driver: Advance the eRoT's own floor when the update agent asks - #511
Merged
Merged
Conversation
chrysh
force-pushed
the
commit-self-floor
branch
2 times, most recently
from
September 27, 2026 07:40
f827ce5 to
9a546b3
Compare
chrysh
force-pushed
the
commit-self-floor
branch
from
September 27, 2026 08:06
9a546b3 to
b963a8c
Compare
chrysh
force-pushed
the
commit-self-floor
branch
3 times, most recently
from
October 4, 2026 09:14
464d340 to
96e65f9
Compare
The counterpart to settle_self_update's hold: commit_self_svn_floor reads the SVN the confirmed session recorded, advances the eRoT's floor, and closes the session. The caller runs it when the FD reports SvnCommitPending, and answers the update agent with what comes back: done on Ok, refused on Err. The request's own SVN is not read; the session is what says which SVN the floor may take. Refused unless the session is confirmed and still open, so a request with nothing behind it cannot move the floor: no image has proven itself at that SVN. Safe to repeat across the crash window between the advance and the close. advance is a no-op at or below the floor, so a request repeated after a crash finishes the close. A repeat after the session is closed is refused, so an answer that never reached the update agent leaves its retry refused with the floor already where it asked. A floor that cannot take the SVN leaves the session open, so the update agent's next request tries again instead of losing the advance. Takes the session and the floor directly, as settle_self_update does. Neither is board wiring yet. Assisted-by: Claude
chrysh
force-pushed
the
commit-self-floor
branch
from
October 4, 2026 09:50
96e65f9 to
db0baad
Compare
chrysh
marked this pull request as ready for review
October 4, 2026 09:51
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rebased onto
ocp-global-demo-wipnow that #509 merged, and reshaped to match it: #509 landed as the free functionsettle_self_update, not aPlatformDrivermethod, so this is a free function too. One commit now, no stack note.The counterpart to #509's hold.
commit_self_svn_floor(session, floor)takes the SVN the confirmed session recorded, advances the eRoT's own floor, and closes the session. The caller runs it when the FD reportsSvnCommitPending, then answers withperform_svn_commitonOkorreject_svn_commitonErr. That is the settled policy: the floor never moves at activation, only when the update agent asks with UpdateSecurityRevision after a trial boot.Refused unless the session is confirmed and still open, so a request with nothing behind it cannot move the floor: no image has proven itself at that SVN. Faults come back as
CommitFloorError, carrying the session's or the floor's own error the waySettleErrordoes.Safe to repeat across the crash window between the advance and the close:
advanceis a no-op at or below the floor, so a request repeated after a crash finishes the close. Once the session is closed a repeat is refused, so an answer that never reached the update agent leaves its retry refused, with the floor already where it asked. Whether the caller should answer that retry withperform_svn_commitanyway is the same open question as a lost IPC response.A floor that cannot take the SVN leaves the session open, so the next request tries again rather than losing the advance.
This completes the openprot half of decision 4 (hold at boot, advance on 0x22). The IPC ops already exist:
SvnCommitPending,perform_svn_commitandreject_svn_commitinpldm/apiand #510's client. What is still missing is on the pldm-lib side: the FdOps callback that turns a received UpdateSecurityRevision into that pending status. pldm-lib #22 landed the message itself.Not here: the board wiring, and the event-loop glue that polls
QueryStatus, seesSvnCommitPendingand routes it here. Also not here: any check that the SVN the request names matches the session's. The session is authoritative and the request's SVN is ignored; if a mismatch should be rejected, that belongs in the FdOps callback.