Linux EFI development
 help / color / mirror / Atom feed
From: dev12124 <joaoanandalima@gmail.com>
To: linux-efi@vger.kernel.org
Cc: ardb@kernel.org, dev12124 <joaoanandalima@gmail.com>
Subject: [PATCH] security: Fix the Capsule-Loader with Lock Mutex, Verifications, factory default initialization and return
Date: Sat, 26 Sep 2026 07:51:28 -0300	[thread overview]
Message-ID: <20260926105128.1113-1-joaoanandalima@gmail.com> (raw)

---
 drivers/firmware/efi/capsule-loader.c | 67 +++++++++++++++++++++++----
 1 file changed, 58 insertions(+), 9 deletions(-)

diff --git a/drivers/firmware/efi/capsule-loader.c b/drivers/firmware/efi/capsule-loader.c
index 8e8f81f0a..6d4d9fec5 100644
--- a/drivers/firmware/efi/capsule-loader.c
+++ b/drivers/firmware/efi/capsule-loader.c
@@ -18,6 +18,59 @@
 #include <linux/vmalloc.h>
 
 #define NO_FURTHER_WRITE_ACTION -1
+#define CAPSULE_HELP_SUCCESS 0
+
+/** 
+ * A Structure for Mutex. 
+ **/
+static DEFINE_MUTEX(capsule_mutex);
+
+/** 
+  * capsule_help_open - A Helper under the Functions,
+  * with Lock Mutex, Variables Protected, Security in the Memory.
+  **/
+static int capsule_help_open(struct capsule_info *cap_info, struct mutex *mtxPointer) 
+{
+
+	// Lock the Pointer
+	mutex_lock(mtxPointer);
+
+    /** Fixing the weak allocation issue that carried a risk 
+	 of the driver writing out of bounds.
+	   A Initial Secure Space (e.g 1024 pointers) */
+	cap_info->pages = kcalloc(1024, sizeof(void *), GFP_KERNEL);
+
+	/** Check if the allocation failed for
+	  Memory Loss */
+	if (!cap_info->pages) {
+       mutex_unlock(mtxPointer);
+	   return -ENOMEM;
+	}
+
+	/**
+	   Now, the Logic of the Physhics Address 
+	**/
+	cap_info->phys = kcalloc(1024, sizeof(phys_addr_t), GFP_KERNEL);
+
+	/** Check if the Allocation failed for
+	  Memory Loss */
+    if (!cap_info->phys) {
+		kfree(cap_info->pages);
+		cap_info->pages = NULL;
+		mutex_unlock(mtxPointer);
+		return -ENOMEM;
+	}
+
+	/** Initializes the rest 
+	     to factory defaults  */
+    cap_info->index = 0;
+	cap_info->page_bytes_remain = 0;
+	cap_info->count = 0;
+
+	/** Return the Success */
+	return CAPSULE_HELP_SUCCESS;
+}
+
 
 /**
  * efi_free_all_buff_pages - free all previous allocated buffer pages
@@ -281,22 +334,18 @@ static int efi_capsule_release(struct inode *inode, struct file *file)
 static int efi_capsule_open(struct inode *inode, struct file *file)
 {
 	struct capsule_info *cap_info;
+    
+	int ret;
 
 	cap_info = kzalloc_obj(*cap_info);
 	if (!cap_info)
 		return -ENOMEM;
 
-	cap_info->pages = kzalloc(sizeof(void *), GFP_KERNEL);
-	if (!cap_info->pages) {
-		kfree(cap_info);
-		return -ENOMEM;
-	}
 
-	cap_info->phys = kzalloc_obj(phys_addr_t);
-	if (!cap_info->phys) {
-		kfree(cap_info->pages);
+	ret = capsule_help_open(cap_info, &capsule_mutex);
+	if (ret != CAPSULE_HELP_SUCCESS) {
 		kfree(cap_info);
-		return -ENOMEM;
+		return ret;
 	}
 
 	file->private_data = cap_info;
-- 
2.55.0.windows.3


                 reply	other threads:[~2026-09-26 10:51 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260926105128.1113-1-joaoanandalima@gmail.com \
    --to=joaoanandalima@gmail.com \
    --cc=ardb@kernel.org \
    --cc=linux-efi@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox