2 Implementation functions and structures for var check protocol.
4 Copyright (c) 2015, Intel Corporation. All rights reserved.<BR>
5 This program and the accompanying materials
6 are licensed and made available under the terms and conditions of the BSD License
7 which accompanies this distribution. The full text of the license may be found at
8 http://opensource.org/licenses/bsd-license.php
10 THE PROGRAM IS DISTRIBUTED UNDER THE BSD LICENSE ON AN "AS IS" BASIS,
11 WITHOUT WARRANTIES OR REPRESENTATIONS OF ANY KIND, EITHER EXPRESS OR IMPLIED.
16 #include <Library/DevicePathLib.h>
18 extern LIST_ENTRY mLockedVariableList
;
19 extern BOOLEAN mEndOfDxe
;
20 extern BOOLEAN mEnableLocking
;
22 #define VAR_CHECK_HANDLER_TABLE_SIZE 0x8
24 UINT32 mNumberOfHandler
= 0;
25 UINT32 mMaxNumberOfHandler
= 0;
26 VAR_CHECK_SET_VARIABLE_CHECK_HANDLER
*mHandlerTable
= NULL
;
31 VAR_CHECK_VARIABLE_PROPERTY VariableProperty
;
33 } VAR_CHECK_VARIABLE_ENTRY
;
35 LIST_ENTRY mVarCheckVariableList
= INITIALIZE_LIST_HEAD_VARIABLE (mVarCheckVariableList
);
39 (EFIAPI
*INTERNAL_VAR_CHECK_FUNCTION
) (
40 IN VAR_CHECK_VARIABLE_PROPERTY
*Propery
,
47 VAR_CHECK_VARIABLE_PROPERTY VariableProperty
;
48 INTERNAL_VAR_CHECK_FUNCTION CheckFunction
;
49 } UEFI_DEFINED_VARIABLE_ENTRY
;
51 typedef struct _EFI_LOAD_OPTION
{
53 UINT16 FilePathListLength
;
54 //CHAR16 Description[];
55 //EFI_DEVICE_PATH_PROTOCOL FilePathList[];
56 //UINT8 OptionalData[];
60 Internal check for load option.
62 @param[in] VariablePropery Pointer to variable property.
63 @param[in] DataSize Data size.
64 @param[in] Data Pointer to data buffer.
66 @retval EFI_SUCCESS The SetVariable check result was success.
67 @retval EFI_INVALID_PARAMETER The data buffer is not a valid load option.
72 InternalVarCheckLoadOption (
73 IN VAR_CHECK_VARIABLE_PROPERTY
*VariablePropery
,
78 EFI_LOAD_OPTION
*LoadOption
;
80 EFI_DEVICE_PATH_PROTOCOL
*FilePathList
;
82 LoadOption
= (EFI_LOAD_OPTION
*) Data
;
87 Description
= (CHAR16
*) ((UINTN
) Data
+ sizeof (EFI_LOAD_OPTION
));
88 while (Description
< (CHAR16
*) ((UINTN
) Data
+ DataSize
)) {
89 if (*Description
== L
'\0') {
94 if ((UINTN
) Description
>= ((UINTN
) Data
+ DataSize
)) {
95 return EFI_INVALID_PARAMETER
;
100 // Check FilePathList
102 FilePathList
= (EFI_DEVICE_PATH_PROTOCOL
*) Description
;
103 if ((UINTN
) FilePathList
> (MAX_ADDRESS
- LoadOption
->FilePathListLength
)) {
104 return EFI_INVALID_PARAMETER
;
106 if (((UINTN
) FilePathList
+ LoadOption
->FilePathListLength
) > ((UINTN
) Data
+ DataSize
)) {
107 return EFI_INVALID_PARAMETER
;
109 if (LoadOption
->FilePathListLength
< sizeof (EFI_DEVICE_PATH_PROTOCOL
)) {
110 return EFI_INVALID_PARAMETER
;
112 if (!IsDevicePathValid (FilePathList
, LoadOption
->FilePathListLength
)) {
113 return EFI_INVALID_PARAMETER
;
120 Internal check for key option.
122 @param[in] VariablePropery Pointer to variable property.
123 @param[in] DataSize Data size.
124 @param[in] Data Pointer to data buffer.
126 @retval EFI_SUCCESS The SetVariable check result was success.
127 @retval EFI_INVALID_PARAMETER The data buffer is not a valid key option.
132 InternalVarCheckKeyOption (
133 IN VAR_CHECK_VARIABLE_PROPERTY
*VariablePropery
,
138 if (((DataSize
- sizeof (EFI_KEY_OPTION
)) % sizeof (EFI_INPUT_KEY
)) != 0) {
139 return EFI_INVALID_PARAMETER
;
146 Internal check for device path.
148 @param[in] VariablePropery Pointer to variable property.
149 @param[in] DataSize Data size.
150 @param[in] Data Pointer to data buffer.
152 @retval EFI_SUCCESS The SetVariable check result was success.
153 @retval EFI_INVALID_PARAMETER The data buffer is not a valid device path.
158 InternalVarCheckDevicePath (
159 IN VAR_CHECK_VARIABLE_PROPERTY
*VariablePropery
,
164 if (!IsDevicePathValid ((EFI_DEVICE_PATH_PROTOCOL
*) Data
, DataSize
)) {
165 return EFI_INVALID_PARAMETER
;
171 Internal check for ASCII string.
173 @param[in] VariablePropery Pointer to variable property.
174 @param[in] DataSize Data size.
175 @param[in] Data Pointer to data buffer.
177 @retval EFI_SUCCESS The SetVariable check result was success.
178 @retval EFI_INVALID_PARAMETER The data buffer is not a Null-terminated ASCII string.
183 InternalVarCheckAsciiString (
184 IN VAR_CHECK_VARIABLE_PROPERTY
*VariablePropery
,
192 String
= (CHAR8
*) Data
;
193 if (String
[DataSize
- 1] == '\0') {
196 for (Index
= 1; Index
< DataSize
&& (String
[DataSize
- 1 - Index
] != '\0'); Index
++);
197 if (Index
== DataSize
) {
198 return EFI_INVALID_PARAMETER
;
205 Internal check for size array.
207 @param[in] VariablePropery Pointer to variable property.
208 @param[in] DataSize Data size.
209 @param[in] Data Pointer to data buffer.
211 @retval EFI_SUCCESS The SetVariable check result was success.
212 @retval EFI_INVALID_PARAMETER The DataSize is not size array.
217 InternalVarCheckSizeArray (
218 IN VAR_CHECK_VARIABLE_PROPERTY
*VariablePropery
,
223 if ((DataSize
% VariablePropery
->MinSize
) != 0) {
224 return EFI_INVALID_PARAMETER
;
230 // To prevent name collisions with possible future globally defined variables,
231 // other internal firmware data variables that are not defined here must be
232 // saved with a unique VendorGuid other than EFI_GLOBAL_VARIABLE or
233 // any other GUID defined by the UEFI Specification. Implementations must
234 // only permit the creation of variables with a UEFI Specification-defined
235 // VendorGuid when these variables are documented in the UEFI Specification.
237 UEFI_DEFINED_VARIABLE_ENTRY mGlobalVariableList
[] = {
239 EFI_LANG_CODES_VARIABLE_NAME
,
241 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
243 VARIABLE_ATTRIBUTE_BS_RT
,
247 InternalVarCheckAsciiString
250 EFI_LANG_VARIABLE_NAME
,
252 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
254 VARIABLE_ATTRIBUTE_NV_BS_RT
,
258 InternalVarCheckAsciiString
261 EFI_TIME_OUT_VARIABLE_NAME
,
263 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
265 VARIABLE_ATTRIBUTE_NV_BS_RT
,
272 EFI_PLATFORM_LANG_CODES_VARIABLE_NAME
,
274 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
276 VARIABLE_ATTRIBUTE_BS_RT
,
280 InternalVarCheckAsciiString
283 EFI_PLATFORM_LANG_VARIABLE_NAME
,
285 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
287 VARIABLE_ATTRIBUTE_NV_BS_RT
,
291 InternalVarCheckAsciiString
294 EFI_CON_IN_VARIABLE_NAME
,
296 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
298 VARIABLE_ATTRIBUTE_NV_BS_RT
,
299 sizeof (EFI_DEVICE_PATH_PROTOCOL
),
302 InternalVarCheckDevicePath
305 EFI_CON_OUT_VARIABLE_NAME
,
307 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
309 VARIABLE_ATTRIBUTE_NV_BS_RT
,
310 sizeof (EFI_DEVICE_PATH_PROTOCOL
