From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from list by lists.gnu.org with archive (Exim 4.90_1) id 1kkq82-0004Zp-CM for mharc-grub-devel@gnu.org; Thu, 03 Dec 2020 10:02:42 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]:46012) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1kkq7z-0004YP-JK for grub-devel@gnu.org; Thu, 03 Dec 2020 10:02:39 -0500 Received: from us-smtp-delivery-124.mimecast.com ([216.205.24.124]:28870) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.90_1) (envelope-from ) id 1kkq7x-00025j-RV for grub-devel@gnu.org; Thu, 03 Dec 2020 10:02:39 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1607007757; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=lM+R+lvhDZHmhameOzzFyPpunHOqEqH9thzdsq+c92M=; b=Qtr//Bee/qLelm7nnran+4Y/p+090ZAuGDkyh/wwLNA+Yplq1S9oCFlsHHnwlc7UijTyKh uUq+C2ysLzSo0gWVuIfjsAbxet2GvG6cfDUWUgSZXgeqs0baZex205HDPdwvaz/3MZUqFR nO6Vpxu5XQ9pQTKYKAJmPoF5Uf+iHcM= Received: from mail-wr1-f72.google.com (mail-wr1-f72.google.com [209.85.221.72]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-131-aLiVBVzpM5mt-n06XwEFFg-1; Thu, 03 Dec 2020 10:02:35 -0500 X-MC-Unique: aLiVBVzpM5mt-n06XwEFFg-1 Received: by mail-wr1-f72.google.com with SMTP id x10so1367111wrs.2 for ; Thu, 03 Dec 2020 07:02:34 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=lM+R+lvhDZHmhameOzzFyPpunHOqEqH9thzdsq+c92M=; b=dB4vJCLI8FSM4jK7XvHd0wAI7hoLrNFgoKBOv7gnLUG7JflwoWiH6luhIm+86Gt4EP W1S2wvdLq1thLgqF/WJ6TdELtFObCYPUrkKlq8VQRhlPnmb1KEBquaIM4fhtD1Nqhl04 yo2YjZZDK3NBq4y/6WtVhYTI0/YxVgn/WJNjwuNGESlk6qb2DxPahijWGDCQdmV3ORiq 3s6lIJ+pp1zPi3d+Ud0ay2tyfiGYajnmrD6T6Kggg4zkH5BGbGxDtiNOJnxiCthCLi0t hU3rRdNo/+k1Qdcw3Hl7iLzV8MBWQ75fw/s6rNEv3XeL6t3Ta2WZRkdP6R8zD8iBiLsp BP0g== X-Gm-Message-State: AOAM533aez61ZunkGflwf9LCfcY4g0G9RtQnFNvGu0dTWQ/2ckZhZIhv anc0vvYItQ7l8uRLtAWh9EEw/6XIXnOFGAvJF/dM59l8q2Yh4V3sDEvmu0SEoFYX6dCfA68iLpi S6Chu+OUo7WJiUxhsEHUL+jSBqizU72dF9yHcZKLpXfppf9HWWyysibRVaEKrJw== X-Received: by 2002:a5d:528a:: with SMTP id c10mr4086584wrv.270.1607007752903; Thu, 03 Dec 2020 07:02:32 -0800 (PST) X-Google-Smtp-Source: ABdhPJyicYjdiEtSZu5OCcekxlsk9I2n5WUFLJZpsppdbeHGy0KkS7zPNmriMVlKKA5swhDfAcpU9Q== X-Received: by 2002:a5d:528a:: with SMTP id c10mr4086551wrv.270.1607007752603; Thu, 03 Dec 2020 07:02:32 -0800 (PST) Received: from minerva.redhat.com ([92.176.231.106]) by smtp.gmail.com with ESMTPSA id n128sm1896759wmb.46.2020.12.03.07.02.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Dec 2020 07:02:30 -0800 (PST) From: Javier Martinez Canillas To: grub-devel@gnu.org Cc: Ignat Korchagin , Michael Chang , Peter Jones , Marco A Benatto , Leif Lindholm , Daniel Kiper , Javier Martinez Canillas Subject: [PATCH 9/9] loader/linux: Report the UEFI Secure Boot status to the Linux kernel Date: Thu, 3 Dec 2020 16:01:50 +0100 Message-Id: <20201203150151.848077-10-javierm@redhat.com> X-Mailer: git-send-email 2.28.0 In-Reply-To: <20201203150151.848077-1-javierm@redhat.com> References: <20201203150151.848077-1-javierm@redhat.com> MIME-Version: 1.0 Authentication-Results: relay.mimecast.com; auth=pass smtp.auth=CUSA124A263 smtp.mailfrom=javierm@redhat.com X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-Transfer-Encoding: 8bit Content-Type: text/plain; charset="US-ASCII" Received-SPF: pass client-ip=216.205.24.124; envelope-from=javierm@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -35 X-Spam_score: -3.6 X-Spam_bar: --- X-Spam_report: (-3.6 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.495, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: grub-devel@gnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: The development of GNU GRUB List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 03 Dec 2020 15:02:39 -0000 From: Daniel Kiper Now that the GRUB has a grub_efi_get_secureboot() function to check the UEFI Secure Boot status, use it to report that to the Linux kernel. Signed-off-by: Ignat Korchagin Signed-off-by: Daniel Kiper Signed-off-by: Marco A Benatto Signed-off-by: Javier Martinez Canillas --- grub-core/loader/i386/linux.c | 6 +++++- include/grub/i386/linux.h | 8 ++++++-- 2 files changed, 11 insertions(+), 3 deletions(-) diff --git a/grub-core/loader/i386/linux.c b/grub-core/loader/i386/linux.c index 976af3fae87..d7e68658f43 100644 --- a/grub-core/loader/i386/linux.c +++ b/grub-core/loader/i386/linux.c @@ -46,6 +46,7 @@ GRUB_MOD_LICENSE ("GPLv3+"); #ifdef GRUB_MACHINE_EFI #include +#include #define HAS_VGA_TEXT 0 #define DEFAULT_VIDEO_MODE "auto" #define ACCEPTS_PURE_TEXT 0 @@ -583,6 +584,9 @@ grub_linux_boot (void) grub_efi_uintn_t efi_desc_size; grub_size_t efi_mmap_target; grub_efi_uint32_t efi_desc_version; + + ctx.params->secure_boot = grub_efi_get_secureboot (); + err = grub_efi_finish_boot_services (&efi_mmap_size, efi_mmap_buf, NULL, &efi_desc_size, &efi_desc_version); if (err) @@ -794,7 +798,7 @@ grub_cmd_linux (grub_command_t cmd __attribute__ ((unused)), linux_params.code32_start = prot_mode_target + lh.code32_start - GRUB_LINUX_BZIMAGE_ADDR; linux_params.kernel_alignment = (1 << align); - linux_params.ps_mouse = linux_params.padding10 = 0; + linux_params.ps_mouse = linux_params.padding11 = 0; linux_params.type_of_loader = GRUB_LINUX_BOOT_LOADER_TYPE; /* These two are used (instead of cmd_line_ptr) by older versions of Linux, diff --git a/include/grub/i386/linux.h b/include/grub/i386/linux.h index 6da5f030fd1..eddf9251d9a 100644 --- a/include/grub/i386/linux.h +++ b/include/grub/i386/linux.h @@ -277,7 +277,11 @@ struct linux_kernel_params grub_uint8_t mmap_size; /* 1e8 */ - grub_uint8_t padding9[0x1f1 - 0x1e9]; + grub_uint8_t padding9[0x1ec - 0x1e9]; + + grub_uint8_t secure_boot; /* 1ec */ + + grub_uint8_t padding10[0x1f1 - 0x1ed]; /* Linux setup header copy - BEGIN. */ grub_uint8_t setup_sects; /* The size of the setup in sectors */ @@ -288,7 +292,7 @@ struct linux_kernel_params grub_uint16_t vid_mode; /* Video mode control */ grub_uint16_t root_dev; /* Default root device number */ - grub_uint8_t padding10; /* 1fe */ + grub_uint8_t padding11; /* 1fe */ grub_uint8_t ps_mouse; /* 1ff */ grub_uint16_t jump; /* Jump instruction */ -- 2.28.0