var-service.h 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191
  1. /*
  2. * SPDX-License-Identifier: GPL-2.0-or-later
  3. *
  4. * uefi-vars device - state struct and function prototypes
  5. */
  6. #ifndef QEMU_UEFI_VAR_SERVICE_H
  7. #define QEMU_UEFI_VAR_SERVICE_H
  8. #include "qemu/uuid.h"
  9. #include "qemu/queue.h"
  10. #include "hw/uefi/var-service-edk2.h"
  11. #define MAX_BUFFER_SIZE (64 * 1024)
  12. typedef struct uefi_variable uefi_variable;
  13. typedef struct uefi_var_policy uefi_var_policy;
  14. typedef struct uefi_vars_state uefi_vars_state;
  15. typedef struct uefi_vars_cert uefi_vars_cert;
  16. typedef struct uefi_vars_hash uefi_vars_hash;
  17. typedef struct uefi_vars_siglist uefi_vars_siglist;
  18. struct uefi_variable {
  19. QemuUUID guid;
  20. uint16_t *name;
  21. uint32_t name_size;
  22. uint32_t attributes;
  23. void *data;
  24. uint32_t data_size;
  25. efi_time time;
  26. void *digest;
  27. uint32_t digest_size;
  28. QTAILQ_ENTRY(uefi_variable) next;
  29. };
  30. struct uefi_var_policy {
  31. variable_policy_entry *entry;
  32. uint32_t entry_size;
  33. uint16_t *name;
  34. uint32_t name_size;
  35. /* number of hashmarks (wildcard character) in name */
  36. uint32_t hashmarks;
  37. QTAILQ_ENTRY(uefi_var_policy) next;
  38. };
  39. struct uefi_vars_state {
  40. MemoryRegion mr;
  41. uint16_t sts;
  42. uint32_t buf_size;
  43. uint32_t buf_addr_lo;
  44. uint32_t buf_addr_hi;
  45. uint8_t *buffer;
  46. QTAILQ_HEAD(, uefi_variable) variables;
  47. QTAILQ_HEAD(, uefi_var_policy) var_policies;
  48. /* pio transfer buffer */
  49. uint32_t pio_xfer_offset;
  50. uint8_t *pio_xfer_buffer;
  51. /* boot phases */
  52. bool end_of_dxe;
  53. bool ready_to_boot;
  54. bool exit_boot_service;
  55. bool policy_locked;
  56. /* storage accounting */
  57. uint64_t max_storage;
  58. uint64_t used_storage;
  59. /* config options */
  60. char *jsonfile;
  61. int jsonfd;
  62. bool force_secure_boot;
  63. bool disable_custom_mode;
  64. bool use_pio;
  65. };
  66. struct uefi_vars_cert {
  67. QTAILQ_ENTRY(uefi_vars_cert) next;
  68. QemuUUID owner;
  69. uint64_t size;
  70. uint8_t data[];
  71. };
  72. struct uefi_vars_hash {
  73. QTAILQ_ENTRY(uefi_vars_hash) next;
  74. QemuUUID owner;
  75. uint8_t data[];
  76. };
  77. struct uefi_vars_siglist {
  78. QTAILQ_HEAD(, uefi_vars_cert) x509;
  79. QTAILQ_HEAD(, uefi_vars_hash) sha256;
  80. };
  81. /* vars-service-guid.c */
  82. extern const QemuUUID EfiGlobalVariable;
  83. extern const QemuUUID EfiImageSecurityDatabase;
  84. extern const QemuUUID EfiCustomModeEnable;
  85. extern const QemuUUID EfiSecureBootEnableDisable;
  86. extern const QemuUUID EfiCertSha256Guid;
  87. extern const QemuUUID EfiCertSha384Guid;
  88. extern const QemuUUID EfiCertSha512Guid;
  89. extern const QemuUUID EfiCertRsa2048Guid;
  90. extern const QemuUUID EfiCertX509Guid;
  91. extern const QemuUUID EfiCertTypePkcs7Guid;
  92. extern const QemuUUID EfiSmmVariableProtocolGuid;
  93. extern const QemuUUID VarCheckPolicyLibMmiHandlerGuid;
  94. extern const QemuUUID EfiEndOfDxeEventGroupGuid;
  95. extern const QemuUUID EfiEventReadyToBootGuid;
  96. extern const QemuUUID EfiEventExitBootServicesGuid;
  97. /* vars-service-utils.c */
  98. gboolean uefi_str_is_valid(const uint16_t *str, size_t len,
  99. gboolean must_be_null_terminated);
  100. size_t uefi_strlen(const uint16_t *str, size_t len);
  101. gboolean uefi_str_equal_ex(const uint16_t *a, size_t alen,
  102. const uint16_t *b, size_t blen,
  103. gboolean wildcards_in_a);
  104. gboolean uefi_str_equal(const uint16_t *a, size_t alen,
  105. const uint16_t *b, size_t blen);
  106. char *uefi_ucs2_to_ascii(const uint16_t *ucs2, uint64_t ucs2_size);
  107. int uefi_time_compare(efi_time *a, efi_time *b);
  108. void uefi_trace_variable(const char *action, QemuUUID guid,
  109. const uint16_t *name, uint64_t name_size);
  110. void uefi_trace_status(const char *action, efi_status status);
  111. /* vars-service-core.c */
  112. extern const VMStateDescription vmstate_uefi_vars;
  113. void uefi_vars_init(Object *obj, uefi_vars_state *uv);
  114. void uefi_vars_realize(uefi_vars_state *uv, Error **errp);
  115. void uefi_vars_hard_reset(uefi_vars_state *uv);
  116. /* vars-service-json.c */
  117. void uefi_vars_json_init(uefi_vars_state *uv, Error **errp);
  118. void uefi_vars_json_save(uefi_vars_state *uv);
  119. void uefi_vars_json_load(uefi_vars_state *uv, Error **errp);
  120. /* vars-service-vars.c */
  121. extern const VMStateDescription vmstate_uefi_variable;
  122. uefi_variable *uefi_vars_find_variable(uefi_vars_state *uv, QemuUUID guid,
  123. const uint16_t *name,
  124. uint64_t name_size);
  125. void uefi_vars_set_variable(uefi_vars_state *uv, QemuUUID guid,
  126. const uint16_t *name, uint64_t name_size,
  127. uint32_t attributes,
  128. void *data, uint64_t data_size);
  129. void uefi_vars_clear_volatile(uefi_vars_state *uv);
  130. void uefi_vars_clear_all(uefi_vars_state *uv);
  131. void uefi_vars_update_storage(uefi_vars_state *uv);
  132. uint32_t uefi_vars_mm_vars_proto(uefi_vars_state *uv);
  133. /* vars-service-auth.c */
  134. bool uefi_vars_is_sb_pk(uefi_variable *var);
  135. bool uefi_vars_is_sb_any(uefi_variable *var);
  136. efi_status uefi_vars_check_auth_2(uefi_vars_state *uv, uefi_variable *var,
  137. mm_variable_access *va, void *data);
  138. efi_status uefi_vars_check_secure_boot(uefi_vars_state *uv, uefi_variable *var);
  139. void uefi_vars_auth_init(uefi_vars_state *uv);
  140. /* vars-service-pkcs7.c */
  141. efi_status uefi_vars_check_pkcs7_2(uefi_variable *siglist,
  142. void **digest, uint32_t *digest_size,
  143. mm_variable_access *va, void *data);
  144. /* vars-service-siglist.c */
  145. void uefi_vars_siglist_init(uefi_vars_siglist *siglist);
  146. void uefi_vars_siglist_free(uefi_vars_siglist *siglist);
  147. void uefi_vars_siglist_parse(uefi_vars_siglist *siglist,
  148. void *data, uint64_t size);
  149. uint64_t uefi_vars_siglist_blob_size(uefi_vars_siglist *siglist);
  150. void uefi_vars_siglist_blob_generate(uefi_vars_siglist *siglist,
  151. void *data, uint64_t size);
  152. /* vars-service-policy.c */
  153. extern const VMStateDescription vmstate_uefi_var_policy;
  154. efi_status uefi_vars_policy_check(uefi_vars_state *uv,
  155. uefi_variable *var,
  156. gboolean is_newvar);
  157. void uefi_vars_policies_clear(uefi_vars_state *uv);
  158. uefi_var_policy *uefi_vars_add_policy(uefi_vars_state *uv,
  159. variable_policy_entry *pe);
  160. uint32_t uefi_vars_mm_check_policy_proto(uefi_vars_state *uv);
  161. #endif /* QEMU_UEFI_VAR_SERVICE_H */