\r
FpdtSmiHandler() will receive untrusted input and do basic validation.\r
\r
- Copyright (c) 2011 - 2013, Intel Corporation. All rights reserved.<BR>\r
+ Copyright (c) 2011 - 2016, Intel Corporation. All rights reserved.<BR>\r
This program and the accompanying materials\r
are licensed and made available under the terms and conditions of the BSD License\r
which accompanies this distribution. The full text of the license may be found at\r
#include <PiSmm.h>\r
\r
#include <Protocol/SmmReportStatusCodeHandler.h>\r
-#include <Protocol/SmmAccess2.h>\r
\r
#include <Guid/FirmwarePerformance.h>\r
\r
#include <Library/MemoryAllocationLib.h>\r
#include <Library/UefiBootServicesTableLib.h>\r
#include <Library/SynchronizationLib.h>\r
+#include <Library/SmmMemLib.h>\r
\r
#define EXTENSION_RECORD_SIZE 0x1000\r
\r
UINT32 mBootRecordMaxSize = 0;\r
UINT8 *mBootRecordBuffer = NULL;\r
\r
-EFI_SMRAM_DESCRIPTOR *mSmramRanges;\r
-UINTN mSmramRangeCount;\r
SPIN_LOCK mSmmFpdtLock;\r
BOOLEAN mSmramIsOutOfResource = FALSE;\r
\r
return EFI_SUCCESS;\r
}\r
\r
-/**\r
- This function check if the address is in SMRAM.\r
-\r
- @param Buffer the buffer address to be checked.\r
- @param Length the buffer length to be checked.\r
-\r
- @retval TRUE this address is in SMRAM.\r
- @retval FALSE this address is NOT in SMRAM.\r
-**/\r
-BOOLEAN\r
-InternalIsAddressInSmram (\r
- IN EFI_PHYSICAL_ADDRESS Buffer,\r
- IN UINT64 Length\r
- )\r
-{\r
- UINTN Index;\r
-\r
- for (Index = 0; Index < mSmramRangeCount; Index ++) {\r
- if (((Buffer >= mSmramRanges[Index].CpuStart) && (Buffer < mSmramRanges[Index].CpuStart + mSmramRanges[Index].PhysicalSize)) ||\r
- ((mSmramRanges[Index].CpuStart >= Buffer) && (mSmramRanges[Index].CpuStart < Buffer + Length))) {\r
- return TRUE;\r
- }\r
- }\r
-\r
- return FALSE;\r
-}\r
-\r
-/**\r
- This function check if the address refered by Buffer and Length is valid.\r
-\r
- @param Buffer the buffer address to be checked.\r
- @param Length the buffer length to be checked.\r
-\r
- @retval TRUE this address is valid.\r
- @retval FALSE this address is NOT valid.\r
-**/\r
-BOOLEAN\r
-InternalIsAddressValid (\r
- IN UINTN Buffer,\r
- IN UINTN Length\r
- )\r
-{\r
- if (Buffer > (MAX_ADDRESS - Length)) {\r
- //\r
- // Overflow happen\r
- //\r
- return FALSE;\r
- }\r
- if (InternalIsAddressInSmram ((EFI_PHYSICAL_ADDRESS)Buffer, (UINT64)Length)) {\r
- return FALSE;\r
- }\r
- return TRUE;\r
-}\r
-\r
/**\r
Communication service SMI Handler entry.\r
\r
{\r
EFI_STATUS Status;\r
SMM_BOOT_RECORD_COMMUNICATE *SmmCommData;\r
+ UINTN BootRecordOffset;\r
UINTN BootRecordSize;\r
VOID *BootRecordData;\r
+ UINTN TempCommBufferSize;\r
\r
//\r
// If input is invalid, stop processing this SMI\r
return EFI_SUCCESS;\r
}\r
\r
- if(*CommBufferSize < sizeof (SMM_BOOT_RECORD_COMMUNICATE)) {\r
+ TempCommBufferSize = *CommBufferSize;\r
+\r
+ if(TempCommBufferSize < sizeof (SMM_BOOT_RECORD_COMMUNICATE)) {\r
return EFI_SUCCESS;\r
}\r
\r
- if (!InternalIsAddressValid ((UINTN)CommBuffer, *CommBufferSize)) {\r
+ if (!SmmIsBufferOutsideSmmValid ((UINTN)CommBuffer, TempCommBufferSize)) {\r
DEBUG ((EFI_D_ERROR, "FpdtSmiHandler: SMM communication data buffer in SMRAM or overflow!\n"));\r
return EFI_SUCCESS;\r
}\r
\r
switch (SmmCommData->Function) {\r
case SMM_FPDT_FUNCTION_GET_BOOT_RECORD_SIZE :\r
- SmmCommData->BootRecordSize = mBootRecordSize;\r
- break;\r
+ SmmCommData->BootRecordSize = mBootRecordSize;\r
+ break;\r
\r
case SMM_FPDT_FUNCTION_GET_BOOT_RECORD_DATA :\r
- BootRecordData = SmmCommData->BootRecordData;\r
- BootRecordSize = SmmCommData->BootRecordSize;\r
- if (BootRecordData == NULL || BootRecordSize < mBootRecordSize) {\r
- Status = EFI_INVALID_PARAMETER;\r
- break;\r
- } \r
-\r
- //\r
- // Sanity check\r
- //\r
- SmmCommData->BootRecordSize = mBootRecordSize;\r
- if (!InternalIsAddressValid ((UINTN)BootRecordData, mBootRecordSize)) {\r
- DEBUG ((EFI_D_ERROR, "FpdtSmiHandler: SMM Data buffer in SMRAM or overflow!\n"));\r
- Status = EFI_ACCESS_DENIED;\r
- break;\r
- }\r
-\r
- CopyMem (\r
- (UINT8*)BootRecordData, \r
- mBootRecordBuffer, \r
- mBootRecordSize\r
- );\r
- break;\r
+ Status = EFI_UNSUPPORTED;\r
+ break;\r
+\r
+ case SMM_FPDT_FUNCTION_GET_BOOT_RECORD_DATA_BY_OFFSET :\r
+ BootRecordOffset = SmmCommData->BootRecordOffset;\r
+ BootRecordData = SmmCommData->BootRecordData;\r
+ BootRecordSize = SmmCommData->BootRecordSize;\r
+ if (BootRecordData == NULL || BootRecordOffset >= mBootRecordSize) {\r
+ Status = EFI_INVALID_PARAMETER;\r
+ break;\r
+ }\r
+ \r
+ //\r
+ // Sanity check\r
+ //\r
+ if (BootRecordSize > mBootRecordSize - BootRecordOffset) {\r
+ BootRecordSize = mBootRecordSize - BootRecordOffset;\r
+ }\r
+ SmmCommData->BootRecordSize = BootRecordSize;\r
+ if (!SmmIsBufferOutsideSmmValid ((UINTN)BootRecordData, BootRecordSize)) {\r
+ DEBUG ((EFI_D_ERROR, "FpdtSmiHandler: SMM Data buffer in SMRAM or overflow!\n"));\r
+ Status = EFI_ACCESS_DENIED;\r
+ break;\r
+ }\r
+ \r
+ CopyMem (\r
+ (UINT8*)BootRecordData, \r
+ mBootRecordBuffer + BootRecordOffset, \r
+ BootRecordSize\r
+ );\r
+ break;\r
\r
default:\r
- Status = EFI_UNSUPPORTED;\r
+ Status = EFI_UNSUPPORTED;\r
}\r
\r
SmmCommData->ReturnStatus = Status;\r
{\r
EFI_STATUS Status;\r
EFI_HANDLE Handle;\r
- EFI_SMM_ACCESS2_PROTOCOL *SmmAccess;\r
- UINTN Size;\r
\r
//\r
// Initialize spin lock\r
Status = mRscHandlerProtocol->Register (FpdtStatusCodeListenerSmm);\r
ASSERT_EFI_ERROR (Status);\r
\r
- //\r
- // Get SMRAM information\r
- //\r
- Status = gBS->LocateProtocol (&gEfiSmmAccess2ProtocolGuid, NULL, (VOID **)&SmmAccess);\r
- ASSERT_EFI_ERROR (Status);\r
-\r
- Size = 0;\r
- Status = SmmAccess->GetCapabilities (SmmAccess, &Size, NULL);\r
- ASSERT (Status == EFI_BUFFER_TOO_SMALL);\r
-\r
- Status = gSmst->SmmAllocatePool (\r
- EfiRuntimeServicesData,\r
- Size,\r
- (VOID **)&mSmramRanges\r
- );\r
- ASSERT_EFI_ERROR (Status);\r
-\r
- Status = SmmAccess->GetCapabilities (SmmAccess, &Size, mSmramRanges);\r
- ASSERT_EFI_ERROR (Status);\r
-\r
- mSmramRangeCount = Size / sizeof (EFI_SMRAM_DESCRIPTOR);\r
-\r
//\r
// Register SMI handler.\r
//\r