* [PATCH] security: Fix the Capsule-Loader with Lock Mutex, Verifications, factory default initialization and return
@ 2026-09-26 10:51 dev12124
0 siblings, 0 replies; only message in thread
From: dev12124 @ 2026-09-26 10:51 UTC (permalink / raw)
To: linux-efi; +Cc: ardb, dev12124
---
drivers/firmware/efi/capsule-loader.c | 67 +++++++++++++++++++++++----
1 file changed, 58 insertions(+), 9 deletions(-)
diff --git a/drivers/firmware/efi/capsule-loader.c b/drivers/firmware/efi/capsule-loader.c
index 8e8f81f0a..6d4d9fec5 100644
--- a/drivers/firmware/efi/capsule-loader.c
+++ b/drivers/firmware/efi/capsule-loader.c
@@ -18,6 +18,59 @@
#include <linux/vmalloc.h>
#define NO_FURTHER_WRITE_ACTION -1
+#define CAPSULE_HELP_SUCCESS 0
+
+/**
+ * A Structure for Mutex.
+ **/
+static DEFINE_MUTEX(capsule_mutex);
+
+/**
+ * capsule_help_open - A Helper under the Functions,
+ * with Lock Mutex, Variables Protected, Security in the Memory.
+ **/
+static int capsule_help_open(struct capsule_info *cap_info, struct mutex *mtxPointer)
+{
+
+ // Lock the Pointer
+ mutex_lock(mtxPointer);
+
+ /** Fixing the weak allocation issue that carried a risk
+ of the driver writing out of bounds.
+ A Initial Secure Space (e.g 1024 pointers) */
+ cap_info->pages = kcalloc(1024, sizeof(void *), GFP_KERNEL);
+
+ /** Check if the allocation failed for
+ Memory Loss */
+ if (!cap_info->pages) {
+ mutex_unlock(mtxPointer);
+ return -ENOMEM;
+ }
+
+ /**
+ Now, the Logic of the Physhics Address
+ **/
+ cap_info->phys = kcalloc(1024, sizeof(phys_addr_t), GFP_KERNEL);
+
+ /** Check if the Allocation failed for
+ Memory Loss */
+ if (!cap_info->phys) {
+ kfree(cap_info->pages);
+ cap_info->pages = NULL;
+ mutex_unlock(mtxPointer);
+ return -ENOMEM;
+ }
+
+ /** Initializes the rest
+ to factory defaults */
+ cap_info->index = 0;
+ cap_info->page_bytes_remain = 0;
+ cap_info->count = 0;
+
+ /** Return the Success */
+ return CAPSULE_HELP_SUCCESS;
+}
+
/**
* efi_free_all_buff_pages - free all previous allocated buffer pages
@@ -281,22 +334,18 @@ static int efi_capsule_release(struct inode *inode, struct file *file)
static int efi_capsule_open(struct inode *inode, struct file *file)
{
struct capsule_info *cap_info;
+
+ int ret;
cap_info = kzalloc_obj(*cap_info);
if (!cap_info)
return -ENOMEM;
- cap_info->pages = kzalloc(sizeof(void *), GFP_KERNEL);
- if (!cap_info->pages) {
- kfree(cap_info);
- return -ENOMEM;
- }
- cap_info->phys = kzalloc_obj(phys_addr_t);
- if (!cap_info->phys) {
- kfree(cap_info->pages);
+ ret = capsule_help_open(cap_info, &capsule_mutex);
+ if (ret != CAPSULE_HELP_SUCCESS) {
kfree(cap_info);
- return -ENOMEM;
+ return ret;
}
file->private_data = cap_info;
--
2.55.0.windows.3
^ permalink raw reply related [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-26 10:51 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-26 10:51 [PATCH] security: Fix the Capsule-Loader with Lock Mutex, Verifications, factory default initialization and return dev12124
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox