lost IPC response.

A floor that cannot take the SVN leaves the session open, so the next request tries again rather than losing the advance.

This completes the openprot half of decision 4 (hold at boot, advance on 0x22). The IPC ops already exist: SvnCommitPending, perform_svn_commit and reject_svn_commit in pldm/api and #510's client. What is still missing is on the pldm-lib side: the FdOps callback that turns a received UpdateSecurityRevision into that pending status. pldm-lib #22 landed the message itself.

Not here: the board wiring, and the event-loop glue that polls QueryStatus, sees SvnCommitPending and routes it here. Also not here: any check that the SVN the request names matches the session's. The session is authoritative and the request's SVN is ignored; if a mismatch should be rejected, that belongs in the FdOps callback.

@chrysh
chrysh force-pushed the commit-self-floor branch 2 times, most recently from f827ce5 to 9a546b3 Compare September 27, 2026 07:40
@chrysh chrysh closed this Sep 29, 2026
@chrysh
chrysh deleted the commit-self-floor branch September 29, 2026 11:10
@chrysh
chrysh restored the commit-self-floor branch September 29, 2026 12:27
@chrysh chrysh reopened this Sep 29, 2026
@chrysh
chrysh force-pushed the commit-self-floor branch 3 times, most recently from 464d340 to 96e65f9 Compare October 4, 2026 09:14
The counterpart to settle_self_update's hold: commit_self_svn_floor reads
the SVN the confirmed session recorded, advances the eRoT's floor, and
closes the session. The caller runs it when the FD reports
SvnCommitPending, and answers the update agent with what comes back: done
on Ok, refused on Err. The request's own SVN is not read; the session is
what says which SVN the floor may take.

Refused unless the session is confirmed and still open, so a request with
nothing behind it cannot move the floor: no image has proven itself at
that SVN.

Safe to repeat across the crash window between the advance and the close.
advance is a no-op at or below the floor, so a request repeated after a
crash finishes the close. A repeat after the session is closed is refused,
so an answer that never reached the update agent leaves its retry refused
with the floor already where it asked. A floor that cannot take the SVN
leaves the session open, so the update agent's next request tries again
instead of losing the advance.

Takes the session and the floor directly, as settle_self_update does.
Neither is board wiring yet.

Assisted-by: Claude
@chrysh
chrysh force-pushed the commit-self-floor branch from 96e65f9 to db0baad Compare October 4, 2026 09:50
@chrysh
chrysh marked this pull request as ready for review October 4, 2026 09:51
@chrysh
chrysh merged commit 99f146e into OpenPRoT:ocp-global-demo-wip Oct 4, 2026
2 checks passed
@chrysh
chrysh deleted the commit-self-floor branch October 4, 2026 09:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant