/** @file\r
The library instance provides security service of TPM measure boot. \r
\r
+ Caution: This file requires additional review when modified.\r
+ This library will have external input - PE/COFF image and GPT partition.\r
+ This external input must be validated carefully to avoid security issue like\r
+ buffer overflow, integer overflow.\r
+\r
+ DxeTpmMeasureBootLibImageRead() function will make sure the PE/COFF image content\r
+ read is within the image buffer.\r
+\r
+ TcgMeasurePeImage() function will accept untrusted PE/COFF image and validate its\r
+ data structure within this image buffer before use.\r
+\r
+ TcgMeasureGptTable() function will receive untrusted GPT partition table, and parse\r
+ partition data carefully.\r
+\r
Copyright (c) 2009 - 2012, Intel Corporation. All rights reserved.<BR>\r
This program and the accompanying materials \r
are licensed and made available under the terms and conditions of the BSD License \r
/**\r
Reads contents of a PE/COFF image in memory buffer.\r
\r
+ Caution: This function may receive untrusted input.\r
+ PE/COFF image is external input, so this function will make sure the PE/COFF image content\r
+ read is within the image buffer.\r
+\r
@param FileHandle Pointer to the file handle to read the PE/COFF image.\r
@param FileOffset Offset into the PE/COFF image to begin the read operation.\r
@param ReadSize On input, the size in bytes of the requested read operation. \r
/**\r
Measure GPT table data into TPM log.\r
\r
+ Caution: This function may receive untrusted input.\r
+ The GPT partition table is external input, so this function should parse partition data carefully.\r
+\r
@param TcgProtocol Pointer to the located TCG protocol instance.\r
@param GptHandle Handle that GPT partition was installed.\r
\r
Measure PE image into TPM log based on the authenticode image hashing in\r
PE/COFF Specification 8.0 Appendix A.\r
\r
+ Caution: This function may receive untrusted input.\r
+ PE/COFF image is external input, so this function will validate its data structure\r
+ within this image buffer before use.\r
+\r
@param[in] TcgProtocol Pointer to the located TCG protocol instance.\r
@param[in] ImageAddress Start address of image buffer.\r
@param[in] ImageSize Image size\r
might be possible to use it at a future time, then EFI_SECURITY_VIOLATION is \r
returned.\r
\r
- @param[in, out] AuthenticationStatus This is the authentication status returned\r
+ @param[in] AuthenticationStatus This is the authentication status returned\r
from the securitymeasurement services for the\r
input file.\r
@param[in] File This is a pointer to the device path of the file that is\r
being dispatched. This will optionally be used for logging.\r
@param[in] FileBuffer File buffer matches the input file device path.\r
@param[in] FileSize Size of File buffer matches the input file device path.\r
+ @param[in] BootPolicy A boot policy that was used to call LoadImage() UEFI service.\r
\r
- @retval EFI_SUCCESS The file specified by File did authenticate, and the\r
- platform policy dictates that the DXE Core may use File.\r
- @retval EFI_INVALID_PARAMETER File is NULL.\r
- @retval EFI_SECURITY_VIOLATION The file specified by File did not authenticate, and\r
- the platform policy dictates that File should be placed\r
- in the untrusted state. A file may be promoted from\r
- the untrusted to the trusted state at a future time\r
- with a call to the Trust() DXE Service.\r
- @retval EFI_ACCESS_DENIED The file specified by File did not authenticate, and\r
- the platform policy dictates that File should not be\r
- used for any purpose.\r
-\r
+ @retval EFI_SUCCESS The file specified by DevicePath and non-NULL\r
+ FileBuffer did authenticate, and the platform policy dictates\r
+ that the DXE Foundation may use the file.\r
+ @retval other error value\r
**/\r
EFI_STATUS\r
EFIAPI\r
DxeTpmMeasureBootHandler (\r
- IN OUT UINT32 AuthenticationStatus,\r
+ IN UINT32 AuthenticationStatus,\r
IN CONST EFI_DEVICE_PATH_PROTOCOL *File,\r
- IN VOID *FileBuffer OPTIONAL,\r
- IN UINTN FileSize OPTIONAL\r
+ IN VOID *FileBuffer,\r
+ IN UINTN FileSize,\r
+ IN BOOLEAN BootPolicy\r
)\r
{\r
EFI_TCG_PROTOCOL *TcgProtocol;\r
BOOLEAN ApplicationRequired;\r
PE_COFF_LOADER_IMAGE_CONTEXT ImageContext;\r
\r
- if (File == NULL) {\r
- return EFI_INVALID_PARAMETER;\r
- }\r
-\r
Status = gBS->LocateProtocol (&gEfiTcgProtocolGuid, NULL, (VOID **) &TcgProtocol);\r
if (EFI_ERROR (Status)) {\r
//\r
// Copy File Device Path\r
//\r
OrigDevicePathNode = DuplicateDevicePath (File);\r
- ASSERT (OrigDevicePathNode != NULL);\r
\r
//\r
// 1. Check whether this device path support BlockIo protocol.\r
// Find the gpt partion on the given devicepath\r
//\r
DevicePathNode = OrigDevicePathNode;\r
+ ASSERT (DevicePathNode != NULL);\r
while (!IsDevicePathEnd (DevicePathNode)) {\r
//\r
// Find the Gpt partition\r
// Done, free the allocated resource.\r
//\r
Finish:\r
- FreePool (OrigDevicePathNode);\r
+ if (OrigDevicePathNode != NULL) {\r
+ FreePool (OrigDevicePathNode);\r
+ }\r
\r
return Status;\r
}\r
IN EFI_SYSTEM_TABLE *SystemTable\r
)\r
{\r
- return RegisterSecurityHandler (\r
+ return RegisterSecurity2Handler (\r
DxeTpmMeasureBootHandler,\r
EFI_AUTH_OPERATION_MEASURE_IMAGE | EFI_AUTH_OPERATION_IMAGE_REQUIRED\r
);\r