xref: /aosp_15_r20/external/coreboot/src/drivers/efi/efivars.c (revision b9411a12aaaa7e1e6a6fb7c5e057f44ee179a49c)
1 /* SPDX-License-Identifier: GPL-2.0-only */
2 
3 #include <stdint.h>
4 #include <string.h>
5 #include <console/console.h>
6 
7 #include <vendorcode/intel/edk2/UDK2017/MdePkg/Include/Uefi/UefiBaseType.h>
8 #include <vendorcode/intel/edk2/UDK2017/MdePkg/Include/Uefi/UefiMultiPhase.h>
9 #include <vendorcode/intel/edk2/UDK2017/MdePkg/Include/Pi/PiFirmwareVolume.h>
10 #include <vendorcode/intel/edk2/UDK2017/MdeModulePkg/Include/Guid/VariableFormat.h>
11 
12 #include "efivars.h"
13 
14 #define PREFIX "EFIVARS: "
15 
16 static const EFI_GUID EfiVariableGuid = {
17 	0xddcf3616, 0x3275, 0x4164, { 0x98, 0xb6, 0xfe, 0x85, 0x70, 0x7f, 0xfe, 0x7d } };
18 static const EFI_GUID EfiAuthenticatedVariableGuid = {
19 	0xaaf32c78, 0x947b, 0x439a, { 0xa1, 0x80, 0x2e, 0x14, 0x4e, 0xc3, 0x77, 0x92 } };
20 static const EFI_GUID EfiSystemNvDataFvGuid = {
21 	0xfff12b8d, 0x7696, 0x4c8b, { 0xa9, 0x85, 0x27, 0x47, 0x07, 0x5b, 0x4f, 0x50 } };
22 
print_guid(int log_level,const EFI_GUID * g)23 static void print_guid(int log_level, const EFI_GUID *g)
24 {
25 	printk(log_level, "GUID: %08x-%04x-%04x-%02x%02x%02x%02x%02x%02x%02x%02x",
26 		g->Data1, g->Data2, g->Data3, g->Data4[0], g->Data4[1], g->Data4[2],
27 		g->Data4[3], g->Data4[4], g->Data4[5], g->Data4[6], g->Data4[7]);
28 }
29 
compare_guid(const EFI_GUID * a,const EFI_GUID * b)30 static bool compare_guid(const EFI_GUID *a, const EFI_GUID *b)
31 {
32 	return memcmp(a, b, sizeof(*a)) == 0;
33 }
34 
35 /* Reads the CHAR16 string from rdev at offset and prints it */
rdev_print_wchar(int log_level,struct region_device * rdev,size_t offset)36 static enum cb_err rdev_print_wchar(int log_level, struct region_device *rdev, size_t offset)
37 {
38 	CHAR16 c;
39 	int i = 0;
40 
41 	/* Convert ASCII to UTF-16 */
42 	do {
43 		if (rdev_readat(rdev, &c, offset + i * sizeof(c), sizeof(c)) != sizeof(c))
44 			return CB_EFI_ACCESS_ERROR;
45 		if (c < 0x80)
46 			printk(log_level, "%c", (char)c);
47 		else
48 			printk(log_level, "\\u%04x", c);
49 
50 		i++;
51 	} while (c);
52 	return CB_SUCCESS;
53 }
54 
55 /* Convert an ASCII string to UTF-16 and write it to the rdev starting at offset. */
rdev_write_wchar(struct region_device * rdev,size_t offset,const char * msg)56 static enum cb_err rdev_write_wchar(struct region_device *rdev, size_t offset, const char *msg)
57 {
58 	size_t i;
59 	CHAR16 c;
60 
61 	/* Convert ASCII to UTF-16 */
62 	for (i = 0; i < strlen(msg) + 1; i++) {
63 		c = msg[i];
64 
65 		if (rdev_writeat(rdev, &c, offset + i * sizeof(c), sizeof(c)) != sizeof(c))
66 			return CB_EFI_ACCESS_ERROR;
67 	}
68 	return CB_SUCCESS;
69 }
70 
71 /* Read an UTF-16 string from rdev at offset and compare it to ASCII string */
rdev_strcmp_wchar_ascii(struct region_device * rdev,size_t offset,const char * msg)72 static int rdev_strcmp_wchar_ascii(struct region_device *rdev, size_t offset, const char *msg)
73 {
74 	size_t i;
75 	CHAR16 c;
76 	int r;
77 
78 	i = 0;
79 	/* Compare UTF-16 and ASCII */
80 	while (1) {
81 		if (rdev_readat(rdev, &c, offset + i * sizeof(c), sizeof(c)) != sizeof(c))
82 			return CB_EFI_ACCESS_ERROR;
83 		if ((r = (c - msg[i])) != 0 || !c)
84 			break;
85 
86 		i++;
87 	}
88 	return r;
89 }
90 
91 /* Compare an rdev region and a data buffer */
rdev_memcmp(struct region_device * rdev,size_t offset,uint8_t * data,size_t size)92 static int rdev_memcmp(struct region_device *rdev, size_t offset, uint8_t *data, size_t size)
93 {
94 	uint8_t buf[16];
95 	size_t i;
96 	int r;
97 
98 	i = 0;
99 	while (size >= sizeof(buf)) {
100 		if (rdev_readat(rdev, buf, offset + i, sizeof(buf)) != sizeof(buf))
101 			return CB_EFI_ACCESS_ERROR;
102 		r = memcmp(buf, data + i, sizeof(buf));
103 		if (r != 0)
104 			return r;
105 		i += sizeof(buf);
106 		size -= sizeof(buf);
107 	}
108 	while (size > 0) {
109 		if (rdev_readat(rdev, buf, offset + i, 1) != 1)
110 			return CB_EFI_ACCESS_ERROR;
111 		r = buf[0] - data[i];
112 		if (r != 0)
113 			return r;
114 		i++;
115 		size--;
116 	}
117 	return 0;
118 }
119 
120 
validate_fv_header(const struct region_device * rdev,EFI_FIRMWARE_VOLUME_HEADER * fw_vol_hdr)121 static enum cb_err validate_fv_header(const struct region_device *rdev,
122 				      EFI_FIRMWARE_VOLUME_HEADER *fw_vol_hdr)
123 {
124 	uint16_t checksum, data;
125 	size_t i;
126 
127 	if (rdev_readat(rdev, fw_vol_hdr, 0, sizeof(*fw_vol_hdr)) != sizeof(*fw_vol_hdr))
128 		return CB_EFI_ACCESS_ERROR;
129 
130 	/*
131 	 * Verify the header revision, header signature, length
132 	 * Length of FvBlock cannot be 2**64-1
133 	 * HeaderLength cannot be an odd number
134 	 */
135 	if ((fw_vol_hdr->Revision != EFI_FVH_REVISION)
136 	    || (fw_vol_hdr->Signature != EFI_FVH_SIGNATURE)
137 	    || (fw_vol_hdr->FvLength > region_device_sz(rdev))
138 	    || (fw_vol_hdr->HeaderLength > region_device_sz(rdev))
139 	    || (fw_vol_hdr->HeaderLength & 1)) {
140 		printk(BIOS_WARNING, PREFIX "No Firmware Volume header present\n");
141 		return CB_EFI_FVH_INVALID;
142 	}
143 
144 	/* Check the Firmware Volume Guid */
145 	if (!compare_guid(&fw_vol_hdr->FileSystemGuid, &EfiSystemNvDataFvGuid)) {
146 		printk(BIOS_WARNING, PREFIX "Firmware Volume Guid non-compatible\n");
147 		return CB_EFI_FVH_INVALID;
148 	}
149 
150 	/* Verify the header checksum */
151 	checksum = 0;
152 	for (i = 0; i < fw_vol_hdr->HeaderLength; i += 2) {
153 		if (rdev_readat(rdev, &data, i, sizeof(data)) != sizeof(data))
154 			return CB_EFI_ACCESS_ERROR;
155 		checksum = (uint16_t)(checksum + data); /* intentionally overflows */
156 	}
157 	if (checksum != 0) {
158 		printk(BIOS_WARNING, PREFIX "FV checksum is invalid: 0x%X\n", checksum);
159 		return CB_EFI_CHECKSUM_INVALID;
160 	}
161 
162 	printk(BIOS_SPEW, PREFIX "UEFI FV with size %lld found\n", fw_vol_hdr->FvLength);
163 
164 	return CB_SUCCESS;
165 }
166 
167 static enum cb_err
validate_variable_store_header(const EFI_FIRMWARE_VOLUME_HEADER * fv_hdr,struct region_device * rdev,bool * auth_format)168 validate_variable_store_header(const EFI_FIRMWARE_VOLUME_HEADER  *fv_hdr,
169 			       struct region_device *rdev,
170 			       bool *auth_format)
171 {
172 	VARIABLE_STORE_HEADER hdr;
173 	size_t length;
174 
175 	if (rdev_readat(rdev, &hdr, fv_hdr->HeaderLength, sizeof(hdr)) != sizeof(hdr))
176 		return CB_EFI_ACCESS_ERROR;
177 
178 	/* Check the Variable Store Guid */
179 	if (!compare_guid(&hdr.Signature, &EfiVariableGuid) &&
180 	    !compare_guid(&hdr.Signature, &EfiAuthenticatedVariableGuid)) {
181 		printk(BIOS_WARNING, PREFIX "Variable Store Guid non-compatible\n");
182 		return CB_EFI_VS_CORRUPTED_INVALID;
183 	}
184 
185 	*auth_format = compare_guid(&hdr.Signature, &EfiAuthenticatedVariableGuid);
186 
187 	length = region_device_sz(rdev) - fv_hdr->HeaderLength;
188 	if (hdr.Size > length) {
189 		printk(BIOS_WARNING, PREFIX "Variable Store Length does not match\n");
190 		return CB_EFI_VS_CORRUPTED_INVALID;
191 	}
192 
193 	if (hdr.Format != VARIABLE_STORE_FORMATTED)
194 		return CB_EFI_VS_NOT_FORMATTED_INVALID;
195 
196 	if (hdr.State != VARIABLE_STORE_HEALTHY)
197 		return CB_EFI_VS_CORRUPTED_INVALID;
198 
199 	if (rdev_chain(rdev, rdev, fv_hdr->HeaderLength + sizeof(hdr), hdr.Size)) {
200 		printk(BIOS_WARNING, PREFIX "rdev_chain failed\n");
201 		return CB_EFI_ACCESS_ERROR;
202 	}
203 
204 	printk(BIOS_SPEW, PREFIX "UEFI variable store with size %zu found\n",
205 		region_device_sz(rdev));
206 
207 	return CB_SUCCESS;
208 }
209 
210 struct efi_find_args {
211 	const EFI_GUID *guid;
212 	const char *name;
213 	uint32_t *size;
214 	void *data;
215 };
216 
match(struct region_device * rdev,VARIABLE_HEADER * hdr,size_t hdr_size,const char * name,const EFI_GUID * guid)217 static bool match(struct region_device *rdev, VARIABLE_HEADER *hdr, size_t hdr_size,
218 		  const char *name, const EFI_GUID *guid)
219 {
220 	/* Only search for valid or in transition to be deleted variables */
221 	if ((hdr->State != VAR_ADDED) &&
222 	    (hdr->State != (VAR_IN_DELETED_TRANSITION & VAR_ADDED)))
223 		return false;
224 
225 	if ((!compare_guid(&hdr->VendorGuid, guid)) ||
226 	    !hdr->NameSize ||
227 	    !hdr->DataSize)
228 		return false;
229 
230 	if (rdev_strcmp_wchar_ascii(rdev, hdr_size, name) != 0)
231 		return false;
232 
233 	return true;
234 }
235 
236 static
find_and_copy(struct region_device * rdev,VARIABLE_HEADER * hdr,size_t hdr_size,void * arg,bool * stop)237 enum cb_err find_and_copy(struct region_device *rdev, VARIABLE_HEADER *hdr, size_t hdr_size,
238 			  void *arg, bool *stop)
239 {
240 	struct efi_find_args *fa = (struct efi_find_args *)arg;
241 
242 	if (!match(rdev, hdr, hdr_size, fa->name, fa->guid))
243 		return CB_SUCCESS;
244 
245 	*stop = true;
246 	if (*(fa->size) < hdr->DataSize)
247 		return CB_EFI_BUFFER_TOO_SMALL;
248 
249 	if (rdev_readat(rdev, fa->data, hdr_size + hdr->NameSize, hdr->DataSize) !=
250 			hdr->DataSize)
251 		return CB_EFI_ACCESS_ERROR;
252 
253 	*(fa->size) = hdr->DataSize;
254 	return CB_SUCCESS;
255 }
256 
257 struct efi_find_compare_args {
258 	const EFI_GUID *guid;
259 	const char *name;
260 	uint32_t size;
261 	void *data;
262 	bool match;
263 };
264 
265 static
find_and_compare(struct region_device * rdev,VARIABLE_HEADER * hdr,size_t hdr_size,void * arg,bool * stop)266 enum cb_err find_and_compare(struct region_device *rdev, VARIABLE_HEADER *hdr, size_t hdr_size,
267 			     void *arg, bool *stop)
268 {
269 	struct efi_find_compare_args *fa = (struct efi_find_compare_args *)arg;
270 
271 	if (!match(rdev, hdr, hdr_size, fa->name, fa->guid))
272 		return CB_SUCCESS;
273 
274 	*stop = true;
275 	if (fa->size != hdr->DataSize) {
276 		fa->match = false;
277 		return CB_SUCCESS;
278 	}
279 
280 	fa->match = rdev_memcmp(rdev, hdr_size + hdr->NameSize, fa->data, hdr->DataSize) == 0;
281 
282 	return CB_SUCCESS;
283 }
284 
noop(struct region_device * rdev,VARIABLE_HEADER * hdr,size_t hdr_size,void * arg,bool * stop)285 static enum cb_err noop(struct region_device *rdev, VARIABLE_HEADER *hdr, size_t hdr_size,
286 			void *arg, bool *stop)
287 {
288 	/* Does nothing. */
289 	return CB_SUCCESS;
290 }
291 
print_var(struct region_device * rdev,VARIABLE_HEADER * hdr,size_t hdr_size,void * arg,bool * stop)292 static enum cb_err print_var(struct region_device *rdev, VARIABLE_HEADER *hdr, size_t hdr_size,
293 			     void *arg, bool *stop)
294 {
295 	uint8_t buf[16];
296 	size_t len, i;
297 
298 	printk(BIOS_DEBUG, "%08zx: Var ", region_device_offset(rdev));
299 	print_guid(BIOS_DEBUG, &hdr->VendorGuid);
300 
301 	printk(BIOS_DEBUG, "-");
302 
303 	rdev_print_wchar(BIOS_DEBUG, rdev, hdr_size);
304 
305 	printk(BIOS_DEBUG, ", State %02x, Size %02x\n", hdr->State, hdr->DataSize);
306 
307 	if (hdr->DataSize && hdr->NameSize) {
308 		len = sizeof(buf) < hdr->DataSize ? sizeof(buf) : hdr->DataSize;
309 		if (rdev_readat(rdev, buf, hdr_size + hdr->NameSize, len) != len)
310 			return CB_EFI_ACCESS_ERROR;
311 		printk(BIOS_DEBUG, "  Data: ");
312 
313 		for (i = 0; i < len; i++)
314 			printk(BIOS_DEBUG, "0x%02x ", buf[i]);
315 
316 		if (hdr->DataSize > len)
317 			printk(BIOS_DEBUG, "...");
318 
319 		printk(BIOS_DEBUG, "\n");
320 	}
321 
322 	return CB_SUCCESS;
323 }
324 
walk_variables(struct region_device * rdev,bool auth_format,enum cb_err (* walker)(struct region_device * rdev,VARIABLE_HEADER * hdr,size_t hdr_size,void * arg,bool * stop),void * walker_arg)325 static enum cb_err walk_variables(struct region_device *rdev,
326 				  bool auth_format,
327 				  enum cb_err (*walker)(struct region_device *rdev,
328 						   VARIABLE_HEADER *hdr,
329 						   size_t hdr_size,
330 						   void *arg,
331 						   bool *stop),
332 				  void *walker_arg)
333 {
334 	AUTHENTICATED_VARIABLE_HEADER auth_hdr;
335 	size_t header_size, var_size;
336 	VARIABLE_HEADER hdr;
337 	bool stop;
338 	enum cb_err ret;
339 
340 	if (auth_format)
341 		header_size = sizeof(AUTHENTICATED_VARIABLE_HEADER);
342 	else
343 		header_size = sizeof(VARIABLE_HEADER);
344 
345 	do {
346 		if (auth_format) {
347 			if (rdev_readat(rdev, &auth_hdr, 0, sizeof(auth_hdr))
348 					!= sizeof(auth_hdr))
349 				return CB_EFI_ACCESS_ERROR;
350 			hdr.Reserved = auth_hdr.Reserved;
351 			hdr.StartId = auth_hdr.StartId;
352 			hdr.State = auth_hdr.State;
353 			hdr.Attributes = auth_hdr.Attributes;
354 			hdr.NameSize = auth_hdr.NameSize;
355 			hdr.DataSize = auth_hdr.DataSize;
356 			memcpy(&hdr.VendorGuid, &auth_hdr.VendorGuid, sizeof(hdr.VendorGuid));
357 		} else if (rdev_readat(rdev, &hdr, 0, sizeof(hdr)) != sizeof(hdr)) {
358 			return CB_EFI_ACCESS_ERROR;
359 		}
360 		if (hdr.StartId != VARIABLE_DATA)
361 			break;
362 
363 		if (hdr.State == UINT8_MAX ||
364 		    hdr.DataSize == UINT32_MAX ||
365 		    hdr.NameSize == UINT32_MAX ||
366 		    hdr.Attributes == UINT32_MAX) {
367 			hdr.NameSize = 0;
368 			hdr.DataSize = 0;
369 		}
370 
371 		printk(BIOS_SPEW, "Found variable with state %02x and ", hdr.State);
372 		print_guid(BIOS_SPEW, &hdr.VendorGuid);
373 		printk(BIOS_SPEW, "\n");
374 
375 		stop = false;
376 
377 		ret = walker(rdev, &hdr, header_size, walker_arg, &stop);
378 
379 		if (ret != CB_SUCCESS || stop)
380 			return ret;
381 
382 		var_size = ALIGN_UP(header_size + hdr.NameSize + hdr.DataSize,
383 				    HEADER_ALIGNMENT);
384 	} while (!rdev_chain(rdev, rdev, var_size, region_device_sz(rdev) - var_size));
385 
386 	return CB_EFI_OPTION_NOT_FOUND;
387 }
388 
efi_fv_init(struct region_device * rdev,bool * auth_format)389 static enum cb_err efi_fv_init(struct region_device *rdev, bool *auth_format)
390 {
391 	EFI_FIRMWARE_VOLUME_HEADER fv_hdr;
392 	enum cb_err ret;
393 
394 	ret = validate_fv_header(rdev, &fv_hdr);
395 	if (ret != CB_SUCCESS) {
396 		printk(BIOS_WARNING, PREFIX "Failed to validate firmware header\n");
397 
398 		return ret;
399 	}
400 	ret = validate_variable_store_header(&fv_hdr, rdev, auth_format);
401 	if (ret != CB_SUCCESS)
402 		printk(BIOS_WARNING, PREFIX "Failed to validate variable store header\n");
403 
404 	return ret;
405 }
406 
efi_fv_print_options(struct region_device * rdev)407 enum cb_err efi_fv_print_options(struct region_device *rdev)
408 {
409 	enum cb_err ret;
410 	bool auth_format;
411 
412 	ret = efi_fv_init(rdev, &auth_format);
413 	if (ret != CB_SUCCESS)
414 		return ret;
415 
416 	return walk_variables(rdev, auth_format, print_var, NULL);
417 }
418 
419 /*
420  * efi_fv_get_option
421  * - writes up to *size bytes into a buffer pointed to by *dest
422  * - rdev is the spi flash region to operate on
423  * - the FVH and variable store header must have been initialized by a third party
424  */
efi_fv_get_option(struct region_device * rdev,const EFI_GUID * guid,const char * name,void * dest,uint32_t * size)425 enum cb_err efi_fv_get_option(struct region_device *rdev,
426 			      const EFI_GUID *guid,
427 			      const char *name,
428 			      void *dest,
429 			      uint32_t *size)
430 {
431 	struct efi_find_args args;
432 	bool auth_format;
433 	enum cb_err ret;
434 
435 	ret = efi_fv_init(rdev, &auth_format);
436 	if (ret != CB_SUCCESS)
437 		return ret;
438 
439 	args.guid = guid;
440 	args.name = name;
441 	args.size = size;
442 	args.data = dest;
443 
444 	return walk_variables(rdev, auth_format, find_and_copy, &args);
445 }
446 
write_auth_hdr(struct region_device * rdev,const EFI_GUID * guid,const char * name,void * data,size_t size)447 static enum cb_err write_auth_hdr(struct region_device *rdev, const EFI_GUID *guid,
448 				  const char *name, void *data, size_t size)
449 {
450 	AUTHENTICATED_VARIABLE_HEADER auth_hdr;
451 	size_t name_size, var_size;
452 	enum cb_err ret;
453 
454 	name_size = (strlen(name) + 1) * sizeof(CHAR16);
455 	var_size = name_size + size + sizeof(auth_hdr);
456 
457 	if (var_size > region_device_sz(rdev))
458 		return CB_EFI_STORE_FULL;
459 
460 	/* Sanity check. flash must be blank */
461 	if (rdev_readat(rdev, &auth_hdr, 0, sizeof(auth_hdr)) != sizeof(auth_hdr))
462 		return CB_EFI_ACCESS_ERROR;
463 
464 	if (auth_hdr.StartId != UINT16_MAX ||
465 	    auth_hdr.State != UINT8_MAX ||
466 	    auth_hdr.DataSize != UINT32_MAX ||
467 	    auth_hdr.NameSize != UINT32_MAX ||
468 	    auth_hdr.Attributes != UINT32_MAX) {
469 		return CB_EFI_ACCESS_ERROR;
470 	}
471 
472 	memset(&auth_hdr, 0xff, sizeof(auth_hdr));
473 
474 	auth_hdr.StartId = VARIABLE_DATA;
475 	auth_hdr.Attributes = EFI_VARIABLE_NON_VOLATILE|
476 			      EFI_VARIABLE_BOOTSERVICE_ACCESS|
477 			      EFI_VARIABLE_RUNTIME_ACCESS;
478 	auth_hdr.NameSize = name_size;
479 	auth_hdr.DataSize = size;
480 	memcpy(&auth_hdr.VendorGuid, guid, sizeof(EFI_GUID));
481 
482 	/* Write header with no State */
483 	if (rdev_writeat(rdev, &auth_hdr, 0, sizeof(auth_hdr)) != sizeof(auth_hdr))
484 		return CB_EFI_ACCESS_ERROR;
485 
486 	/* Set header State to valid header */
487 	auth_hdr.State = VAR_HEADER_VALID_ONLY;
488 	if (rdev_writeat(rdev, &auth_hdr.State, offsetof(AUTHENTICATED_VARIABLE_HEADER, State),
489 			 sizeof(auth_hdr.State)) != sizeof(auth_hdr.State))
490 		return CB_EFI_ACCESS_ERROR;
491 
492 	/* Write the name */
493 	ret = rdev_write_wchar(rdev, sizeof(auth_hdr), name);
494 	if (ret != CB_SUCCESS)
495 		return ret;
496 
497 	/* Write the data */
498 	if (rdev_writeat(rdev, data, sizeof(auth_hdr) + name_size, size) != size)
499 		return CB_EFI_ACCESS_ERROR;
500 
501 	/* Set header State to valid data */
502 	auth_hdr.State = VAR_ADDED;
503 	if (rdev_writeat(rdev, &auth_hdr.State, offsetof(AUTHENTICATED_VARIABLE_HEADER, State),
504 				sizeof(auth_hdr.State)) != sizeof(auth_hdr.State))
505 		return CB_EFI_ACCESS_ERROR;
506 
507 	return CB_SUCCESS;
508 }
509 
write_hdr(struct region_device * rdev,const EFI_GUID * guid,const char * name,void * data,size_t size)510 static enum cb_err write_hdr(struct region_device *rdev, const EFI_GUID *guid,
511 			     const char *name,
512 			     void *data,
513 			     size_t size)
514 {
515 	VARIABLE_HEADER hdr;
516 	size_t name_size, var_size;
517 	enum cb_err ret;
518 
519 	name_size = (strlen(name) + 1) * sizeof(CHAR16);
520 	var_size = name_size + size + sizeof(hdr);
521 	if (var_size > region_device_sz(rdev))
522 		return CB_EFI_STORE_FULL;
523 
524 	/* Sanity check. flash must be blank */
525 	if (rdev_readat(rdev, &hdr, 0, sizeof(hdr)) != sizeof(hdr))
526 		return CB_EFI_ACCESS_ERROR;
527 
528 	if (hdr.StartId != UINT16_MAX ||
529 	    hdr.State != UINT8_MAX ||
530 	    hdr.DataSize != UINT32_MAX ||
531 	    hdr.NameSize != UINT32_MAX ||
532 	    hdr.Attributes != UINT32_MAX) {
533 		return CB_EFI_ACCESS_ERROR;
534 	}
535 
536 	memset(&hdr, 0xff, sizeof(hdr));
537 
538 	hdr.StartId = VARIABLE_DATA;
539 	hdr.Attributes = EFI_VARIABLE_NON_VOLATILE|
540 			 EFI_VARIABLE_BOOTSERVICE_ACCESS|
541 			 EFI_VARIABLE_RUNTIME_ACCESS;
542 	hdr.NameSize = name_size;
543 	hdr.DataSize = size;
544 	memcpy(&hdr.VendorGuid, guid, sizeof(EFI_GUID));
545 
546 	/* Write header with no State */
547 	if (rdev_writeat(rdev, &hdr, 0, sizeof(hdr)) != sizeof(hdr))
548 		return CB_EFI_ACCESS_ERROR;
549 
550 	/* Set header State to valid header */
551 	hdr.State = VAR_HEADER_VALID_ONLY;
552 	if (rdev_writeat(rdev, &hdr.State, offsetof(VARIABLE_HEADER, State),
553 			 sizeof(hdr.State)) != sizeof(hdr.State))
554 		return CB_EFI_ACCESS_ERROR;
555 
556 	/* Write the name */
557 	ret = rdev_write_wchar(rdev, sizeof(hdr), name);
558 	if (ret != CB_SUCCESS)
559 		return ret;
560 
561 	/* Write the data */
562 	if (rdev_writeat(rdev, data, sizeof(hdr) + name_size, size) != size)
563 		return CB_EFI_ACCESS_ERROR;
564 
565 	/* Set header State to valid data */
566 	hdr.State = VAR_ADDED;
567 	if (rdev_writeat(rdev, &hdr.State, offsetof(VARIABLE_HEADER, State),
568 				sizeof(hdr.State)) != sizeof(hdr.State))
569 		return CB_EFI_ACCESS_ERROR;
570 
571 	return CB_SUCCESS;
572 }
573 
574 /*
575  * efi_fv_set_option
576  * - writes size bytes read from the buffer pointed to by *data
577  * - rdev is the spi flash region to operate on
578  * - the FVH and variable store header must have been initialized by a third party
579  */
efi_fv_set_option(struct region_device * rdev,const EFI_GUID * guid,const char * name,void * data,uint32_t size)580 enum cb_err efi_fv_set_option(struct region_device *rdev,
581 			      const EFI_GUID *guid,
582 			      const char *name,
583 			      void *data,
584 			      uint32_t size)
585 {
586 	struct region_device rdev_old;
587 	struct efi_find_compare_args args;
588 	bool found_existing;
589 	VARIABLE_HEADER hdr;
590 	bool auth_format;
591 	enum cb_err ret;
592 
593 	ret = efi_fv_init(rdev, &auth_format);
594 	if (ret != CB_SUCCESS)
595 		return ret;
596 
597 	/* Find existing variable */
598 	args.guid = guid;
599 	args.name = name;
600 	args.size = size;
601 	args.match = false;
602 	args.data = data;
603 
604 	ret = walk_variables(rdev, auth_format, find_and_compare, &args);
605 	found_existing = ret == CB_SUCCESS;
606 
607 	if (found_existing) {
608 		printk(BIOS_ERR, "found existing variable %s, match =%d\n", name, args.match);
609 
610 		if (args.match)
611 			return CB_SUCCESS;
612 
613 		rdev_old = *rdev;
614 
615 		/* Mark as to be deleted */
616 		hdr.State = VAR_IN_DELETED_TRANSITION;
617 		if (rdev_writeat(rdev, &hdr.State, offsetof(VARIABLE_HEADER, State),
618 			sizeof(hdr.State)) != sizeof(hdr.State))
619 			return CB_EFI_ACCESS_ERROR;
620 	}
621 
622 	/* Walk to end of variable store */
623 	ret = walk_variables(rdev, auth_format, noop, NULL);
624 	if (ret != CB_EFI_OPTION_NOT_FOUND)
625 		return ret;
626 
627 	/* Now append new variable:
628 	 * 1. Write the header without State field.
629 	 * 2. Write the State field and set it to HEADER_VALID.
630 	 * 3. Write data
631 	 * 4. Write the State field and set it to VAR_ADDED
632 	 */
633 
634 	if (auth_format)
635 		ret = write_auth_hdr(rdev, guid, name, data, size);
636 	else
637 		ret = write_hdr(rdev, guid, name, data, size);
638 	if (ret != CB_SUCCESS)
639 		return ret;
640 
641 	if (found_existing) {
642 		/* Mark old variable as deleted */
643 		hdr.State = VAR_DELETED;
644 		if (rdev_writeat(&rdev_old, &hdr.State, offsetof(VARIABLE_HEADER, State),
645 			sizeof(hdr.State)) != sizeof(hdr.State))
646 			return CB_EFI_ACCESS_ERROR;
647 	}
648 
649 	return CB_SUCCESS;
650 }
651