),
313 InternalVarCheckDevicePath
316 EFI_ERR_OUT_VARIABLE_NAME
,
318 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
320 VARIABLE_ATTRIBUTE_NV_BS_RT
,
321 sizeof (EFI_DEVICE_PATH_PROTOCOL
),
324 InternalVarCheckDevicePath
327 EFI_CON_IN_DEV_VARIABLE_NAME
,
329 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
331 VARIABLE_ATTRIBUTE_BS_RT
,
332 sizeof (EFI_DEVICE_PATH_PROTOCOL
),
335 InternalVarCheckDevicePath
338 EFI_CON_OUT_DEV_VARIABLE_NAME
,
340 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
342 VARIABLE_ATTRIBUTE_BS_RT
,
343 sizeof (EFI_DEVICE_PATH_PROTOCOL
),
346 InternalVarCheckDevicePath
349 EFI_ERR_OUT_DEV_VARIABLE_NAME
,
351 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
353 VARIABLE_ATTRIBUTE_BS_RT
,
354 sizeof (EFI_DEVICE_PATH_PROTOCOL
),
357 InternalVarCheckDevicePath
360 EFI_BOOT_ORDER_VARIABLE_NAME
,
362 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
364 VARIABLE_ATTRIBUTE_NV_BS_RT
,
368 InternalVarCheckSizeArray
371 EFI_BOOT_NEXT_VARIABLE_NAME
,
373 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
375 VARIABLE_ATTRIBUTE_NV_BS_RT
,
382 EFI_BOOT_CURRENT_VARIABLE_NAME
,
384 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
386 VARIABLE_ATTRIBUTE_BS_RT
,
393 EFI_BOOT_OPTION_SUPPORT_VARIABLE_NAME
,
395 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
397 VARIABLE_ATTRIBUTE_BS_RT
,
404 EFI_DRIVER_ORDER_VARIABLE_NAME
,
406 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
408 VARIABLE_ATTRIBUTE_NV_BS_RT
,
412 InternalVarCheckSizeArray
415 EFI_HW_ERR_REC_SUPPORT_VARIABLE_NAME
,
417 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
419 VARIABLE_ATTRIBUTE_NV_BS_RT
,
428 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
429 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
430 VARIABLE_ATTRIBUTE_BS_RT
,
437 EFI_KEY_EXCHANGE_KEY_NAME
,
439 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
441 VARIABLE_ATTRIBUTE_NV_BS_RT_AT
,
448 EFI_PLATFORM_KEY_NAME
,
450 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
452 VARIABLE_ATTRIBUTE_NV_BS_RT_AT
,
459 EFI_SIGNATURE_SUPPORT_NAME
,
461 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
462 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
463 VARIABLE_ATTRIBUTE_BS_RT
,
467 InternalVarCheckSizeArray
470 EFI_SECURE_BOOT_MODE_NAME
,
472 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
473 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
474 VARIABLE_ATTRIBUTE_BS_RT
,
481 EFI_KEK_DEFAULT_VARIABLE_NAME
,
483 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
484 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
485 VARIABLE_ATTRIBUTE_BS_RT
,
492 EFI_PK_DEFAULT_VARIABLE_NAME
,
494 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
495 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
496 VARIABLE_ATTRIBUTE_BS_RT
,
503 EFI_DB_DEFAULT_VARIABLE_NAME
,
505 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
506 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
507 VARIABLE_ATTRIBUTE_BS_RT
,
514 EFI_DBX_DEFAULT_VARIABLE_NAME
,
516 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
517 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
518 VARIABLE_ATTRIBUTE_BS_RT
,
525 EFI_DBT_DEFAULT_VARIABLE_NAME
,
527 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
528 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
529 VARIABLE_ATTRIBUTE_BS_RT
,
536 EFI_OS_INDICATIONS_SUPPORT_VARIABLE_NAME
,
538 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
540 VARIABLE_ATTRIBUTE_BS_RT
,
547 EFI_OS_INDICATIONS_VARIABLE_NAME
,
549 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
551 VARIABLE_ATTRIBUTE_NV_BS_RT
,
558 EFI_VENDOR_KEYS_VARIABLE_NAME
,
560 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
561 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
562 VARIABLE_ATTRIBUTE_BS_RT
,
569 UEFI_DEFINED_VARIABLE_ENTRY mGlobalVariableList2
[] = {
573 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
575 VARIABLE_ATTRIBUTE_NV_BS_RT
,
576 sizeof (EFI_LOAD_OPTION
),
579 InternalVarCheckLoadOption
584 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
586 VARIABLE_ATTRIBUTE_NV_BS_RT
,
587 sizeof (EFI_LOAD_OPTION
),
590 InternalVarCheckLoadOption
595 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
597 VARIABLE_ATTRIBUTE_NV_BS_RT
,
598 sizeof (EFI_KEY_OPTION
),
599 sizeof (EFI_KEY_OPTION
) + 3 * sizeof (EFI_INPUT_KEY
)
601 InternalVarCheckKeyOption
606 // EFI_IMAGE_SECURITY_DATABASE_GUID
608 UEFI_DEFINED_VARIABLE_ENTRY mImageSecurityVariableList
[] = {
610 EFI_IMAGE_SECURITY_DATABASE
,
612 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
614 VARIABLE_ATTRIBUTE_NV_BS_RT_AT
,
621 EFI_IMAGE_SECURITY_DATABASE1
,
623 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
625 VARIABLE_ATTRIBUTE_NV_BS_RT_AT
,
632 EFI_IMAGE_SECURITY_DATABASE2
,
634 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
636 VARIABLE_ATTRIBUTE_NV_BS_RT_AT
,
647 VAR_CHECK_VARIABLE_PROPERTY VariableProperty
;
648 INTERNAL_VAR_CHECK_FUNCTION CheckFunction
;
649 } VARIABLE_DRIVER_VARIABLE_ENTRY
;
651 VARIABLE_DRIVER_VARIABLE_ENTRY mVariableDriverVariableList
[] = {
653 &gEfiSecureBootEnableDisableGuid
,
654 EFI_SECURE_BOOT_ENABLE_NAME
,
656 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
658 VARIABLE_ATTRIBUTE_NV_BS
,
665 &gEfiCustomModeEnableGuid
,
666 EFI_CUSTOM_MODE_NAME
,
668 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
670 VARIABLE_ATTRIBUTE_NV_BS
,
677 &gEfiVendorKeysNvGuid
,
678 EFI_VENDOR_KEYS_NV_VARIABLE_NAME
,
680 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
682 VARIABLE_ATTRIBUTE_NV_BS_RT_AT
,
689 &gEfiAuthenticatedVariableGuid
,
690 L
"AuthVarKeyDatabase",
692 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
694 VARIABLE_ATTRIBUTE_NV_BS_RT_AW
,
704 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
706 VARIABLE_ATTRIBUTE_NV_BS_RT_AT
,
715 Get UEFI defined global variable or image security database variable property.
716 The code will check if variable guid is global variable or image security database guid first.
717 If yes, further check if variable name is in mGlobalVariableList, mGlobalVariableList2 or mImageSecurityVariableList.
719 @param[in] VariableName Pointer to variable name.
720 @param[in] VendorGuid Variable Vendor Guid.
721 @param[in] WildcardMatch Try wildcard match or not.
722 @param[out] VariableProperty Pointer to variable property.
723 @param[out] VarCheckFunction Pointer to check function.
725 @retval EFI_SUCCESS Variable is not global variable or image security database variable.
726 @retval EFI_INVALID_PARAMETER Variable is global variable or image security database variable, but variable name is not in the lists.
730 GetUefiDefinedVariableProperty (
731 IN CHAR16
*VariableName
,
732 IN EFI_GUID
*VendorGuid
,
733 IN BOOLEAN WildcardMatch
,
734 OUT VAR_CHECK_VARIABLE_PROPERTY
**VariableProperty
,
735 OUT INTERNAL_VAR_CHECK_FUNCTION
*VarCheckFunction OPTIONAL
741 if (CompareGuid (VendorGuid
, &gEfiGlobalVariableGuid
)){
743 // Try list 1, exactly match.
745 for (Index
= 0; Index
< sizeof (mGlobalVariableList
)/sizeof (mGlobalVariableList
[0]); Index
++) {
746 if (StrCmp (mGlobalVariableList
[Index
].Name
, VariableName
) == 0) {
747 if (VarCheckFunction
!= NULL
) {
748 *VarCheckFunction
= mGlobalVariableList
[Index
].CheckFunction
;
750 *VariableProperty
= &mGlobalVariableList
[Index
].VariableProperty
;
758 NameLength
= StrLen (VariableName
) - 4;
759 for (Index
= 0; Index
< sizeof (mGlobalVariableList2
)/sizeof (mGlobalVariableList2
[0]); Index
++) {
761 if ((StrLen (VariableName
) == StrLen (mGlobalVariableList2
[Index
].Name
)) &&
762 (StrnCmp (mGlobalVariableList2
[Index
].Name
, VariableName
, NameLength
) == 0) &&
763 IsHexaDecimalDigitCharacter (VariableName
[NameLength
]) &&
764 IsHexaDecimalDigitCharacter (VariableName
[NameLength
+ 1]) &&
765 IsHexaDecimalDigitCharacter (VariableName
[NameLength
+ 2]) &&
766 IsHexaDecimalDigitCharacter (VariableName
[NameLength
+ 3])) {
767 if (VarCheckFunction
!= NULL
) {
768 *VarCheckFunction
= mGlobalVariableList2
[Index
].CheckFunction
;
770 *VariableProperty
= &mGlobalVariableList2
[Index
].VariableProperty
;
774 if (StrCmp (mGlobalVariableList2
[Index
].Name
, VariableName
) == 0) {
775 if (VarCheckFunction
!= NULL
) {
776 *VarCheckFunction
= mGlobalVariableList2
[Index
].CheckFunction
;
778 *VariableProperty
= &mGlobalVariableList2
[Index
].VariableProperty
;
785 // The variable name is not in the lists.
787 return EFI_INVALID_PARAMETER
;
790 if (CompareGuid (VendorGuid
, &gEfiImageSecurityDatabaseGuid
)){
791 for (Index
= 0; Index
< sizeof (mImageSecurityVariableList
)/sizeof (mImageSecurityVariableList
[0]); Index
++) {
792 if (StrCmp (mImageSecurityVariableList
[Index
].Name
, VariableName
) == 0) {
793 if (VarCheckFunction
!= NULL
) {
794 *VarCheckFunction
= mImageSecurityVariableList
[Index
].CheckFunction
;
796 *VariableProperty
= &mImageSecurityVariableList
[Index
].VariableProperty
;
801 return EFI_INVALID_PARAMETER
;
805 // It is not global variable or image security database variable.
811 Get variable property for variables managed by Varaible driver.
813 @param[in] VariableName Pointer to variable name.
814 @param[in] VendorGuid Variable Vendor Guid.
815 @param[out] VarCheckFunction Pointer to check function.
817 @return Pointer to variable property.
820 VAR_CHECK_VARIABLE_PROPERTY
*
821 GetVariableDriverVariableProperty (
822 IN CHAR16
*VariableName
,
823 IN EFI_GUID
*VendorGuid
,
824 OUT INTERNAL_VAR_CHECK_FUNCTION
*VarCheckFunction OPTIONAL
829 for (Index
= 0; Index
< sizeof (mVariableDriverVariableList
)/sizeof (mVariableDriverVariableList
[0]); Index
++) {
830 if ((CompareGuid (mVariableDriverVariableList
[Index
].Guid
, VendorGuid
)) && (StrCmp (mVariableDriverVariableList
[Index
].Name
, VariableName
) == 0)) {
831 if (VarCheckFunction
!= NULL
) {
832 *VarCheckFunction
= mVariableDriverVariableList
[Index
].CheckFunction
;
834 return &mVariableDriverVariableList
[Index
].VariableProperty
;
842 Internal SetVariable check.
844 @param[in] VariableName Name of Variable to set.
845 @param[in] VendorGuid Variable vendor GUID.
846 @param[in] Attributes Attribute value of the variable.
847 @param[in] DataSize Size of Data to set.
848 @param[in] Data Data pointer.
850 @retval EFI_SUCCESS The SetVariable check result was success.
851 @retval EFI_INVALID_PARAMETER An invalid combination of attribute bits, name, and GUID was supplied,
852 or the DataSize exceeds the minimum or maximum allowed,
853 or the Data value is not following UEFI spec for UEFI defined variables.
854 @retval EFI_WRITE_PROTECTED The variable in question is read-only.
855 @retval Others The return status from check handler.
860 InternalVarCheckSetVariableCheck (
861 IN CHAR16
*VariableName
,
862 IN EFI_GUID
*VendorGuid
,
863 IN UINT32 Attributes
,
871 VAR_CHECK_VARIABLE_ENTRY
*Entry
;
873 VAR_CHECK_VARIABLE_PROPERTY
*Property
;
874 INTERNAL_VAR_CHECK_FUNCTION VarCheckFunction
;
878 // Only do check after End Of Dxe.
884 Status
= GetUefiDefinedVariableProperty (VariableName
, VendorGuid
, TRUE
, &Property
, &VarCheckFunction
);
885 if (EFI_ERROR (Status
)) {
886 DEBUG ((EFI_D_INFO
, "[Variable]: Var Check UEFI defined variable fail %r - %g:%s\n", Status
, VendorGuid
, VariableName
));
889 if (Property
== NULL
) {
890 Property
= GetVariableDriverVariableProperty (VariableName
, VendorGuid
, &VarCheckFunction
);
892 if (Property
== NULL
) {
893 VarCheckFunction
= NULL
;
894 for ( Link
= GetFirstNode (&mVarCheckVariableList
)
895 ; !IsNull (&mVarCheckVariableList
, Link
)
896 ; Link
= GetNextNode (&mVarCheckVariableList
, Link
)
898 Entry
= BASE_CR (Link
, VAR_CHECK_VARIABLE_ENTRY
, Link
);
899 Name
= (CHAR16
*) ((UINTN
) Entry
+ sizeof (*Entry
));
900 if (CompareGuid (&Entry
->Guid
, VendorGuid
) && (StrCmp (Name
, VariableName
) == 0)) {
901 Property
= &Entry
->VariableProperty
;
906 if (Property
!= NULL
) {
907 if (mEnableLocking
&& ((Property
->Property
& VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
) != 0)) {
908 DEBUG ((EFI_D_INFO
, "[Variable]: Var Check ReadOnly variable fail %r - %g:%s\n", EFI_WRITE_PROTECTED
, VendorGuid
, VariableName
));
909 return EFI_WRITE_PROTECTED
;
911 if ((((Attributes
& EFI_VARIABLE_APPEND_WRITE
) == 0) && (DataSize
== 0)) || (Attributes
== 0)) {
913 // Do not check delete variable.
917 if ((Attributes
& (~EFI_VARIABLE_APPEND_WRITE
)) != Property
->Attributes
) {
918 DEBUG ((EFI_D_INFO
, "[Variable]: Var Check Attributes fail %r - %g:%s\n", EFI_INVALID_PARAMETER
, VendorGuid
, VariableName
));
919 return EFI_INVALID_PARAMETER
;
922 if ((DataSize
< Property
->MinSize
) || (DataSize
> Property
->MaxSize
)) {
923 DEBUG ((EFI_D_INFO
, "[Variable]: Var Check DataSize fail %r - %g:%s\n", EFI_INVALID_PARAMETER
, VendorGuid
, VariableName
));
924 return EFI_INVALID_PARAMETER
;
926 if (VarCheckFunction
!= NULL
) {
927 Status
= VarCheckFunction (
932 if (EFI_ERROR (Status
)) {
933 DEBUG ((EFI_D_INFO
, "[Variable]: Internal Var Check function fail %r - %g:%s\n", Status
, VendorGuid
, VariableName
));
940 for (Index
= 0; Index
< mNumberOfHandler
; Index
++) {
941 Status
= mHandlerTable
[Index
] (
948 if (EFI_ERROR (Status
)) {
949 DEBUG ((EFI_D_INFO
, "[Variable]: Var Check handler fail %r - %g:%s\n", Status
, VendorGuid
, VariableName
));
957 Reallocates more global memory to store the registered handler list.
959 @retval RETURN_SUCCESS Reallocate memory successfully.
960 @retval RETURN_OUT_OF_RESOURCES No enough memory to allocate.
965 ReallocateHandlerTable (
969 VAR_CHECK_SET_VARIABLE_CHECK_HANDLER
*HandlerTable
;
972 // Reallocate memory for check handler table.
974 HandlerTable
= ReallocateRuntimePool (
975 mMaxNumberOfHandler
* sizeof (VAR_CHECK_SET_VARIABLE_CHECK_HANDLER
),
976 (mMaxNumberOfHandler
+ VAR_CHECK_HANDLER_TABLE_SIZE
) * sizeof (VAR_CHECK_SET_VARIABLE_CHECK_HANDLER
),
981 // No enough resource to allocate.
983 if (HandlerTable
== NULL
) {
984 return RETURN_OUT_OF_RESOURCES
;
987 mHandlerTable
= HandlerTable
;
989 // Increase max handler number.
991 mMaxNumberOfHandler
= mMaxNumberOfHandler
+ VAR_CHECK_HANDLER_TABLE_SIZE
;
992 return RETURN_SUCCESS
;
996 Register SetVariable check handler.
998 @param[in] Handler Pointer to check handler.
1000 @retval EFI_SUCCESS The SetVariable check handler was registered successfully.
1001 @retval EFI_INVALID_PARAMETER Handler is NULL.
1002 @retval EFI_ACCESS_DENIED EFI_END_OF_DXE_EVENT_GROUP_GUID or EFI_EVENT_GROUP_READY_TO_BOOT has
1003 already been signaled.
1004 @retval EFI_OUT_OF_RESOURCES There is not enough resource for the SetVariable check handler register request.
1005 @retval EFI_UNSUPPORTED This interface is not implemented.
1006 For example, it is unsupported in VarCheck protocol if both VarCheck and SmmVarCheck protocols are present.
1011 VarCheckRegisterSetVariableCheckHandler (
1012 IN VAR_CHECK_SET_VARIABLE_CHECK_HANDLER Handler
1017 if (Handler
== NULL
) {
1018 return EFI_INVALID_PARAMETER
;
1022 return EFI_ACCESS_DENIED
;
1025 DEBUG ((EFI_D_INFO
, "RegisterSetVariableCheckHandler - 0x%x\n", Handler
));
1028 // Check whether the handler list is enough to store new handler.
1030 if (mNumberOfHandler
== mMaxNumberOfHandler
) {
1032 // Allocate more resources for new handler.
1034 Status
= ReallocateHandlerTable();
1035 if (EFI_ERROR (Status
)) {
1041 // Register new handler into the handler list.
1043 mHandlerTable
[mNumberOfHandler
] = Handler
;
1044 mNumberOfHandler
++;
1050 Internal variable property get.
1052 @param[in] Name Pointer to the variable name.
1053 @param[in] Guid Pointer to the vendor GUID.
1055 @return Pointer to the property of variable specified by the Name and Guid.
1058 VAR_CHECK_VARIABLE_PROPERTY
*
1059 InternalVarCheckVariablePropertyGet (
1065 VAR_CHECK_VARIABLE_ENTRY
*Entry
;
1066 CHAR16
*VariableName
;
1067 VAR_CHECK_VARIABLE_PROPERTY
*Property
;
1070 GetUefiDefinedVariableProperty (Name
, Guid
, FALSE
, &Property
, NULL
);
1071 if (Property
== NULL
) {
1072 Property
= GetVariableDriverVariableProperty (Name
, Guid
, NULL
);
1074 if (Property
!= NULL
) {
1077 for ( Link
= GetFirstNode (&mVarCheckVariableList
)
1078 ; !IsNull (&mVarCheckVariableList
, Link
)
1079 ; Link
= GetNextNode (&mVarCheckVariableList
, Link
)
1081 Entry
= BASE_CR (Link
, VAR_CHECK_VARIABLE_ENTRY
, Link
);
1082 VariableName
= (CHAR16
*) ((UINTN
) Entry
+ sizeof (*Entry
));
1083 if (CompareGuid (&Entry
->Guid
, Guid
) && (StrCmp (VariableName
, Name
) == 0)) {
1084 return &Entry
->VariableProperty
;
1093 Variable property set.
1095 @param[in] Name Pointer to the variable name.
1096 @param[in] Guid Pointer to the vendor GUID.
1097 @param[in] VariableProperty Pointer to the input variable property.
1099 @retval EFI_SUCCESS The property of variable specified by the Name and Guid was set successfully.
1100 @retval EFI_INVALID_PARAMETER Name, Guid or VariableProperty is NULL, or Name is an empty string,
1101 or the fields of VariableProperty are not valid.
1102 @retval EFI_ACCESS_DENIED EFI_END_OF_DXE_EVENT_GROUP_GUID or EFI_EVENT_GROUP_READY_TO_BOOT has
1103 already been signaled.
1104 @retval EFI_OUT_OF_RESOURCES There is not enough resource for the variable property set request.
1109 VarCheckVariablePropertySet (
1112 IN VAR_CHECK_VARIABLE_PROPERTY
*VariableProperty
1116 VAR_CHECK_VARIABLE_ENTRY
*Entry
;
1117 CHAR16
*VariableName
;
1118 VAR_CHECK_VARIABLE_PROPERTY
*Property
;
1120 if (Name
== NULL
|| Name
[0] == 0 || Guid
== NULL
) {
1121 return EFI_INVALID_PARAMETER
;
1124 if (VariableProperty
== NULL
) {
1125 return EFI_INVALID_PARAMETER
;
1128 if (VariableProperty
->Revision
!= VAR_CHECK_VARIABLE_PROPERTY_REVISION
) {
1129 return EFI_INVALID_PARAMETER
;
1133 return EFI_ACCESS_DENIED
;
1136 Status
= EFI_SUCCESS
;
1138 AcquireLockOnlyAtBootTime (&mVariableModuleGlobal
->VariableGlobal
.VariableServicesLock
);
1140 Property
= InternalVarCheckVariablePropertyGet (Name
, Guid
);
1141 if (Property
!= NULL
) {
1142 CopyMem (Property
, VariableProperty
, sizeof (*VariableProperty
));
1144 Entry
= AllocateRuntimeZeroPool (sizeof (*Entry
) + StrSize (Name
));
1145 if (Entry
== NULL
) {
1146 Status
= EFI_OUT_OF_RESOURCES
;
1149 VariableName
= (CHAR16
*) ((UINTN
) Entry
+ sizeof (*Entry
));
1150 StrnCpy (VariableName
, Name
, StrLen (Name
));
1151 CopyGuid (&Entry
->Guid
, Guid
);
1152 CopyMem (&Entry
->VariableProperty
, VariableProperty
, sizeof (*VariableProperty
));
1153 InsertTailList (&mVarCheckVariableList
, &Entry
->Link
);
1157 ReleaseLockOnlyAtBootTime (&mVariableModuleGlobal
->VariableGlobal
.VariableServicesLock
);
1163 Variable property get.
1165 @param[in] Name Pointer to the variable name.
1166 @param[in] Guid Pointer to the vendor GUID.
1167 @param[out] VariableProperty Pointer to the output variable property.
1169 @retval EFI_SUCCESS The property of variable specified by the Name and Guid was got successfully.
1170 @retval EFI_INVALID_PARAMETER Name, Guid or VariableProperty is NULL, or Name is an empty string.
1171 @retval EFI_NOT_FOUND The property of variable specified by the Name and Guid was not found.
1176 VarCheckVariablePropertyGet (
1179 OUT VAR_CHECK_VARIABLE_PROPERTY
*VariableProperty
1183 VARIABLE_ENTRY
*Entry
;
1184 CHAR16
*VariableName
;
1186 VAR_CHECK_VARIABLE_PROPERTY
*Property
;
1188 if (Name
== NULL
|| Name
[0] == 0 || Guid
== NULL
) {
1189 return EFI_INVALID_PARAMETER
;
1192 if (VariableProperty
== NULL
) {
1193 return EFI_INVALID_PARAMETER
;
1198 AcquireLockOnlyAtBootTime (&mVariableModuleGlobal
->VariableGlobal
.VariableServicesLock
);
1200 Property
= InternalVarCheckVariablePropertyGet (Name
, Guid
);
1201 if (Property
!= NULL
) {
1202 CopyMem (VariableProperty
, Property
, sizeof (*VariableProperty
));
1206 for ( Link
= GetFirstNode (&mLockedVariableList
)
1207 ; !IsNull (&mLockedVariableList
, Link
)
1208 ; Link
= GetNextNode (&mLockedVariableList
, Link
)
1210 Entry
= BASE_CR (Link
, VARIABLE_ENTRY
, Link
);
1211 VariableName
= (CHAR16
*) ((UINTN
) Entry
+ sizeof (*Entry
));
1212 if (CompareGuid (&Entry
->Guid
, Guid
) && (StrCmp (VariableName
, Name
) == 0)) {
1213 VariableProperty
->Property
|= VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
;
1215 VariableProperty
->Revision
= VAR_CHECK_VARIABLE_PROPERTY_REVISION
;
1221 ReleaseLockOnlyAtBootTime (&mVariableModuleGlobal
->VariableGlobal
.VariableServicesLock
);
1223 return (Found
? EFI_SUCCESS
: EFI_NOT_FOUND
);