From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9EB60C433FE for ; Wed, 6 Oct 2021 13:16:03 +0000 (UTC) Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id BDD5A610C8 for ; Wed, 6 Oct 2021 13:16:02 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.4.1 mail.kernel.org BDD5A610C8 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=canonical.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=lists.denx.de Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id 9FA92832B8; Wed, 6 Oct 2021 15:15:58 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=canonical.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (2048-bit key; unprotected) header.d=canonical.com header.i=@canonical.com header.b="n3BHwCcS"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id 2330F8328D; Wed, 6 Oct 2021 15:15:55 +0200 (CEST) Received: from smtp-relay-internal-1.canonical.com (smtp-relay-internal-1.canonical.com [185.125.188.123]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id 92B4383273 for ; Wed, 6 Oct 2021 15:15:49 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=canonical.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=heinrich.schuchardt@canonical.com Received: from mail-wr1-f70.google.com (mail-wr1-f70.google.com [209.85.221.70]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by smtp-relay-internal-1.canonical.com (Postfix) with ESMTPS id 15D053FFE0 for ; Wed, 6 Oct 2021 13:15:49 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=canonical.com; s=20210705; t=1633526149; bh=YMrgvngJqJmiemquT8uApTaZRrk8jsquG+5pBl+dzcA=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=n3BHwCcSAt9JGcWQOXxDTPA6c8dMcyn0Yj7O/uKIRj1OzbGm2uPZWb6UpSIJosu/r Rs3aQn7TatU8ML3VSiw3GYRoOJuHbkpDpVY+AaS/OJG9le63OcgkklhLyJzChKaZsM A0Z9L5sBAbggrTMU8N2Va4Jg6J8VK6l3F/lhjByxkNN+ouaMc2fw1lTj97i+itqY6K FRkpGaZyIL0XXU22aZyfd0cxNi9KVMuVrjp4o1corGgCN7iZEPqK51/pGHWtJV9xsV nbbexwpwVjkZzSgUXsIy19MpwjtrudrRqv1o/L0rZQ55WAB/6O1tBlMjnYO2In4ab0 Ok5B2TgYA+hcA== Received: by mail-wr1-f70.google.com with SMTP id r25-20020adfab59000000b001609ddd5579so2009734wrc.21 for ; Wed, 06 Oct 2021 06:15:49 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:message-id:date:mime-version:user-agent:subject :content-language:to:cc:references:from:in-reply-to :content-transfer-encoding; bh=YMrgvngJqJmiemquT8uApTaZRrk8jsquG+5pBl+dzcA=; b=DrM9W7QN98vbE9pzEiZ1SE6dJVfQ1G85H79wj5xafAL8CBMde+WsvkXXaEaL0+6BNi SUnaZb850eSl6nmfmq8E94Jd52Qh2j5maKXpbJcocC5hHQYshzLabNjVGicuK4S2pVvy aw30z/9twcuRLILZZ8znkI9hKZTv+JLgpcztPyV7NsgZlFNy34Zms7hkA7b3kWEU5rzt cm9RGNgvNew6EcUFMwOPHXKSQagiDppekmebySrF7YcOoIb/2OuZeACX1KtBaVlx1lCe PQVwUxkVIPaPkMj4LnNuwlYhX23nqi8cGfosUjs7Yp5xuklsQdxxOYRztXNukMrX011X 4hHQ== X-Gm-Message-State: AOAM5335ta5uAPqJCjGnSmfXD+LCCjk1JM6A9GbkHcBD6VDC0iTFqj/V J3YU7U6c7TXwS6hiwZtisPTsRz79TLN+8hliHHb+cF6r9JtO/LxpMnExSZSGTrMirxUl+24NAyX 6bGScjxyAdWnomKToXtBZXItlzMO3Yl8= X-Received: by 2002:adf:9b8a:: with SMTP id d10mr4943678wrc.151.1633526148854; Wed, 06 Oct 2021 06:15:48 -0700 (PDT) X-Google-Smtp-Source: ABdhPJyI7VDcYfQiKxN00rKzu+nKtEVSup6UU8mIkXKa/bPMGNXrc6SHxD3gWhUSVUFeqCZA/5fOZw== X-Received: by 2002:adf:9b8a:: with SMTP id d10mr4943654wrc.151.1633526148693; Wed, 06 Oct 2021 06:15:48 -0700 (PDT) Received: from [192.168.123.55] (ip-88-152-144-157.hsi03.unitymediagroup.de. [88.152.144.157]) by smtp.gmail.com with ESMTPSA id h1sm5172429wmb.7.2021.10.06.06.15.48 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 06 Oct 2021 06:15:48 -0700 (PDT) Message-ID: Date: Wed, 6 Oct 2021 15:15:47 +0200 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Thunderbird/91.1.2 Subject: Re: [PATCH v3 3/4] efi_loader: simplify efi_sigstore_parse_sigdb() Content-Language: en-US To: Ilias Apalodimas Cc: U-Boot Mailing List , Alexander Graf , Masahisa Kojima , AKASHI Takahiro , Sughosh Ganu References: <20211003092320.4671-1-heinrich.schuchardt@canonical.com> <20211003092320.4671-4-heinrich.schuchardt@canonical.com> <4efe1a01-4853-c9e6-9be3-f51780759ca5@canonical.com> From: Heinrich Schuchardt In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.34 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.2 at phobos.denx.de X-Virus-Status: Clean On 10/6/21 10:02, Ilias Apalodimas wrote: > On Wed, 6 Oct 2021 at 10:21, Heinrich Schuchardt > wrote: >> >> >> >> On 10/6/21 08:29, Ilias Apalodimas wrote: >>> On Sun, Oct 03, 2021 at 11:23:19AM +0200, Heinrich Schuchardt wrote: >>>> Simplify efi_sigstore_parse_sigdb() by using existing functions. >>>> >>>> Signed-off-by: Heinrich Schuchardt >>>> --- >>>> v3: >>>> Keep error handling in efi_sigstore_parse_sigdb() >>>> v2: >>>> remove a superfluous check >>>> --- >>>> lib/efi_loader/efi_signature.c | 11 ++--------- >>>> 1 file changed, 2 insertions(+), 9 deletions(-) >>>> >>>> diff --git a/lib/efi_loader/efi_signature.c b/lib/efi_loader/efi_signature.c >>>> index bdd09881fc..97f6dfacd9 100644 >>>> --- a/lib/efi_loader/efi_signature.c >>>> +++ b/lib/efi_loader/efi_signature.c >>>> @@ -746,18 +746,11 @@ struct efi_signature_store *efi_sigstore_parse_sigdb(u16 *name) >>>> efi_uintn_t db_size; >>>> efi_status_t ret; >>>> >>>> - if (!u16_strcmp(name, L"PK") || !u16_strcmp(name, L"KEK")) { >>>> - vendor = &efi_global_variable_guid; >>>> - } else if (!u16_strcmp(name, L"db") || !u16_strcmp(name, L"dbx")) { >>>> - vendor = &efi_guid_image_security_database; >>>> - } else { >>>> - EFI_PRINT("unknown signature database, %ls\n", name); >>>> - return NULL; >>>> - } >>>> + vendor = efi_auth_var_get_guid(name); >>> >>> Should we return NULL if we get back the default guid? >> >> efi_sigstore_parse_sigdb() is only called with fixed values of 'name'. >> So how should this occur? > > Bugs that slip through maybe? I generally prefer being more pedantic > with security related code PK and KEK use efi_global_variable_guid and will be used as argument for efi_sigstore_parse_sigdb(). Your proposed check would break the code. Best regards Heinrich > > Regards > /Ilias >> >> Best regards >> >> Heinrich >> >>> >>>> >>>> /* retrieve variable data */ >>>> db_size = 0; >>>> - ret = EFI_CALL(efi_get_variable(name, vendor, NULL, &db_size, NULL)); >>>> + ret = efi_get_variable_int(name, vendor, NULL, &db_size, NULL); >>>> if (ret == EFI_NOT_FOUND) { >>>> EFI_PRINT("variable, %ls, not found\n", name); >>>> sigstore = calloc(sizeof(*sigstore), 1); >>>> -- >>>> 2.32.0 >>>> >>> >>> Regards >>> /Ilias >>>