From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from list by lists.gnu.org with archive (Exim 4.90_1) id 1kkq86-0004bV-CU for mharc-grub-devel@gnu.org; Thu, 03 Dec 2020 10:02:46 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]:46024) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1kkq82-0004Zz-Lm for grub-devel@gnu.org; Thu, 03 Dec 2020 10:02:42 -0500 Received: from us-smtp-delivery-124.mimecast.com ([63.128.21.124]:44086) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.90_1) (envelope-from ) id 1kkq7u-00024V-QL for grub-devel@gnu.org; Thu, 03 Dec 2020 10:02:42 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1607007754; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=fbh177JQhEglkwUHUI9zfIKbCCilUtz2YTVTNqAvYtk=; b=NKnoF4+gc90Fz3mlw1aiCua/fbTELZ+bvIHZ+MS6AzeXpy/EQ/L59tiEfSjoSJUQ2xAAAo Vx8e8ldYN5pzLVDKvK5vXtFUnDignOGPE+YuW9fj+32dHZFohs8jTm8mO900oCF25/5ayX 9hON7CpxlgYIJ3gpLu9wNzggS8ShEqk= Received: from mail-wm1-f70.google.com (mail-wm1-f70.google.com [209.85.128.70]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-170-Y-DUosSKPB2q3-4DKTgx9Q-1; Thu, 03 Dec 2020 10:02:31 -0500 X-MC-Unique: Y-DUosSKPB2q3-4DKTgx9Q-1 Received: by mail-wm1-f70.google.com with SMTP id q1so1469788wmq.2 for ; Thu, 03 Dec 2020 07:02:31 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=fbh177JQhEglkwUHUI9zfIKbCCilUtz2YTVTNqAvYtk=; b=tzXKi+WLrZdLOzoXfdAWI8HPOd7ZDinvDBH48rx0Zyq6I4gAX8JR49wXpVgSab3f0J p6Ebcsy9Xbm/xJ6rlxZLue5wympzB2f51s3hdmSvFMKx4EmsClnmd4//fgE+eLfSvVGn +r1zfmnIcGADeExltQRkyqpeSi1OXs5gq0/HOIuAo7WspoNSuIVOJ5RhsGvnVD3FiHtf rSQ/oF3NMeT2hRfziIrje2MW2ekoS3UI+SCw3K6ZE4bsdTdUcie33HslV0JkIkqxuBPe SkwavK51YYVqp+anfUVA5RR6mzh3FqnRXpCv0J2wl3qNn/TpOM3FyLy+W1Dew+9RfNnL 6T0g== X-Gm-Message-State: AOAM5328swEcj0brPzy3fOvabPJgJoA+A/o19/rQgT/HbUNmobIb2ZRR F82Zo3U0o72EEG0lUhhNMEgMgqwUZUVd5/ALsxeY9kyyTnURiecQXQXZ7aZdAMKIcrVOvFN+NUk yQNYxnuUxzvQ4Bb4aPy52cczjdIJSwWyiDnKtAKkmveTup8jt03WBAeOS+UPU5w== X-Received: by 2002:adf:f3d1:: with SMTP id g17mr4148219wrp.201.1607007749538; Thu, 03 Dec 2020 07:02:29 -0800 (PST) X-Google-Smtp-Source: ABdhPJz2l7w8OiRbjw5dCuxUgwWdoS9lgNk7Fucfixv7hToEmJi5e8rPeLBjAt2rTg/FHXPyiDrUeA== X-Received: by 2002:adf:f3d1:: with SMTP id g17mr4148180wrp.201.1607007749264; Thu, 03 Dec 2020 07:02:29 -0800 (PST) Received: from minerva.redhat.com ([92.176.231.106]) by smtp.gmail.com with ESMTPSA id n128sm1896759wmb.46.2020.12.03.07.02.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Dec 2020 07:02:28 -0800 (PST) From: Javier Martinez Canillas To: grub-devel@gnu.org Cc: Ignat Korchagin , Michael Chang , Peter Jones , Marco A Benatto , Leif Lindholm , Daniel Kiper , Javier Martinez Canillas Subject: [PATCH 8/9] efi: Only register shim_lock verifier if shim_lock protocol is found and SB enabled Date: Thu, 3 Dec 2020 16:01:49 +0100 Message-Id: <20201203150151.848077-9-javierm@redhat.com> X-Mailer: git-send-email 2.28.0 In-Reply-To: <20201203150151.848077-1-javierm@redhat.com> References: <20201203150151.848077-1-javierm@redhat.com> MIME-Version: 1.0 Authentication-Results: relay.mimecast.com; auth=pass smtp.auth=CUSA124A263 smtp.mailfrom=javierm@redhat.com X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-Transfer-Encoding: 8bit Content-Type: text/plain; charset="US-ASCII" Received-SPF: pass client-ip=63.128.21.124; envelope-from=javierm@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -35 X-Spam_score: -3.6 X-Spam_bar: --- X-Spam_report: (-3.6 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.495, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: grub-devel@gnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: The development of GNU GRUB List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 03 Dec 2020 15:02:43 -0000 The shim_lock module registers a verifier to call shim's verify, but the handler is registered even when the shim_lock protocol was not installed. This doesn't cause a NULL pointer dereference in shim_lock_write() because the shim_lock_init() function just returns GRUB_ERR_NONE if sl isn't set. But in that case there's no point to even register the shim_lock verifier since won't do anything. Additionally, it is only useful when Secure Boot is enabled. Finally, don't assume that the shim_lock protocol will always be present when the shim_lock_write() function is called, and check for it on every call to this function. Reported-by: Michael Chang Reported-by: Peter Jones Signed-off-by: Javier Martinez Canillas --- grub-core/commands/efi/shim_lock.c | 16 +++++++++------- 1 file changed, 9 insertions(+), 7 deletions(-) diff --git a/grub-core/commands/efi/shim_lock.c b/grub-core/commands/efi/shim_lock.c index d8f52d721c3..5259b27e8fc 100644 --- a/grub-core/commands/efi/shim_lock.c +++ b/grub-core/commands/efi/shim_lock.c @@ -28,7 +28,6 @@ GRUB_MOD_LICENSE ("GPLv3+"); static grub_efi_guid_t shim_lock_guid = GRUB_EFI_SHIM_LOCK_GUID; -static grub_efi_shim_lock_protocol_t *sl; /* List of modules which cannot be loaded if UEFI secure boot mode is enabled. */ static const char * const disabled_mods[] = {"iorw", "memrw", "wrmsr", NULL}; @@ -43,9 +42,6 @@ shim_lock_init (grub_file_t io, enum grub_file_type type, *flags = GRUB_VERIFY_FLAGS_SKIP_VERIFICATION; - if (!sl) - return GRUB_ERR_NONE; - switch (type & GRUB_FILE_TYPE_MASK) { case GRUB_FILE_TYPE_GRUB_MODULE: @@ -100,6 +96,11 @@ shim_lock_init (grub_file_t io, enum grub_file_type type, static grub_err_t shim_lock_write (void *context __attribute__ ((unused)), void *buf, grub_size_t size) { + grub_efi_shim_lock_protocol_t *sl = grub_efi_locate_protocol (&shim_lock_guid, 0); + + if (sl == NULL) + return grub_error (GRUB_ERR_ACCESS_DENIED, N_("shim_lock protocol not found")); + if (sl->verify (buf, size) != GRUB_EFI_SUCCESS) return grub_error (GRUB_ERR_BAD_SIGNATURE, N_("bad shim signature")); @@ -115,12 +116,13 @@ struct grub_file_verifier shim_lock = GRUB_MOD_INIT(shim_lock) { - sl = grub_efi_locate_protocol (&shim_lock_guid, 0); - grub_verifier_register (&shim_lock); + grub_efi_shim_lock_protocol_t *sl = grub_efi_locate_protocol (&shim_lock_guid, 0); - if (!sl) + if (sl == NULL || grub_efi_get_secureboot () != GRUB_EFI_SECUREBOOT_MODE_ENABLED) return; + grub_verifier_register (&shim_lock); + grub_dl_set_persistent (mod); } -- 2.28.0