2 Implementation functions and structures for var check protocol.
4 Copyright (c) 2015, Intel Corporation. All rights reserved.<BR>
5 This program and the accompanying materials
6 are licensed and made available under the terms and conditions of the BSD License
7 which accompanies this distribution. The full text of the license may be found at
8 http://opensource.org/licenses/bsd-license.php
10 THE PROGRAM IS DISTRIBUTED UNDER THE BSD LICENSE ON AN "AS IS" BASIS,
11 WITHOUT WARRANTIES OR REPRESENTATIONS OF ANY KIND, EITHER EXPRESS OR IMPLIED.
16 #include <Library/DevicePathLib.h>
18 extern LIST_ENTRY mLockedVariableList
;
19 extern BOOLEAN mEndOfDxe
;
20 extern BOOLEAN mEnableLocking
;
22 #define VAR_CHECK_HANDLER_TABLE_SIZE 0x8
24 UINT32 mNumberOfHandler
= 0;
25 UINT32 mMaxNumberOfHandler
= 0;
26 VAR_CHECK_SET_VARIABLE_CHECK_HANDLER
*mHandlerTable
= NULL
;
31 VAR_CHECK_VARIABLE_PROPERTY VariableProperty
;
33 } VAR_CHECK_VARIABLE_ENTRY
;
35 LIST_ENTRY mVarCheckVariableList
= INITIALIZE_LIST_HEAD_VARIABLE (mVarCheckVariableList
);
39 (EFIAPI
*INTERNAL_VAR_CHECK_FUNCTION
) (
40 IN VAR_CHECK_VARIABLE_PROPERTY
*Propery
,
47 VAR_CHECK_VARIABLE_PROPERTY VariableProperty
;
48 INTERNAL_VAR_CHECK_FUNCTION CheckFunction
;
49 } UEFI_DEFINED_VARIABLE_ENTRY
;
52 Internal check for load option.
54 @param[in] VariablePropery Pointer to variable property.
55 @param[in] DataSize Data size.
56 @param[in] Data Pointer to data buffer.
58 @retval EFI_SUCCESS The SetVariable check result was success.
59 @retval EFI_INVALID_PARAMETER The data buffer is not a valid load option.
64 InternalVarCheckLoadOption (
65 IN VAR_CHECK_VARIABLE_PROPERTY
*VariablePropery
,
70 UINT16 FilePathListLength
;
72 EFI_DEVICE_PATH_PROTOCOL
*FilePathList
;
74 FilePathListLength
= *((UINT16
*) ((UINTN
) Data
+ sizeof (UINT32
)));
79 Description
= (CHAR16
*) ((UINTN
) Data
+ sizeof (UINT32
) + sizeof (UINT16
));
80 while (Description
< (CHAR16
*) ((UINTN
) Data
+ DataSize
)) {
81 if (*Description
== L
'\0') {
86 if ((UINTN
) Description
>= ((UINTN
) Data
+ DataSize
)) {
87 return EFI_INVALID_PARAMETER
;
94 FilePathList
= (EFI_DEVICE_PATH_PROTOCOL
*) Description
;
95 if ((UINTN
) FilePathList
> (MAX_ADDRESS
- FilePathListLength
)) {
96 return EFI_INVALID_PARAMETER
;
98 if (((UINTN
) FilePathList
+ FilePathListLength
) > ((UINTN
) Data
+ DataSize
)) {
99 return EFI_INVALID_PARAMETER
;
101 if (FilePathListLength
< sizeof (EFI_DEVICE_PATH_PROTOCOL
)) {
102 return EFI_INVALID_PARAMETER
;
104 if (!IsDevicePathValid (FilePathList
, FilePathListLength
)) {
105 return EFI_INVALID_PARAMETER
;
112 Internal check for key option.
114 @param[in] VariablePropery Pointer to variable property.
115 @param[in] DataSize Data size.
116 @param[in] Data Pointer to data buffer.
118 @retval EFI_SUCCESS The SetVariable check result was success.
119 @retval EFI_INVALID_PARAMETER The data buffer is not a valid key option.
124 InternalVarCheckKeyOption (
125 IN VAR_CHECK_VARIABLE_PROPERTY
*VariablePropery
,
130 if (((DataSize
- sizeof (EFI_KEY_OPTION
)) % sizeof (EFI_INPUT_KEY
)) != 0) {
131 return EFI_INVALID_PARAMETER
;
138 Internal check for device path.
140 @param[in] VariablePropery Pointer to variable property.
141 @param[in] DataSize Data size.
142 @param[in] Data Pointer to data buffer.
144 @retval EFI_SUCCESS The SetVariable check result was success.
145 @retval EFI_INVALID_PARAMETER The data buffer is not a valid device path.
150 InternalVarCheckDevicePath (
151 IN VAR_CHECK_VARIABLE_PROPERTY
*VariablePropery
,
156 if (!IsDevicePathValid ((EFI_DEVICE_PATH_PROTOCOL
*) Data
, DataSize
)) {
157 return EFI_INVALID_PARAMETER
;
163 Internal check for ASCII string.
165 @param[in] VariablePropery Pointer to variable property.
166 @param[in] DataSize Data size.
167 @param[in] Data Pointer to data buffer.
169 @retval EFI_SUCCESS The SetVariable check result was success.
170 @retval EFI_INVALID_PARAMETER The data buffer is not a Null-terminated ASCII string.
175 InternalVarCheckAsciiString (
176 IN VAR_CHECK_VARIABLE_PROPERTY
*VariablePropery
,
184 String
= (CHAR8
*) Data
;
185 if (String
[DataSize
- 1] == '\0') {
188 for (Index
= 1; Index
< DataSize
&& (String
[DataSize
- 1 - Index
] != '\0'); Index
++);
189 if (Index
== DataSize
) {
190 return EFI_INVALID_PARAMETER
;
197 Internal check for size array.
199 @param[in] VariablePropery Pointer to variable property.
200 @param[in] DataSize Data size.
201 @param[in] Data Pointer to data buffer.
203 @retval EFI_SUCCESS The SetVariable check result was success.
204 @retval EFI_INVALID_PARAMETER The DataSize is not size array.
209 InternalVarCheckSizeArray (
210 IN VAR_CHECK_VARIABLE_PROPERTY
*VariablePropery
,
215 if ((DataSize
% VariablePropery
->MinSize
) != 0) {
216 return EFI_INVALID_PARAMETER
;
222 // To prevent name collisions with possible future globally defined variables,
223 // other internal firmware data variables that are not defined here must be
224 // saved with a unique VendorGuid other than EFI_GLOBAL_VARIABLE or
225 // any other GUID defined by the UEFI Specification. Implementations must
226 // only permit the creation of variables with a UEFI Specification-defined
227 // VendorGuid when these variables are documented in the UEFI Specification.
229 UEFI_DEFINED_VARIABLE_ENTRY mGlobalVariableList
[] = {
231 EFI_LANG_CODES_VARIABLE_NAME
,
233 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
235 VARIABLE_ATTRIBUTE_BS_RT
,
239 InternalVarCheckAsciiString
242 EFI_LANG_VARIABLE_NAME
,
244 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
246 VARIABLE_ATTRIBUTE_NV_BS_RT
,
250 InternalVarCheckAsciiString
253 EFI_TIME_OUT_VARIABLE_NAME
,
255 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
257 VARIABLE_ATTRIBUTE_NV_BS_RT
,
264 EFI_PLATFORM_LANG_CODES_VARIABLE_NAME
,
266 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
268 VARIABLE_ATTRIBUTE_BS_RT
,
272 InternalVarCheckAsciiString
275 EFI_PLATFORM_LANG_VARIABLE_NAME
,
277 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
279 VARIABLE_ATTRIBUTE_NV_BS_RT
,
283 InternalVarCheckAsciiString
286 EFI_CON_IN_VARIABLE_NAME
,
288 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
290 VARIABLE_ATTRIBUTE_NV_BS_RT
,
291 sizeof (EFI_DEVICE_PATH_PROTOCOL
),
294 InternalVarCheckDevicePath
297 EFI_CON_OUT_VARIABLE_NAME
,
299 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
301 VARIABLE_ATTRIBUTE_NV_BS_RT
,
302 sizeof (EFI_DEVICE_PATH_PROTOCOL
),
305 InternalVarCheckDevicePath
308 EFI_ERR_OUT_VARIABLE_NAME
,
310 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
312 VARIABLE_ATTRIBUTE_NV_BS_RT
,
313 sizeof (EFI_DEVICE_PATH_PROTOCOL
),
316 InternalVarCheckDevicePath
319 EFI_CON_IN_DEV_VARIABLE_NAME
,
321 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
323 VARIABLE_ATTRIBUTE_BS_RT
,
324 sizeof (EFI_DEVICE_PATH_PROTOCOL
),
327 InternalVarCheckDevicePath
330 EFI_CON_OUT_DEV_VARIABLE_NAME
,
332 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
334 VARIABLE_ATTRIBUTE_BS_RT
,
335 sizeof (EFI_DEVICE_PATH_PROTOCOL
),
338 InternalVarCheckDevicePath
341 EFI_ERR_OUT_DEV_VARIABLE_NAME
,
343 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
345 VARIABLE_ATTRIBUTE_BS_RT
,
346 sizeof (EFI_DEVICE_PATH_PROTOCOL
),
349 InternalVarCheckDevicePath
352 EFI_BOOT_ORDER_VARIABLE_NAME
,
354 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
356 VARIABLE_ATTRIBUTE_NV_BS_RT
,
360 InternalVarCheckSizeArray
363 EFI_BOOT_NEXT_VARIABLE_NAME
,
365 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
367 VARIABLE_ATTRIBUTE_NV_BS_RT
,
374 EFI_BOOT_CURRENT_VARIABLE_NAME
,
376 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
378 VARIABLE_ATTRIBUTE_BS_RT
,
385 EFI_BOOT_OPTION_SUPPORT_VARIABLE_NAME
,
387 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
389 VARIABLE_ATTRIBUTE_BS_RT
,
396 EFI_DRIVER_ORDER_VARIABLE_NAME
,
398 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
400 VARIABLE_ATTRIBUTE_NV_BS_RT
,
404 InternalVarCheckSizeArray
407 EFI_SYS_PREP_ORDER_VARIABLE_NAME
,
409 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
411 VARIABLE_ATTRIBUTE_NV_BS_RT
,
415 InternalVarCheckSizeArray
418 EFI_HW_ERR_REC_SUPPORT_VARIABLE_NAME
,
420 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
422 VARIABLE_ATTRIBUTE_NV_BS_RT
,
431 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
432 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
433 VARIABLE_ATTRIBUTE_BS_RT
,
440 EFI_KEY_EXCHANGE_KEY_NAME
,
442 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
444 VARIABLE_ATTRIBUTE_NV_BS_RT_AT
,
451 EFI_PLATFORM_KEY_NAME
,
453 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
455 VARIABLE_ATTRIBUTE_NV_BS_RT_AT
,
462 EFI_SIGNATURE_SUPPORT_NAME
,
464 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
465 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
466 VARIABLE_ATTRIBUTE_BS_RT
,
470 InternalVarCheckSizeArray
473 EFI_SECURE_BOOT_MODE_NAME
,
475 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
476 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
477 VARIABLE_ATTRIBUTE_BS_RT
,
484 EFI_KEK_DEFAULT_VARIABLE_NAME
,
486 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
487 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
488 VARIABLE_ATTRIBUTE_BS_RT
,
495 EFI_PK_DEFAULT_VARIABLE_NAME
,
497 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
498 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
499 VARIABLE_ATTRIBUTE_BS_RT
,
506 EFI_DB_DEFAULT_VARIABLE_NAME
,
508 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
509 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
510 VARIABLE_ATTRIBUTE_BS_RT
,
517 EFI_DBX_DEFAULT_VARIABLE_NAME
,
519 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
520 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
521 VARIABLE_ATTRIBUTE_BS_RT
,
528 EFI_DBT_DEFAULT_VARIABLE_NAME
,
530 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
531 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
532 VARIABLE_ATTRIBUTE_BS_RT
,
539 EFI_OS_INDICATIONS_SUPPORT_VARIABLE_NAME
,
541 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
543 VARIABLE_ATTRIBUTE_BS_RT
,
550 EFI_OS_INDICATIONS_VARIABLE_NAME
,
552 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
554 VARIABLE_ATTRIBUTE_NV_BS_RT
,
561 EFI_VENDOR_KEYS_VARIABLE_NAME
,
563 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
564 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
565 VARIABLE_ATTRIBUTE_BS_RT
,
572 UEFI_DEFINED_VARIABLE_ENTRY mGlobalVariableList2
[] = {
576 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
578 VARIABLE_ATTRIBUTE_NV_BS_RT
,
579 sizeof (UINT32
) + sizeof (UINT16
),
582 InternalVarCheckLoadOption
587 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
589 VARIABLE_ATTRIBUTE_NV_BS_RT
,
590 sizeof (UINT32
) + sizeof (UINT16
),
593 InternalVarCheckLoadOption
598 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
600 VARIABLE_ATTRIBUTE_NV_BS_RT
,
601 sizeof (UINT32
) + sizeof (UINT16
),
604 InternalVarCheckLoadOption
609 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
611 VARIABLE_ATTRIBUTE_NV_BS_RT
,
612 sizeof (EFI_KEY_OPTION
),
613 sizeof (EFI_KEY_OPTION
) + 3 * sizeof (EFI_INPUT_KEY
)
615 InternalVarCheckKeyOption
620 // EFI_IMAGE_SECURITY_DATABASE_GUID
622 UEFI_DEFINED_VARIABLE_ENTRY mImageSecurityVariableList
[] = {
624 EFI_IMAGE_SECURITY_DATABASE
,
626 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
628 VARIABLE_ATTRIBUTE_NV_BS_RT_AT
,
635 EFI_IMAGE_SECURITY_DATABASE1
,
637 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
639 VARIABLE_ATTRIBUTE_NV_BS_RT_AT
,
646 EFI_IMAGE_SECURITY_DATABASE2
,
648 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
650 VARIABLE_ATTRIBUTE_NV_BS_RT_AT
,
659 Get UEFI defined global variable or image security database variable property.
660 The code will check if variable guid is global variable or image security database guid first.
661 If yes, further check if variable name is in mGlobalVariableList, mGlobalVariableList2 or mImageSecurityVariableList.
663 @param[in] VariableName Pointer to variable name.
664 @param[in] VendorGuid Variable Vendor Guid.
665 @param[in] WildcardMatch Try wildcard match or not.
666 @param[out] VariableProperty Pointer to variable property.
667 @param[out] VarCheckFunction Pointer to check function.
669 @retval EFI_SUCCESS Variable is not global variable or image security database variable.
670 @retval EFI_INVALID_PARAMETER Variable is global variable or image security database variable, but variable name is not in the lists.
674 GetUefiDefinedVariableProperty (
675 IN CHAR16
*VariableName
,
676 IN EFI_GUID
*VendorGuid
,
677 IN BOOLEAN WildcardMatch
,
678 OUT VAR_CHECK_VARIABLE_PROPERTY
**VariableProperty
,
679 OUT INTERNAL_VAR_CHECK_FUNCTION
*VarCheckFunction OPTIONAL
685 if (CompareGuid (VendorGuid
, &gEfiGlobalVariableGuid
)) {
687 // Try list 1, exactly match.
689 for (Index
= 0; Index
< sizeof (mGlobalVariableList
)/sizeof (mGlobalVariableList
[0]); Index
++) {
690 if (StrCmp (mGlobalVariableList
[Index
].Name
, VariableName
) == 0) {
691 if (VarCheckFunction
!= NULL
) {
692 *VarCheckFunction
= mGlobalVariableList
[Index
].CheckFunction
;
694 *VariableProperty
= &mGlobalVariableList
[Index
].VariableProperty
;
702 NameLength
= StrLen (VariableName
) - 4;
703 for (Index
= 0; Index
< sizeof (mGlobalVariableList2
)/sizeof (mGlobalVariableList2
[0]); Index
++) {
705 if ((StrLen (VariableName
) == StrLen (mGlobalVariableList2
[Index
].Name
)) &&
706 (StrnCmp (mGlobalVariableList2
[Index
].Name
, VariableName
, NameLength
) == 0) &&
707 IsHexaDecimalDigitCharacter (VariableName
[NameLength
]) &&
708 IsHexaDecimalDigitCharacter (VariableName
[NameLength
+ 1]) &&
709 IsHexaDecimalDigitCharacter (VariableName
[NameLength
+ 2]) &&
710 IsHexaDecimalDigitCharacter (VariableName
[NameLength
+ 3])) {
711 if (VarCheckFunction
!= NULL
) {
712 *VarCheckFunction
= mGlobalVariableList2
[Index
].CheckFunction
;
714 *VariableProperty
= &mGlobalVariableList2
[Index
].VariableProperty
;
718 if (StrCmp (mGlobalVariableList2
[Index
].Name
, VariableName
) == 0) {
719 if (VarCheckFunction
!= NULL
) {
720 *VarCheckFunction
= mGlobalVariableList2
[Index
].CheckFunction
;
722 *VariableProperty
= &mGlobalVariableList2
[Index
].VariableProperty
;
728 // The variable name is not in the lists.
730 return EFI_INVALID_PARAMETER
;
733 if (CompareGuid (VendorGuid
, &gEfiImageSecurityDatabaseGuid
)) {
734 for (Index
= 0; Index
< sizeof (mImageSecurityVariableList
)/sizeof (mImageSecurityVariableList
[0]); Index
++) {
735 if (StrCmp (mImageSecurityVariableList
[Index
].Name
, VariableName
) == 0) {
736 if (VarCheckFunction
!= NULL
) {
737 *VarCheckFunction
= mImageSecurityVariableList
[Index
].CheckFunction
;
739 *VariableProperty
= &mImageSecurityVariableList
[Index
].VariableProperty
;
744 return EFI_INVALID_PARAMETER
;
748 // It is not global variable, image security database variable.
754 Internal SetVariable check.
756 @param[in] VariableName Name of Variable to set.
757 @param[in] VendorGuid Variable vendor GUID.
758 @param[in] Attributes Attribute value of the variable.
759 @param[in] DataSize Size of Data to set.
760 @param[in] Data Data pointer.
762 @retval EFI_SUCCESS The SetVariable check result was success.
763 @retval EFI_INVALID_PARAMETER An invalid combination of attribute bits, name, and GUID was supplied,
764 or the DataSize exceeds the minimum or maximum allowed,
765 or the Data value is not following UEFI spec for UEFI defined variables.
766 @retval EFI_WRITE_PROTECTED The variable in question is read-only.
767 @retval Others The return status from check handler.
772 InternalVarCheckSetVariableCheck (
773 IN CHAR16
*VariableName
,
774 IN EFI_GUID
*VendorGuid
,
775 IN UINT32 Attributes
,
783 VAR_CHECK_VARIABLE_ENTRY
*Entry
;
785 VAR_CHECK_VARIABLE_PROPERTY
*Property
;
786 INTERNAL_VAR_CHECK_FUNCTION VarCheckFunction
;
790 // Only do check after End Of Dxe.
796 VarCheckFunction
= NULL
;
798 for ( Link
= GetFirstNode (&mVarCheckVariableList
)
799 ; !IsNull (&mVarCheckVariableList
, Link
)
800 ; Link
= GetNextNode (&mVarCheckVariableList
, Link
)
802 Entry
= BASE_CR (Link
, VAR_CHECK_VARIABLE_ENTRY
, Link
);
803 Name
= (CHAR16
*) ((UINTN
) Entry
+ sizeof (*Entry
));
804 if (CompareGuid (&Entry
->Guid
, VendorGuid
) && (StrCmp (Name
, VariableName
) == 0)) {
805 Property
= &Entry
->VariableProperty
;
809 if (Property
== NULL
) {
810 Status
= GetUefiDefinedVariableProperty (VariableName
, VendorGuid
, TRUE
, &Property
, &VarCheckFunction
);
811 if (EFI_ERROR (Status
)) {
813 // To prevent name collisions with possible future globally defined variables,
814 // other internal firmware data variables that are not defined here must be
815 // saved with a unique VendorGuid other than EFI_GLOBAL_VARIABLE or
816 // any other GUID defined by the UEFI Specification. Implementations must
817 // only permit the creation of variables with a UEFI Specification-defined
818 // VendorGuid when these variables are documented in the UEFI Specification.
820 DEBUG ((EFI_D_INFO
, "Variable Check UEFI defined variable fail %r - %s not in %g namespace\n", Status
, VariableName
, VendorGuid
));
824 if (Property
!= NULL
) {
825 if (mEnableLocking
&& ((Property
->Property
& VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
) != 0)) {
826 DEBUG ((EFI_D_INFO
, "[Variable]: Var Check ReadOnly variable fail %r - %g:%s\n", EFI_WRITE_PROTECTED
, VendorGuid
, VariableName
));
827 return EFI_WRITE_PROTECTED
;
829 if (!((((Attributes
& EFI_VARIABLE_APPEND_WRITE
) == 0) && (DataSize
== 0)) || (Attributes
== 0))) {
831 // Not to delete variable.
