2 Implementation functions and structures for var check protocol.
4 Copyright (c) 2015, Intel Corporation. All rights reserved.<BR>
5 This program and the accompanying materials
6 are licensed and made available under the terms and conditions of the BSD License
7 which accompanies this distribution. The full text of the license may be found at
8 http://opensource.org/licenses/bsd-license.php
10 THE PROGRAM IS DISTRIBUTED UNDER THE BSD LICENSE ON AN "AS IS" BASIS,
11 WITHOUT WARRANTIES OR REPRESENTATIONS OF ANY KIND, EITHER EXPRESS OR IMPLIED.
16 #include <Library/DevicePathLib.h>
18 extern LIST_ENTRY mLockedVariableList
;
19 extern BOOLEAN mEndOfDxe
;
20 extern BOOLEAN mEnableLocking
;
22 #define VAR_CHECK_HANDLER_TABLE_SIZE 0x8
24 UINT32 mNumberOfHandler
= 0;
25 UINT32 mMaxNumberOfHandler
= 0;
26 VAR_CHECK_SET_VARIABLE_CHECK_HANDLER
*mHandlerTable
= NULL
;
31 VAR_CHECK_VARIABLE_PROPERTY VariableProperty
;
33 } VAR_CHECK_VARIABLE_ENTRY
;
35 LIST_ENTRY mVarCheckVariableList
= INITIALIZE_LIST_HEAD_VARIABLE (mVarCheckVariableList
);
39 (EFIAPI
*INTERNAL_VAR_CHECK_FUNCTION
) (
40 IN VAR_CHECK_VARIABLE_PROPERTY
*Propery
,
47 VAR_CHECK_VARIABLE_PROPERTY VariableProperty
;
48 INTERNAL_VAR_CHECK_FUNCTION CheckFunction
;
49 } UEFI_DEFINED_VARIABLE_ENTRY
;
52 Internal check for load option.
54 @param[in] VariablePropery Pointer to variable property.
55 @param[in] DataSize Data size.
56 @param[in] Data Pointer to data buffer.
58 @retval EFI_SUCCESS The SetVariable check result was success.
59 @retval EFI_INVALID_PARAMETER The data buffer is not a valid load option.
64 InternalVarCheckLoadOption (
65 IN VAR_CHECK_VARIABLE_PROPERTY
*VariablePropery
,
70 UINT16 FilePathListLength
;
72 EFI_DEVICE_PATH_PROTOCOL
*FilePathList
;
74 FilePathListLength
= *((UINT16
*) ((UINTN
) Data
+ sizeof (UINT32
)));
79 Description
= (CHAR16
*) ((UINTN
) Data
+ sizeof (UINT32
) + sizeof (UINT16
));
80 while (Description
< (CHAR16
*) ((UINTN
) Data
+ DataSize
)) {
81 if (*Description
== L
'\0') {
86 if ((UINTN
) Description
>= ((UINTN
) Data
+ DataSize
)) {
87 return EFI_INVALID_PARAMETER
;
94 FilePathList
= (EFI_DEVICE_PATH_PROTOCOL
*) Description
;
95 if ((UINTN
) FilePathList
> (MAX_ADDRESS
- FilePathListLength
)) {
96 return EFI_INVALID_PARAMETER
;
98 if (((UINTN
) FilePathList
+ FilePathListLength
) > ((UINTN
) Data
+ DataSize
)) {
99 return EFI_INVALID_PARAMETER
;
101 if (FilePathListLength
< sizeof (EFI_DEVICE_PATH_PROTOCOL
)) {
102 return EFI_INVALID_PARAMETER
;
104 if (!IsDevicePathValid (FilePathList
, FilePathListLength
)) {
105 return EFI_INVALID_PARAMETER
;
112 Internal check for key option.
114 @param[in] VariablePropery Pointer to variable property.
115 @param[in] DataSize Data size.
116 @param[in] Data Pointer to data buffer.
118 @retval EFI_SUCCESS The SetVariable check result was success.
119 @retval EFI_INVALID_PARAMETER The data buffer is not a valid key option.
124 InternalVarCheckKeyOption (
125 IN VAR_CHECK_VARIABLE_PROPERTY
*VariablePropery
,
130 if (((DataSize
- sizeof (EFI_KEY_OPTION
)) % sizeof (EFI_INPUT_KEY
)) != 0) {
131 return EFI_INVALID_PARAMETER
;
138 Internal check for device path.
140 @param[in] VariablePropery Pointer to variable property.
141 @param[in] DataSize Data size.
142 @param[in] Data Pointer to data buffer.
144 @retval EFI_SUCCESS The SetVariable check result was success.
145 @retval EFI_INVALID_PARAMETER The data buffer is not a valid device path.
150 InternalVarCheckDevicePath (
151 IN VAR_CHECK_VARIABLE_PROPERTY
*VariablePropery
,
156 if (!IsDevicePathValid ((EFI_DEVICE_PATH_PROTOCOL
*) Data
, DataSize
)) {
157 return EFI_INVALID_PARAMETER
;
163 Internal check for ASCII string.
165 @param[in] VariablePropery Pointer to variable property.
166 @param[in] DataSize Data size.
167 @param[in] Data Pointer to data buffer.
169 @retval EFI_SUCCESS The SetVariable check result was success.
170 @retval EFI_INVALID_PARAMETER The data buffer is not a Null-terminated ASCII string.
175 InternalVarCheckAsciiString (
176 IN VAR_CHECK_VARIABLE_PROPERTY
*VariablePropery
,
184 String
= (CHAR8
*) Data
;
185 if (String
[DataSize
- 1] == '\0') {
188 for (Index
= 1; Index
< DataSize
&& (String
[DataSize
- 1 - Index
] != '\0'); Index
++);
189 if (Index
== DataSize
) {
190 return EFI_INVALID_PARAMETER
;
197 Internal check for size array.
199 @param[in] VariablePropery Pointer to variable property.
200 @param[in] DataSize Data size.
201 @param[in] Data Pointer to data buffer.
203 @retval EFI_SUCCESS The SetVariable check result was success.
204 @retval EFI_INVALID_PARAMETER The DataSize is not size array.
209 InternalVarCheckSizeArray (
210 IN VAR_CHECK_VARIABLE_PROPERTY
*VariablePropery
,
215 if ((DataSize
% VariablePropery
->MinSize
) != 0) {
216 return EFI_INVALID_PARAMETER
;
222 // To prevent name collisions with possible future globally defined variables,
223 // other internal firmware data variables that are not defined here must be
224 // saved with a unique VendorGuid other than EFI_GLOBAL_VARIABLE or
225 // any other GUID defined by the UEFI Specification. Implementations must
226 // only permit the creation of variables with a UEFI Specification-defined
227 // VendorGuid when these variables are documented in the UEFI Specification.
229 UEFI_DEFINED_VARIABLE_ENTRY mGlobalVariableList
[] = {
231 EFI_LANG_CODES_VARIABLE_NAME
,
233 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
235 VARIABLE_ATTRIBUTE_BS_RT
,
239 InternalVarCheckAsciiString
242 EFI_LANG_VARIABLE_NAME
,
244 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
246 VARIABLE_ATTRIBUTE_NV_BS_RT
,
250 InternalVarCheckAsciiString
253 EFI_TIME_OUT_VARIABLE_NAME
,
255 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
257 VARIABLE_ATTRIBUTE_NV_BS_RT
,
264 EFI_PLATFORM_LANG_CODES_VARIABLE_NAME
,
266 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
268 VARIABLE_ATTRIBUTE_BS_RT
,
272 InternalVarCheckAsciiString
275 EFI_PLATFORM_LANG_VARIABLE_NAME
,
277 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
279 VARIABLE_ATTRIBUTE_NV_BS_RT
,
283 InternalVarCheckAsciiString
286 EFI_CON_IN_VARIABLE_NAME
,
288 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
290 VARIABLE_ATTRIBUTE_NV_BS_RT
,
291 sizeof (EFI_DEVICE_PATH_PROTOCOL
),
294 InternalVarCheckDevicePath
297 EFI_CON_OUT_VARIABLE_NAME
,
299 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
301 VARIABLE_ATTRIBUTE_NV_BS_RT
,
302 sizeof (EFI_DEVICE_PATH_PROTOCOL
),
305 InternalVarCheckDevicePath
308 EFI_ERR_OUT_VARIABLE_NAME
,
310 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
312 VARIABLE_ATTRIBUTE_NV_BS_RT
,
313 sizeof (EFI_DEVICE_PATH_PROTOCOL
),
316 InternalVarCheckDevicePath
319 EFI_CON_IN_DEV_VARIABLE_NAME
,
321 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
323 VARIABLE_ATTRIBUTE_BS_RT
,
324 sizeof (EFI_DEVICE_PATH_PROTOCOL
),
327 InternalVarCheckDevicePath
330 EFI_CON_OUT_DEV_VARIABLE_NAME
,
332 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
334 VARIABLE_ATTRIBUTE_BS_RT
,
335 sizeof (EFI_DEVICE_PATH_PROTOCOL
),
338 InternalVarCheckDevicePath
341 EFI_ERR_OUT_DEV_VARIABLE_NAME
,
343 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
345 VARIABLE_ATTRIBUTE_BS_RT
,
346 sizeof (EFI_DEVICE_PATH_PROTOCOL
),
349 InternalVarCheckDevicePath
352 EFI_BOOT_ORDER_VARIABLE_NAME
,
354 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
356 VARIABLE_ATTRIBUTE_NV_BS_RT
,
360 InternalVarCheckSizeArray
363 EFI_BOOT_NEXT_VARIABLE_NAME
,
365 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
367 VARIABLE_ATTRIBUTE_NV_BS_RT
,
374 EFI_BOOT_CURRENT_VARIABLE_NAME
,
376 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
378 VARIABLE_ATTRIBUTE_BS_RT
,
385 EFI_BOOT_OPTION_SUPPORT_VARIABLE_NAME
,
387 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
389 VARIABLE_ATTRIBUTE_BS_RT
,
396 EFI_DRIVER_ORDER_VARIABLE_NAME
,
398 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
400 VARIABLE_ATTRIBUTE_NV_BS_RT
,
404 InternalVarCheckSizeArray
407 EFI_HW_ERR_REC_SUPPORT_VARIABLE_NAME
,
409 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
411 VARIABLE_ATTRIBUTE_NV_BS_RT
,
420 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
421 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
422 VARIABLE_ATTRIBUTE_BS_RT
,
429 EFI_KEY_EXCHANGE_KEY_NAME
,
431 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
433 VARIABLE_ATTRIBUTE_NV_BS_RT_AT
,
440 EFI_PLATFORM_KEY_NAME
,
442 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
444 VARIABLE_ATTRIBUTE_NV_BS_RT_AT
,
451 EFI_SIGNATURE_SUPPORT_NAME
,
453 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
454 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
455 VARIABLE_ATTRIBUTE_BS_RT
,
459 InternalVarCheckSizeArray
462 EFI_SECURE_BOOT_MODE_NAME
,
464 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
465 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
466 VARIABLE_ATTRIBUTE_BS_RT
,
473 EFI_KEK_DEFAULT_VARIABLE_NAME
,
475 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
476 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
477 VARIABLE_ATTRIBUTE_BS_RT
,
484 EFI_PK_DEFAULT_VARIABLE_NAME
,
486 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
487 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
488 VARIABLE_ATTRIBUTE_BS_RT
,
495 EFI_DB_DEFAULT_VARIABLE_NAME
,
497 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
498 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
499 VARIABLE_ATTRIBUTE_BS_RT
,
506 EFI_DBX_DEFAULT_VARIABLE_NAME
,
508 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
509 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
510 VARIABLE_ATTRIBUTE_BS_RT
,
517 EFI_DBT_DEFAULT_VARIABLE_NAME
,
519 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
520 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
521 VARIABLE_ATTRIBUTE_BS_RT
,
528 EFI_OS_INDICATIONS_SUPPORT_VARIABLE_NAME
,
530 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
532 VARIABLE_ATTRIBUTE_BS_RT
,
539 EFI_OS_INDICATIONS_VARIABLE_NAME
,
541 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
543 VARIABLE_ATTRIBUTE_NV_BS_RT
,
550 EFI_VENDOR_KEYS_VARIABLE_NAME
,
552 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
553 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
554 VARIABLE_ATTRIBUTE_BS_RT
,
561 UEFI_DEFINED_VARIABLE_ENTRY mGlobalVariableList2
[] = {
565 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
567 VARIABLE_ATTRIBUTE_NV_BS_RT
,
568 sizeof (UINT32
) + sizeof (UINT16
),
571 InternalVarCheckLoadOption
576 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
578 VARIABLE_ATTRIBUTE_NV_BS_RT
,
579 sizeof (UINT32
) + sizeof (UINT16
),
582 InternalVarCheckLoadOption
587 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
589 VARIABLE_ATTRIBUTE_NV_BS_RT
,
590 sizeof (EFI_KEY_OPTION
),
591 sizeof (EFI_KEY_OPTION
) + 3 * sizeof (EFI_INPUT_KEY
)
593 InternalVarCheckKeyOption
598 // EFI_IMAGE_SECURITY_DATABASE_GUID
600 UEFI_DEFINED_VARIABLE_ENTRY mImageSecurityVariableList
[] = {
602 EFI_IMAGE_SECURITY_DATABASE
,
604 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
606 VARIABLE_ATTRIBUTE_NV_BS_RT_AT
,
613 EFI_IMAGE_SECURITY_DATABASE1
,
615 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
617 VARIABLE_ATTRIBUTE_NV_BS_RT_AT
,
624 EFI_IMAGE_SECURITY_DATABASE2
,
626 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
628 VARIABLE_ATTRIBUTE_NV_BS_RT_AT
,
639 VAR_CHECK_VARIABLE_PROPERTY VariableProperty
;
640 INTERNAL_VAR_CHECK_FUNCTION CheckFunction
;
641 } VARIABLE_DRIVER_VARIABLE_ENTRY
;
643 VARIABLE_DRIVER_VARIABLE_ENTRY mVariableDriverVariableList
[] = {
645 &gEfiSecureBootEnableDisableGuid
,
646 EFI_SECURE_BOOT_ENABLE_NAME
,
648 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
650 VARIABLE_ATTRIBUTE_NV_BS
,
656 &gEfiCustomModeEnableGuid
,
657 EFI_CUSTOM_MODE_NAME
,
659 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
661 VARIABLE_ATTRIBUTE_NV_BS
,
667 &gEfiVendorKeysNvGuid
,
668 EFI_VENDOR_KEYS_NV_VARIABLE_NAME
,
670 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
672 VARIABLE_ATTRIBUTE_NV_BS_RT_AT
,
678 &gEfiAuthenticatedVariableGuid
,
679 L
"AuthVarKeyDatabase",
681 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
683 VARIABLE_ATTRIBUTE_NV_BS_RT_AW
,
692 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
694 VARIABLE_ATTRIBUTE_NV_BS_RT_AT
,
700 &gEdkiiVarErrorFlagGuid
,
703 VAR_CHECK_VARIABLE_PROPERTY_REVISION
,
704 VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
,
705 VARIABLE_ATTRIBUTE_NV_BS_RT
,
706 sizeof (VAR_ERROR_FLAG
),
707 sizeof (VAR_ERROR_FLAG
)
713 Get UEFI defined global variable or image security database variable property.
714 The code will check if variable guid is global variable or image security database guid first.
715 If yes, further check if variable name is in mGlobalVariableList, mGlobalVariableList2 or mImageSecurityVariableList.
717 @param[in] VariableName Pointer to variable name.
718 @param[in] VendorGuid Variable Vendor Guid.
719 @param[in] WildcardMatch Try wildcard match or not.
720 @param[out] VariableProperty Pointer to variable property.
721 @param[out] VarCheckFunction Pointer to check function.
723 @retval EFI_SUCCESS Variable is not global variable or image security database variable.
724 @retval EFI_INVALID_PARAMETER Variable is global variable or image security database variable, but variable name is not in the lists.
728 GetUefiDefinedVariableProperty (
729 IN CHAR16
*VariableName
,
730 IN EFI_GUID
*VendorGuid
,
731 IN BOOLEAN WildcardMatch
,
732 OUT VAR_CHECK_VARIABLE_PROPERTY
**VariableProperty
,
733 OUT INTERNAL_VAR_CHECK_FUNCTION
*VarCheckFunction OPTIONAL
739 if (CompareGuid (VendorGuid
, &gEfiGlobalVariableGuid
)) {
741 // Try list 1, exactly match.
743 for (Index
= 0; Index
< sizeof (mGlobalVariableList
)/sizeof (mGlobalVariableList
[0]); Index
++) {
744 if (StrCmp (mGlobalVariableList
[Index
].Name
, VariableName
) == 0) {
745 if (VarCheckFunction
!= NULL
) {
746 *VarCheckFunction
= mGlobalVariableList
[Index
].CheckFunction
;
748 *VariableProperty
= &mGlobalVariableList
[Index
].VariableProperty
;
756 NameLength
= StrLen (VariableName
) - 4;
757 for (Index
= 0; Index
< sizeof (mGlobalVariableList2
)/sizeof (mGlobalVariableList2
[0]); Index
++) {
759 if ((StrLen (VariableName
) == StrLen (mGlobalVariableList2
[Index
].Name
)) &&
760 (StrnCmp (mGlobalVariableList2
[Index
].Name
, VariableName
, NameLength
) == 0) &&
761 IsHexaDecimalDigitCharacter (VariableName
[NameLength
]) &&
762 IsHexaDecimalDigitCharacter (VariableName
[NameLength
+ 1]) &&
763 IsHexaDecimalDigitCharacter (VariableName
[NameLength
+ 2]) &&
764 IsHexaDecimalDigitCharacter (VariableName
[NameLength
+ 3])) {
765 if (VarCheckFunction
!= NULL
) {
766 *VarCheckFunction
= mGlobalVariableList2
[Index
].CheckFunction
;
768 *VariableProperty
= &mGlobalVariableList2
[Index
].VariableProperty
;
772 if (StrCmp (mGlobalVariableList2
[Index
].Name
, VariableName
) == 0) {
773 if (VarCheckFunction
!= NULL
) {
774 *VarCheckFunction
= mGlobalVariableList2
[Index
].CheckFunction
;
776 *VariableProperty
= &mGlobalVariableList2
[Index
].VariableProperty
;
782 // The variable name is not in the lists.
784 return EFI_INVALID_PARAMETER
;
787 if (CompareGuid (VendorGuid
, &gEfiImageSecurityDatabaseGuid
)){
788 for (Index
= 0; Index
< sizeof (mImageSecurityVariableList
)/sizeof (mImageSecurityVariableList
[0]); Index
++) {
789 if (StrCmp (mImageSecurityVariableList
[Index
].Name
, VariableName
) == 0) {
790 if (VarCheckFunction
!= NULL
) {
791 *VarCheckFunction
= mImageSecurityVariableList
[Index
].CheckFunction
;
793 *VariableProperty
= &mImageSecurityVariableList
[Index
].VariableProperty
;
798 return EFI_INVALID_PARAMETER
;
802 // It is not global variable or image security database variable.
808 Get variable property for variables managed by Varaible driver.
810 @param[in] VariableName Pointer to variable name.
811 @param[in] VendorGuid Variable Vendor Guid.
813 @return Pointer to variable property.
816 VAR_CHECK_VARIABLE_PROPERTY
*
817 GetVariableDriverVariableProperty (
818 IN CHAR16
*VariableName
,
819 IN EFI_GUID
*VendorGuid
824 for (Index
= 0; Index
< sizeof (mVariableDriverVariableList
)/sizeof (mVariableDriverVariableList
[0]); Index
++) {
825 if ((CompareGuid (mVariableDriverVariableList
[Index
].Guid
, VendorGuid
)) && (StrCmp (mVariableDriverVariableList
[Index
].Name
, VariableName
) == 0)) {
826 return &mVariableDriverVariableList
[Index
].VariableProperty
;
834 Internal SetVariable check.
836 @param[in] VariableName Name of Variable to set.
837 @param[in] VendorGuid Variable vendor GUID.
838 @param[in] Attributes Attribute value of the variable.
839 @param[in] DataSize Size of Data to set.
840 @param[in] Data Data pointer.
842 @retval EFI_SUCCESS The SetVariable check result was success.
843 @retval EFI_INVALID_PARAMETER An invalid combination of attribute bits, name, and GUID was supplied,
844 or the DataSize exceeds the minimum or maximum allowed,
845 or the Data value is not following UEFI spec for UEFI defined variables.
846 @retval EFI_WRITE_PROTECTED The variable in question is read-only.
847 @retval Others The return status from check handler.
852 InternalVarCheckSetVariableCheck (
853 IN CHAR16
*VariableName
,
854 IN EFI_GUID
*VendorGuid
,
855 IN UINT32 Attributes
,
863 VAR_CHECK_VARIABLE_ENTRY
*Entry
;
865 VAR_CHECK_VARIABLE_PROPERTY
*Property
;
866 INTERNAL_VAR_CHECK_FUNCTION VarCheckFunction
;
870 // Only do check after End Of Dxe.
876 VarCheckFunction
= NULL
;
878 for ( Link
= GetFirstNode (&mVarCheckVariableList
)
879 ; !IsNull (&mVarCheckVariableList
, Link
)
880 ; Link
= GetNextNode (&mVarCheckVariableList
, Link
)
882 Entry
= BASE_CR (Link
, VAR_CHECK_VARIABLE_ENTRY
, Link
);
883 Name
= (CHAR16
*) ((UINTN
) Entry
+ sizeof (*Entry
));
884 if (CompareGuid (&Entry
->Guid
, VendorGuid
) && (StrCmp (Name
, VariableName
) == 0)) {
885 Property
= &Entry
->VariableProperty
;
889 if (Property
== NULL
) {
890 Property
= GetVariableDriverVariableProperty (VariableName
, VendorGuid
);
892 if (Property
== NULL
) {
893 Status
= GetUefiDefinedVariableProperty (VariableName
, VendorGuid
, TRUE
, &Property
, &VarCheckFunction
);
894 if (EFI_ERROR (Status
)) {
895 DEBUG ((EFI_D_INFO
, "[Variable]: Var Check UEFI defined variable fail %r - %g:%s\n", Status
, VendorGuid
, VariableName
));
899 if (Property
!= NULL
) {
900 if (mEnableLocking
&& ((Property
->Property
& VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
) != 0)) {
901 DEBUG ((EFI_D_INFO
, "[Variable]: Var Check ReadOnly variable fail %r - %g:%s\n", EFI_WRITE_PROTECTED
, VendorGuid
, VariableName
));
902 return EFI_WRITE_PROTECTED
;
904 if (!((((Attributes
& EFI_VARIABLE_APPEND_WRITE
) == 0) && (DataSize
== 0)) || (Attributes
== 0))) {
906 // Not to delete variable.
908 if ((Attributes
& (~EFI_VARIABLE_APPEND_WRITE
)) != Property
->Attributes
) {
909 DEBUG ((EFI_D_INFO
, "[Variable]: Var Check Attributes(0x%08x to 0x%08x) fail %r - %g:%s\n", Property
->Attributes
, Attributes
, EFI_INVALID_PARAMETER
, VendorGuid
, VariableName
));
910 return EFI_INVALID_PARAMETER
;
913 if ((DataSize
< Property
->MinSize
) || (DataSize
> Property
->MaxSize
)) {
914 DEBUG ((EFI_D_INFO
, "[Variable]: Var Check DataSize fail(0x%x not in 0x%x - 0x%x) %r - %g:%s\n", DataSize
, Property
->MinSize
, Property
->MaxSize
, EFI_INVALID_PARAMETER
, VendorGuid
, VariableName
));
915 return EFI_INVALID_PARAMETER
;
917 if (VarCheckFunction
!= NULL
) {
918 Status
= VarCheckFunction (
923 if (EFI_ERROR (Status
)) {
924 DEBUG ((EFI_D_INFO
, "[Variable]: Internal Var Check function fail %r - %g:%s\n", Status
, VendorGuid
, VariableName
));
932 for (Index
= 0; Index
< mNumberOfHandler
; Index
++) {
933 Status
= mHandlerTable
[Index
] (
940 if (EFI_ERROR (Status
)) {
941 DEBUG ((EFI_D_INFO
, "[Variable]: Var Check handler fail %r - %g:%s\n", Status
, VendorGuid
, VariableName
));
949 Reallocates more global memory to store the registered handler list.
951 @retval RETURN_SUCCESS Reallocate memory successfully.
952 @retval RETURN_OUT_OF_RESOURCES No enough memory to allocate.
957 ReallocateHandlerTable (
961 VAR_CHECK_SET_VARIABLE_CHECK_HANDLER
*HandlerTable
;
964 // Reallocate memory for check handler table.
966 HandlerTable
= ReallocateRuntimePool (
967 mMaxNumberOfHandler
* sizeof (VAR_CHECK_SET_VARIABLE_CHECK_HANDLER
),
968 (mMaxNumberOfHandler
+ VAR_CHECK_HANDLER_TABLE_SIZE
) * sizeof (VAR_CHECK_SET_VARIABLE_CHECK_HANDLER
),
973 // No enough resource to allocate.
975 if (HandlerTable
== NULL
) {
976 return RETURN_OUT_OF_RESOURCES
;
979 mHandlerTable
= HandlerTable
;
981 // Increase max handler number.
983 mMaxNumberOfHandler
= mMaxNumberOfHandler
+ VAR_CHECK_HANDLER_TABLE_SIZE
;
984 return RETURN_SUCCESS
;
988 Register SetVariable check handler.
990 @param[in] Handler Pointer to check handler.
992 @retval EFI_SUCCESS The SetVariable check handler was registered successfully.
993 @retval EFI_INVALID_PARAMETER Handler is NULL.
994 @retval EFI_ACCESS_DENIED EFI_END_OF_DXE_EVENT_GROUP_GUID or EFI_EVENT_GROUP_READY_TO_BOOT has
995 already been signaled.
996 @retval EFI_OUT_OF_RESOURCES There is not enough resource for the SetVariable check handler register request.
997 @retval EFI_UNSUPPORTED This interface is not implemented.
998 For example, it is unsupported in VarCheck protocol if both VarCheck and SmmVarCheck protocols are present.
1003 VarCheckRegisterSetVariableCheckHandler (
1004 IN VAR_CHECK_SET_VARIABLE_CHECK_HANDLER Handler
1009 if (Handler
== NULL
) {
1010 return EFI_INVALID_PARAMETER
;
1014 return EFI_ACCESS_DENIED
;
1017 DEBUG ((EFI_D_INFO
, "RegisterSetVariableCheckHandler - 0x%x\n", Handler
));
1020 // Check whether the handler list is enough to store new handler.
1022 if (mNumberOfHandler
== mMaxNumberOfHandler
) {
1024 // Allocate more resources for new handler.
1026 Status
= ReallocateHandlerTable();
1027 if (EFI_ERROR (Status
)) {
1033 // Register new handler into the handler list.
1035 mHandlerTable
[mNumberOfHandler
] = Handler
;
1036 mNumberOfHandler
++;
1042 Variable property get function.
1044 @param[in] Name Pointer to the variable name.
1045 @param[in] Guid Pointer to the vendor GUID.
1046 @param[in] WildcardMatch Try wildcard match or not.
1048 @return Pointer to the property of variable specified by the Name and Guid.
1051 VAR_CHECK_VARIABLE_PROPERTY
*
1052 VariablePropertyGetFunction (
1055 IN BOOLEAN WildcardMatch
1059 VAR_CHECK_VARIABLE_ENTRY
*Entry
;
1060 CHAR16
*VariableName
;
1061 VAR_CHECK_VARIABLE_PROPERTY
*Property
;
1063 for ( Link
= GetFirstNode (&mVarCheckVariableList
)
1064 ; !IsNull (&mVarCheckVariableList
, Link
)
1065 ; Link
= GetNextNode (&mVarCheckVariableList
, Link
)
1067 Entry
= BASE_CR (Link
, VAR_CHECK_VARIABLE_ENTRY
, Link
);
1068 VariableName
= (CHAR16
*) ((UINTN
) Entry
+ sizeof (*Entry
));
1069 if (CompareGuid (&Entry
->Guid
, Guid
) && (StrCmp (VariableName
, Name
) == 0)) {
1070 return &Entry
->VariableProperty
;
1074 Property
= GetVariableDriverVariableProperty (Name
, Guid
);
1075 if (Property
== NULL
) {
1076 GetUefiDefinedVariableProperty (Name
, Guid
, WildcardMatch
, &Property
, NULL
);
1083 Variable property set.
1085 @param[in] Name Pointer to the variable name.
1086 @param[in] Guid Pointer to the vendor GUID.
1087 @param[in] VariableProperty Pointer to the input variable property.
1089 @retval EFI_SUCCESS The property of variable specified by the Name and Guid was set successfully.
1090 @retval EFI_INVALID_PARAMETER Name, Guid or VariableProperty is NULL, or Name is an empty string,
1091 or the fields of VariableProperty are not valid.
1092 @retval EFI_ACCESS_DENIED EFI_END_OF_DXE_EVENT_GROUP_GUID or EFI_EVENT_GROUP_READY_TO_BOOT has
1093 already been signaled.
1094 @retval EFI_OUT_OF_RESOURCES There is not enough resource for the variable property set request.
1099 VarCheckVariablePropertySet (
1102 IN VAR_CHECK_VARIABLE_PROPERTY
*VariableProperty
1106 VAR_CHECK_VARIABLE_ENTRY
*Entry
;
1107 CHAR16
*VariableName
;
1108 VAR_CHECK_VARIABLE_PROPERTY
*Property
;
1110 if (Name
== NULL
|| Name
[0] == 0 || Guid
== NULL
) {
1111 return EFI_INVALID_PARAMETER
;
1114 if (VariableProperty
== NULL
) {
1115 return EFI_INVALID_PARAMETER
;
1118 if (VariableProperty
->Revision
!= VAR_CHECK_VARIABLE_PROPERTY_REVISION
) {
1119 return EFI_INVALID_PARAMETER
;
1123 return EFI_ACCESS_DENIED
;
1126 Status
= EFI_SUCCESS
;
1128 AcquireLockOnlyAtBootTime (&mVariableModuleGlobal
->VariableGlobal
.VariableServicesLock
);
1130 Property
= VariablePropertyGetFunction (Name
, Guid
, FALSE
);
1131 if (Property
!= NULL
) {
1132 CopyMem (Property
, VariableProperty
, sizeof (*VariableProperty
));
1134 Entry
= AllocateRuntimeZeroPool (sizeof (*Entry
) + StrSize (Name
));
1135 if (Entry
== NULL
) {
1136 Status
= EFI_OUT_OF_RESOURCES
;
1139 VariableName
= (CHAR16
*) ((UINTN
) Entry
+ sizeof (*Entry
));
1140 StrnCpy (VariableName
, Name
, StrLen (Name
));
1141 CopyGuid (&Entry
->Guid
, Guid
);
1142 CopyMem (&Entry
->VariableProperty
, VariableProperty
, sizeof (*VariableProperty
));
1143 InsertTailList (&mVarCheckVariableList
, &Entry
->Link
);
1147 ReleaseLockOnlyAtBootTime (&mVariableModuleGlobal
->VariableGlobal
.VariableServicesLock
);
1153 Internal variable property get.
1155 @param[in] Name Pointer to the variable name.
1156 @param[in] Guid Pointer to the vendor GUID.
1157 @param[out] VariableProperty Pointer to the output variable property.
1159 @retval EFI_SUCCESS The property of variable specified by the Name and Guid was got successfully.
1160 @retval EFI_NOT_FOUND The property of variable specified by the Name and Guid was not found.
1165 InternalVarCheckVariablePropertyGet (
1168 OUT VAR_CHECK_VARIABLE_PROPERTY
*VariableProperty
1172 VARIABLE_ENTRY
*Entry
;
1173 CHAR16
*VariableName
;
1175 VAR_CHECK_VARIABLE_PROPERTY
*Property
;
1179 Property
= VariablePropertyGetFunction (Name
, Guid
, TRUE
);
1180 if (Property
!= NULL
) {
1181 CopyMem (VariableProperty
, Property
, sizeof (*VariableProperty
));
1185 for ( Link
= GetFirstNode (&mLockedVariableList
)
1186 ; !IsNull (&mLockedVariableList
, Link
)
1187 ; Link
= GetNextNode (&mLockedVariableList
, Link
)
1189 Entry
= BASE_CR (Link
, VARIABLE_ENTRY
, Link
);
1190 VariableName
= (CHAR16
*) ((UINTN
) Entry
+ sizeof (*Entry
));
1191 if (CompareGuid (&Entry
->Guid
, Guid
) && (StrCmp (VariableName
, Name
) == 0)) {
1192 VariableProperty
->Property
|= VAR_CHECK_VARIABLE_PROPERTY_READ_ONLY
;
1194 VariableProperty
->Revision
= VAR_CHECK_VARIABLE_PROPERTY_REVISION
;
1200 return (Found
? EFI_SUCCESS
: EFI_NOT_FOUND
);
1204 Variable property get.
1206 @param[in] Name Pointer to the variable name.
1207 @param[in] Guid Pointer to the vendor GUID.
1208 @param[out] VariableProperty Pointer to the output variable property.
1210 @retval EFI_SUCCESS The property of variable specified by the Name and Guid was got successfully.
1211 @retval EFI_INVALID_PARAMETER Name, Guid or VariableProperty is NULL, or Name is an empty string.
1212 @retval EFI_NOT_FOUND The property of variable specified by the Name and Guid was not found.
1217 VarCheckVariablePropertyGet (
1220 OUT VAR_CHECK_VARIABLE_PROPERTY
*VariableProperty
1225 if (Name
== NULL
|| Name
[0] == 0 || Guid
== NULL
) {
1226 return EFI_INVALID_PARAMETER
;
1229 if (VariableProperty
== NULL
) {
1230 return EFI_INVALID_PARAMETER
;
1233 AcquireLockOnlyAtBootTime (&mVariableModuleGlobal
->VariableGlobal
.VariableServicesLock
);
1235 Status
= InternalVarCheckVariablePropertyGet (Name
, Guid
, VariableProperty
);
1237 ReleaseLockOnlyAtBootTime (&mVariableModuleGlobal
->VariableGlobal
.VariableServicesLock
);