mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "Lee, Chun-Yi" <joeyli.kernel@gmail.com>
To: linux-kernel@vger.kernel.org
Cc: linux-efi@vger.kernel.org, linux-pm@vger.kernel.org,
	"Rafael J. Wysocki" <rjw@sisk.pl>,
	Matthew Garrett <matthew.garrett@nebula.com>,
	Len Brown <len.brown@intel.com>, Pavel Machek <pavel@ucw.cz>,
	Josh Boyer <jwboyer@redhat.com>, Vojtech Pavlik <vojtech@suse.cz>,
	Matt Fleming <matt.fleming@intel.com>,
	Jiri Kosina <jkosina@suse.cz>, "H. Peter Anvin" <hpa@zytor.com>,
	"Lee, Chun-Yi" <jlee@suse.com>
Subject: [RFC PATCH 08/16] x86/efi: Carrying swsusp key by setup data
Date: Thu, 16 Jul 2015 22:25:22 +0800	[thread overview]
Message-ID: <1437056730-15247-9-git-send-email-jlee@suse.com> (raw)
In-Reply-To: <1437056730-15247-1-git-send-email-jlee@suse.com>

For forwarding swsusp key from EFI stub to boot kernel, this patch
allocates setup data for carrying swsusp key, size and the status
of efi operating.

Signed-off-by: Lee, Chun-Yi <jlee@suse.com>
---
 arch/x86/boot/compressed/eboot.c      | 29 +++++++++++++++++++++++++----
 arch/x86/include/uapi/asm/bootparam.h |  1 +
 2 files changed, 26 insertions(+), 4 deletions(-)

diff --git a/arch/x86/boot/compressed/eboot.c b/arch/x86/boot/compressed/eboot.c
index 97b356f..5e1476e 100644
--- a/arch/x86/boot/compressed/eboot.c
+++ b/arch/x86/boot/compressed/eboot.c
@@ -1392,19 +1392,23 @@ free_mem_map:
 
 static void setup_swsusp_keys(struct boot_params *params)
 {
-	unsigned long key_size, attributes;
+	struct setup_data *setup_data, *swsusp_setup_data;
 	struct swsusp_keys *swsusp_keys;
+	int size = 0;
+	unsigned long key_size, attributes;
 	efi_status_t status;
 
 	/* Allocate setup_data to carry keys */
+	size = sizeof(struct setup_data) + sizeof(struct swsusp_keys);
 	status = efi_call_early(allocate_pool, EFI_LOADER_DATA,
-				sizeof(struct swsusp_keys), &swsusp_keys);
+				size, &swsusp_setup_data);
 	if (status != EFI_SUCCESS) {
 		efi_printk(sys_table, "Failed to alloc mem for swsusp_keys\n");
 		return;
 	}
 
-	memset(swsusp_keys, 0, sizeof(struct swsusp_keys));
+	memset(swsusp_setup_data, 0, size);
+	swsusp_keys = (struct swsusp_keys *)swsusp_setup_data->data;
 
 	status = efi_call_early(get_variable, SWSUSP_KEY, &EFI_SWSUSP_GUID,
 				&attributes, &key_size, swsusp_keys->swsusp_key);
@@ -1413,7 +1417,9 @@ static void setup_swsusp_keys(struct boot_params *params)
 		memset(swsusp_keys->swsusp_key, 0, SWSUSP_DIGEST_SIZE);
 		status = efi_call_early(set_variable, SWSUSP_KEY,
 					&EFI_SWSUSP_GUID, attributes, 0, NULL);
-		if (status == EFI_SUCCESS) {
+		if (status)
+			goto clean_fail;
+		else {
 			efi_printk(sys_table, "Cleaned existing swsusp key\n");
 			status = EFI_NOT_FOUND;
 		}
@@ -1433,6 +1439,21 @@ static void setup_swsusp_keys(struct boot_params *params)
 		if (status != EFI_SUCCESS)
 			efi_printk(sys_table, "Failed to set swsusp key\n");
 	}
+
+clean_fail:
+	swsusp_setup_data->type = SETUP_SWSUSP_KEYS;
+	swsusp_setup_data->len = sizeof(struct swsusp_keys);
+	swsusp_setup_data->next = 0;
+	swsusp_keys->skey_status = efi_status_to_err(status);
+
+	setup_data = (struct setup_data *)params->hdr.setup_data;
+	while (setup_data && setup_data->next)
+		setup_data = (struct setup_data *)setup_data->next;
+
+	if (setup_data)
+		setup_data->next = (unsigned long)swsusp_setup_data;
+	else
+		params->hdr.setup_data = (unsigned long)swsusp_setup_data;
 }
 #else
 static void setup_swsusp_keys(struct boot_params *params) {}
diff --git a/arch/x86/include/uapi/asm/bootparam.h b/arch/x86/include/uapi/asm/bootparam.h
index ab456dc..12e0a203 100644
--- a/arch/x86/include/uapi/asm/bootparam.h
+++ b/arch/x86/include/uapi/asm/bootparam.h
@@ -7,6 +7,7 @@
 #define SETUP_DTB			2
 #define SETUP_PCI			3
 #define SETUP_EFI			4
+#define SETUP_SWSUSP_KEYS		5
 
 /* ram_size flags */
 #define RAMDISK_IMAGE_START_MASK	0x07FF
-- 
1.8.4.5


  parent reply	other threads:[~2015-07-16 14:27 UTC|newest]

Thread overview: 52+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-07-16 14:25 [RFC PATCH 00/16] Signature verification of hibernate snapshot Lee, Chun-Yi
2015-07-16 14:25 ` [RFC PATCH 01/16] PM / hibernate: define HMAC algorithm and digest size of swsusp Lee, Chun-Yi
2015-07-28 12:01   ` Pavel Machek
2015-07-31 10:08     ` joeyli
2015-07-31 12:49       ` Pavel Machek
2015-07-31 15:46         ` joeyli
2015-07-16 14:25 ` [RFC PATCH 02/16] x86/efi: Add get and set variable to EFI services pointer table Lee, Chun-Yi
2015-07-30 15:19   ` Matt Fleming
2015-07-31 10:14     ` joeyli
2015-07-16 14:25 ` [RFC PATCH 03/16] x86/boot: Public getting random boot function Lee, Chun-Yi
2015-07-28 12:21   ` Pavel Machek
2015-07-31 10:52     ` joeyli
2015-07-31 12:50       ` Pavel Machek
2015-07-16 14:25 ` [RFC PATCH 04/16] x86/efi: Generating random number in EFI stub Lee, Chun-Yi
2015-07-28 12:01   ` Pavel Machek
2015-07-31  9:06     ` joeyli
2015-07-30 15:37   ` Matt Fleming
2015-07-31  9:12     ` joeyli
2015-07-16 14:25 ` [RFC PATCH 05/16] x86/efi: Get entropy through EFI random number generator protocol Lee, Chun-Yi
2015-07-28 12:28   ` Pavel Machek
2015-07-31  9:58     ` joeyli
2015-07-31 12:01       ` Matt Fleming
2015-07-31 16:05         ` joeyli
2015-07-30 16:11   ` Matt Fleming
2015-07-31 14:59     ` joeyli
2015-07-31 15:01       ` joeyli
2015-07-16 14:25 ` [RFC PATCH 06/16] x86/efi: Generating random HMAC key for siging hibernate image Lee, Chun-Yi
2015-07-28 12:30   ` Pavel Machek
2015-07-31 10:56     ` joeyli
2015-07-30 16:20   ` Matt Fleming
2015-07-31 15:09     ` joeyli
2015-07-16 14:25 ` [RFC PATCH 07/16] efi: Public the function of transferring EFI status to kernel error Lee, Chun-Yi
2015-07-30 16:23   ` Matt Fleming
2015-07-31 15:11     ` joeyli
2015-08-02  0:23     ` Valdis.Kletnieks
2015-07-16 14:25 ` Lee, Chun-Yi [this message]
2015-07-30 16:30   ` [RFC PATCH 08/16] x86/efi: Carrying swsusp key by setup data Matt Fleming
2015-07-31 15:31     ` joeyli
2015-07-16 14:25 ` [RFC PATCH 09/16] PM / hibernate: Reserve swsusp key and earse footprints Lee, Chun-Yi
2015-07-28 12:35   ` Pavel Machek
2015-07-31 15:43     ` joeyli
2015-07-16 14:25 ` [RFC PATCH 10/16] PM / hibernate: Generate and verify signature of hibernate snapshot Lee, Chun-Yi
2015-07-16 14:25 ` [RFC PATCH 11/16] PM / hibernate: Avoid including swsusp key to hibernate image Lee, Chun-Yi
2015-07-16 14:25 ` [RFC PATCH 12/16] PM / hibernate: Forward signature verifying result and key to image kernel Lee, Chun-Yi
2015-07-16 14:25 ` [RFC PATCH 13/16] PM / hibernate: Add configuration to enforce signature verification Lee, Chun-Yi
2015-07-16 14:25 ` [RFC PATCH 14/16] PM / hibernate: Allow user trigger swsusp key re-generating Lee, Chun-Yi
2015-07-16 14:25 ` [RFC PATCH 15/16] PM / hibernate: Bypass verification logic on legacy BIOS Lee, Chun-Yi
2015-07-16 14:25 ` [RFC PATCH 16/16] PM / hibernate: Document signature verification of hibernate snapshot Lee, Chun-Yi
2015-07-24 17:08 ` [RFC PATCH 00/16] Signature " Jiri Kosina
2015-07-24 20:08   ` Rafael J. Wysocki
2015-07-28 12:09     ` Matt Fleming
2015-07-25 14:32   ` joeyli

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1437056730-15247-9-git-send-email-jlee@suse.com \
    --to=joeyli.kernel@gmail.com \
    --cc=hpa@zytor.com \
    --cc=jkosina@suse.cz \
    --cc=jlee@suse.com \
    --cc=jwboyer@redhat.com \
    --cc=len.brown@intel.com \
    --cc=linux-efi@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-pm@vger.kernel.org \
    --cc=matt.fleming@intel.com \
    --cc=matthew.garrett@nebula.com \
    --cc=pavel@ucw.cz \
    --cc=rjw@sisk.pl \
    --cc=vojtech@suse.cz \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®