833 if ((Attributes
!= 0) && ((Attributes
& (~EFI_VARIABLE_APPEND_WRITE
)) != Property
->Attributes
)) {
834 DEBUG ((EFI_D_INFO
, "Variable Check Attributes(0x%08x to 0x%08x) fail %r - %g:%s\n", Property
->Attributes
, Attributes
, EFI_INVALID_PARAMETER
, VendorGuid
, VariableName
));
835 return EFI_INVALID_PARAMETER
;
838 if ((DataSize
< Property
->MinSize
) || (DataSize
> Property
->MaxSize
)) {
839 DEBUG ((EFI_D_INFO
, "Variable Check DataSize fail(0x%x not in 0x%x - 0x%x) %r - %g:%s\n", DataSize
, Property
->MinSize
, Property
->MaxSize
, EFI_INVALID_PARAMETER
, VendorGuid
, VariableName
));
840 return EFI_INVALID_PARAMETER
;
842 if (VarCheckFunction
!= NULL
) {
843 Status
= VarCheckFunction (
848 if (EFI_ERROR (Status
)) {
849 DEBUG ((EFI_D_INFO
, "Internal Variable Check function fail %r - %g:%s\n", Status
, VendorGuid
, VariableName
));
857 for (Index
= 0; Index
< mNumberOfHandler
; Index
++) {
858 Status
= mHandlerTable
[Index
] (
865 if (EFI_ERROR (Status
)) {
866 DEBUG ((EFI_D_INFO
, "Variable Check handler fail %r - %g:%s\n", Status
, VendorGuid
, VariableName
));
874 Reallocates more global memory to store the registered handler list.
876 @retval RETURN_SUCCESS Reallocate memory successfully.
877 @retval RETURN_OUT_OF_RESOURCES No enough memory to allocate.
882 ReallocateHandlerTable (
886 VAR_CHECK_SET_VARIABLE_CHECK_HANDLER
*HandlerTable
;
889 // Reallocate memory for check handler table.
891 HandlerTable
= ReallocateRuntimePool (
892 mMaxNumberOfHandler
* sizeof (VAR_CHECK_SET_VARIABLE_CHECK_HANDLER
),
893 (mMaxNumberOfHandler
+ VAR_CHECK_HANDLER_TABLE_SIZE
) * sizeof (VAR_CHECK_SET_VARIABLE_CHECK_HANDLER
),
898 // No enough resource to allocate.
900 if (HandlerTable
== NULL
) {
901 return RETURN_OUT_OF_RESOURCES
;
904 mHandlerTable
= HandlerTable
;
906 // Increase max handler number.
908 mMaxNumberOfHandler
= mMaxNumberOfHandler
+ VAR_CHECK_HANDLER_TABLE_SIZE
;
909 return RETURN_SUCCESS
;
913 Register SetVariable check handler.
915 @param[in] Handler Pointer to check handler.
917 @retval EFI_SUCCESS The SetVariable check handler was registered successfully.
918 @retval EFI_INVALID_PARAMETER Handler is NULL.
919 @retval EFI_ACCESS_DENIED EFI_END_OF_DXE_EVENT_GROUP_GUID or EFI_EVENT_GROUP_READY_TO_BOOT has
920 already been signaled.
921 @retval EFI_OUT_OF_RESOURCES There is not enough resource for the SetVariable check handler register request.
922 @retval EFI_UNSUPPORTED This interface is not implemented.
923 For example, it is unsupported in VarCheck protocol if both VarCheck and SmmVarCheck protocols are present.
928 VarCheckRegisterSetVariableCheckHandler (
929 IN VAR_CHECK_SET_VARIABLE_CHECK_HANDLER Handler
934 if (Handler
== NULL
) {
935 return EFI_INVALID_PARAMETER
;
939 return EFI_ACCESS_DENIED
;
942 DEBUG ((EFI_D_INFO
, "RegisterSetVariableCheckHandler - 0x%x\n", Handler
));
944 Status
= EFI_SUCCESS
;
946 AcquireLockOnlyAtBootTime (&mVariableModuleGlobal
->VariableGlobal
.VariableServicesLock
);
949 // Check whether the handler list is enough to store new handler.
951 if (mNumberOfHandler
== mMaxNumberOfHandler
) {
953 // Allocate more resources for new handler.
955 Status
= ReallocateHandlerTable();
956 if (EFI_ERROR (Status
)) {
962 // Register new handler into the handler list.
964 mHandlerTable
[mNumberOfHandler
] = Handler
;
968 ReleaseLockOnlyAtBootTime (&mVariableModuleGlobal
->VariableGlobal
.VariableServicesLock
);
974 Variable property get function.
976 @param[in] Name Pointer to the variable name.
977 @param[in] Guid Pointer to the vendor GUID.
978 @param[in] WildcardMatch Try wildcard match or not.
980 @return Pointer to the property of variable specified by the Name and Guid.
983 VAR_CHECK_VARIABLE_PROPERTY
*
984 VariablePropertyGetFunction (
987 IN BOOLEAN WildcardMatch
991 VAR_CHECK_VARIABLE_ENTRY
*Entry
;
992 CHAR16
*VariableName
;
993 VAR_CHECK_VARIABLE_PROPERTY
*Property
;
997 for ( Link
= GetFirstNode (&mVarCheckVariableList
)
998 ; !IsNull (&mVarCheckVariableList
, Link
)
999 ; Link
= GetNextNode (&mVarCheckVariableList
, Link
)
1001 Entry
= BASE_CR (Link
, VAR_CHECK_VARIABLE_ENTRY
, Link
);
1002 VariableName
= (CHAR16
*) ((UINTN
) Entry
+ sizeof (*Entry
));
1003 if (CompareGuid (&Entry
->Guid
, Guid
) && (StrCmp (VariableName
, Name
) == 0)) {
1004 return &Entry
->VariableProperty
;
1008 GetUefiDefinedVariableProperty (Name
, Guid
, WildcardMatch
, &Property
, NULL
);
1014 Internal variable property set.
1016 @param[in] Name Pointer to the variable name.
1017 @param[in] Guid Pointer to the vendor GUID.
1018 @param[in] VariableProperty Pointer to the input variable property.
1020 @retval EFI_SUCCESS The property of variable specified by the Name and Guid was set successfully.
1021 @retval EFI_OUT_OF_RESOURCES There is not enough resource for the variable property set request.
1026 InternalVarCheckVariablePropertySet (
1029 IN VAR_CHECK_VARIABLE_PROPERTY
*VariableProperty
1033 VAR_CHECK_VARIABLE_ENTRY
*Entry
;
1034 CHAR16
*VariableName
;
1035 VAR_CHECK_VARIABLE_PROPERTY
*Property
;
1037 Status
= EFI_SUCCESS
;
1039 Property
= VariablePropertyGetFunction (Name
, Guid
, FALSE
);
1040 if (Property
!= NULL
) {
1041 CopyMem (Property
, VariableProperty
, sizeof (*VariableProperty
));
1043 Entry
= AllocateRuntimeZeroPool (sizeof (*Entry
) + StrSize (Name
));
1044 if (Entry
== NULL
) {
1045 Status
= EFI_OUT_OF_RESOURCES
;
1048 VariableName
= (CHAR16
*) ((UINTN
) Entry
+ sizeof (*Entry
));
1049 StrnCpy (VariableName
, Name
, StrLen (Name
));
1050 CopyGuid (&Entry
->Guid
, Guid
);
1051 CopyMem (&Entry
->VariableProperty
, VariableProperty
, sizeof (*VariableProperty
));
1052 InsertTailList (&mVarCheckVariableList
, &Entry
->Link
);
1060 Variable property set.
1062 @param[in] Name Pointer to the variable name.
1063 @param[in] Guid Pointer to the vendor GUID.
1064 @param[in] VariableProperty Pointer to the input variable property.
1066 @retval EFI_SUCCESS The property of variable specified by the Name and Guid was set successfully.
1067 @retval EFI_INVALID_PARAMETER Name, Guid or VariableProperty is NULL, or Name is an empty string,
1068 or the fields of VariableProperty are not valid.
