]> git.proxmox.com Git - mirror_edk2.git/blame - MdeModulePkg/Universal/Disk/PartitionDxe/Mbr.c
MdeModulePkg/PartitionDxe: Ensure blocksize holds MBR (CVE-2018-12180)
[mirror_edk2.git] / MdeModulePkg / Universal / Disk / PartitionDxe / Mbr.c
CommitLineData
f42be642 1/** @file\r
adbcbf8f 2 Decode a hard disk partitioned with the legacy MBR found on most PC's\r
3\r
4 MBR - Master Boot Record is in the first sector of a partitioned hard disk.\r
5 The MBR supports four partitions per disk. The MBR also contains legacy\r
d1102dba
LG
6 code that is not run on an EFI system. The legacy code reads the\r
7 first sector of the active partition into memory and\r
adbcbf8f 8\r
d1102dba
LG
9 BPB - BIOS Parameter Block is in the first sector of a FAT file system.\r
10 The BPB contains information about the FAT file system. The BPB is\r
adbcbf8f 11 always on the first sector of a media. The first sector also contains\r
12 the legacy boot strap code.\r
13\r
709c9fd5 14Copyright (c) 2018 Qualcomm Datacenter Technologies, Inc.\r
01331951 15Copyright (c) 2014, Hewlett-Packard Development Company, L.P.<BR>\r
fccdb880 16Copyright (c) 2006 - 2019, Intel Corporation. All rights reserved.<BR>\r
e5eed7d3 17This program and the accompanying materials\r
f42be642 18are licensed and made available under the terms and conditions of the BSD License\r
19which accompanies this distribution. The full text of the license may be found at\r
20http://opensource.org/licenses/bsd-license.php\r
21\r
22THE PROGRAM IS DISTRIBUTED UNDER THE BSD LICENSE ON AN "AS IS" BASIS,\r
23WITHOUT WARRANTIES OR REPRESENTATIONS OF ANY KIND, EITHER EXPRESS OR IMPLIED.\r
24\r
25**/\r
adbcbf8f 26\r
27#include "Partition.h"\r
28\r
a8d0c20e 29/**\r
30 Test to see if the Mbr buffer is a valid MBR.\r
31\r
32 @param Mbr Parent Handle.\r
33 @param LastLba Last Lba address on the device.\r
d1102dba 34\r
a8d0c20e 35 @retval TRUE Mbr is a Valid MBR.\r
36 @retval FALSE Mbr is not a Valid MBR.\r
37\r
38**/\r
adbcbf8f 39BOOLEAN\r
40PartitionValidMbr (\r
41 IN MASTER_BOOT_RECORD *Mbr,\r
42 IN EFI_LBA LastLba\r
43 )\r
adbcbf8f 44{\r
45 UINT32 StartingLBA;\r
46 UINT32 EndingLBA;\r
47 UINT32 NewEndingLBA;\r
48 INTN Index1;\r
49 INTN Index2;\r
50 BOOLEAN MbrValid;\r
51\r
52 if (Mbr->Signature != MBR_SIGNATURE) {\r
53 return FALSE;\r
54 }\r
55 //\r
56 // The BPB also has this signature, so it can not be used alone.\r
57 //\r
58 MbrValid = FALSE;\r
59 for (Index1 = 0; Index1 < MAX_MBR_PARTITIONS; Index1++) {\r
60 if (Mbr->Partition[Index1].OSIndicator == 0x00 || UNPACK_UINT32 (Mbr->Partition[Index1].SizeInLBA) == 0) {\r
61 continue;\r
62 }\r
63\r
64 MbrValid = TRUE;\r
65 StartingLBA = UNPACK_UINT32 (Mbr->Partition[Index1].StartingLBA);\r
66 EndingLBA = StartingLBA + UNPACK_UINT32 (Mbr->Partition[Index1].SizeInLBA) - 1;\r
67 if (EndingLBA > LastLba) {\r
68 //\r
69 // Compatibility Errata:\r
70 // Some systems try to hide drive space with their INT 13h driver\r
71 // This does not hide space from the OS driver. This means the MBR\r
72 // that gets created from DOS is smaller than the MBR created from\r
73 // a real OS (NT & Win98). This leads to BlockIo->LastBlock being\r
74 // wrong on some systems FDISKed by the OS.\r
75 //\r
76 // return FALSE since no block devices on a system are implemented\r
77 // with INT 13h\r
78 //\r
d1102dba 79\r
01331951
SEHM
80 DEBUG((EFI_D_INFO, "PartitionValidMbr: Bad MBR partition size EndingLBA(%1x) > LastLBA(%1x)\n", EndingLBA, LastLba));\r
81\r
adbcbf8f 82 return FALSE;\r
83 }\r
84\r
85 for (Index2 = Index1 + 1; Index2 < MAX_MBR_PARTITIONS; Index2++) {\r
86 if (Mbr->Partition[Index2].OSIndicator == 0x00 || UNPACK_UINT32 (Mbr->Partition[Index2].SizeInLBA) == 0) {\r
87 continue;\r
88 }\r
89\r
90 NewEndingLBA = UNPACK_UINT32 (Mbr->Partition[Index2].StartingLBA) + UNPACK_UINT32 (Mbr->Partition[Index2].SizeInLBA) - 1;\r
91 if (NewEndingLBA >= StartingLBA && UNPACK_UINT32 (Mbr->Partition[Index2].StartingLBA) <= EndingLBA) {\r
92 //\r
93 // This region overlaps with the Index1'th region\r
94 //\r
95 return FALSE;\r
96 }\r
97 }\r
98 }\r
99 //\r
ea7cb08c 100 // None of the regions overlapped so MBR is O.K.\r
adbcbf8f 101 //\r
102 return MbrValid;\r
103}\r
104\r
a8d0c20e 105\r
106/**\r
107 Install child handles if the Handle supports MBR format.\r
108\r
490b5ea1 109 @param[in] This Calling context.\r
110 @param[in] Handle Parent Handle.\r
111 @param[in] DiskIo Parent DiskIo interface.\r
493d8e3a 112 @param[in] DiskIo2 Parent DiskIo2 interface.\r
490b5ea1 113 @param[in] BlockIo Parent BlockIo interface.\r
114 @param[in] BlockIo2 Parent BlockIo2 interface.\r
115 @param[in] DevicePath Parent Device Path.\r
d1102dba 116\r
a8d0c20e 117 @retval EFI_SUCCESS A child handle was added.\r
118 @retval EFI_MEDIA_CHANGED Media change was detected.\r
119 @retval Others MBR partition was not found.\r
120\r
121**/\r
adbcbf8f 122EFI_STATUS\r
123PartitionInstallMbrChildHandles (\r
124 IN EFI_DRIVER_BINDING_PROTOCOL *This,\r
125 IN EFI_HANDLE Handle,\r
126 IN EFI_DISK_IO_PROTOCOL *DiskIo,\r
493d8e3a 127 IN EFI_DISK_IO2_PROTOCOL *DiskIo2,\r
adbcbf8f 128 IN EFI_BLOCK_IO_PROTOCOL *BlockIo,\r
490b5ea1 129 IN EFI_BLOCK_IO2_PROTOCOL *BlockIo2,\r
adbcbf8f 130 IN EFI_DEVICE_PATH_PROTOCOL *DevicePath\r
131 )\r
adbcbf8f 132{\r
3a3d62d2
HW
133 EFI_STATUS Status;\r
134 MASTER_BOOT_RECORD *Mbr;\r
135 UINT32 ExtMbrStartingLba;\r
136 UINT32 Index;\r
137 HARDDRIVE_DEVICE_PATH HdDev;\r
138 HARDDRIVE_DEVICE_PATH ParentHdDev;\r
139 EFI_STATUS Found;\r
140 EFI_DEVICE_PATH_PROTOCOL *DevicePathNode;\r
141 EFI_DEVICE_PATH_PROTOCOL *LastDevicePathNode;\r
142 UINT32 BlockSize;\r
143 UINT32 MediaId;\r
144 EFI_LBA LastBlock;\r
145 EFI_PARTITION_INFO_PROTOCOL PartitionInfo;\r
adbcbf8f 146\r
adbcbf8f 147 Found = EFI_NOT_FOUND;\r
148\r
490b5ea1 149 BlockSize = BlockIo->Media->BlockSize;\r
150 MediaId = BlockIo->Media->MediaId;\r
151 LastBlock = BlockIo->Media->LastBlock;\r
152\r
fccdb880
HW
153 //\r
154 // Ensure the block size can hold the MBR\r
155 //\r
156 if (BlockSize < sizeof (MASTER_BOOT_RECORD)) {\r
157 return EFI_NOT_FOUND;\r
158 }\r
159\r
490b5ea1 160 Mbr = AllocatePool (BlockSize);\r
adbcbf8f 161 if (Mbr == NULL) {\r
737dfc36 162 return Found;\r
adbcbf8f 163 }\r
164\r
96f99e1d 165 Status = DiskIo->ReadDisk (\r
166 DiskIo,\r
490b5ea1 167 MediaId,\r
96f99e1d 168 0,\r
490b5ea1 169 BlockSize,\r
96f99e1d 170 Mbr\r
171 );\r
adbcbf8f 172 if (EFI_ERROR (Status)) {\r
173 Found = Status;\r
174 goto Done;\r
175 }\r
490b5ea1 176 if (!PartitionValidMbr (Mbr, LastBlock)) {\r
adbcbf8f 177 goto Done;\r
178 }\r
179 //\r
180 // We have a valid mbr - add each partition\r
181 //\r
182 //\r
183 // Get starting and ending LBA of the parent block device.\r
184 //\r
185 LastDevicePathNode = NULL;\r
186 ZeroMem (&ParentHdDev, sizeof (ParentHdDev));\r
187 DevicePathNode = DevicePath;\r
1232b214 188 while (!IsDevicePathEnd (DevicePathNode)) {\r
adbcbf8f 189 LastDevicePathNode = DevicePathNode;\r
1232b214 190 DevicePathNode = NextDevicePathNode (DevicePathNode);\r
adbcbf8f 191 }\r
192\r
193 if (LastDevicePathNode != NULL) {\r
194 if (DevicePathType (LastDevicePathNode) == MEDIA_DEVICE_PATH &&\r
195 DevicePathSubType (LastDevicePathNode) == MEDIA_HARDDRIVE_DP\r
196 ) {\r
197 CopyMem (&ParentHdDev, LastDevicePathNode, sizeof (ParentHdDev));\r
198 } else {\r
199 LastDevicePathNode = NULL;\r
200 }\r
201 }\r
202\r
adbcbf8f 203 ZeroMem (&HdDev, sizeof (HdDev));\r
204 HdDev.Header.Type = MEDIA_DEVICE_PATH;\r
205 HdDev.Header.SubType = MEDIA_HARDDRIVE_DP;\r
206 SetDevicePathNodeLength (&HdDev.Header, sizeof (HdDev));\r
207 HdDev.MBRType = MBR_TYPE_PCAT;\r
208 HdDev.SignatureType = SIGNATURE_TYPE_MBR;\r
209\r
210 if (LastDevicePathNode == NULL) {\r
211 //\r
212 // This is a MBR, add each partition\r
213 //\r
214 for (Index = 0; Index < MAX_MBR_PARTITIONS; Index++) {\r
215 if (Mbr->Partition[Index].OSIndicator == 0x00 || UNPACK_UINT32 (Mbr->Partition[Index].SizeInLBA) == 0) {\r
216 //\r
217 // Don't use null MBR entries\r
218 //\r
219 continue;\r
220 }\r
221\r
222 if (Mbr->Partition[Index].OSIndicator == PMBR_GPT_PARTITION) {\r
223 //\r
224 // This is the guard MBR for the GPT. If you ever see a GPT disk with zero partitions you can get here.\r
d1102dba 225 // We can not produce an MBR BlockIo for this device as the MBR spans the GPT headers. So formating\r
adbcbf8f 226 // this BlockIo would corrupt the GPT structures and require a recovery that would corrupt the format\r
d1102dba 227 // that corrupted the GPT partition.\r
adbcbf8f 228 //\r
229 continue;\r
230 }\r
231\r
e665a69d 232 HdDev.PartitionNumber = Index + 1;\r
adbcbf8f 233 HdDev.PartitionStart = UNPACK_UINT32 (Mbr->Partition[Index].StartingLBA);\r
234 HdDev.PartitionSize = UNPACK_UINT32 (Mbr->Partition[Index].SizeInLBA);\r
48557c65 235 CopyMem (HdDev.Signature, &(Mbr->UniqueMbrSignature[0]), sizeof (Mbr->UniqueMbrSignature));\r
adbcbf8f 236\r
3a3d62d2
HW
237 ZeroMem (&PartitionInfo, sizeof (EFI_PARTITION_INFO_PROTOCOL));\r
238 PartitionInfo.Revision = EFI_PARTITION_INFO_PROTOCOL_REVISION;\r
239 PartitionInfo.Type = PARTITION_TYPE_MBR;\r
240 if (Mbr->Partition[Index].OSIndicator == EFI_PARTITION) {\r
241 PartitionInfo.System = 1;\r
242 }\r
243 CopyMem (&PartitionInfo.Info.Mbr, &Mbr->Partition[Index], sizeof (MBR_PARTITION_RECORD));\r
244\r
adbcbf8f 245 Status = PartitionInstallChildHandle (\r
246 This,\r
247 Handle,\r
248 DiskIo,\r
493d8e3a 249 DiskIo2,\r
adbcbf8f 250 BlockIo,\r
490b5ea1 251 BlockIo2,\r
adbcbf8f 252 DevicePath,\r
253 (EFI_DEVICE_PATH_PROTOCOL *) &HdDev,\r
3a3d62d2 254 &PartitionInfo,\r
adbcbf8f 255 HdDev.PartitionStart,\r
256 HdDev.PartitionStart + HdDev.PartitionSize - 1,\r
709c9fd5
JB
257 MBR_SIZE,\r
258 ((Mbr->Partition[Index].OSIndicator == EFI_PARTITION) ? &gEfiPartTypeSystemPartGuid: NULL)\r
adbcbf8f 259 );\r
260\r
261 if (!EFI_ERROR (Status)) {\r
262 Found = EFI_SUCCESS;\r
263 }\r
264 }\r
265 } else {\r
266 //\r
267 // It's an extended partition. Follow the extended partition\r
268 // chain to get all the logical drives\r
269 //\r
e665a69d 270 Index = 0;\r
adbcbf8f 271 ExtMbrStartingLba = 0;\r
272\r
273 do {\r
274\r
96f99e1d 275 Status = DiskIo->ReadDisk (\r
276 DiskIo,\r
490b5ea1 277 MediaId,\r
278 MultU64x32 (ExtMbrStartingLba, BlockSize),\r
279 BlockSize,\r
96f99e1d 280 Mbr\r
281 );\r
adbcbf8f 282 if (EFI_ERROR (Status)) {\r
283 Found = Status;\r
284 goto Done;\r
285 }\r
286\r
c63cd426 287 if (UNPACK_UINT32 (Mbr->Partition[0].SizeInLBA) == 0) {\r
adbcbf8f 288 break;\r
289 }\r
290\r
291 if ((Mbr->Partition[0].OSIndicator == EXTENDED_DOS_PARTITION) ||\r
292 (Mbr->Partition[0].OSIndicator == EXTENDED_WINDOWS_PARTITION)) {\r
293 ExtMbrStartingLba = UNPACK_UINT32 (Mbr->Partition[0].StartingLBA);\r
294 continue;\r
295 }\r
e665a69d 296 HdDev.PartitionNumber = ++Index;\r
adbcbf8f 297 HdDev.PartitionStart = UNPACK_UINT32 (Mbr->Partition[0].StartingLBA) + ExtMbrStartingLba + ParentHdDev.PartitionStart;\r
298 HdDev.PartitionSize = UNPACK_UINT32 (Mbr->Partition[0].SizeInLBA);\r
299 if ((HdDev.PartitionStart + HdDev.PartitionSize - 1 >= ParentHdDev.PartitionStart + ParentHdDev.PartitionSize) ||\r
300 (HdDev.PartitionStart <= ParentHdDev.PartitionStart)) {\r
301 break;\r
302 }\r
303\r
304 //\r
305 // The signature in EBR(Extended Boot Record) should always be 0.\r
306 //\r
307 *((UINT32 *) &HdDev.Signature[0]) = 0;\r
308\r
3a3d62d2
HW
309 ZeroMem (&PartitionInfo, sizeof (EFI_PARTITION_INFO_PROTOCOL));\r
310 PartitionInfo.Revision = EFI_PARTITION_INFO_PROTOCOL_REVISION;\r
311 PartitionInfo.Type = PARTITION_TYPE_MBR;\r
312 if (Mbr->Partition[0].OSIndicator == EFI_PARTITION) {\r
313 PartitionInfo.System = 1;\r
314 }\r
315 CopyMem (&PartitionInfo.Info.Mbr, &Mbr->Partition[0], sizeof (MBR_PARTITION_RECORD));\r
316\r
adbcbf8f 317 Status = PartitionInstallChildHandle (\r
490b5ea1 318 This,\r
319 Handle,\r
320 DiskIo,\r
493d8e3a 321 DiskIo2,\r
490b5ea1 322 BlockIo,\r
323 BlockIo2,\r
324 DevicePath,\r
325 (EFI_DEVICE_PATH_PROTOCOL *) &HdDev,\r
3a3d62d2 326 &PartitionInfo,\r
490b5ea1 327 HdDev.PartitionStart - ParentHdDev.PartitionStart,\r
328 HdDev.PartitionStart - ParentHdDev.PartitionStart + HdDev.PartitionSize - 1,\r
709c9fd5
JB
329 MBR_SIZE,\r
330 ((Mbr->Partition[0].OSIndicator == EFI_PARTITION) ? &gEfiPartTypeSystemPartGuid: NULL)\r
490b5ea1 331 );\r
adbcbf8f 332 if (!EFI_ERROR (Status)) {\r
333 Found = EFI_SUCCESS;\r
334 }\r
335\r
336 if ((Mbr->Partition[1].OSIndicator != EXTENDED_DOS_PARTITION) &&\r
337 (Mbr->Partition[1].OSIndicator != EXTENDED_WINDOWS_PARTITION)\r
338 ) {\r
339 break;\r
340 }\r
341\r
342 ExtMbrStartingLba = UNPACK_UINT32 (Mbr->Partition[1].StartingLBA);\r
343 //\r
344 // Don't allow partition to be self referencing\r
345 //\r
346 if (ExtMbrStartingLba == 0) {\r
347 break;\r
348 }\r
349 } while (ExtMbrStartingLba < ParentHdDev.PartitionSize);\r
350 }\r
351\r
352Done:\r
353 FreePool (Mbr);\r
354\r
355 return Found;\r
356}\r