From nobody Fri Sep 25 19:13:36 2026 Received: from mail-ej1-f71.google.com (mail-ej1-f71.google.com [209.85.218.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1ED1654A7FB for ; Wed, 9 Sep 2026 11:55:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.71 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954960; cv=none; b=NBJXH6q7tM0xzbevWF8lT+Z8oLfUmkyHEb+h66vvyPiPStJ4kbGtRcD8sMvlP/R92spTwYA9Dnoj63aDa32SRX+syUfYEE6Cdbqy++ke4d2kHMcSgoUJzPsJlK2z7f81/M5O8S+CVVdU7BSzirZzKeS6pROFyeFN3idFM5iDsB4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954960; c=relaxed/simple; bh=sGZSDI9LoB4j8Q58me441VivPfwEK65+W5D4R01Y4jw=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=s6SKB6mgWSQ8/oQkJb3IJUW2imvlfaVL/tZBn/wt10mM3ge17HGOZ1ETjhvRC5bCrSQputXo+7sTmDz1/0onIDZowb5IRKthetrKzotZqWSipO9F/r9Sbp2KOMqzTLlljHqiyq1bSwaifCNNKqvRaoOeHljj2rLjLis2XPr3WZw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=viFGTJg/; arc=none smtp.client-ip=209.85.218.71 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="viFGTJg/" Received: by mail-ej1-f71.google.com with SMTP id a640c23a62f3a-c251c140b41so404018466b.3 for ; Wed, 09 Sep 2026 04:55:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788954956; x=1789559756; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=/8G2xiGwGscqCz2TsV89VXPggp4ynR4SYjKKcXLzYJM=; b=viFGTJg/ClyL8LKBVVDztDXA7aBs2dnWkBLyL6ykO5nQK0cmevhFGlnhjEUomrSABP XBASyLQWt7fEk7f5lPtiwfAKWqZB1ci2crYfVYCsH0dTlszSaIYDbKdEn30m1f4sLjEw aF7BbrcH2BqtyleROj6VPx20S0n28TYh4v/DyhdLz6gsoRe7dkYFea3IqjU3zkB+GGFe MhS0cnWAor3PuttfhKCdQQlE51fLWWOhTu6r/en+3kbDvp7Hzazv064rnm4+0NVEhXXx BuOElkhxIJSr7fGP1oEsF6HCScWaqpNuQm6y+SwaIPMiaHUq9HPzMrvwgrO0mSAxtOBN G8Iw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788954956; x=1789559756; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/8G2xiGwGscqCz2TsV89VXPggp4ynR4SYjKKcXLzYJM=; b=KQcVDdcyRtFUF3rDpz4QDyKNu4/kq6sziM23oIxhlrQSoFp46KD0ZGvBbqeFzXYZn3 +sfjk1xl4+hVK2iil0yHahnuWz3I0Jhf3dsTK7hEb5VwHfoPx9IMAmEUiKceltuMVPLr EzwYQOqRelxmJJmzqfDddhwkqX2YSg51+pXK9Ah6A9xyyazxO0Z0pQHjGvoy03qI21e7 fCD5UL8VRoP78mMOUmXmSKDyffI+MqjITNuRpvtfZ6Ca2OBbTC1hPdBh0ErsLyDcK6f5 vI5Mvrwbm4NAv5KGh5KTDxZ1t+2N59WMHOrSxhPZ3tdBu/k4qL3fE07kxFIRdKAuQraS 5dFg== X-Gm-Message-State: AFuF++mYR6EWxxdgeDh4Qa6p0PDJiLb+DmtJ47F0VmSVvIWKeEr6L292 2wx4xoptGTA9SRpc/4AYYfVBK7bpItKVYDe+NSH0fqBL8Ot7/WpkP4piEzcl+NbFezmdVtT15Q= = X-Received: from ejbb16.prod.google.com ([2002:a17:906:30d0:b0:c29:3b60:12fd]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a17:906:2083:b0:c26:1649:47ba with SMTP id a640c23a62f3a-c26164956afmr846902566b.48.1788954956190; Wed, 09 Sep 2026 04:55:56 -0700 (PDT) Date: Wed, 9 Sep 2026 13:55:32 +0200 In-Reply-To: <20260909115530.1924665-12-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260909115530.1924665-12-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=2537; i=ardb@kernel.org; h=from:subject; bh=jHiqT7EJ3nijNDYj+fN+c7L8/vUmjy+4wIUAjyL6m/c=; b=owGbwMvMwCVmkMcZplerG8N4Wi2JIWuhp4kAjx6TWD23a7nuIsmEa/eN34avUfQz3relLKGfP 9f10oWOUhYGMS4GWTFFFoHZf9/tPD1RqtZ5lizMHFYmkCEMXJwCcJOZGP4pdZRman658sWTM2a7 uvm+3sCXUoVx5hcMbojIf1A+ePcsw18xGUH724VXPkrt87lzTs8t+pXXJl5FIaaq/Lu5iR8m9XI CAA== X-Mailer: git-send-email 2.55.0.1003.g10538fe699-goog Message-ID: <20260909115530.1924665-13-ardb+git@google.com> Subject: [PATCH v2 01/10] x86/boot: Drop pointless re-implementation of panic() From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Vincent Mailhol , x86@kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ard Biesheuvel The decompressor has its own implementation of panic(), which is based on the vsnprintf() routine provided by the EFI stub. Relying on the EFI stub from code that does not execute in the context of the EFI boot services is a bad idea. It is also completely pointless in this case, given that the only user of this version of panic() only passes a compile time constant string, without any printf conversions. So use error() instead of panic() in that case, and drop the panic() implementation entirely. This is needed so that the EFI stub's vsnprintf() can be modified in a manner that is incompatible with the expectations of this caller. Signed-off-by: Ard Biesheuvel Acked-by: Kiryl Shutsemau (Meta) --- arch/x86/boot/compressed/error.c | 19 ------------------- arch/x86/boot/compressed/error.h | 1 - arch/x86/boot/compressed/mem.c | 2 +- 3 files changed, 1 insertion(+), 21 deletions(-) diff --git a/arch/x86/boot/compressed/error.c b/arch/x86/boot/compressed/er= ror.c index 19a8251de506..ce5ed7d8265e 100644 --- a/arch/x86/boot/compressed/error.c +++ b/arch/x86/boot/compressed/error.c @@ -22,22 +22,3 @@ void error(char *m) while (1) asm("hlt"); } - -/* EFI libstub provides vsnprintf() */ -#ifdef CONFIG_EFI_STUB -void panic(const char *fmt, ...) -{ - static char buf[1024]; - va_list args; - int len; - - va_start(args, fmt); - len =3D vsnprintf(buf, sizeof(buf), fmt, args); - va_end(args); - - if (len && buf[len - 1] =3D=3D '\n') - buf[len - 1] =3D '\0'; - - error(buf); -} -#endif diff --git a/arch/x86/boot/compressed/error.h b/arch/x86/boot/compressed/er= ror.h index 31f9e080d61a..87062dea9a20 100644 --- a/arch/x86/boot/compressed/error.h +++ b/arch/x86/boot/compressed/error.h @@ -6,6 +6,5 @@ =20 void warn(const char *m); void error(char *m) __noreturn; -void panic(const char *fmt, ...) __noreturn __cold; =20 #endif /* BOOT_COMPRESSED_ERROR_H */ diff --git a/arch/x86/boot/compressed/mem.c b/arch/x86/boot/compressed/mem.c index 0e9f84ab4bdc..e1c017b55184 100644 --- a/arch/x86/boot/compressed/mem.c +++ b/arch/x86/boot/compressed/mem.c @@ -37,7 +37,7 @@ void arch_accept_memory(phys_addr_t start, phys_addr_t en= d) /* Platform-specific memory-acceptance call goes here */ if (early_is_tdx_guest()) { if (!tdx_accept_memory(start, end)) - panic("TDX: Failed to accept memory\n"); + error("TDX: Failed to accept memory\n"); } else if (early_is_sevsnp_guest()) { snp_accept_memory(start, end); } else { --=20 2.55.0.1003.g10538fe699-goog From nobody Fri Sep 25 19:13:36 2026 Received: from mail-ed1-f72.google.com (mail-ed1-f72.google.com [209.85.208.72]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 607B554DACA for ; Wed, 9 Sep 2026 11:55:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.72 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954961; cv=none; b=Mbs9cGgc/7iheZVEAYQG7kKgsnUp4lZ7jHG6+3EHauhkmwmWTxv80XOAfK6Lsnxy9/4PFXhuWJ54QFeRhn3Dbte4nySiUcphxwToXDEXDkXUt3vFFSI3AtAnTzsKe+2HVnMoWqIC6wJmwJpdGq8Pn8OZ9uKaGhuK4eK1HAgMgl8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954961; c=relaxed/simple; bh=IdKBvI7mqdasCvjDRpPew5rCar4w3KM52tqCqnCnNoQ=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=AACYLgZI9371jMWKn/8JAKPgxT16mpiXBWEQx4Ht2kJJQLt3MJvDida/pQVAw90aEHGsIMbUUTcQiR/ZQIo9U/50S/tOL2AycWTC0Vm+NgJQj8lYudTSCZTDRV+4+quXZ74hP36QgYwYe/SV1NAFI7db9Bo2PphAhth1+0bpwD0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=QUA2wCfa; arc=none smtp.client-ip=209.85.208.72 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="QUA2wCfa" Received: by mail-ed1-f72.google.com with SMTP id 4fb4d7f45d1cf-6a677b003aaso1676805a12.1 for ; Wed, 09 Sep 2026 04:55:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788954957; x=1789559757; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=DJhrVBAWrexjqr5iinpdHbX84bROtKiyiiaiXCWB80M=; b=QUA2wCfaTNa6lQGgdS53rxkqbZKPtAYPDTn4ij3pvkmsv10S6SW/p1PlFrF3JO02j7 r+DGqTI6GGnLw5qp5YpoohilAgTZ6V0HUMX6bhjp1Mbd6/TEKKCOg3tk5CJEpWYafrjp euUopM/+nRYtalEWx0sE7gasZCM1dw+053gGiI9NcGMpiWJxvf3LlG102JR5aEEOhX9u fUEhFCAc7hDsi3HnSr83qiAmTVF8W78tta+fz450mI98H74yPCW5g8FUs4DetiHFFXas hYzBgDPHY6adVu9zNF9FOtwgOyKGz06bJ4y7gdH8EkKOToe5MGye6NC299yzx9Wp/g47 r72A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788954957; x=1789559757; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=DJhrVBAWrexjqr5iinpdHbX84bROtKiyiiaiXCWB80M=; b=ixjMRqeRkmF7YNITw+WumgmqYj9gWoCVwEfwyU4yoA6jul7fPdVrs0q3iCwJoCCtDy dnifCn41A/iJjwRqp5+EDNBzy0Fi1XumBBPUB+TSjvCpeIEcnZhAlnS9of8py6zut/ip 2RDe/1JWUxaQzLyI0op1kAeG6JkeKnR5xTHSx3pd7PeH5acC0uPhSgsRWEoS39h9zBFJ vvJo4MS6Rx466rEH/IdrdHRX0onDuRSqtybq1aVpWdg7Qx7SZ07XXrZiz5TzHfx0Z5h0 5u7chw2kJYpnTWjKtWqQvDYUnHnwvxSDYB+Er9x+/Aw9fJlHCBEeVr5a9Sm4iQJEKDPH H3FA== X-Gm-Message-State: AFuF++n0suL1axexa/En74Ik7Pwyf3kVYYYPiJ9mZp54H2FXh5uU3ZoM HbtBfXCs6hFH0UY7gk8YNrNa8SSk5/H6+8E+6j1JlkLfwUU0NZ8KOjCLSTpJnliYNNlpCspQRw= = X-Received: from edvj18.prod.google.com ([2002:aa7:de92:0:b0:6a8:5f9:b58f]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6402:3783:b0:6a6:92ca:40a4 with SMTP id 4fb4d7f45d1cf-6a696aa6121mr14983854a12.11.1788954957196; Wed, 09 Sep 2026 04:55:57 -0700 (PDT) Date: Wed, 9 Sep 2026 13:55:33 +0200 In-Reply-To: <20260909115530.1924665-12-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260909115530.1924665-12-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=873; i=ardb@kernel.org; h=from:subject; bh=DCPAKHSt1MvEF3l2OCYFuyQlxzeVLTEHo6sm95Z+hIo=; b=owGbwMvMwCVmkMcZplerG8N4Wi2JIWuhp+lUMQbN/zXyXlMZ8hNW/ZbrPxhsJv0xLfqpfZqW8 EqJLqaOUhYGMS4GWTFFFoHZf9/tPD1RqtZ5lizMHFYmkCEMXJwCMBEXKUaGielucQauXj8Cfqqs 5C85ZO5hrtlSVm6mJx1l/vuV9tEYhv/RO8/sTCq0itBw2awhH9wRHnOkabmeyAN2idRi0/2X2Bg B X-Mailer: git-send-email 2.55.0.1003.g10538fe699-goog Message-ID: <20260909115530.1924665-14-ardb+git@google.com> Subject: [PATCH v2 02/10] lib/ucs2_string: Drop arbitrary input size limit and associated WARN() From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Vincent Mailhol , x86@kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ard Biesheuvel It's not really the job of library code to WARN and potentially bring down the system (with panic_on_warn=3D1) on a condition that is fairly arbitrary to begin with. So drop the WARN_ON_ONCE() as well as the condition from ucs2_strscpy(). Signed-off-by: Ard Biesheuvel --- lib/ucs2_string.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/ucs2_string.c b/lib/ucs2_string.c index 1f7dd4eb640a..d66fef9c9b81 100644 --- a/lib/ucs2_string.c +++ b/lib/ucs2_string.c @@ -57,7 +57,7 @@ ssize_t ucs2_strscpy(ucs2_char_t *dst, const ucs2_char_t = *src, size_t count) * Ensure that we have a valid amount of space. We need to store at * least one NUL-character. */ - if (count =3D=3D 0 || WARN_ON_ONCE(count > INT_MAX / sizeof(*dst))) + if (count =3D=3D 0) return -E2BIG; =20 /* --=20 2.55.0.1003.g10538fe699-goog From nobody Fri Sep 25 19:13:36 2026 Received: from mail-ed1-f69.google.com (mail-ed1-f69.google.com [209.85.208.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3329C54DAD4 for ; Wed, 9 Sep 2026 11:56:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.69 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954962; cv=none; b=AcPufm2Z/e4kr37DAbPtlHSN17MaOWlxHU/Etrk3uRIcggPVhb/sJAYZqoi7cBdd9ms6Xw5ixnZWA8+xt0b7ES9kHm5EJGuTRhouUJOQtucWzYz8M/nTqFG7IYKRexYtwVazAcvpHZJR1kYEW2g3cgcJL8xCX/OaF6v4FwCb2DQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954962; c=relaxed/simple; bh=tcpQtPG1LqjWHQcdYdyBj3c6VFVNWxy+XZ+d+QXhJr4=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=FmU49roPeSae983o+bCN0gP2U4jINOGQiHAG2EZIGZrDk4kc6wj4mnSmc98T5d+EPVjIhVwciyGSp0Ja1Zjt1a/3he5iD6mfXD0LLuubm/dC6MLWUuF6HNoqaEXy73fbm9P1PdPIpx/uQPogymFPuo6GqNKJglRZESQqYx649vA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=AGES0Dby; arc=none smtp.client-ip=209.85.208.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="AGES0Dby" Received: by mail-ed1-f69.google.com with SMTP id 4fb4d7f45d1cf-6a57aa07476so6013539a12.3 for ; Wed, 09 Sep 2026 04:56:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788954958; x=1789559758; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Pd/4A8F8XRZbl4sQpabJjlKenkBbaEXlaZ5AQnmnAzk=; b=AGES0DbySFOzYybzmCWoEYhXnbGh5GuQ5vOHFKZhk9Y20YlXe97iaXOvrXwycocnIL 7+U5LU4ct+AWZKk+JRR8+o+CyMIxxn1l4X/6ERfr1722W78ynJXk5tqzKWc/Fvs/p6sX mWcrcZ6EtwaoIdQ/VFsPUsBaHVpi7cV859RB+1WN3ysTYQmXSmXxdiIFN/Zw4KKnF1e9 zTiJhzUbcZIXD/0gnvVV8yU3kSRDVh9BRrJmy0h7gmLJdELJ1yaxAijlgyOphx94yWhz CTRYdEL88uDrvUh3vwg/gWtp1rAkMTB30LpG7K34btRLV6/ThvxiKW10AOmXkDLe/I/W LXqg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788954958; x=1789559758; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Pd/4A8F8XRZbl4sQpabJjlKenkBbaEXlaZ5AQnmnAzk=; b=Mn4o9uP+/6VmZqvBr6cCnwRE3ACGxpG9zz84oPJVlzNcCAp5tjn8MDtBaBESv2G3CI atmw5XiGhy+NDgllKe/ffUEVCNw0c8eGclhjAP25SJ3wsQk7aJVRK7NmKOr0IN2GP2IN 8XPFg9ual3H6M5disDkMzWGJOkQ0ZrH2krCN/PggEAhU8bVkyhBXAM17EaDikyTT0d5z 65rEzfTjnmXtUXrXhDb6qImIzholwSMzFa9/0FWsPGN13W3wmmYwHH1//XPHqAfsGfwO bnqh9FlOn1eshJNoCR4t61GTymct4qpdrMXBU+rHGV84I71OsD/NQOmq7uBNDwQYlcGI RRTw== X-Gm-Message-State: AFuF++lvLL4BJXhFVfxd/pZmo9a3R9YG8uvzh5zzYEjOqJ/iC7UpPmDa 5nUSF7he/pect5ct/4g6TsJeckQWdXQwnLYaIINQDZl9os3rJUKR4q2uIcIHGhc5/ASPf2J8vA= = X-Received: from edvf14.prod.google.com ([2002:a05:6402:160e:b0:6a8:210f:72ce]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6402:27ce:b0:6a6:7882:89f2 with SMTP id 4fb4d7f45d1cf-6a7e8f9623cmr12327207a12.17.1788954958326; Wed, 09 Sep 2026 04:55:58 -0700 (PDT) Date: Wed, 9 Sep 2026 13:55:34 +0200 In-Reply-To: <20260909115530.1924665-12-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260909115530.1924665-12-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=705; i=ardb@kernel.org; h=from:subject; bh=/LdgSZFzZjtYA02calFNa+IAiCgEi1RyLw02qhfaQIg=; b=owGbwMvMwCVmkMcZplerG8N4Wi2JIWuhp9nb/j1SGZxHnZ6Ln7iTX91mUVK8sXuaeKjllpfbd /yU5ajsKGVhEONikBVTZBGY/ffdztMTpWqdZ8nCzGFlAhnCwMUpABNZWs3wV7j6vcbHsJrQ5q15 c5f/FQsIapx6UzLj0R9F4xdNG0UiWBl+s3TMWFXpkMNsEWGzqnxllszBua//2d8y4V7zd/WmSYW TmAA= X-Mailer: git-send-email 2.55.0.1003.g10538fe699-goog Message-ID: <20260909115530.1924665-15-ardb+git@google.com> Subject: [PATCH v2 03/10] lib/ucs2_string: Suppress modinfo when __DISABLE_EXPORTS is set From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Vincent Mailhol , x86@kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ard Biesheuvel Allow the UCS-2 string library to be reused in the EFI stub, by suppressing the modinfo data that is usually emitted so that the library can be built as a module. Signed-off-by: Ard Biesheuvel --- lib/ucs2_string.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/lib/ucs2_string.c b/lib/ucs2_string.c index d66fef9c9b81..f75fb4f7961a 100644 --- a/lib/ucs2_string.c +++ b/lib/ucs2_string.c @@ -165,5 +165,7 @@ ucs2_as_utf8(u8 *dest, const ucs2_char_t *src, unsigned= long maxlength) } EXPORT_SYMBOL(ucs2_as_utf8); =20 +#ifndef __DISABLE_EXPORTS MODULE_DESCRIPTION("UCS2 string handling"); MODULE_LICENSE("GPL v2"); +#endif --=20 2.55.0.1003.g10538fe699-goog From nobody Fri Sep 25 19:13:36 2026 Received: from mail-wm1-f70.google.com (mail-wm1-f70.google.com [209.85.128.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B024B54DACD for ; Wed, 9 Sep 2026 11:56:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.70 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954963; cv=none; b=fIlctKGJc9SyUROgOIWXu+qZn23I7fgCLXeeEnTpCRz8AEILwRQxDITBFeOZF8vDJUnKHcHcguYwzIeYHorOSBgvXvqpmCbdgykioJbMrz3wA97oGClky4nU2F8Dl/MYDzJdZ3PsvSB098mVatuwexNoZt+sOxQb8bxTI8lamOg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954963; c=relaxed/simple; bh=X6rSS2Ud/nPCzc6nAeL1YpQCFMZ1iQCr+SIHwWuezlI=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=k5Fnz8j83hrG/3uembFGUqWPliOvL9HYRvG4eWtwideW2OhFrpLGp13pekoINPFsf4Rxx146K6MfvZprieRbsgtcqYzDoaMlNL01KKXNWsekt9f3rhZ+AVaPq29u2s3L4xZqCksPHo6Ow1N93FtbR7POZ5h6wJGtWmCM5QrhbqA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=Ilu7rR+V; arc=none smtp.client-ip=209.85.128.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="Ilu7rR+V" Received: by mail-wm1-f70.google.com with SMTP id 5b1f17b1804b1-4957287363bso45648935e9.0 for ; Wed, 09 Sep 2026 04:56:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788954960; x=1789559760; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=SJt8ZcdZG9yVISY4f4k7yj08nGsSFwJkPsldz9PZDh0=; b=Ilu7rR+VTURlTU0BhiSVcrdfrxklIcawRizCNO+M3rEW46QRMfKhMMqxu/s9ID5ome cyAktLjoG2DL6Rw512DVnyL9ogUUYvQoDXo2hZqe4BRUkVlc73KHSBSJem13eo7KT9J/ +6X/PexOwbtW3I/y+6ORQwVN6MNIOkQUDA5/eiymJQfFvi5YY2Uc7MEAspi2eWkpwJiP hbAPFhST4MADQbfJ+nmhx4XrTwHeCPWBa2roEffeCoD2kbwYC7b7h/iPTZPzt3pAl1RT 3oFyVCUsCaluGn9CErxm0WVhEOWYfqP4vBYl9zeJASNgw+4XSHu0MnUd2JgOTmbRzrVu TqFQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788954960; x=1789559760; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=SJt8ZcdZG9yVISY4f4k7yj08nGsSFwJkPsldz9PZDh0=; b=hk+1dPrZxBDRjbJ9Yb1JsfUO0kHFT+vq3x30uFYZJOFfBlRTeiY3EJnymXLJD/q+py LOQZ9gbY+mWvnPWgcOd9GFcK88T6y5xx42PaEQpRRAJ3jVBri7XVYWc0J3UZjgnlPLpL NUpU9o1CVxSJOCEwT5SCRL5XcyY1DuYwEGXCNOqhECy0MXTTRsCmftblbn23qwAGPooX I/mFI/941hjfwsM0SIYKf7en2sHXhh4EcmiAFGFJEkSmEBv1hOBO84MbRCKnhYHpBnEz h2jWzpJ2WTzhtxhXr48IYN37Ew4xdrk6TF8pP2Faa9t/DdFUdLdgxdLbQJdrhJ5/dRXi 45iQ== X-Gm-Message-State: AFuF++nri1sO3tqb6AI6kH5cXYaBcVD6h9maymMK6XA7QQHNQzg02n43 ip2mZfqlose2f89J5gBV6myc8fNIftiGL4zK2Kp1bqNeh2FTU5mdJxz03ar2qKcwZJjsjendkw= = X-Received: from wmpm28.prod.google.com ([2002:a05:600c:91c:b0:49b:90c7:d488]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600d:8446:20b0:49c:fc7a:22d5 with SMTP id 5b1f17b1804b1-49cfc7a2342mr240560935e9.4.1788954959579; Wed, 09 Sep 2026 04:55:59 -0700 (PDT) Date: Wed, 9 Sep 2026 13:55:35 +0200 In-Reply-To: <20260909115530.1924665-12-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260909115530.1924665-12-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=2725; i=ardb@kernel.org; h=from:subject; bh=Ou0gz9BnagvIIpYFujImcdi2acgBEwyYNpUmbejvkVs=; b=owGbwMvMwCVmkMcZplerG8N4Wi2JIWuhp7lEzXwPlyTBkm0iYjZr2H+vW18zZZvVGvVJUpcXV VbEr2rvKGVhEONikBVTZBGY/ffdztMTpWqdZ8nCzGFlAhnCwMUpABPh3M7I8KKdpf9BxcSO5kfm k/UqPl7jePvD49q/K0Jed5cYn2gKNGdkeNkjpz9B4Oy2yys+/HxS0RWQXjcv2SJxipU5Y96nuQs 2sQAA X-Mailer: git-send-email 2.55.0.1003.g10538fe699-goog Message-ID: <20260909115530.1924665-16-ardb+git@google.com> Subject: [PATCH v2 04/10] lib/ucs2_string: Split out ucs2_as_utf8_l() taking a separate limit From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Vincent Mailhol , x86@kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ard Biesheuvel ucs2_as_utf() takes a maxlength argument, which specifies how many bytes the function is permitted to store into the destination buffer. The same value is used as an upper bound for the ucs2_strnlen() invocation, which is reasonable in the general case, as each UCS-2 character produces at least one byte of UTF-8 output, and so there is never a need to process more than 'maxlength' UCS-2 characters. However, if the UCS-2 string is not NUL terminated, ucs2_strnlen() may read past the end of the buffer if 'maxlength' is set to a high value. Current callers pass UCS-2 strings that are expected to be NUL terminated, but for processing the load options in the EFI stub, a version is needed that takes a separate limit argument. So split that off from the current implementation. Signed-off-by: Ard Biesheuvel --- include/linux/ucs2_string.h | 11 ++++++++++- lib/ucs2_string.c | 6 +++--- 2 files changed, 13 insertions(+), 4 deletions(-) diff --git a/include/linux/ucs2_string.h b/include/linux/ucs2_string.h index c499ae809c7d..74f23ca5a967 100644 --- a/include/linux/ucs2_string.h +++ b/include/linux/ucs2_string.h @@ -14,7 +14,16 @@ ssize_t ucs2_strscpy(ucs2_char_t *dst, const ucs2_char_t= *src, size_t count); int ucs2_strncmp(const ucs2_char_t *a, const ucs2_char_t *b, size_t len); =20 unsigned long ucs2_utf8size(const ucs2_char_t *src); +unsigned long +ucs2_as_utf8_l(u8 *dest, const ucs2_char_t *src, unsigned long limit, + unsigned long maxlength); + +static inline unsigned long ucs2_as_utf8(u8 *dest, const ucs2_char_t *src, - unsigned long maxlength); + unsigned long maxlength) +{ + return ucs2_as_utf8_l(dest, src, ucs2_strnlen(src, maxlength), + maxlength); +} =20 #endif /* _LINUX_UCS2_STRING_H_ */ diff --git a/lib/ucs2_string.c b/lib/ucs2_string.c index f75fb4f7961a..2df9bef79eea 100644 --- a/lib/ucs2_string.c +++ b/lib/ucs2_string.c @@ -132,11 +132,11 @@ EXPORT_SYMBOL(ucs2_utf8size); * final NUL character. */ unsigned long -ucs2_as_utf8(u8 *dest, const ucs2_char_t *src, unsigned long maxlength) +ucs2_as_utf8_l(u8 *dest, const ucs2_char_t *src, unsigned long limit, + unsigned long maxlength) { unsigned int i; unsigned long j =3D 0; - unsigned long limit =3D ucs2_strnlen(src, maxlength); =20 for (i =3D 0; maxlength && i < limit; i++) { u16 c =3D src[i]; @@ -163,7 +163,7 @@ ucs2_as_utf8(u8 *dest, const ucs2_char_t *src, unsigned= long maxlength) dest[j] =3D '\0'; return j; } -EXPORT_SYMBOL(ucs2_as_utf8); +EXPORT_SYMBOL(ucs2_as_utf8_l); =20 #ifndef __DISABLE_EXPORTS MODULE_DESCRIPTION("UCS2 string handling"); --=20 2.55.0.1003.g10538fe699-goog From nobody Fri Sep 25 19:13:36 2026 Received: from mail-wm1-f72.google.com (mail-wm1-f72.google.com [209.85.128.72]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0904B54EEC7 for ; Wed, 9 Sep 2026 11:56:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.72 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954964; cv=none; b=ZX/yN/Gzi7WNU8wYvu8ivcJmHUOR3xzIukdslRPx/12f8NfaSyFYPFIRjK7EQGEXBBctIYqsVWs4ZzOGrO6S0+JA0mEqEE/BDTZ+E3TEGlhTARh9JjciNjIaVUc8Yk30pZXJVSqO7s4s5yTqpoRuBVqp/QDgs9T6Lda6hN0zqXc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954964; c=relaxed/simple; bh=ku20SOigH8CJ8SYKLPGcw9FWogCbCHali0pAF7pIo/Y=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=dt8yJuUzRXmNGZQhSReef3oQ6EAOjvesuhcXEShrFk7Upkyb4Bi/3c3kUCLDGonsNY3qxKPHRgz5frL+mQHoVzxZhrqQCf4sfk7WBgoGfP3D8nTaW7trHmXNfVKwU2jOmQHWA42YXdfUyEoFDmBpPSQG8En/rFoupCAyO3ApDhY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=Xb0iYXJA; arc=none smtp.client-ip=209.85.128.72 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="Xb0iYXJA" Received: by mail-wm1-f72.google.com with SMTP id 5b1f17b1804b1-4994cf6cdb9so41229995e9.3 for ; Wed, 09 Sep 2026 04:56:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788954961; x=1789559761; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=5sXaakZK3FdjYjcilMqr9ZDO21ZR7yjsXqS533qtI9o=; b=Xb0iYXJARnEJ7HWqHHH+ipsAY67B4Ls/3RYgkGowGlG12VLtWNOw9ziSTYCQ1NvABh Qzm+rGPN8Ej4T0PTb/pSOgmNHjrzRHobW/4Oc75oXGtbXdlyFT5R7/VpgiDp8TBQnOyy lfrpFIWvd93SpuQx1OTOsMxwg3X9RdLI9BThyXpz+PTe+hatLxzI3oP8SIp6OzNXIjln cWgXy6XUf/0YxSPEhucj6fH3F65hMc7GGcap49ySivwjR+hav2MvDHH8U6dFsgsKg1cO xpcsfTDCRaE/cC89/4LxLExBb59SCu0WMUH6icvXhoSSx9KKv/4mYuur3SJeo3qihrFa FFsw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788954961; x=1789559761; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=5sXaakZK3FdjYjcilMqr9ZDO21ZR7yjsXqS533qtI9o=; b=gzbnTE/72cbhCixez0/4aEiPI+U0buVgo6cuUVVVPapNWvpMzR+ba3j8OwfUQQhnt9 eltg5DsIIstxEfFLFxw597bTMedIXtxEKgMhavR6aMkn310q5O4v9sg/ZQVMGNFpfCTf 7Wq1O5aFzGWgMbHeLHuQpb7RQpvJgfTPy1sPWzxGGZ8va0eJluVs1EGh3oOCl5HC4Ur1 Dxz+abZ28ki7hU10AAD5J2NpUiUTpl3/JmBtxbq3bWgzMC3i8gxZHqFz0ZEzvigFAnHp Mb44kLFhW1mcXe+/nJIHvUGvFbP4zGREL9OwIbwcSG1YDv7yItniQk6qBk5lfQHYnc9J C6Ww== X-Gm-Message-State: AFuF++lIh0w2cQACeZXbX87ucCrpC+V7VhGAxV3ka0/ReuTe7olXvIlf rpr3Xu4OJDu+FyIAELr6Wo02geetwpSUzk6DL1P30pgIyGVYBYzElJE2jHwb7VBrjMM08uFkOw= = X-Received: from wmoy23.prod.google.com ([2002:a05:600c:17d7:b0:49c:e6be:fb62]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:310e:b0:49c:fa21:1c84 with SMTP id 5b1f17b1804b1-49cfa211ce7mr321466165e9.25.1788954960859; Wed, 09 Sep 2026 04:56:00 -0700 (PDT) Date: Wed, 9 Sep 2026 13:55:36 +0200 In-Reply-To: <20260909115530.1924665-12-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260909115530.1924665-12-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=6503; i=ardb@kernel.org; h=from:subject; bh=gKNtPYPXH1wWBdst62Gf5YPrCrwaAq8jBD0FshjFfRc=; b=owGbwMvMwCVmkMcZplerG8N4Wi2JIWuhp0VTtr6k0wK3FN6lU6v2HnJv+Jn/nKPoiezW/2uUZ asW3e/vKGVhEONikBVTZBGY/ffdztMTpWqdZ8nCzGFlAhnCwMUpABP5t5Xhn6HTsxaDWKMtD3Yf uzVLwpo1tHPJAa71nVU7dqdlfLD5ksnwP1W0N95y+7u5h+Sb/kZMSnxxLCyIr/ZijYWk+KTNItk i3AA= X-Mailer: git-send-email 2.55.0.1003.g10538fe699-goog Message-ID: <20260909115530.1924665-17-ardb+git@google.com> Subject: [PATCH v2 05/10] efi/libstub: Use ucs2_string library for UTF-16 to UTF-8 conversion From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Vincent Mailhol , x86@kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ard Biesheuvel Don't rely on sprintf() with a wide string conversion modifier to convert the command line from UTF-16 to UTF-8. Instead, use the existing ucs2 string library routine that does the same. Note that while UEFI claims support for UTF-16, in practice it ignores surrogate pairs entirely, and so the simplified UCS-2 character set (where each character takes up exactly 2 bytes) is sufficient here. This removes the only user of sprintf() in the EFI stub, so drop that function as well. Since boot memory is plentiful on UEFI systems, just establish a worst case upper bound for the size of the buffer (which can never exceed COMMAND_LINE_SIZE), and allocate that first. Then, perform the conversion, and only fall back to processing the command line character by character if that resulted in truncation. This makes the common execution path much simpler. Signed-off-by: Ard Biesheuvel --- drivers/firmware/efi/libstub/Makefile | 3 +- drivers/firmware/efi/libstub/efi-stub-helper.c | 100 ++++++++------------ drivers/firmware/efi/libstub/vsprintf.c | 11 --- 3 files changed, 41 insertions(+), 73 deletions(-) diff --git a/drivers/firmware/efi/libstub/Makefile b/drivers/firmware/efi/l= ibstub/Makefile index 77a2b2d74f3f..12c0c7deb5cb 100644 --- a/drivers/firmware/efi/libstub/Makefile +++ b/drivers/firmware/efi/libstub/Makefile @@ -66,7 +66,8 @@ KBUILD_AFLAGS :=3D $(KBUILD_CFLAGS) -D__ASSEMBLY__ lib-y :=3D efi-stub-helper.o gop.o secureboot.o tpm.o \ file.o mem.o random.o randomalloc.o pci.o \ skip_spaces.o lib-cmdline.o lib-ctype.o \ - alignedmem.o printk.o vsprintf.o + alignedmem.o printk.o vsprintf.o \ + lib-ucs2_string.o =20 # include the stub's libfdt dependencies from lib/ when needed libfdt-deps :=3D fdt_rw.c fdt_ro.c fdt_wip.c fdt.c \ diff --git a/drivers/firmware/efi/libstub/efi-stub-helper.c b/drivers/firmw= are/efi/libstub/efi-stub-helper.c index f27f2e1f0019..4b51a0bf0e66 100644 --- a/drivers/firmware/efi/libstub/efi-stub-helper.c +++ b/drivers/firmware/efi/libstub/efi-stub-helper.c @@ -12,6 +12,7 @@ #include #include #include +#include #include #include =20 @@ -334,81 +335,58 @@ char *efi_convert_cmdline(efi_loaded_image_t *image) { const efi_char16_t *options =3D efi_table_attr(image, load_options); u32 options_size =3D efi_table_attr(image, load_options_size); - int options_bytes =3D 0, safe_options_bytes =3D 0; /* UTF-8 bytes */ - unsigned long cmdline_addr =3D 0; - const efi_char16_t *s2; - bool in_quote =3D false; + unsigned long options_chars =3D 0; + unsigned long cmdline_bytes; efi_status_t status; - u32 options_chars; + char *cmdline_addr; =20 if (options_size > 0) efi_measure_tagged_event((unsigned long)options, options_size, EFISTUB_EVT_LOAD_OPTIONS); =20 efi_apply_loadoptions_quirk((const void **)&options, &options_size); - options_chars =3D options_size / sizeof(efi_char16_t); - - if (options) { - s2 =3D options; - while (options_bytes < COMMAND_LINE_SIZE && options_chars--) { - efi_char16_t c =3D *s2++; - - if (c < 0x80) { - if (c =3D=3D L'\0' || c =3D=3D L'\n') - break; - if (c =3D=3D L'"') - in_quote =3D !in_quote; - else if (!in_quote && isspace((char)c)) - safe_options_bytes =3D options_bytes; - - options_bytes++; - continue; - } - - /* - * Get the number of UTF-8 bytes corresponding to a - * UTF-16 character. - * The first part handles everything in the BMP. - */ - options_bytes +=3D 2 + (c >=3D 0x800); - /* - * Add one more byte for valid surrogate pairs. Invalid - * surrogates will be replaced with 0xfffd and take up - * only 3 bytes. - */ - if ((c & 0xfc00) =3D=3D 0xd800) { - /* - * If the very last word is a high surrogate, - * we must ignore it since we can't access the - * low surrogate. - */ - if (!options_chars) { - options_bytes -=3D 3; - } else if ((*s2 & 0xfc00) =3D=3D 0xdc00) { - options_bytes++; - options_chars--; - s2++; - } - } - } - if (options_bytes >=3D COMMAND_LINE_SIZE) { - options_bytes =3D safe_options_bytes; - efi_err("Command line is too long: truncated to %d bytes\n", - options_bytes); - } - } + if (options) + options_chars =3D ucs2_strnlen(options, + options_size / sizeof(efi_char16_t)); =20 - options_bytes++; /* NUL termination */ + /* Each UCS-2 char takes up at most 3 UTF-8 bytes */ + cmdline_bytes =3D min(3 * options_chars, COMMAND_LINE_SIZE - 1) + 1; =20 - status =3D efi_bs_call(allocate_pool, EFI_LOADER_DATA, options_bytes, + status =3D efi_bs_call(allocate_pool, EFI_LOADER_DATA, cmdline_bytes, (void **)&cmdline_addr); if (status !=3D EFI_SUCCESS) return NULL; =20 - snprintf((char *)cmdline_addr, options_bytes, "%.*ls", - options_bytes - 1, options); + if (ucs2_as_utf8_l(cmdline_addr, options, options_chars, + cmdline_bytes) >=3D COMMAND_LINE_SIZE) { + /* + * The output fills up the entire buffer, and may have been + * truncated. This can only happen when options_bytes equals + * COMMAND_LINE_SIZE. + * + * Work backwards through the buffer to find a safe truncation + * point (i.e., a blank character not inside a quoted string). + */ + int safe_pos[2] =3D {}; + int in_quote =3D 0; + + for (int i =3D COMMAND_LINE_SIZE - 1; i >=3D 0; i--) { + char c =3D cmdline_addr[i]; + + if (!c) + return cmdline_addr; + else if (c =3D=3D '"') + in_quote ^=3D 1; + else if (!safe_pos[in_quote] && isspace(c)) + safe_pos[in_quote] =3D i; + } + + efi_err("Command line is too long: truncated to %d bytes\n", + safe_pos[in_quote]); + cmdline_addr[safe_pos[in_quote]] =3D '\0'; + } =20 - return (char *)cmdline_addr; + return cmdline_addr; } =20 /** diff --git a/drivers/firmware/efi/libstub/vsprintf.c b/drivers/firmware/efi= /libstub/vsprintf.c index 71c71c222346..dba136679172 100644 --- a/drivers/firmware/efi/libstub/vsprintf.c +++ b/drivers/firmware/efi/libstub/vsprintf.c @@ -551,14 +551,3 @@ int vsnprintf(char *buf, size_t size, const char *fmt,= va_list ap) =20 return pos; } - -int snprintf(char *buf, size_t size, const char *fmt, ...) -{ - va_list args; - int i; - - va_start(args, fmt); - i =3D vsnprintf(buf, size, fmt, args); - va_end(args); - return i; -} --=20 2.55.0.1003.g10538fe699-goog From nobody Fri Sep 25 19:13:36 2026 Received: from mail-wr1-f72.google.com (mail-wr1-f72.google.com [209.85.221.72]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 05C5054CF78 for ; Wed, 9 Sep 2026 11:56:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.72 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954965; cv=none; b=TJt5RamzFRq4Ogb2dH3+t29HPhegRMYsGLhpf1Lr+cVTeww1vroBrFFNjnOwIC7xYel7oLSEQr50qiRrp8aWuy/UP3p12pVPqjVNJSTetcE5hFRisfiC7/yueTCmMLv4pXz6MeHhWuRien+AobL7DEqWBteHuxlERjwzmzvfsYs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954965; c=relaxed/simple; bh=cpND4ajGQ4whtwDxApGKl+yItkF1v+76zOyXZudaCQc=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=ktt2WTRNSYQDb5MVkMSlyb1RC2gvINAY7lvMgXd2WV/xDf3c62yXAv5PIeIVodytfT/JwXoau2oEUIZgXNB6XD/hwjp3neNDiJFMt9ELF7lMddEHFrynfpA5hr/tu4PeGf/b+5F35/k9H12YKTK7fSX73Ktv2SfAvqGC3fPE/WQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=aCk3c5ON; arc=none smtp.client-ip=209.85.221.72 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="aCk3c5ON" Received: by mail-wr1-f72.google.com with SMTP id ffacd0b85a97d-485b0c83a89so382461f8f.2 for ; Wed, 09 Sep 2026 04:56:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788954962; x=1789559762; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=6YxIvPRsg58vNQqeM13M4GmviuEdPs+Gy7tCd4tfN1w=; b=aCk3c5ON9MrtmS3jNpv5QswjHT1lAwYhlxHoPQriKuqjQQM8ExT5AZmOiac8CQDpJG 1eVrKVPyxvgsXftSUIyl9kl4M0Hs/pwzgfxGm3XRQMoQairACl6gob3MPMnPpj+QIM8+ dR4O/lVh/Ha5qd3PrGsIo3IfRE/bFUByinuii++t/eX+3zH9QdDGbbAoD/aGyEUDebjm Z+vL1rm5qsTnN7E85d0fRhXsoyrlrHzJNFhyKg6Ns/CN5VVAkRxnNMFfSVtP+p14TINQ FqHgiKUe02oJr78/Ff7vpQpz7PgU+mQH7w3RK07cScXfMIap71Am5sudLj2v9pYow4nG OyxA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788954962; x=1789559762; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=6YxIvPRsg58vNQqeM13M4GmviuEdPs+Gy7tCd4tfN1w=; b=ZNIcGvx1JWxtjrKP8LTWAr9AVcXLAIyMDFH+09Tzu9W/uh7nCDlUUlm1piYY3yDT7E HDYkhFqgWjs0jUhVQC7Y+zLYBzVlK44hJ0GNFmi1scORt1KgrwzOkvMCeKoFyRTUNH+2 adzx0PazZWXpvregKW4z4GxeZ2QHBOk5nZpWVCgSQsHd5G3N7zQpo/zx+n35svn+33Cz 5G6bcegSywThvJWYXNWR/6hgZR0CZk3ReCdhK0OB4AU86LVWKd30PElYdaKMzvN/rRuI DOGFDDicLZtcF0+VXddIwN9H3g9Z8UjWb+65HYrzKvY1fEEybyf6Va6YfiKTGmbX4+pR LoNQ== X-Gm-Message-State: AFuF++kEtF6sRfoa/fsYD50e0U8O9soKJlO2HqyW1FzdzkwOdFg4Nya9 x17zvUZi6aLykWx2LvnzhzxdFq6PYkFzd1aUQ8aDOWljBSg8O15bN2V+irnbe10zzgnKommVsQ= = X-Received: from wrbfm8.prod.google.com ([2002:a05:6000:2808:b0:47f:552e:8614]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6000:240e:b0:485:8f9c:2879 with SMTP id ffacd0b85a97d-4858f9c29e1mr27912309f8f.6.1788954962028; Wed, 09 Sep 2026 04:56:02 -0700 (PDT) Date: Wed, 9 Sep 2026 13:55:37 +0200 In-Reply-To: <20260909115530.1924665-12-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260909115530.1924665-12-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=2167; i=ardb@kernel.org; h=from:subject; bh=7/E8aF0Htzhx3o/l045gN63OQScc68FeKEQViLjvVRA=; b=owGbwMvMwCVmkMcZplerG8N4Wi2JIWuhp6WIefaHhAn5NxbyCB5ROr8tXC40hfPXhNOCLWV3n rxZIC3VUcrCIMbFICumyCIw+++7nacnStU6z5KFmcPKBDKEgYtTACayK5KR4XCbo8/ba9XbF0cf +67/0dntxbwWmQfxkiWp+w01eHjUghn+Cl+wXXizl8s7fYr7/ITNYu/tg1ib6zPj7yRblPG5HnN jAgA= X-Mailer: git-send-email 2.55.0.1003.g10538fe699-goog Message-ID: <20260909115530.1924665-18-ardb+git@google.com> Subject: [PATCH v2 06/10] efi/libstub: Avoid efi_puts() for compile time constant strings From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Vincent Mailhol , x86@kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ard Biesheuvel efi_puts() performs a UTF-8 to UTF-16 conversion on its input, as the EFI console's native character set is UTF-16. This is pointless for compile time constant strings, since we can simply define those as UTF-16 to begin with. Note that efi_puts() also performs LF to CR-LF conversion, so this needs to be taken into account as well. Signed-off-by: Ard Biesheuvel --- drivers/firmware/efi/libstub/gop.c | 6 +++--- drivers/firmware/efi/libstub/printk.c | 4 ++-- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/drivers/firmware/efi/libstub/gop.c b/drivers/firmware/efi/libs= tub/gop.c index 80dc8cfeb33e..6919e28ba92b 100644 --- a/drivers/firmware/efi/libstub/gop.c +++ b/drivers/firmware/efi/libstub/gop.c @@ -309,12 +309,12 @@ static u32 choose_mode_list(efi_graphics_output_proto= col_t *gop) efi_status_t status; =20 efi_printk("Available graphics modes are 0-%u\n", max_mode-1); - efi_puts(" * =3D current mode\n" - " - =3D unusable mode\n"); + efi_char16_puts(L" * =3D current mode\r\n" + " - =3D unusable mode\r\n"); =20 choose_mode(gop, match_list, (void *)cur_mode); =20 - efi_puts("\nPress any key to continue (or wait 10 seconds)\n"); + efi_char16_puts(L"\r\nPress any key to continue (or wait 10 seconds)\r\n"= ); status =3D efi_wait_for_key(10 * EFI_USEC_PER_SEC, &key); if (status !=3D EFI_SUCCESS && status !=3D EFI_TIMEOUT) { efi_err("Unable to read key, continuing in 10 seconds\n"); diff --git a/drivers/firmware/efi/libstub/printk.c b/drivers/firmware/efi/l= ibstub/printk.c index bc599212c05d..f36639886d00 100644 --- a/drivers/firmware/efi/libstub/printk.c +++ b/drivers/firmware/efi/libstub/printk.c @@ -136,7 +136,7 @@ int efi_printk(const char *fmt, ...) return 0; =20 if (loglevel >=3D 0) - efi_puts("EFI stub: "); + efi_char16_puts(L"EFI stub: "); =20 fmt =3D printk_skip_level(fmt); =20 @@ -146,7 +146,7 @@ int efi_printk(const char *fmt, ...) =20 efi_puts(printf_buf); if (printed >=3D sizeof(printf_buf)) { - efi_puts("[Message truncated]\n"); + efi_char16_puts(L"[Message truncated]\r\n"); return -1; } =20 --=20 2.55.0.1003.g10538fe699-goog From nobody Fri Sep 25 19:13:36 2026 Received: from mail-wm1-f70.google.com (mail-wm1-f70.google.com [209.85.128.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D4B7D54EEBF for ; Wed, 9 Sep 2026 11:56:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.70 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954966; cv=none; b=KMoOmu/EswT0FL/rjMD0r3tMdR+5JyVYAPWO2Vklc7JxlMvc4WAUP/jl2hSOlFenSp1QUiwSl+S6cz2aDZsO/MUt9ilABMX3LN7TuK+xvGr5z8L7H203nN/JOlpOad92jH2XO4L8lotxrCyx6d48BFflFQjVywvYtXCgRFo94UQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954966; c=relaxed/simple; bh=Zwt0YiBEDCQK+Cormq85j9ZdjD4ex4uFhJdiF7GkcRo=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=rz5H2GuTEmKKpV350paNhsbszbOqKId10FDDsC5BOyicJUyv4I3wIizdDixkuN9CNulFNU6UQsN5qxOVCswO5NC5mmEKXngMv8HLD7LBNOOSAkdN+kRkPdelE5idkSaUkG7/qZvSDW/EhulwXgp1tVFMk6TC5xHi8fVhi2EczcA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=saGDrZBO; arc=none smtp.client-ip=209.85.128.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="saGDrZBO" Received: by mail-wm1-f70.google.com with SMTP id 5b1f17b1804b1-49d0ae342b9so28323405e9.1 for ; Wed, 09 Sep 2026 04:56:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788954963; x=1789559763; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=bSy3jB3blwxo3cqUryQeWVid+UYsufcubecd2NTDsjQ=; b=saGDrZBOKRzFfQqaDYSe5aceYEzMGQPICH+HEnqGggTBc1p1RywkHIpz3G2vwtrnRw oLDaQau8EIs83/1p1dbwEX7nhCalsX1Te0r8Ria6XHo6P+tqEqyBWY28hk09Y920CQ0W L+jAD4r8hTnjJrFQVKLrf2i08kAfNgrugqNgIPkYN0UupwsEV8HKHxw8csSkLL6YwaA6 v45g55ndGHTj1Xg3/SI0M7TtwSu8O3VwX1b8OHCCHN6espo9wF/SMWgVMDFtrAR4yBIi NDmy9azITPNgVXks5B9aUwr7sAwhgJ/47Faj3cMgRjKjBtGewQuiXPncBSwpLt/1EFxm iBsg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788954963; x=1789559763; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=bSy3jB3blwxo3cqUryQeWVid+UYsufcubecd2NTDsjQ=; b=ZdpOoaKAPl6LGmnsrJMpoSdgInEyzMB371uirz3jxGfeIt8jJbFBop9MaHwRfU2Yq0 vJYwOwjI69aT5A6WZq7qcrZg03v1gEGbRAy6fNoPr5V4mZaFfgD9uggXuuLwRYSMv3Qo crVh2LzWiEKiW7/4V4pb4tbo7TNB3UZ8ejiUfjmrTyoUAARVelJPRf0BenqXF+izJeBf 5nZxM8Iwnji2e6Jf+W2uRRLygQtwITmoVBL/V+RsM44ARYYQVqFjoGSdN+YwF81HdRwb BvqL/prF0r4Yq51Iy3EbP9O3E4mVXRE5lbkcyPegR878qw7UeOoNK3ovROWJdexuDgPw 6L/Q== X-Gm-Message-State: AFuF++nInaqLiLYbwd8gbpLsqdae/6IJtsSxJgp+MB6SLK2qstUbf+tr lWU0uuXq7vRk3OE7QeDr/xJ05OYKhENFqiVn/MC188qBoS6IRupjv33/CBnFIhslqtKQ2gBxjA= = X-Received: from wmbf17.prod.google.com ([2002:a05:600c:5951:b0:49d:23ae:8429]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:698c:b0:49c:fc6e:a3df with SMTP id 5b1f17b1804b1-49cfc6ea7camr340114115e9.30.1788954963023; Wed, 09 Sep 2026 04:56:03 -0700 (PDT) Date: Wed, 9 Sep 2026 13:55:38 +0200 In-Reply-To: <20260909115530.1924665-12-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260909115530.1924665-12-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=9530; i=ardb@kernel.org; h=from:subject; bh=PJF6hAVvzPDzaVpBjuHCyEhWK6Oza3jt1IYjY2Y611s=; b=owGbwMvMwCVmkMcZplerG8N4Wi2JIWuhp3Xr6ypumzZGg9IZMc+fyPz2P+3d/yDiygW5xvU1Y nVMDj4dpSwMYlwMsmKKLAKz/77beXqiVK3zLFmYOaxMIEMYuDgFYCJ6oYwMT2LX3M03azwV1igW sfjKpYuxzwy6F5h1lG62O3Yrql5jEiPDH++t4qorNiy6+crZzklRwll/V0C96r8LWjaWsyVaYza wAQA= X-Mailer: git-send-email 2.55.0.1003.g10538fe699-goog Message-ID: <20260909115530.1924665-19-ardb+git@google.com> Subject: [PATCH v2 07/10] efi/libstub: Output UTF-16 directly from vsnprintf() From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Vincent Mailhol , x86@kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ard Biesheuvel The only remaining users of vsnprintf() in the EFI stub are the diagnostic printk()'s, which are emitted to the console and not recorded for posterity. The EFI console uses UTF-16 (or actually, UCS-2) natively, and so all non-UTF16 strings that are emitted need to be converted. Given the stub's vsnprintf() support for wide strings (using the %ls conversion modifier), which uses UTF-16 to UTF-8 conversion internally, the final conversion to UTF-16 needs to support not just plain ASCII but UTF-8 as well. This is all pointless, of course, and it makes more sense to use UTF-16 internally. This removes the need for UTF-16 to UTF-8 conversion in vsnprintf(), and given that all non-wide string inputs to vsnprintf() that exist in the stub today are compile time constant ASCII strings, the need to convert UTF-8 to UTF-16 disappears as well. So implement efi_vsnprintf() taking a const char *fmt as before, but outputting a efi_char16_t[] that can be passed to the EFI console directly, rather than via efi_puts(), leaving the latter unused and therefore removed. Note that efi_puts() performs LF to CR-LF conversion internally, so add this capability to efi_vsnprintf() as well. Signed-off-by: Ard Biesheuvel --- drivers/firmware/efi/libstub/efistub.h | 5 +- drivers/firmware/efi/libstub/printk.c | 91 ++----------------- drivers/firmware/efi/libstub/vsprintf.c | 96 +++----------------- 3 files changed, 22 insertions(+), 170 deletions(-) diff --git a/drivers/firmware/efi/libstub/efistub.h b/drivers/firmware/efi/= libstub/efistub.h index fd91fc15ec81..36056c624782 100644 --- a/drivers/firmware/efi/libstub/efistub.h +++ b/drivers/firmware/efi/libstub/efistub.h @@ -1078,9 +1078,10 @@ efi_status_t check_platform_features(void); =20 void *get_efi_config_table(efi_guid_t guid); =20 -/* NOTE: These functions do not print a trailing newline after the string = */ void efi_char16_puts(efi_char16_t *); -void efi_puts(const char *str); + +int efi_vsnprintf(efi_char16_t *buf, size_t size, const char *fmt, va_list= ap, + bool crlf); =20 __printf(1, 2) int efi_printk(char const *fmt, ...); =20 diff --git a/drivers/firmware/efi/libstub/printk.c b/drivers/firmware/efi/l= ibstub/printk.c index f36639886d00..0a18cfe32528 100644 --- a/drivers/firmware/efi/libstub/printk.c +++ b/drivers/firmware/efi/libstub/printk.c @@ -23,98 +23,20 @@ void efi_char16_puts(efi_char16_t *str) output_string, str); } =20 -static -u32 utf8_to_utf32(const u8 **s8) -{ - u32 c32; - u8 c0, cx; - size_t clen, i; - - c0 =3D cx =3D *(*s8)++; - /* - * The position of the most-significant 0 bit gives us the length of - * a multi-octet encoding. - */ - for (clen =3D 0; cx & 0x80; ++clen) - cx <<=3D 1; - /* - * If the 0 bit is in position 8, this is a valid single-octet - * encoding. If the 0 bit is in position 7 or positions 1-3, the - * encoding is invalid. - * In either case, we just return the first octet. - */ - if (clen < 2 || clen > 4) - return c0; - /* Get the bits from the first octet. */ - c32 =3D cx >> clen--; - for (i =3D 0; i < clen; ++i) { - /* Trailing octets must have 10 in most significant bits. */ - cx =3D (*s8)[i] ^ 0x80; - if (cx & 0xc0) - return c0; - c32 =3D (c32 << 6) | cx; - } - /* - * Check for validity: - * - The character must be in the Unicode range. - * - It must not be a surrogate. - * - It must be encoded using the correct number of octets. - */ - if (c32 > 0x10ffff || - (c32 & 0xf800) =3D=3D 0xd800 || - clen !=3D (c32 >=3D 0x80) + (c32 >=3D 0x800) + (c32 >=3D 0x10000)) - return c0; - *s8 +=3D clen; - return c32; -} - -/** - * efi_puts() - Write a UTF-8 encoded string to the console - * @str: UTF-8 encoded string - */ -void efi_puts(const char *str) -{ - efi_char16_t buf[128]; - size_t pos =3D 0, lim =3D ARRAY_SIZE(buf); - const u8 *s8 =3D (const u8 *)str; - u32 c32; - - while (*s8) { - if (*s8 =3D=3D '\n') - buf[pos++] =3D L'\r'; - c32 =3D utf8_to_utf32(&s8); - if (c32 < 0x10000) { - /* Characters in plane 0 use a single word. */ - buf[pos++] =3D c32; - } else { - /* - * Characters in other planes encode into a surrogate - * pair. - */ - buf[pos++] =3D (0xd800 - (0x10000 >> 10)) + (c32 >> 10); - buf[pos++] =3D 0xdc00 + (c32 & 0x3ff); - } - if (*s8 =3D=3D '\0' || pos >=3D lim - 2) { - buf[pos] =3D L'\0'; - efi_char16_puts(buf); - pos =3D 0; - } - } -} - /** * efi_printk() - Print a kernel message * @fmt: format string * * The first letter of the format string is used to determine the logging = level * of the message. If the level is less then the current EFI logging level= , the - * message is suppressed. The message will be truncated to 255 bytes. + * message is suppressed. The message will be truncated to 255 characters + * (ignoring surrogates). * * Return: number of printed characters */ int efi_printk(const char *fmt, ...) { - char printf_buf[256]; + efi_char16_t printf_buf[256]; va_list args; int printed; int loglevel =3D printk_get_level(fmt); @@ -141,11 +63,12 @@ int efi_printk(const char *fmt, ...) fmt =3D printk_skip_level(fmt); =20 va_start(args, fmt); - printed =3D vsnprintf(printf_buf, sizeof(printf_buf), fmt, args); + printed =3D efi_vsnprintf(printf_buf, ARRAY_SIZE(printf_buf), fmt, args, + true); va_end(args); =20 - efi_puts(printf_buf); - if (printed >=3D sizeof(printf_buf)) { + efi_char16_puts(printf_buf); + if (printed >=3D ARRAY_SIZE(printf_buf)) { efi_char16_puts(L"[Message truncated]\r\n"); return -1; } diff --git a/drivers/firmware/efi/libstub/vsprintf.c b/drivers/firmware/efi= /libstub/vsprintf.c index dba136679172..bd32af6b4f4d 100644 --- a/drivers/firmware/efi/libstub/vsprintf.c +++ b/drivers/firmware/efi/libstub/vsprintf.c @@ -14,10 +14,14 @@ =20 #include #include +#include #include #include #include #include +#include + +#include "efistub.h" =20 static int skip_atoi(const char **s) @@ -239,58 +243,6 @@ char get_sign(long long *num, int flags) return 0; } =20 -static -size_t utf16s_utf8nlen(const u16 *s16, size_t maxlen) -{ - size_t len, clen; - - for (len =3D 0; len < maxlen && *s16; len +=3D clen) { - u16 c0 =3D *s16++; - - /* First, get the length for a BMP character */ - clen =3D 1 + (c0 >=3D 0x80) + (c0 >=3D 0x800); - if (len + clen > maxlen) - break; - /* - * If this is a high surrogate, and we're already at maxlen, we - * can't include the character if it's a valid surrogate pair. - * Avoid accessing one extra word just to check if it's valid - * or not. - */ - if ((c0 & 0xfc00) =3D=3D 0xd800) { - if (len + clen =3D=3D maxlen) - break; - if ((*s16 & 0xfc00) =3D=3D 0xdc00) { - ++s16; - ++clen; - } - } - } - - return len; -} - -static -u32 utf16_to_utf32(const u16 **s16) -{ - u16 c0, c1; - - c0 =3D *(*s16)++; - /* not a surrogate */ - if ((c0 & 0xf800) !=3D 0xd800) - return c0; - /* invalid: low surrogate instead of high */ - if (c0 & 0x0400) - return 0xfffd; - c1 =3D **s16; - /* invalid: missing low surrogate */ - if ((c1 & 0xfc00) !=3D 0xdc00) - return 0xfffd; - /* valid surrogate pair */ - ++(*s16); - return (0x10000 - (0xd800 << 10) - 0xdc00) + (c0 << 10) + c1; -} - #define PUTC(c) \ do { \ if (pos < size) \ @@ -298,7 +250,8 @@ do { \ ++pos; \ } while (0); =20 -int vsnprintf(char *buf, size_t size, const char *fmt, va_list ap) +int efi_vsnprintf(efi_char16_t *buf, size_t size, const char *fmt, va_list= ap, + bool crlf) { /* The maximum space required is to print a 64-bit number in octal */ char tmp[(sizeof(unsigned long long) * 8 + 2) / 3]; @@ -336,6 +289,8 @@ int vsnprintf(char *buf, size_t size, const char *fmt, = va_list ap) =20 for (pos =3D 0; *fmt; ++fmt) { if (*fmt !=3D '%' || *++fmt =3D=3D '%') { + if (crlf && *fmt =3D=3D '\n') + PUTC('\r'); PUTC(*fmt); continue; } @@ -400,7 +355,7 @@ int vsnprintf(char *buf, size_t size, const char *fmt, = va_list ap) else if (qualifier =3D=3D 'l') { wstring: flags |=3D WIDE; - precision =3D len =3D utf16s_utf8nlen((const u16 *)s, precision); + precision =3D len =3D ucs2_strnlen((const u16 *)s, precision); goto output; } precision =3D len =3D strnlen(s, precision); @@ -505,36 +460,9 @@ int vsnprintf(char *buf, size_t size, const char *fmt,= va_list ap) if (flags & WIDE) { const u16 *ws =3D (const u16 *)s; =20 - while (len-- > 0) { - u32 c32 =3D utf16_to_utf32(&ws); - u8 *s8; - size_t clen; - - if (c32 < 0x80) { - PUTC(c32); - continue; - } - - /* Number of trailing octets */ - clen =3D 1 + (c32 >=3D 0x800) + (c32 >=3D 0x10000); - - len -=3D clen; - s8 =3D (u8 *)&buf[pos]; - - /* Avoid writing partial character */ - PUTC('\0'); - pos +=3D clen; - if (pos >=3D size) - continue; - - /* Set high bits of leading octet */ - *s8 =3D (0xf00 >> 1) >> clen; - /* Write trailing octets in reverse order */ - for (s8 +=3D clen; clen; --clen, c32 >>=3D 6) - *s8-- =3D 0x80 | (c32 & 0x3f); - /* Set low bits of leading octet */ - *s8 |=3D c32; - } + if (pos < size) + memcpy(&buf[pos], ws, min(len, size - pos) * sizeof(*ws)); + pos +=3D len; } else { while (len-- > 0) PUTC(*s++); --=20 2.55.0.1003.g10538fe699-goog From nobody Fri Sep 25 19:13:36 2026 Received: from mail-wm1-f70.google.com (mail-wm1-f70.google.com [209.85.128.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 552B6550DBC for ; Wed, 9 Sep 2026 11:56:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.70 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954968; cv=none; b=TK+lL/jKRsjDgJc3EuCynesuWDt41xBdtz5Ug6eISAZxFDOXZAfct25K0utE+/GplCwXKjSWSsRBmL4nVTP1E28WzA73UYfKHf6Gyeo/oGSeSnwqTGe3aHTE21bT9qCP0lkKYuE4YpcTmodUJyAOUItrI9xBXTU9sNwg53/wm+g= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954968; c=relaxed/simple; bh=s1/82MTGgkzbBwlpgHOrnKNXWZF9hy81U2YebCpxGTs=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=IFLmTLB76zjd+QzXtBC95Gh39uxWV1QCJFetNUH8gKSnDkXZc6b6VkWrCk324dzEufHERQv5IyqxFVaF53We5DZemgBqo5vyZMd7rvOp01zx8G8a9DCagBmWAtksyNQRi0SZRC8grBTZtEA5o1VV5ClNKYJYiUn/80Kig4KTKbo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=BUnzup7m; arc=none smtp.client-ip=209.85.128.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="BUnzup7m" Received: by mail-wm1-f70.google.com with SMTP id 5b1f17b1804b1-49b8c651ac0so85270425e9.2 for ; Wed, 09 Sep 2026 04:56:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788954964; x=1789559764; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=UBQRet/chWy4OOOfuuDBVXfyuNkZdYYoGG6zjY0T2rg=; b=BUnzup7mbsF04KZhUQWvTvTiWgnFYf/1r0V8ZWK6fVKQ9JQh5kjhexDU0XQdg5D9Sa wy3xjqhkbw0yLL0aL9vM9Nd7BzaSGg+rZga5DDL2C4brjNQ3aQb5BLX0iw+6AKCLkjhu 6ml6cwZ0k+CWs4Vw6oskocg8wM2pNFeuvicb/jIxQbM+NaciVXvZcyxi3TYoTrRgg3Ci Jlke/9+U14tg72vU5NIy9IWRqWl3Qqq+9UNjAHmU+c9fSHIatUwvY8gEtCeCej1U+Xti 25me1c1qrGjXGsZ1F/PYaT2mZd9DKoIoeYd/Deyk6dFKiK0tCrxY3I70XHND4gOr+3ib lN6Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788954964; x=1789559764; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=UBQRet/chWy4OOOfuuDBVXfyuNkZdYYoGG6zjY0T2rg=; b=Xxp8E1u87QuGCzyM2U0qgrHPNW1Y6f1kxvSICE+FFgGrOLvzczBvOcqgKkHW3fTxLR Fcb9UUtm+/6RPAUp93Km3t/YWuqltV0QlIjl3xhlx138d8iyGl2NawkMF5cVY2SgAtPw ne6XFpL7Q+xBS3jKR9BBeS3xv15PuaA7FFcbgwiyFbT2oEznTYUi0/b9+PzQ6+BPtklJ Azx1ij21r1LitoTxfL0NbKFAHQJF9aVKx6URJzF4umN5Hg/8CU+GNndA0PefAOAo4qcl YDoV6ZLIRtFWbbRtesZSMmdxP+cdWo6LXzrvfdMCub2pOQIVs/r3Ye+w1rZKsWA1kWFj 345w== X-Gm-Message-State: AFuF++lBMIR9uF8lfRQivTUD1ZFUswD5WLAU2PpYByz0Y2mIj27x4T6u VYMJ7VCsSIJc2YOryJBQ0Yt9xl0jzOKkOwzWQTZgkU5JT21rSOLODP5gf5yZI6Q7RaEbD065dQ= = X-Received: from wmpm28.prod.google.com ([2002:a05:600c:91c:b0:49b:90c7:d488]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600d:848e:20b0:495:4d88:e630 with SMTP id 5b1f17b1804b1-49cf824f697mr252322075e9.10.1788954964312; Wed, 09 Sep 2026 04:56:04 -0700 (PDT) Date: Wed, 9 Sep 2026 13:55:39 +0200 In-Reply-To: <20260909115530.1924665-12-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260909115530.1924665-12-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=2963; i=ardb@kernel.org; h=from:subject; bh=8w5CNhvLDyt2eBYmWjMeec5mW8SnFbz6woyBTfjX6VE=; b=owGbwMvMwCVmkMcZplerG8N4Wi2JIWuhp42oXIilb4t0cMLbFZf8Kxgl1DcsT42/stbh08Xa4 +IFE3Z3lLIwiHExyIopsgjM/vtu5+mJUrXOs2Rh5rAygQxh4OIUgIkskGX4K+SWbvqo/xj7nZvC CUonHF7vtHzg8/pWxEomdQ976e/fjBgZOvNK+27s8vC6E3KIzWr9lh08h00vVKs1rJ77qdje9dh ubgA= X-Mailer: git-send-email 2.55.0.1003.g10538fe699-goog Message-ID: <20260909115530.1924665-20-ardb+git@google.com> Subject: [PATCH v2 08/10] efi/libstub: Add support for printing human readable GUIDs From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Vincent Mailhol , x86@kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ard Biesheuvel Add support for the %pUl printk conversion specifier, which takes a pointer to a GUID and prints it in the usual format: aaaaaaaa-bbbb-cccc-dddd-dddddddddddd Co-developed-by: Vincent Mailhol Signed-off-by: Vincent Mailhol Signed-off-by: Ard Biesheuvel --- drivers/firmware/efi/libstub/vsprintf.c | 40 +++++++++++++++++--- 1 file changed, 35 insertions(+), 5 deletions(-) diff --git a/drivers/firmware/efi/libstub/vsprintf.c b/drivers/firmware/efi= /libstub/vsprintf.c index bd32af6b4f4d..7f6b891a338a 100644 --- a/drivers/firmware/efi/libstub/vsprintf.c +++ b/drivers/firmware/efi/libstub/vsprintf.c @@ -113,6 +113,9 @@ char *put_dec(char *end, unsigned long long n) return p; } =20 +/* we are called with base 8, 10 or 16, only, thus don't need "G..." */ +static const char digits[16] =3D "0123456789ABCDEF"; /* "GHIJKLMNOPQRSTUVW= XYZ"; */ + static char *number(char *end, unsigned long long num, int base, char locase) { @@ -121,9 +124,6 @@ char *number(char *end, unsigned long long num, int bas= e, char locase) * produces same digits or (maybe lowercased) letters */ =20 - /* we are called with base 8, 10 or 16, only, thus don't need "G..." */ - static const char digits[16] =3D "0123456789ABCDEF"; /* "GHIJKLMNOPQRSTUV= WXYZ"; */ - switch (base) { case 10: if (num !=3D 0) @@ -144,6 +144,29 @@ char *number(char *end, unsigned long long num, int ba= se, char locase) return end; } =20 +static char *guid_to_str(const efi_guid_t *guid, char *out, char locase) +{ + static const u8 guid_index[UUID_SIZE] =3D { + 3, 2, 1, 0, 5, 4, 7, 6, 8, 9, 10, 11, 12, 13, 14, 15, + }; + + for (int i =3D 0, p =3D 0; i < ARRAY_SIZE(guid_index); i++) { + u8 byte =3D guid->b[guid_index[i]]; + + out[p++] =3D locase | digits[byte >> 4]; + out[p++] =3D locase | digits[byte & 0xf]; + + switch (i) { + case 3: + case 5: + case 7: + case 9: + out[p++] =3D '-'; + } + } + return out; +} + #define ZEROPAD 1 /* pad with zero */ #define SIGN 2 /* unsigned/signed long */ #define PLUS 4 /* show plus */ @@ -253,8 +276,7 @@ do { \ int efi_vsnprintf(efi_char16_t *buf, size_t size, const char *fmt, va_list= ap, bool crlf) { - /* The maximum space required is to print a 64-bit number in octal */ - char tmp[(sizeof(unsigned long long) * 8 + 2) / 3]; + char tmp[UUID_STRING_LEN]; char *tmp_end =3D &tmp[ARRAY_SIZE(tmp)]; long long num; int base; @@ -367,6 +389,14 @@ int efi_vsnprintf(efi_char16_t *buf, size_t size, cons= t char *fmt, va_list ap, break; =20 case 'p': + if (fmt[1] =3D=3D 'U' && (fmt[2] | 0x20) =3D=3D 'l') { + flags &=3D LEFT; + s =3D guid_to_str(va_arg(args, efi_guid_t *), tmp, fmt[2] & 0x20); + precision =3D len =3D UUID_STRING_LEN; + fmt +=3D 2; + goto output; + } + if (precision < 0) precision =3D 2 * sizeof(void *); fallthrough; --=20 2.55.0.1003.g10538fe699-goog From nobody Fri Sep 25 19:13:36 2026 Received: from mail-wm1-f70.google.com (mail-wm1-f70.google.com [209.85.128.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 60C445519A2 for ; Wed, 9 Sep 2026 11:56:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.70 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954969; cv=none; b=chSWI9iEnuTROxOFQNmNRYhfwDWTHSxU6a20vyUGlUNI1EPgyu8p8ofbCTX6JFYgYz0E3SgAdhFlBAlz3albwMij0FBFSovgWJVaUMijkx62TL0maFC3B+Xkpzhy8qXKZPcPhYAUqkURpTWzfECiV8f8sSjMjCdBeqzi7t++zAc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954969; c=relaxed/simple; bh=nApRI5xFcTlqGwc2l4tHLOqA5hh9r3n8CfsjMUrRmbg=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=A+22JWDPsilKE+jP8pOn8E/xx5oEK/IGIcaa2d4cgjSTni/YW7svKCds4JfCsnAizc45reIjiDkqHW+NtKsBUO7RCC0hvOZ1S/TM+aR3nqHVN2LLAIuomF72bz/Jy5U8+eVpPj8iXwDnJL4ayz1TnFC7vosAht7XLFKNLiW5kq8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=NBmoxH1l; arc=none smtp.client-ip=209.85.128.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="NBmoxH1l" Received: by mail-wm1-f70.google.com with SMTP id 5b1f17b1804b1-49d0ae342b9so28323795e9.1 for ; Wed, 09 Sep 2026 04:56:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788954966; x=1789559766; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=JN+BC6ry/kWEdgNANYcdxE9IvlLiYz9YH0i3KnXc+nw=; b=NBmoxH1lPwQv2yoL58DgLaAF+hHRmEg+UDjH463PwaZ0mBY8K1aayDy9P25fJkjVPJ p6/kFExO70+UqmnAP/VQiQpneNkTytxOu6fzYDJnAKBCzZnPrv9PO+0SNRGTjVT9WVCQ qJmSh0xh8Xvy3bnyrcSCNiFWLW8gQJr4dcZhfhCDWsB8u5MwQ3ZMvsF1GX1RmL87IjB1 bP0nx8VTP935fCHmMJyeStgiCAN2Pe42jioU+tIP8OTbhGLmZsidr+0yRm5/9VnvB02U /zC60Al2bzSZuICuxXR/tIte4KkjqqMCRSxsvrBqeLlMw3E/PfWoaHH+DQW+wNOhDQvF sTzQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788954966; x=1789559766; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=JN+BC6ry/kWEdgNANYcdxE9IvlLiYz9YH0i3KnXc+nw=; b=BBGIgYT80fxB9OEsaYe3rVlTkcEn+WIGkq0ioa7/WaRCkRSk/NocgCzz7lMYb082jF WQg3nfTZU1VM80ljS+2lBuVnyX1byKCyKyzf9XIvqfUD9OSm2G+yqwsDMW77KcCSHGep p62NNr6IsytScxZAYlJwKcL/ORwwWpJNl5aJb+nMIj3R0qsIxfsRxf2wrXH1nARDT/qV t0wMJr9dryaAjKKSPq29yRNMf/A929irnZJBh4wQjAgoLV4Yk8GZ3iDm3KC3k7eGjyHu wSHRN2LiUSxgHz8NDdPtGJUpElV2uESEr4l5wLvYGalcHdfIXWAE9oHsQxjs2Uiy40Gj 9Y6w== X-Gm-Message-State: AFuF++mF29DSKDQDqVjSxlzZsbeIbzcLJkXh0cDVSnLcezEp+PuUBBGP 106IPSTHxiKyQITeptR7WPeFtO5fg2/183Sb/dwW31TMFfeFvlTagtK4j1JPh7Y7OqIlroTbXw= = X-Received: from wrbeg6.prod.google.com ([2002:a05:6000:21c6:b0:484:4268:849d]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:3588:b0:49c:fc6e:a3d7 with SMTP id 5b1f17b1804b1-49cfc6ea7d5mr331543535e9.22.1788954965277; Wed, 09 Sep 2026 04:56:05 -0700 (PDT) Date: Wed, 9 Sep 2026 13:55:40 +0200 In-Reply-To: <20260909115530.1924665-12-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260909115530.1924665-12-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=1793; i=ardb@kernel.org; h=from:subject; bh=C2R/2A0OSQiIXep0It779ZTyIOZrKQNdvmBQDXeIiBI=; b=owGbwMvMwCVmkMcZplerG8N4Wi2JIWuhp23ijfCcE9c/PZhrVfi6P9rOP9qvNuGVVfVTDgb7g 1sNTvt2lLIwiHExyIopsgjM/vtu5+mJUrXOs2Rh5rAygQxh4OIUgIm0KDIyvLz1Vcp/nZVT7jHl WNkZgsyP4xue5cRWL2s5f33nxojEcwx/RQ9aFdfJbCl8p6sZ9vDAd9Zb4VGlK9rbeCXqF8t7crz kBwA= X-Mailer: git-send-email 2.55.0.1003.g10538fe699-goog Message-ID: <20260909115530.1924665-21-ardb+git@google.com> Subject: [PATCH v2 09/10] efi/libstub: Add efi_snprintf() to construct wide strings From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Vincent Mailhol , x86@kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ard Biesheuvel The native EFI character set is UTF-16 (or in practice, UCS-2). Implement efi_snprintf() to construct UTF-16 strings using printf style templates. This will be used in a subsequent patch to set the LoaderDevicePartUUID EFI variable. Link: https://lore.kernel.org/all/20260903-efi_stub_bli-v2-1-dbf7ba915117@k= ernel.org/ Signed-off-by: Ard Biesheuvel --- drivers/firmware/efi/libstub/efistub.h | 1 + drivers/firmware/efi/libstub/vsprintf.c | 11 +++++++++++ 2 files changed, 12 insertions(+) diff --git a/drivers/firmware/efi/libstub/efistub.h b/drivers/firmware/efi/= libstub/efistub.h index 36056c624782..880c1d0c464b 100644 --- a/drivers/firmware/efi/libstub/efistub.h +++ b/drivers/firmware/efi/libstub/efistub.h @@ -1084,6 +1084,7 @@ int efi_vsnprintf(efi_char16_t *buf, size_t size, con= st char *fmt, va_list ap, bool crlf); =20 __printf(1, 2) int efi_printk(char const *fmt, ...); +__printf(3, 4) int efi_snprintf(efi_char16_t *buf, size_t size, const char= *fmt, ...); =20 void efi_free(unsigned long size, unsigned long addr); DEFINE_FREE(efi_pool, void *, if (_T) efi_bs_call(free_pool, _T)); diff --git a/drivers/firmware/efi/libstub/vsprintf.c b/drivers/firmware/efi= /libstub/vsprintf.c index 7f6b891a338a..34a19495dace 100644 --- a/drivers/firmware/efi/libstub/vsprintf.c +++ b/drivers/firmware/efi/libstub/vsprintf.c @@ -509,3 +509,14 @@ int efi_vsnprintf(efi_char16_t *buf, size_t size, cons= t char *fmt, va_list ap, =20 return pos; } + +int efi_snprintf(efi_char16_t *buf, size_t size, const char *fmt, ...) +{ + va_list args; + int i; + + va_start(args, fmt); + i =3D efi_vsnprintf(buf, size, fmt, args, false); + va_end(args); + return i; +} --=20 2.55.0.1003.g10538fe699-goog From nobody Fri Sep 25 19:13:36 2026 Received: from mail-wm1-f71.google.com (mail-wm1-f71.google.com [209.85.128.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 88C15552931 for ; Wed, 9 Sep 2026 11:56:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.71 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954970; cv=none; b=IDNvUBqwkwHmtsF3N325KFPVUUA9QspQeZTEu/9Z0e6X/p351arWiR2vwRG/mh362mMD82PHJRNIY/Z+eMcyjCNDF0AfOVOwdZy7JpdDQdut/VGT9q04WMCsggU0M3mUPF28imOrlCS3eGZKeZ0+a6g4bhoD7NUByU1f0y0Q4ME= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788954970; c=relaxed/simple; bh=pRW4HEecg9x05VlvvNHWyO+Xj06f//HTE1CvA11M7fI=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=drF9SN3lpgm8RaNK+7HAWRXTYG36g6yAAHfP4OCv2LEo/FONkpoX5AdrhcH3B5x17EVZCBQ9v/Zag8gyDDfF67LNEx66SwwUQcM5DwV/oZObHe+dr98JZRxKs2wMK+5VWtZ6BsWlDCaP1b4jgnlhjnyQnmMtfkeo+oiCGOVqFtQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=DpyRsEZA; arc=none smtp.client-ip=209.85.128.71 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="DpyRsEZA" Received: by mail-wm1-f71.google.com with SMTP id 5b1f17b1804b1-49d0ae342b9so28323895e9.1 for ; Wed, 09 Sep 2026 04:56:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788954967; x=1789559767; darn=vger.kernel.org; h=content-transfer-encoding:content-type:cc:to:from:subject :message-id:references:mime-version:in-reply-to:date:from:to:cc :subject:date:message-id:reply-to:content-type; bh=M1PgB2C5uHj9PbLGcmV0eg0x/me0oU1kp6bOAlQo5bk=; b=DpyRsEZAKKHhuwEhn6S7VedCpwlLL6ZQAhyPdLp7bU/VvT6hst7tfEimQPDcJYtFBW qZo6icMSjOSADZIslGj771L2SPR50Nv1Pod413m70+0E/n9WE0EEGzGqiDX35dD/f8TA 5gQ1cTmM/CnAFKSmNcXabv3XXf9OGl+VWWlqS4jZxoNlTr/tGY4CKNd1Wl42lR2spiOV ZpMwHQHy5Ij1Vnnr1lbolVbJ9l1+NPnzusahrPeB3VNb508sstgo6B7p2loQToX6vYXK k6uguxkfq00LhuGabJXOupquDBUdLn6dKSev08V/lMZGHKB7yr6jv/1NzPKpHBKoc9Ue SY8g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788954967; x=1789559767; h=content-transfer-encoding:content-type:cc:to:from:subject :message-id:references:mime-version:in-reply-to:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=M1PgB2C5uHj9PbLGcmV0eg0x/me0oU1kp6bOAlQo5bk=; b=kdVwaoPz9SpfksbiYIZybsUMheyLdCkJFALFnwbSPF34UF8CmP5eY5F3BuSe5QNnO/ ao5MZV258l3MLkQpvrQcRh3xuQLUJUKdQf/a0kQTbf3IrbQSYe2xQ5c7GCBfCqA3oC1b n8OMfjgB4GLC0mk2ZKZXpzzkPF7pf/LtpucI6lMdiONlmLqfIFfNgobtizZAqQ64p+E6 1I6iKqs7TCBrBg+0S7cj/HR0swwyEh/MzScxY3Hy8Jj6puBkQplpIXHITYIXkAw5iG+X tzFyM3/vOexE6LxZt4Pt8Rj06XgEWrHfD+Cmz1gFM/eWRFqVwhmXQGwZYO+VXb1ymFd2 B73w== X-Gm-Message-State: AFuF++mDDyW9vKs/aOO5j6SZxWYNq9pfdt3X+8AXjVUT1qBmIYFEZZ4O 2kIhx8OubBqgzctCzzummXTDtWTfYbEoIyfBoQWePwG4UD3OeiCxJxZHFocwunXcaqyegN3ksg= = X-Received: from wmbeu9.prod.google.com ([2002:a05:600c:81c9:b0:49c:ce06:6657]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:81c8:b0:49d:1f10:8b9f with SMTP id 5b1f17b1804b1-49d1f109802mr48575265e9.7.1788954966686; Wed, 09 Sep 2026 04:56:06 -0700 (PDT) Date: Wed, 9 Sep 2026 13:55:41 +0200 In-Reply-To: <20260909115530.1924665-12-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260909115530.1924665-12-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=8323; i=ardb@kernel.org; h=from:subject; bh=4dLVPZyjs94kAN2Ujs1pKn8L7TMMSfHm0tBktF2p2CE=; b=owGbwMvMwCVmkMcZplerG8N4Wi2JIWuhp90qeZldv7k9n70TizgX+3jvH/3sKcYFLqs18hvk7 0468OlFRykLgxgXg6yYIovA7L/vdp6eKFXrPEsWZg4rE8gQBi5OAZjIJQeG/6FvuRTO6qQnb2f7 6ypy2OeV7pJipxROq/snZOvuCzlKazL801mZtUnO7XZhsues9fLnc534VnxePPvJrGbz3vLJ+9X PMwAA X-Mailer: git-send-email 2.55.0.1003.g10538fe699-goog Message-ID: <20260909115530.1924665-22-ardb+git@google.com> Subject: [PATCH v2 10/10] efi/libstub: add initial Boot Loader Interface support From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Vincent Mailhol , x86@kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Vincent Mailhol The Boot Loader Interface (BLI) [1] defines EFI variables that expose boot loader state to the running OS. LoaderInfo identifies the boot loader, while LoaderDevicePartUUID records the GPT partition UUID of the partition containing it. LoaderDevicePartUUID is used, for example, by systemd-gpt-auto-generator [2] to identify the disk the boot loader was launched from and automatically detect and mount partitions on it. GRUB [3] and systemd-boot [4] populate these variables, but when the kernel is started directly by EFI firmware, there is no conventional external boot loader to provide them. In that case, because the EFI stub performs the boot loader role, it should provide the variables itself. Use LoaderInfo as a sentinel: if it is already set by an earlier boot stage or cannot be set, bail out. Otherwise, populate the other BLI variables. Parse the loaded image device path, extract the GUID signature from its GPT HD() node and publish it under the Linux loader entry vendor GUID as the volatile LoaderDevicePartUUID EFI variable. Install the efi_bli_set_variables() hook in both the generic efi-stub.c path and the x86-specific x86-stub.c path. [1] The Boot Loader Interface Link: https://systemd.io/BOOT_LOADER_INTERFACE/ [2] systemd-gpt-auto-generator Link: https://www.freedesktop.org/software/systemd/man/latest/systemd-gpt-a= uto-generator.html [3] GRUB -- =C2=A716.2 bli Link: https://www.gnu.org/software/grub/manual/grub/html_node/bli_005fmodul= e.html [4] systemd -- systemd-boot UEFI Boot Manager Link: https://github.com/systemd/systemd/blob/main/docs/BOOT.md?plain=3D1#L= 102 Signed-off-by: Vincent Mailhol [ardb: - constify 'image' pointer parameter - pass efi_guid_t* to efi_snprintf()] Signed-off-by: Ard Biesheuvel --- drivers/firmware/efi/libstub/Makefile | 2 +- drivers/firmware/efi/libstub/bli.c | 87 ++++++++++++++++++++ drivers/firmware/efi/libstub/efi-stub.c | 1 + drivers/firmware/efi/libstub/efistub.h | 2 + drivers/firmware/efi/libstub/x86-stub.c | 1 + include/linux/efi.h | 22 +++++ 6 files changed, 114 insertions(+), 1 deletion(-) diff --git a/drivers/firmware/efi/libstub/Makefile b/drivers/firmware/efi/l= ibstub/Makefile index 12c0c7deb5cb..564773c89d14 100644 --- a/drivers/firmware/efi/libstub/Makefile +++ b/drivers/firmware/efi/libstub/Makefile @@ -66,7 +66,7 @@ KBUILD_AFLAGS :=3D $(KBUILD_CFLAGS) -D__ASSEMBLY__ lib-y :=3D efi-stub-helper.o gop.o secureboot.o tpm.o \ file.o mem.o random.o randomalloc.o pci.o \ skip_spaces.o lib-cmdline.o lib-ctype.o \ - alignedmem.o printk.o vsprintf.o \ + alignedmem.o printk.o vsprintf.o bli.o \ lib-ucs2_string.o =20 # include the stub's libfdt dependencies from lib/ when needed diff --git a/drivers/firmware/efi/libstub/bli.c b/drivers/firmware/efi/libs= tub/bli.c new file mode 100644 index 000000000000..b2407f63b743 --- /dev/null +++ b/drivers/firmware/efi/libstub/bli.c @@ -0,0 +1,87 @@ +// SPDX-License-Identifier: GPL-2.0 + +#include + +#include +#include +#include + +#include "efistub.h" + +static efi_guid_t loader_entry_guid =3D LINUX_EFI_LOADER_ENTRY_GUID; + +static const struct efi_hd_dev_path * +efi_bli_find_hd_node(const struct efi_dev_path *path) +{ + const struct efi_dev_path *node; + u16 node_len; + + for (node =3D path; + node->header.type !=3D EFI_DEV_END_PATH && + node->header.type !=3D EFI_DEV_END_PATH2; + node =3D (const void *)node + node_len) { + node_len =3D get_unaligned_le16(&node->header.length); + + if (node_len < sizeof(node->header)) + return NULL; + + if (node->header.type !=3D EFI_DEV_MEDIA || + node->header.sub_type !=3D EFI_DEV_MEDIA_HARD_DRIVE) + continue; + + if (node_len < sizeof(node->hd)) + return NULL; + + if (node->hd.partition_format !=3D EFI_HD_PARTITION_FORMAT_GPT || + node->hd.signature_type !=3D EFI_HD_SIGNATURE_TYPE_GUID) + continue; + + return &node->hd; + } + + return NULL; +} + +static void efi_bli_populate_loader_part_uuid(const efi_loaded_image_t *im= age) +{ + static efi_guid_t device_path_guid =3D EFI_DEVICE_PATH_PROTOCOL_GUID; + efi_char16_t partuuid[UUID_STRING_LEN + 1]; + const struct efi_hd_dev_path *hd_node; + const struct efi_dev_path *path; + + if (efi_bs_call(handle_protocol, efi_table_attr(image, device_handle), + &device_path_guid, (void **)&path) !=3D EFI_SUCCESS) + return; + + hd_node =3D efi_bli_find_hd_node(path); + if (!hd_node) + return; + + if (efi_snprintf(partuuid, ARRAY_SIZE(partuuid), "%pUl", + &hd_node->signature) !=3D UUID_STRING_LEN) + return; + + set_efi_var(L"LoaderDevicePartUUID", &loader_entry_guid, + EFI_VARIABLE_BOOTSERVICE_ACCESS | EFI_VARIABLE_RUNTIME_ACCESS, + sizeof(partuuid), partuuid); +} + +void efi_bli_set_variables(const efi_loaded_image_t *image) +{ + static efi_char16_t loader_info[] =3D L"Linux EFI stub " UTS_RELEASE; + unsigned long size =3D 0; + + if (!image) + return; + + if (get_efi_var(L"LoaderInfo", &loader_entry_guid, + NULL, &size, NULL) !=3D EFI_NOT_FOUND) + return; + + if (set_efi_var(L"LoaderInfo", &loader_entry_guid, + EFI_VARIABLE_BOOTSERVICE_ACCESS | EFI_VARIABLE_RUNTIME_ACCESS, + sizeof(loader_info), loader_info) !=3D EFI_SUCCESS) + return; + + efi_bli_populate_loader_part_uuid(image); +} diff --git a/drivers/firmware/efi/libstub/efi-stub.c b/drivers/firmware/efi= /libstub/efi-stub.c index 42d6073bcd06..2a95f4ea104a 100644 --- a/drivers/firmware/efi/libstub/efi-stub.c +++ b/drivers/firmware/efi/libstub/efi-stub.c @@ -165,6 +165,7 @@ efi_status_t efi_stub_common(efi_handle_t handle, dpy =3D setup_primary_display(); =20 efi_retrieve_eventlog(); + efi_bli_set_variables(image); =20 /* Ask the firmware to clear memory on unclean shutdown */ efi_enable_reset_attack_mitigation(); diff --git a/drivers/firmware/efi/libstub/efistub.h b/drivers/firmware/efi/= libstub/efistub.h index 880c1d0c464b..4f9e7ae28b6c 100644 --- a/drivers/firmware/efi/libstub/efistub.h +++ b/drivers/firmware/efi/libstub/efistub.h @@ -1072,6 +1072,8 @@ efi_status_t efi_random_alloc(unsigned long size, uns= igned long align, int memory_type, unsigned long alloc_min, unsigned long alloc_max); =20 +void efi_bli_set_variables(const efi_loaded_image_t *image); + efi_status_t efi_random_get_seed(void); =20 efi_status_t check_platform_features(void); diff --git a/drivers/firmware/efi/libstub/x86-stub.c b/drivers/firmware/efi= /libstub/x86-stub.c index cef32e2c82d8..b762f7f37f28 100644 --- a/drivers/firmware/efi/libstub/x86-stub.c +++ b/drivers/firmware/efi/libstub/x86-stub.c @@ -1014,6 +1014,7 @@ void __noreturn efi_stub_entry(efi_handle_t handle, efi_random_get_seed(); =20 efi_retrieve_eventlog(); + efi_bli_set_variables(image); =20 setup_graphics(boot_params); =20 diff --git a/include/linux/efi.h b/include/linux/efi.h index c35446a0b66f..ecb34be37a87 100644 --- a/include/linux/efi.h +++ b/include/linux/efi.h @@ -957,6 +957,17 @@ extern int efi_status_to_err(efi_status_t status); #define EFI_DEV_END_INSTANCE 0x01 #define EFI_DEV_END_ENTIRE 0xFF =20 +enum efi_hd_partition_format { + EFI_HD_PARTITION_FORMAT_MBR =3D 1, + EFI_HD_PARTITION_FORMAT_GPT, +}; + +enum efi_hd_signature_type { + EFI_HD_SIGNATURE_TYPE_NONE, + EFI_HD_SIGNATURE_TYPE_MBR, + EFI_HD_SIGNATURE_TYPE_GUID, +}; + struct efi_generic_dev_path { u8 type; u8 sub_type; @@ -988,6 +999,16 @@ struct efi_rel_offset_dev_path { u64 ending_offset; } __packed; =20 +struct efi_hd_dev_path { + struct efi_generic_dev_path header; + u32 partition_number; + u64 partition_start; + u64 partition_size; + efi_guid_t signature; + u8 partition_format; + u8 signature_type; +} __packed; + struct efi_mem_mapped_dev_path { struct efi_generic_dev_path header; u32 memory_type; @@ -1007,6 +1028,7 @@ struct efi_dev_path { struct efi_pci_dev_path pci; struct efi_vendor_dev_path vendor; struct efi_rel_offset_dev_path rel_offset; + struct efi_hd_dev_path hd; }; } __packed; =20 --=20 2.55.0.1003.g10538fe699-goog