1069 @retval EFI_ACCESS_DENIED EFI_END_OF_DXE_EVENT_GROUP_GUID or EFI_EVENT_GROUP_READY_TO_BOOT has
1070 already been signaled.
1071 @retval EFI_OUT_OF_RESOURCES There is not enough resource for the variable property set request.
1076 VarCheckVariablePropertySet (
1079 IN VAR_CHECK_VARIABLE_PROPERTY
*VariableProperty
1084 if (Name
== NULL
|| Name
[0] == 0 || Guid
== NULL
) {
1085 return EFI_INVALID_PARAMETER
;
1088 if (VariableProperty
== NULL
) {
1089 return EFI_INVALID_PARAMETER
;
1092 if (VariableProperty
->Revision
!= VAR_CHECK_VARIABLE_PROPERTY_REVISION
) {
1093 return EFI_INVALID_PARAMETER
;
1097 return EFI_ACCESS_DENIED
;
1100 AcquireLockOnlyAtBootTime (&mVariableModuleGlobal
->VariableGlobal
.VariableServicesLock
);
1102 Status
= InternalVarCheckVariablePropertySet (Name
, Guid
, VariableProperty
);
1104 ReleaseLockOnlyAtBootTime (&mVariableModuleGlobal
->VariableGlobal
.VariableServicesLock
);
1110 Internal variable property get.
1112 @param[in] Name Pointer to the variable name.
1113 @param[in] Guid Pointer to the vendor GUID.
1114 @param[out] VariableProperty Pointer to the output variable property.
1116 @retval EFI_SUCCESS The property of variable specified by the Name and Guid was got successfully.
1117 @retval EFI_NOT_FOUND The property of variable specified by the Name and Guid was not found.
1122 InternalVarCheckVariablePropertyGet (
1125 OUT VAR_CHECK_VARIABLE_PROPERTY
*VariableProperty
1129 VARIABLE_ENTRY
*Entry
;
1130 CHAR16
*VariableName
;
1132 VAR_CHECK_VARIABLE_PROPERTY
*Property
;
1136 Property
= VariablePropertyGetFunction (Name
, Guid
, TRUE
);
1137 if (Property
!= NULL
) {
1138 CopyMem (VariableProperty
, Property
, sizeof (*VariableProperty
));
1142 for ( Link
= GetFirstNode (&mLockedVariableList
)
1143 ; !IsNull (&mLockedVariableList
, Link
)
1144 ; Link
= GetNextNode (&mLockedVariableList
, Link
)
1146 Entry
= BASE_CR (Link
, VARIABLE_ENTRY
, Link
);
1147 VariableName
= (CHAR16
*) ((UINTN
) Entry
+ sizeof (*Entry
));
1148 if (CompareGuid (&Entry
->Guid
, Guid
) && (StrCmp (VariableName
, Name
) == 0)) {
1149 VariableProperty
->Property
|= VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
;
1151 VariableProperty
->Revision
= VAR_CHECK_VARIABLE_PROPERTY_REVISION
;
1157 return (Found
? EFI_SUCCESS
: EFI_NOT_FOUND
);
1161 Variable property get.
1163 @param[in] Name Pointer to the variable name.
1164 @param[in] Guid Pointer to the vendor GUID.
1165 @param[out] VariableProperty Pointer to the output variable property.
1167 @retval EFI_SUCCESS The property of variable specified by the Name and Guid was got successfully.
1168 @retval EFI_INVALID_PARAMETER Name, Guid or VariableProperty is NULL, or Name is an empty string.
1169 @retval EFI_NOT_FOUND The property of variable specified by the Name and Guid was not found.
1174 VarCheckVariablePropertyGet (
1177 OUT VAR_CHECK_VARIABLE_PROPERTY
*VariableProperty
1182 if (Name
== NULL
|| Name
[0] == 0 || Guid
== NULL
) {
1183 return EFI_INVALID_PARAMETER
;
1186 if (VariableProperty
== NULL
) {
1187 return EFI_INVALID_PARAMETER
;
1190 AcquireLockOnlyAtBootTime (&mVariableModuleGlobal
->VariableGlobal
.VariableServicesLock
);
1192 Status
= InternalVarCheckVariablePropertyGet (Name
, Guid
, VariableProperty
);
1194 ReleaseLockOnlyAtBootTime (&mVariableModuleGlobal
->VariableGlobal
.VariableServicesLock
);