Linux EFI development
 help / color / mirror / Atom feed
* [PATCH] security: Fix the Capsule-Loader with Lock Mutex, Verifications, factory default initialization and return
@ 2026-09-26 10:51 dev12124
  0 siblings, 0 replies; only message in thread
From: dev12124 @ 2026-09-26 10:51 UTC (permalink / raw)
  To: linux-efi; +Cc: ardb, dev12124

---
 drivers/firmware/efi/capsule-loader.c | 67 +++++++++++++++++++++++----
 1 file changed, 58 insertions(+), 9 deletions(-)

diff --git a/drivers/firmware/efi/capsule-loader.c b/drivers/firmware/efi/capsule-loader.c
index 8e8f81f0a..6d4d9fec5 100644
--- a/drivers/firmware/efi/capsule-loader.c
+++ b/drivers/firmware/efi/capsule-loader.c
@@ -18,6 +18,59 @@
 #include <linux/vmalloc.h>
 
 #define NO_FURTHER_WRITE_ACTION -1
+#define CAPSULE_HELP_SUCCESS 0
+
+/** 
+ * A Structure for Mutex. 
+ **/
+static DEFINE_MUTEX(capsule_mutex);
+
+/** 
+  * capsule_help_open - A Helper under the Functions,
+  * with Lock Mutex, Variables Protected, Security in the Memory.
+  **/
+static int capsule_help_open(struct capsule_info *cap_info, struct mutex *mtxPointer) 
+{
+
+	// Lock the Pointer
+	mutex_lock(mtxPointer);
+
+    /** Fixing the weak allocation issue that carried a risk 
+	 of the driver writing out of bounds.
+	   A Initial Secure Space (e.g 1024 pointers) */
+	cap_info->pages = kcalloc(1024, sizeof(void *), GFP_KERNEL);
+
+	/** Check if the allocation failed for
+	  Memory Loss */
+	if (!cap_info->pages) {
+       mutex_unlock(mtxPointer);
+	   return -ENOMEM;
+	}
+
+	/**
+	   Now, the Logic of the Physhics Address 
+	**/
+	cap_info->phys = kcalloc(1024, sizeof(phys_addr_t), GFP_KERNEL);
+
+	/** Check if the Allocation failed for
+	  Memory Loss */
+    if (!cap_info->phys) {
+		kfree(cap_info->pages);
+		cap_info->pages = NULL;
+		mutex_unlock(mtxPointer);
+		return -ENOMEM;
+	}
+
+	/** Initializes the rest 
+	     to factory defaults  */
+    cap_info->index = 0;
+	cap_info->page_bytes_remain = 0;
+	cap_info->count = 0;
+
+	/** Return the Success */
+	return CAPSULE_HELP_SUCCESS;
+}
+
 
 /**
  * efi_free_all_buff_pages - free all previous allocated buffer pages
@@ -281,22 +334,18 @@ static int efi_capsule_release(struct inode *inode, struct file *file)
 static int efi_capsule_open(struct inode *inode, struct file *file)
 {
 	struct capsule_info *cap_info;
+    
+	int ret;
 
 	cap_info = kzalloc_obj(*cap_info);
 	if (!cap_info)
 		return -ENOMEM;
 
-	cap_info->pages = kzalloc(sizeof(void *), GFP_KERNEL);
-	if (!cap_info->pages) {
-		kfree(cap_info);
-		return -ENOMEM;
-	}
 
-	cap_info->phys = kzalloc_obj(phys_addr_t);
-	if (!cap_info->phys) {
-		kfree(cap_info->pages);
+	ret = capsule_help_open(cap_info, &capsule_mutex);
+	if (ret != CAPSULE_HELP_SUCCESS) {
 		kfree(cap_info);
-		return -ENOMEM;
+		return ret;
 	}
 
 	file->private_data = cap_info;
-- 
2.55.0.windows.3


^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-26 10:51 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-26 10:51 [PATCH] security: Fix the Capsule-Loader with Lock Mutex, Verifications, factory default initialization and return dev12124

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox