]> git.sur5r.net Git - u-boot/blob - lib/efi_selftest/efi_selftest_variables.c
efi_selftest: check for buffer overflow in efi_get_variable
[u-boot] / lib / efi_selftest / efi_selftest_variables.c
1 // SPDX-License-Identifier: GPL-2.0+
2 /*
3  * efi_selftest_variables
4  *
5  * Copyright (c) 2018 Heinrich Schuchardt <xypron.glpk@gmx.de>
6  *
7  * This unit test checks the following protocol services:
8  * ConnectController, DisconnectController,
9  * InstallProtocol, ReinstallProtocol, UninstallProtocol,
10  * OpenProtocol, CloseProtcol, OpenProtocolInformation
11  */
12
13 #include <efi_selftest.h>
14
15 #define EFI_ST_MAX_DATA_SIZE 16
16 #define EFI_ST_MAX_VARNAME_SIZE 40
17
18 static struct efi_boot_services *boottime;
19 static struct efi_runtime_services *runtime;
20 static efi_guid_t guid_vendor0 =
21         EFI_GUID(0x67029eb5, 0x0af2, 0xf6b1,
22                  0xda, 0x53, 0xfc, 0xb5, 0x66, 0xdd, 0x1c, 0xe6);
23 static efi_guid_t guid_vendor1 =
24         EFI_GUID(0xff629290, 0x1fc1, 0xd73f,
25                  0x8f, 0xb1, 0x32, 0xf9, 0x0c, 0xa0, 0x42, 0xea);
26
27 /*
28  * Setup unit test.
29  *
30  * @handle      handle of the loaded image
31  * @systable    system table
32  */
33 static int setup(const efi_handle_t img_handle,
34                  const struct efi_system_table *systable)
35 {
36         boottime = systable->boottime;
37         runtime = systable->runtime;
38
39         return EFI_ST_SUCCESS;
40 }
41
42 /*
43  * Execute unit test.
44  */
45 static int execute(void)
46 {
47         efi_status_t ret;
48         efi_uintn_t len;
49         u32 attr;
50         u8 v[16] = {0x5d, 0xd1, 0x5e, 0x51, 0x5a, 0x05, 0xc7, 0x0c,
51                     0x35, 0x4a, 0xae, 0x87, 0xa5, 0xdf, 0x0f, 0x65,};
52         u8 data[EFI_ST_MAX_DATA_SIZE];
53         u16 varname[EFI_ST_MAX_VARNAME_SIZE];
54         int flag;
55         efi_guid_t guid;
56         u64 max_storage, rem_storage, max_size;
57
58         ret = runtime->query_variable_info(EFI_VARIABLE_BOOTSERVICE_ACCESS,
59                                            &max_storage, &rem_storage,
60                                            &max_size);
61         if (ret != EFI_SUCCESS) {
62                 efi_st_todo("QueryVariableInfo failed\n");
63         } else if (!max_storage || !rem_storage || !max_size) {
64                 efi_st_error("QueryVariableInfo: wrong info\n");
65                 return EFI_ST_FAILURE;
66         }
67         /* Set variable 0 */
68         ret = runtime->set_variable(L"efi_st_var0", &guid_vendor0,
69                                     EFI_VARIABLE_BOOTSERVICE_ACCESS,
70                                     3, v + 4);
71         if (ret != EFI_SUCCESS) {
72                 efi_st_error("SetVariable failed\n");
73                 return EFI_ST_FAILURE;
74         }
75         data[3] = 0xff;
76         len = 3;
77         ret = runtime->get_variable(L"efi_st_var0", &guid_vendor0,
78                                     &attr, &len, data);
79         if (ret != EFI_SUCCESS) {
80                 efi_st_error("GetVariable failed\n");
81                 return EFI_ST_FAILURE;
82         }
83         if (efi_st_memcmp(data, v + 4, 3)) {
84                 efi_st_error("GetVariable returned wrong value\n");
85                 return EFI_ST_FAILURE;
86         }
87         if (data[3] != 0xff) {
88                 efi_st_error("GetVariable wrote past the end of the buffer\n");
89                 return EFI_ST_FAILURE;
90         }
91         /* Set variable 1 */
92         ret = runtime->set_variable(L"efi_st_var1", &guid_vendor1,
93                                     EFI_VARIABLE_BOOTSERVICE_ACCESS,
94                                     8, v);
95         if (ret != EFI_SUCCESS) {
96                 efi_st_error("SetVariable failed\n");
97                 return EFI_ST_FAILURE;
98         }
99         len = EFI_ST_MAX_DATA_SIZE;
100         ret = runtime->get_variable(L"efi_st_var1", &guid_vendor1,
101                                     &attr, &len, data);
102         if (ret != EFI_SUCCESS) {
103                 efi_st_error("GetVariable failed\n");
104                 return EFI_ST_FAILURE;
105         }
106         if (len != 8) {
107                 efi_st_error("GetVariable returned wrong length %u\n",
108                              (unsigned int)len);
109                 return EFI_ST_FAILURE;
110         }
111         if (efi_st_memcmp(data, v, 8)) {
112                 efi_st_error("GetVariable returned wrong value\n");
113                 return EFI_ST_FAILURE;
114         }
115         /* Append variable 1 */
116         ret = runtime->set_variable(L"efi_st_var1", &guid_vendor1,
117                                     EFI_VARIABLE_BOOTSERVICE_ACCESS |
118                                     EFI_VARIABLE_APPEND_WRITE,
119                                     7, v + 8);
120         if (ret != EFI_SUCCESS) {
121                 efi_st_error("SetVariable failed\n");
122                 return EFI_ST_FAILURE;
123         }
124         len = EFI_ST_MAX_DATA_SIZE;
125         ret = runtime->get_variable(L"efi_st_var1", &guid_vendor1,
126                                     &attr, &len, data);
127         if (ret != EFI_SUCCESS) {
128                 efi_st_error("GetVariable failed\n");
129                 return EFI_ST_FAILURE;
130         }
131         if (len != 15)
132                 efi_st_todo("GetVariable returned wrong length %u\n",
133                             (unsigned int)len);
134         if (efi_st_memcmp(data, v, len))
135                 efi_st_todo("GetVariable returned wrong value\n");
136         /* Enumerate variables */
137         boottime->set_mem(&guid, 16, 0);
138         *varname = 0;
139         flag = 0;
140         for (;;) {
141                 len = EFI_ST_MAX_VARNAME_SIZE;
142                 ret = runtime->get_next_variable_name(&len, varname, &guid);
143                 if (ret == EFI_NOT_FOUND)
144                         break;
145                 if (ret != EFI_SUCCESS) {
146                         efi_st_todo("GetNextVariableName failed\n");
147                         break;
148                 }
149                 if (!efi_st_memcmp(&guid, &guid_vendor0, sizeof(efi_guid_t)) &&
150                     !efi_st_strcmp_16_8(varname, "efi_st_var0"))
151                         flag |= 2;
152                 if (!efi_st_memcmp(&guid, &guid_vendor1, sizeof(efi_guid_t)) &&
153                     !efi_st_strcmp_16_8(varname, "efi_st_var1"))
154                         flag |= 2;
155         }
156         if (flag != 3)
157                 efi_st_todo(
158                         "GetNextVariableName did not return all variables\n");
159         /* Delete variable 1 */
160         ret = runtime->set_variable(L"efi_st_var1", &guid_vendor1,
161                                     0, 0, NULL);
162         if (ret != EFI_SUCCESS) {
163                 efi_st_error("SetVariable failed\n");
164                 return EFI_ST_FAILURE;
165         }
166         len = EFI_ST_MAX_DATA_SIZE;
167         ret = runtime->get_variable(L"efi_st_var1", &guid_vendor1,
168                                     &attr, &len, data);
169         if (ret != EFI_NOT_FOUND) {
170                 efi_st_error("Variable was not deleted\n");
171                 return EFI_ST_FAILURE;
172         }
173         /* Delete variable 0 */
174         ret = runtime->set_variable(L"efi_st_var0", &guid_vendor0,
175                                     0, 0, NULL);
176         if (ret != EFI_SUCCESS) {
177                 efi_st_error("SetVariable failed\n");
178                 return EFI_ST_FAILURE;
179         }
180         len = EFI_ST_MAX_DATA_SIZE;
181         ret = runtime->get_variable(L"efi_st_var0", &guid_vendor0,
182                                     &attr, &len, data);
183         if (ret != EFI_NOT_FOUND) {
184                 efi_st_error("Variable was not deleted\n");
185                 return EFI_ST_FAILURE;
186         }
187
188         return EFI_ST_SUCCESS;
189 }
190
191 EFI_UNIT_TEST(variables) = {
192         .name = "variables",
193         .phase = EFI_EXECUTE_BEFORE_BOOTTIME_EXIT,
194         .setup = setup,
195         .execute = execute,
196 };