From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from list by lists.gnu.org with archive (Exim 4.90_1) id 1kkq85-0004b0-DU for mharc-grub-devel@gnu.org; Thu, 03 Dec 2020 10:02:45 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]:45984) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1kkq7x-0004YA-Vm for grub-devel@gnu.org; Thu, 03 Dec 2020 10:02:39 -0500 Received: from us-smtp-delivery-124.mimecast.com ([63.128.21.124]:33895) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.90_1) (envelope-from ) id 1kkq7t-00023g-Ee for grub-devel@gnu.org; Thu, 03 Dec 2020 10:02:37 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1607007752; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=jCxL03Rfl2daeYcdqDk+vZXrJYCR0DXFwkjvPqRIv2A=; b=CFjgyUnRNsPAKAWmcqaKFW4jxOksvcKooKl3bQJkKx4j7cFppTlOwM3CXRPXVEy8hgMNo+ S+2WsQt+y2KKmIdTZsesL8SoEL1Ilsg/yz1bgQ9LPkKB8NpL9VGm+HPEcKxTyLTOb7c3Ab DtYmu6woXn5QJxgvUpRPrX0bVie2gqU= Received: from mail-wm1-f69.google.com (mail-wm1-f69.google.com [209.85.128.69]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-398-QaHvIZjNO9iDEnoCClTnrg-1; Thu, 03 Dec 2020 10:02:29 -0500 X-MC-Unique: QaHvIZjNO9iDEnoCClTnrg-1 Received: by mail-wm1-f69.google.com with SMTP id r5so1626362wma.2 for ; Thu, 03 Dec 2020 07:02:29 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=jCxL03Rfl2daeYcdqDk+vZXrJYCR0DXFwkjvPqRIv2A=; b=FH3E4Nz+L/prNTMsGYejHtMTzpIzaCbqz78SqgE5zAhGNjLPP5iByRsPm9wxkf1OuR Y4FfnzkDIOtfhcB9B5shS5s2XhnLIpBNXPt08UGYEDJCYUEsZ+xnhrE0tKGBhwbRl5jq vTTV93QBfxr2joqjp1jDD3lOkpagB5qHWzuR0A98rZCmsdz4zp6+BL6BFeKSy6EEVYgJ Mq4iT7lu8ZWi843H55wl/rajhz31rzK+NHM6Qfpo6R//tbraFeZLGtOg5Sj6E6pLPrAp TvX1JVTjBWXFyRf7DEsbKo6A+VuMT0Ju2jzaVfppFCPtAYbPGWpdeZUPZQOIm4lFmpED vhsA== X-Gm-Message-State: AOAM532FKaO/EUZHZAKihJLRzBdJl7lkshjYZvBrj0GucDNzl7ZKg/cD UADzuA+z/jjph3bvjdC38GRgcX+AbqA3lUi9meaKHbUgmI6SO+dp3YAvHwVi4/WBz8Xo1uMEui0 SUdDyirSZKZxAAhf7QpE3newm5uqHaqcXVr0BCoOo1/MEVEI9DjHe394wSFoVNw== X-Received: by 2002:a1c:6002:: with SMTP id u2mr3890711wmb.29.1607007747793; Thu, 03 Dec 2020 07:02:27 -0800 (PST) X-Google-Smtp-Source: ABdhPJyOrTOUDGMqDv9jpvzD8nEfons3RUVKUVk7BmVe1QeNqmoIBONdhZtkCPczP4ZMOZnFcnfrQQ== X-Received: by 2002:a1c:6002:: with SMTP id u2mr3890674wmb.29.1607007747496; Thu, 03 Dec 2020 07:02:27 -0800 (PST) Received: from minerva.redhat.com ([92.176.231.106]) by smtp.gmail.com with ESMTPSA id n128sm1896759wmb.46.2020.12.03.07.02.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Dec 2020 07:02:26 -0800 (PST) From: Javier Martinez Canillas To: grub-devel@gnu.org Cc: Ignat Korchagin , Michael Chang , Peter Jones , Marco A Benatto , Leif Lindholm , Daniel Kiper , Javier Martinez Canillas Subject: [PATCH 7/9] efi: Add secure boot detection Date: Thu, 3 Dec 2020 16:01:48 +0100 Message-Id: <20201203150151.848077-8-javierm@redhat.com> X-Mailer: git-send-email 2.28.0 In-Reply-To: <20201203150151.848077-1-javierm@redhat.com> References: <20201203150151.848077-1-javierm@redhat.com> MIME-Version: 1.0 Authentication-Results: relay.mimecast.com; auth=pass smtp.auth=CUSA124A263 smtp.mailfrom=javierm@redhat.com X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-Transfer-Encoding: 8bit Content-Type: text/plain; charset="US-ASCII" Received-SPF: pass client-ip=63.128.21.124; envelope-from=javierm@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -35 X-Spam_score: -3.6 X-Spam_bar: --- X-Spam_report: (-3.6 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.495, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: grub-devel@gnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: The development of GNU GRUB List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 03 Dec 2020 15:02:39 -0000 From: Daniel Kiper Introduce grub_efi_get_secureboot() function which returns whether UEFI Secure Boot is enabled or not on UEFI systems. Signed-off-by: Ignat Korchagin Signed-off-by: Daniel Kiper Signed-off-by: Marco A Benatto Signed-off-by: Javier Martinez Canillas --- grub-core/Makefile.am | 1 + grub-core/Makefile.core.def | 1 + grub-core/kern/efi/sb.c | 109 ++++++++++++++++++++++++++++++++++++ include/grub/efi/sb.h | 40 +++++++++++++ 4 files changed, 151 insertions(+) create mode 100644 grub-core/kern/efi/sb.c create mode 100644 include/grub/efi/sb.h diff --git a/grub-core/Makefile.am b/grub-core/Makefile.am index 3ea8e7ff45f..c6ba5b2d763 100644 --- a/grub-core/Makefile.am +++ b/grub-core/Makefile.am @@ -71,6 +71,7 @@ KERNEL_HEADER_FILES += $(top_srcdir)/include/grub/command.h KERNEL_HEADER_FILES += $(top_srcdir)/include/grub/device.h KERNEL_HEADER_FILES += $(top_srcdir)/include/grub/disk.h KERNEL_HEADER_FILES += $(top_srcdir)/include/grub/dl.h +KERNEL_HEADER_FILES += $(top_srcdir)/include/grub/efi/sb.h KERNEL_HEADER_FILES += $(top_srcdir)/include/grub/env.h KERNEL_HEADER_FILES += $(top_srcdir)/include/grub/env_private.h KERNEL_HEADER_FILES += $(top_srcdir)/include/grub/err.h diff --git a/grub-core/Makefile.core.def b/grub-core/Makefile.core.def index b5f47fc41b5..68b9e9f68dc 100644 --- a/grub-core/Makefile.core.def +++ b/grub-core/Makefile.core.def @@ -203,6 +203,7 @@ kernel = { efi = term/efi/console.c; efi = kern/acpi.c; efi = kern/efi/acpi.c; + efi = kern/efi/sb.c; i386_coreboot = kern/i386/pc/acpi.c; i386_multiboot = kern/i386/pc/acpi.c; i386_coreboot = kern/acpi.c; diff --git a/grub-core/kern/efi/sb.c b/grub-core/kern/efi/sb.c new file mode 100644 index 00000000000..19658d9626d --- /dev/null +++ b/grub-core/kern/efi/sb.c @@ -0,0 +1,109 @@ +/* + * GRUB -- GRand Unified Bootloader + * Copyright (C) 2020 Free Software Foundation, Inc. + * + * GRUB is free software: you can redistribute it and/or modify + * it under the terms of the GNU General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * GRUB is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with GRUB. If not, see . + * + * UEFI Secure Boot related checkings. + */ + +#include +#include +#include +#include +#include +#include +#include + +/* + * Determine whether we're in secure boot mode. + * + * Please keep the logic in sync with the Linux kernel, + * drivers/firmware/efi/libstub/secureboot.c:efi_get_secureboot(). + */ +grub_uint8_t +grub_efi_get_secureboot (void) +{ + static grub_efi_guid_t efi_variable_guid = GRUB_EFI_GLOBAL_VARIABLE_GUID; + static grub_efi_guid_t efi_shim_lock_guid = GRUB_EFI_SHIM_LOCK_GUID; + grub_efi_status_t status; + grub_efi_uint32_t attr = 0; + grub_size_t size = 0; + grub_uint8_t *secboot = NULL; + grub_uint8_t *setupmode = NULL; + grub_uint8_t *moksbstate = NULL; + grub_uint8_t secureboot = GRUB_EFI_SECUREBOOT_MODE_UNKNOWN; + const char *secureboot_str = "UNKNOWN"; + + status = grub_efi_get_variable ("SecureBoot", &efi_variable_guid, + &size, (void **) &secboot); + + if (status == GRUB_EFI_NOT_FOUND) + { + secureboot = GRUB_EFI_SECUREBOOT_MODE_DISABLED; + goto out; + } + + if (status != GRUB_EFI_SUCCESS) + goto out; + + status = grub_efi_get_variable ("SetupMode", &efi_variable_guid, + &size, (void **) &setupmode); + + if (status != GRUB_EFI_SUCCESS) + goto out; + + if ((*secboot == 0) || (*setupmode == 1)) + { + secureboot = GRUB_EFI_SECUREBOOT_MODE_DISABLED; + goto out; + } + + /* + * See if a user has put the shim into insecure mode. If so, and if the + * variable doesn't have the runtime attribute set, we might as well + * honor that. + */ + status = grub_efi_get_variable_with_attributes ("MokSBState", &efi_shim_lock_guid, + &size, (void **) &moksbstate, &attr); + + /* If it fails, we don't care why. Default to secure. */ + if (status != GRUB_EFI_SUCCESS) + { + secureboot = GRUB_EFI_SECUREBOOT_MODE_ENABLED; + goto out; + } + + if (!(attr & GRUB_EFI_VARIABLE_RUNTIME_ACCESS) && *moksbstate == 1) + { + secureboot = GRUB_EFI_SECUREBOOT_MODE_DISABLED; + goto out; + } + + secureboot = GRUB_EFI_SECUREBOOT_MODE_ENABLED; + + out: + grub_free (moksbstate); + grub_free (setupmode); + grub_free (secboot); + + if (secureboot == GRUB_EFI_SECUREBOOT_MODE_DISABLED) + secureboot_str = "Disabled"; + else if (secureboot == GRUB_EFI_SECUREBOOT_MODE_ENABLED) + secureboot_str = "Enabled"; + + grub_dprintf ("efi", "UEFI Secure Boot state: %s\n", secureboot_str); + + return secureboot; +} diff --git a/include/grub/efi/sb.h b/include/grub/efi/sb.h new file mode 100644 index 00000000000..a33d985e3c4 --- /dev/null +++ b/include/grub/efi/sb.h @@ -0,0 +1,40 @@ +/* + * GRUB -- GRand Unified Bootloader + * Copyright (C) 2020 Free Software Foundation, Inc. + * + * GRUB is free software: you can redistribute it and/or modify + * it under the terms of the GNU General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * GRUB is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with GRUB. If not, see . + */ + +#ifndef GRUB_EFI_SB_H +#define GRUB_EFI_SB_H 1 + +#include +#include + +#define GRUB_EFI_SECUREBOOT_MODE_UNSET 0 +#define GRUB_EFI_SECUREBOOT_MODE_UNKNOWN 1 +#define GRUB_EFI_SECUREBOOT_MODE_DISABLED 2 +#define GRUB_EFI_SECUREBOOT_MODE_ENABLED 3 + +#ifdef GRUB_MACHINE_EFI +extern grub_uint8_t +EXPORT_FUNC (grub_efi_get_secureboot) (void); +#else +static inline grub_uint8_t +grub_efi_get_secureboot (void) +{ + return GRUB_EFI_SECUREBOOT_MODE_UNSET; +} +#endif +#endif /* GRUB_EFI_SB_H */ -- 2.28.0