From: Simon Glass <sjg@chromium.org>
To: u-boot@lists.denx.de
Subject: [U-Boot] [PATCH 05/10] arm: Add CONFIG_DELAY_ENVIRONMENT to delay environment loading
Date: Thu, 1 Nov 2012 16:42:05 -0700 [thread overview]
Message-ID: <1351813330-23741-5-git-send-email-sjg@chromium.org> (raw)
In-Reply-To: <1351813330-23741-1-git-send-email-sjg@chromium.org>
This option delays loading of the environment until later, so that only the
default environment will be available to U-Boot.
This can address the security risk of untrusted data being used during boot.
When CONFIG_DELAY_ENVIRONMENT is defined, it is convenient to have a
run-time way of enabling loadinlg of the environment. Add this to the
fdt as /config/delay-environment.
Note: This patch depends on http://patchwork.ozlabs.org/patch/194342/
Signed-off-by: Doug Anderson <dianders@chromium.org>
Signed-off-by: Simon Glass <sjg@chromium.org>
---
README | 9 +++++++++
arch/arm/lib/board.c | 29 +++++++++++++++++++++++++++--
2 files changed, 36 insertions(+), 2 deletions(-)
diff --git a/README b/README
index 22fd6b7..589e22a 100644
--- a/README
+++ b/README
@@ -2311,6 +2311,15 @@ CBFS (Coreboot Filesystem) support
- CONFIG_SYS_VENDOR
- CONFIG_SYS_SOC
+ CONFIG_DELAY_ENVIRONMENT
+
+ Normally the environment is loaded when the board is
+ intialised so that it is available to U-Boot. This inhibits
+ that so that the environment is not available until
+ explicitly loaded later by U-Boot code. With CONFIG_OF_CONTROL
+ this is instead controlled by the value of
+ /config/load-environment.
+
- DataFlash Support:
CONFIG_HAS_DATAFLASH
diff --git a/arch/arm/lib/board.c b/arch/arm/lib/board.c
index 2ec6a43..d3053d8 100644
--- a/arch/arm/lib/board.c
+++ b/arch/arm/lib/board.c
@@ -40,6 +40,7 @@
#include <common.h>
#include <command.h>
+#include <environment.h>
#include <malloc.h>
#include <stdio_dev.h>
#include <version.h>
@@ -469,7 +470,28 @@ static char *failed = "*** failed ***\n";
#endif
/*
- ************************************************************************
+ * Tell if it's OK to load the environment early in boot.
+ *
+ * If CONFIG_OF_CONFIG is defined, we'll check with the FDT to see
+ * if this is OK (defaulting to saying it's not OK).
+ *
+ * NOTE: Loading the environment early can be a bad idea if security is
+ * important, since no verification is done on the environment.
+ *
+ * @return 0 if environment should not be loaded, !=0 if it is ok to load
+ */
+static int should_load_env(void)
+{
+#ifdef CONFIG_OF_CONTROL
+ return fdtdec_get_config_int(gd->fdt_blob, "load-environment", 0);
+#elif defined CONFIG_DELAY_ENVIRONMENT
+ return 0;
+#else
+ return 1;
+#endif
+}
+
+/************************************************************************
*
* This is the next part if the initialization sequence: we are now
* running from RAM and have a "normal" C environment, i. e. global
@@ -575,7 +597,10 @@ void board_init_r(gd_t *id, ulong dest_addr)
#endif
/* initialize environment */
- env_relocate();
+ if (should_load_env())
+ env_relocate();
+ else
+ set_default_env(NULL);
#if defined(CONFIG_CMD_PCI) || defined(CONFIG_PCI)
arm_pci_init();
--
1.7.7.3
next prev parent reply other threads:[~2012-11-01 23:42 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-11-01 23:42 [U-Boot] [PATCH 01/10] arm: Compile cache_disable() with -O2 to avoid failure Simon Glass
2012-11-01 23:42 ` [U-Boot] [PATCH 02/10] arm: move flush_dcache_all() to just before disable cache Simon Glass
2012-11-01 23:42 ` [U-Boot] [PATCH 03/10] arm: Keep track of the tlb size as well as its location Simon Glass
2012-11-01 23:42 ` [U-Boot] [PATCH 04/10] arm: Move fdt check earlier so that board_early_init_f() can use it Simon Glass
2012-11-03 14:56 ` Wolfgang Denk
2012-11-03 21:53 ` Simon Glass
2012-11-01 23:42 ` Simon Glass [this message]
2012-11-03 12:30 ` [U-Boot] [PATCH 05/10] arm: Add CONFIG_DELAY_ENVIRONMENT to delay environment loading Wolfgang Denk
2012-11-07 0:16 ` Simon Glass
2013-01-18 12:06 ` Lucas Stach
2013-01-18 13:29 ` Simon Glass
2012-11-01 23:42 ` [U-Boot] [PATCH 06/10] arm: Add CONFIG_DISPLAY_BOARDINFO_LATE to display board info on LCD Simon Glass
2012-11-03 12:33 ` Wolfgang Denk
2012-11-15 22:37 ` Simon Glass
2012-11-01 23:42 ` [U-Boot] [PATCH 07/10] arm: Add option to display customised memory information Simon Glass
2012-11-03 14:54 ` Wolfgang Denk
2012-11-15 22:45 ` Simon Glass
2012-11-01 23:42 ` [U-Boot] [PATCH 08/10] arm: Make interrupts.o and reset.o in libarm also appear in SPL Simon Glass
2012-11-01 23:42 ` [U-Boot] [PATCH 09/10] arm: Move bootstage record for board_init_f() to after arch_cpu_init() Simon Glass
2012-11-03 14:55 ` Wolfgang Denk
2012-11-07 0:51 ` Simon Glass
2012-11-07 13:18 ` Wolfgang Denk
2012-11-22 14:57 ` Simon Glass
2012-11-01 23:42 ` [U-Boot] [PATCH 10/10] arm: Tabify code for MMC initialization Simon Glass
2012-11-03 8:32 ` [U-Boot] [PATCH 01/10] arm: Compile cache_disable() with -O2 to avoid failure Marek Vasut
2012-11-03 12:29 ` Wolfgang Denk
2012-11-07 0:45 ` Simon Glass
2012-11-07 12:55 ` Wolfgang Denk
2012-11-07 15:42 ` Simon Glass
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1351813330-23741-5-git-send-email-sjg@chromium.org \
--to=sjg@chromium.org \
--cc=u-boot@lists.denx.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox