From nobody Fri Sep 25 04:38:15 2026 Received: from mail-wm1-f69.google.com (mail-wm1-f69.google.com [209.85.128.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 332BD2F8E8E for ; Wed, 16 Sep 2026 14:47:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.69 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789570051; cv=none; b=qAkBmBOztf9USBHjQsaADYoWG/96qEgM6GCKrmrOkftEwwkVFQJQnzN1JN6OS0NFXnm0DJRwGU1Sg4qN7dxdUFBPmQIAG/eEzFFt9DhXh+Z/bMBGQHAfbHPGOLiCsm3O8A8CMdGGSyYdYvO2/xgN5Zt+r/14vCSjSTWtYt0yZVQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789570051; c=relaxed/simple; bh=2xhGhsnM6cFg9XqwguWnmGOLniqfg3yffsSq814n3oY=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=N8hgecYWPc1gybv8oPc9mdEyrvOA5tmL9U2hrrZdzYJV8Xu7ULry/rIe0E0KPH19L0j1C60Qg5O49KwyagldLyiZbTRjm6QmxoR6ijfrhk3K+OI8dxYyE8cuLGEyv1TXaTpka8JGNXF2COubKNsPo6mBBPsEuoESU1sQS8wuGKo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=C2TpLZgK; arc=none smtp.client-ip=209.85.128.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="C2TpLZgK" Received: by mail-wm1-f69.google.com with SMTP id 5b1f17b1804b1-49953abe51fso34901785e9.1 for ; Wed, 16 Sep 2026 07:47:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789570047; x=1790174847; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=adQpVVPYDSCv+/CQimrvUBYO3H49guv1JLukjJuQ+Nw=; b=C2TpLZgKvbqrLxGl3GBqP4xjqJWRtdNDpVU6FsPgBOhCcy0ftRcorh66sutaniGFFs ff3kAVI+0FcQSF6by6xZTVW4PVrxg4LUU7P0lNApyzhgvPpC6vYGj4eUFBxfly/NwgOy koLsOqZxNQIqeiC5/PhODkSkwJy777tOZJiL9zxZok98bUSmwsRu+wkdRn2MxOzqYrdt fRGuO8P/rAB9pkNkhl574P95e/h1oPOvmiEbQJm/x5sgZKbUN5WOoIksCpSg84lVA2LS swNsOOvZLwbUHuHUh8YJbqwZTQkLKtU7OmPeC8QHdmyCkuBLQRklpc7LVTbB1koKCgh8 puWA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789570047; x=1790174847; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=adQpVVPYDSCv+/CQimrvUBYO3H49guv1JLukjJuQ+Nw=; b=rYcRIv/bws1Q3FRy/aJYXgJXBMVfT7U5OGAtljNX/DHdZehB81QxHuqqYaX2MsSKTd coyNyxhUOeblF5uMIedcF0NEOX5fy/3ikWewHuPdMupjNaCHkPYJDTM6umSuyAfzc7Td 0ak3Af5Flpdxlsk5wsLp+bHqTdUuH4DN5NFETn88JXKaQkYzT2z185MwMlKBKXaCTtgv bIz070oLwu45cnoxVACnVna5LR727Vs3eQN/P1vcm1FsnwyjPJzqD9SHel3ndMLX2zxt Y/Fq25qqLyV3qN6mpP2gBFawb4NIepvZq+cKTSoW6ZrCnHs6LbNJNawEBcg6QHdJqtDZ U2xg== X-Gm-Message-State: AFuF++l2uNaeT8mKDhbjCM9xYn1Ut1sPPMsMQuII3X673dncE3eHToYg y8GLyTDRcGD85BSBTfnKM4e/DEpR+Se4ngFgUwS0JGB1utehyKtT0sXknZIbBVk108Y/5P8BRA= = X-Received: from wmwb6-n1.prod.google.com ([2002:a05:600d:4446:10b0:49e:6be1:415d]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:1f8f:b0:49c:cee2:1697 with SMTP id 5b1f17b1804b1-49eb7322d4fmr34446395e9.16.1789570047100; Wed, 16 Sep 2026 07:47:27 -0700 (PDT) Date: Wed, 16 Sep 2026 16:46:49 +0200 In-Reply-To: <20260916144647.2651379-11-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260916144647.2651379-11-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=873; i=ardb@kernel.org; h=from:subject; bh=YU1ElVLaCeA6lifqtbLFaABcpHCwQcZWRxgO278csYc=; b=owGbwMvMwCVmkMcZplerG8N4Wi2JIWvV6psf7zU3fTJ3kP7pnrSCtW6/kUitm/SL1rUPVDbVy +XXSdzpKGVhEONikBVTZBGY/ffdztMTpWqdZ8nCzGFlAhnCwMUpABPR+Mrwz+Cdr4KHy9zUVRpu vu8vTT1+wvVhfMHvcusCT/mZ978bX2P4X6+7Y4b+MxXun7N/zfOMFN3XvMcubJGCiKjnp7z921d 2MAIA X-Mailer: git-send-email 2.55.0.1032.g73a4cd73de-goog Message-ID: <20260916144647.2651379-12-ardb+git@google.com> Subject: [PATCH v3 1/9] lib/ucs2_string: Drop arbitrary input size limit and associated WARN() From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Vincent Mailhol Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ard Biesheuvel It's not really the job of library code to WARN and potentially bring down the system (with panic_on_warn=3D1) on a condition that is fairly arbitrary to begin with. So drop the WARN_ON_ONCE() as well as the condition from ucs2_strscpy(). Signed-off-by: Ard Biesheuvel Reviewed-by: Vincent Mailhol --- lib/ucs2_string.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/ucs2_string.c b/lib/ucs2_string.c index 1f7dd4eb640a..d66fef9c9b81 100644 --- a/lib/ucs2_string.c +++ b/lib/ucs2_string.c @@ -57,7 +57,7 @@ ssize_t ucs2_strscpy(ucs2_char_t *dst, const ucs2_char_t = *src, size_t count) * Ensure that we have a valid amount of space. We need to store at * least one NUL-character. */ - if (count =3D=3D 0 || WARN_ON_ONCE(count > INT_MAX / sizeof(*dst))) + if (count =3D=3D 0) return -E2BIG; =20 /* --=20 2.55.0.1032.g73a4cd73de-goog From nobody Fri Sep 25 04:38:15 2026 Received: from mail-wm1-f69.google.com (mail-wm1-f69.google.com [209.85.128.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CDA35314A65 for ; Wed, 16 Sep 2026 14:47:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.69 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789570051; cv=none; b=BANHi6ETr5gxL2UbnVWSS0kQfLoVtB2qstM+rziUP66EYySRPSN4t0yAIQIQV/1EYelZhzrkqUjQwATQPOuMZ9Q9P9Sr93ocA4KnmK0lorOLd1pLHxaaoSc4rDFP1rm/IAHjuSxqUgdZJ/rCjjfUqiA/1iroWr0Arg8A/REHCVI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789570051; c=relaxed/simple; bh=C1oNciHcEscYHEFiBPOAp/Z1rml/FIlWarmSgscZ6yc=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=muzozJjeL3H2pwNhyUebGaxnH1zjzV/1KSzVScPErEri91z/wCmaXiPZjNDkKRj19dUcib0i33WebXnb9Xga9dSgG7/N64G4mSxCirAtimROgAnGbOIO/JqIArTkFMzaoadEYk3N34iKM1PJzqL6+ULzn6tnSuZoKTSZP/Mg/fk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=ram7WL1U; arc=none smtp.client-ip=209.85.128.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="ram7WL1U" Received: by mail-wm1-f69.google.com with SMTP id 5b1f17b1804b1-495689bfcc8so47446985e9.1 for ; Wed, 16 Sep 2026 07:47:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789570048; x=1790174848; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=SChD6gZN6HYF8sdEF4kgrqs3H/vnYWBrVFLBfW4Uqts=; b=ram7WL1UkFun17DGGjfsO6e/gXDih8BVBZPFc6KbHc+b7rw+7UxT/tQ2XAvTuXTaqB 5oNh2oFIRZpK3VjWZpC0kSqSA5iIDhTIbO5Sds/bruL8eR+WkhjBiZj86N4sSaB3z7Aa GmMy8M6ACk/70uM/tMNBkwRgGAWC6dInIXAAtCCSrQBYPBeSFEar/674vTThJZseCqY/ aB5t7kbNvAtUy9s6DYPdcvU8Fz0eIpyEYFZU3ZP+2562G88s/ASIzheutpWiFffoUgdo emC4bPyNhYhoJuqFgIVLlyXEPATiFEvCzN8LBYzHSN1TjkddQal/bcw/eTKqHdpRPNIV orrw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789570048; x=1790174848; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=SChD6gZN6HYF8sdEF4kgrqs3H/vnYWBrVFLBfW4Uqts=; b=fGd137K5We2VYxlnij9jNbswloWztHHt0xK7EmjINIznpljrDxqUZ7rDAqEhnntvlH ARpGSEomm01THXIC1k7oKkIUn49fjavRxEqEqLLJcgvnrmKNTGs0SWAEsRdEnEpfpeSq 0P8n/QpTCjzVOrXCa5JSSqjpA+/MktfKxgUF9EWl7HxORUAeKQiwrDoVNZfGwRDIy/M6 r7Xr7Bh90I4Ry2Uz6qm3tNFPMlayuSfyFP+0IPX+fKcTZPxk4qlXu5lGeh9FGe4HV6Fl sS8KXixfUfipG245yv+6WvznLpvBwuXYB75fBpH83Ov+WUyb3sjsLvg2BQch9aZsWC1+ bwyg== X-Gm-Message-State: AFuF++nexjbJK7f8nPOXl7bmjzlcJARCY6zq0gqirw4pBfEybqgJcwi5 r6UJLYxqJTTJLc3FULT33jEeX5KAFsdVOxWhaQ3cfbZUG8FKyH7dkdbjSuCVyps0bctdGuWx6A= = X-Received: from wmbgx11.prod.google.com ([2002:a05:600c:858b:b0:49f:646f:58cf]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:3b29:b0:49c:fa21:e74a with SMTP id 5b1f17b1804b1-49eb733e4camr32594375e9.32.1789570048115; Wed, 16 Sep 2026 07:47:28 -0700 (PDT) Date: Wed, 16 Sep 2026 16:46:50 +0200 In-Reply-To: <20260916144647.2651379-11-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260916144647.2651379-11-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=705; i=ardb@kernel.org; h=from:subject; bh=qgkzqtEAKN071Ee9/bQchBV2SIPhg66nmHFUwJgGBhA=; b=owGbwMvMwCVmkMcZplerG8N4Wi2JIWvV6tt+qv/5vh6efeW1WvZCDaON99Uy1h/fbsCW8PJ8U GG1rLNYRykLgxgXg6yYIovA7L/vdp6eKFXrPEsWZg4rE8gQBi5OAZiIRRDDP8XLBYaKknVxKc+1 dk897rVIyeXJI9vLkQG8B6x2Gj2pWsLIcGRGY0P9vA/Vou/Zp88LmcNlc31RyXOTjwttfZTsIw4 U8wIA X-Mailer: git-send-email 2.55.0.1032.g73a4cd73de-goog Message-ID: <20260916144647.2651379-13-ardb+git@google.com> Subject: [PATCH v3 2/9] lib/ucs2_string: Suppress modinfo when __DISABLE_EXPORTS is set From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Vincent Mailhol Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ard Biesheuvel Allow the UCS-2 string library to be reused in the EFI stub, by suppressing the modinfo data that is usually emitted so that the library can be built as a module. Signed-off-by: Ard Biesheuvel Reviewed-by: Vincent Mailhol --- lib/ucs2_string.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/lib/ucs2_string.c b/lib/ucs2_string.c index d66fef9c9b81..f75fb4f7961a 100644 --- a/lib/ucs2_string.c +++ b/lib/ucs2_string.c @@ -165,5 +165,7 @@ ucs2_as_utf8(u8 *dest, const ucs2_char_t *src, unsigned= long maxlength) } EXPORT_SYMBOL(ucs2_as_utf8); =20 +#ifndef __DISABLE_EXPORTS MODULE_DESCRIPTION("UCS2 string handling"); MODULE_LICENSE("GPL v2"); +#endif --=20 2.55.0.1032.g73a4cd73de-goog From nobody Fri Sep 25 04:38:15 2026 Received: from mail-wm1-f70.google.com (mail-wm1-f70.google.com [209.85.128.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 772A62F1FE4 for ; Wed, 16 Sep 2026 14:47:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.70 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789570053; cv=none; b=sKbtf1i2T94WUVU5rUVGW1Osfi89oNeZLNNSN8/v8ESeRE5fBp1dvPRsNICA8/duKLo26+44FBs9u6/nQaMRaXFH2uq4blnRXR2bYCrZoIIVuAPlvQx/Gecl0mef9xI0oek6S0oeMGjCp5ym2UvZSg8DuOnGe8SnYXaWiglxVeY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789570053; c=relaxed/simple; bh=eqWkJSmv/tiBGGD3+FSHwBakwbSAKn+5SWHD5Y176es=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=WiFsZgQWqc6uB5t28/7gUSuKbURS0RHTJx2nUWU8qSnuoOMmWZSIqhArd43Q2FR+AxeHaOmt/EqMdPtAsznZY6pdgEqKXWeSbpLs2IydR7UHdTIFl+vzItcKEag5vwX1gkE8SP2BAWnnNq98EUHVUgS043RWSqx+I0jejprdoiw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=moEFLI5z; arc=none smtp.client-ip=209.85.128.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="moEFLI5z" Received: by mail-wm1-f70.google.com with SMTP id 5b1f17b1804b1-49e6b5c5f44so37943945e9.2 for ; Wed, 16 Sep 2026 07:47:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789570049; x=1790174849; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=VEK2A1EMPHm2wewONLMkfK/EPHAjA+H6M8lM4TvNREg=; b=moEFLI5z8hObgBF+l6eDz3V5/pSP7848c/fAi4BYcBbX6E38FiiScdnURwJJ3yxBSH qL80Idx9zKC0ly1rGrjBHk0L+mwWVgA1vxrx0MM0vdJYbbcpMHqDRndRLYAB/KLzsBMA H0my9/pCvik/k0L+aHn/y4Ez7HDzle3Cl/IFJE1GcLtmkngcTsOUqhGugw9LGWSATQYM +2N5299SEtKpLBTrHwzJifdXHv6CuUFVUO7GGHcK9ktEzQUCtY06ztzheaOIpqDPh6OX fxtcBgz5tUClOpBVMSaB1CuJ0kqAUQzpEajOZMNFZJpKzcHwFYuJdZel9a+3v44D7SiZ xIkQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789570049; x=1790174849; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=VEK2A1EMPHm2wewONLMkfK/EPHAjA+H6M8lM4TvNREg=; b=RsOCT/2K0wQCL6D/m/4xO0JZFPERcPQ7cdhYzBPKmnR36lXiluC/1s0Gp8cL/9kvAg uL6iSBwfGpFuUqDa3slt0G1UoDphV1Qb0zJxozgyqEX0hs54iOgYAtL/VfxCZymirxZl QkApp3xwwMUX+6nKpihisFjpSwLQVevQYTjO9qR2sbUWZu4O1Iy2dLwYX7qSY9HN0tr+ EXQNdcRBo97L8dptUD76BlAleNVhXfzCJ2jwFxFtSubsW1tTrz172U4u/EAmHGnMIwU2 fPbl2UGMZLwB/sAfaRJAGYBas23vbYtZVi4ygjwGd8vrgbvkpx5J4XdYI6zyWdeV9S8I vD7Q== X-Gm-Message-State: AFuF++mA/zvSMkK0fB5z3iogeityod6PlFzXum9uifnwYWJdntdfioZo VlnRnygamqrfd8Jnkfz5WzCt9R3MP67MlavBFQDnL6Qr8b2/c3Tu3KFyklE8YuJJHaSlFcw1Og= = X-Received: from wmoo14.prod.google.com ([2002:a05:600d:10e:b0:499:b2b5:78e8]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:4713:b0:49d:4ef:bf70 with SMTP id 5b1f17b1804b1-49eac467915mr34495405e9.10.1789570049219; Wed, 16 Sep 2026 07:47:29 -0700 (PDT) Date: Wed, 16 Sep 2026 16:46:51 +0200 In-Reply-To: <20260916144647.2651379-11-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260916144647.2651379-11-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=3279; i=ardb@kernel.org; h=from:subject; bh=Lgsb/yq0Dq6T5v71CGxty1QuUmSRQI4tlUIGP++kj0I=; b=owGbwMvMwCVmkMcZplerG8N4Wi2JIWvV6jsstjJcUfP+pp2QVK5huc4T4lP51VOkeYdP4DHBt gmzv8R3lLIwiHExyIopsgjM/vtu5+mJUrXOs2Rh5rAygQxh4OIUgIms/cTIsMp0w4z8EhmXTo2d oam89xeLaBRumS+36YM4z+P+1a/uGjP8Zl+8zynS0uZIGRPzZ3/B9c8/zWorV7mX6fPkxR42fvX ZXAA= X-Mailer: git-send-email 2.55.0.1032.g73a4cd73de-goog Message-ID: <20260916144647.2651379-14-ardb+git@google.com> Subject: [PATCH v3 3/9] lib/ucs2_string: Split out ucs2_as_utf8_l() taking a separate limit From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Vincent Mailhol Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ard Biesheuvel ucs2_as_utf8() takes a maxlength argument, which specifies how many bytes the function is permitted to store into the destination buffer. The same value is used as an upper bound for the ucs2_strnlen() invocation, which is reasonable in the general case, as each UCS-2 character produces at least one byte of UTF-8 output, and so there is never a need to process more than 'maxlength' UCS-2 characters. However, if the UCS-2 string is not NUL terminated, ucs2_strnlen() may read past the end of the buffer if 'maxlength' is set to a high value. Current callers pass UCS-2 strings that are expected to be NUL terminated, but for processing the load options in the EFI stub, a version is needed that takes a separate limit argument. So split that off from the current implementation. Signed-off-by: Ard Biesheuvel Reviewed-by: Vincent Mailhol --- include/linux/ucs2_string.h | 11 ++++++++++- lib/ucs2_string.c | 15 ++++++++------- 2 files changed, 18 insertions(+), 8 deletions(-) diff --git a/include/linux/ucs2_string.h b/include/linux/ucs2_string.h index c499ae809c7d..74f23ca5a967 100644 --- a/include/linux/ucs2_string.h +++ b/include/linux/ucs2_string.h @@ -14,7 +14,16 @@ ssize_t ucs2_strscpy(ucs2_char_t *dst, const ucs2_char_t= *src, size_t count); int ucs2_strncmp(const ucs2_char_t *a, const ucs2_char_t *b, size_t len); =20 unsigned long ucs2_utf8size(const ucs2_char_t *src); +unsigned long +ucs2_as_utf8_l(u8 *dest, const ucs2_char_t *src, unsigned long limit, + unsigned long maxlength); + +static inline unsigned long ucs2_as_utf8(u8 *dest, const ucs2_char_t *src, - unsigned long maxlength); + unsigned long maxlength) +{ + return ucs2_as_utf8_l(dest, src, ucs2_strnlen(src, maxlength), + maxlength); +} =20 #endif /* _LINUX_UCS2_STRING_H_ */ diff --git a/lib/ucs2_string.c b/lib/ucs2_string.c index f75fb4f7961a..6c067b4280b9 100644 --- a/lib/ucs2_string.c +++ b/lib/ucs2_string.c @@ -125,18 +125,19 @@ ucs2_utf8size(const ucs2_char_t *src) EXPORT_SYMBOL(ucs2_utf8size); =20 /* - * copy at most maxlength bytes of whole utf8 characters to dest from the - * ucs2 string src. + * Copy at most @limit whole utf8 characters to @dest from the ucs2 string + * @src, using no more than @maxlength bytes of buffer space. * - * The return value is the number of characters copied, not including the - * final NUL character. + * The return value is the number of bytes copied, not including the final= NUL + * character. No NUL character will be appended if the output length equals + * @maxlength. */ unsigned long -ucs2_as_utf8(u8 *dest, const ucs2_char_t *src, unsigned long maxlength) +ucs2_as_utf8_l(u8 *dest, const ucs2_char_t *src, unsigned long limit, + unsigned long maxlength) { unsigned int i; unsigned long j =3D 0; - unsigned long limit =3D ucs2_strnlen(src, maxlength); =20 for (i =3D 0; maxlength && i < limit; i++) { u16 c =3D src[i]; @@ -163,7 +164,7 @@ ucs2_as_utf8(u8 *dest, const ucs2_char_t *src, unsigned= long maxlength) dest[j] =3D '\0'; return j; } -EXPORT_SYMBOL(ucs2_as_utf8); +EXPORT_SYMBOL(ucs2_as_utf8_l); =20 #ifndef __DISABLE_EXPORTS MODULE_DESCRIPTION("UCS2 string handling"); --=20 2.55.0.1032.g73a4cd73de-goog From nobody Fri Sep 25 04:38:15 2026 Received: from mail-ed1-f69.google.com (mail-ed1-f69.google.com [209.85.208.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BCE0334F27F for ; Wed, 16 Sep 2026 14:47:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.69 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789570054; cv=none; b=o4cgSiCzLbRjpEUPVUfIl39oihWS0l+LPB8pAPOrBxKPW1Mqjd6K9Bs5RrHXgGb1oehGbdMalnaiuuSX+Nr1xKJ/TqBXORMBsda3TAnTMoLC6E+XvqhdScDdLx/tHCSWISJ8TQ6lnC/DJlK70GGVNXxtJYKKLwkayeNfIJSaVkI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789570054; c=relaxed/simple; bh=lV61vs9JQIXl38QxVWcMXNAs0mu8Nv86ErgGTYp+mDc=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=b352MiBKoauYSaI3PxQ8vbBEIvJHl3ac2jSB+v7+bW9gC0W0yQDZ2W6S+KkGX910sQpUlO4mMAvxqmIZ4rxN1XV77EdSi3MTWRdzXHzgylKvEfdvwuPdtB756zGwpgeMT+bddAvVcJM30LuWSlJW/qXHUwZa1mINygaEAbCOJow= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=MPrS5gAR; arc=none smtp.client-ip=209.85.208.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="MPrS5gAR" Received: by mail-ed1-f69.google.com with SMTP id 4fb4d7f45d1cf-6a6735afb87so5853341a12.2 for ; Wed, 16 Sep 2026 07:47:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789570051; x=1790174851; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=GBPfJ5mOgmXCGpvBT7L71rofeWFO21wBMVUvFZChAjM=; b=MPrS5gARbs9tigTMJ8B1plfxWjSvusBNi+4EtWfufNnlbqP7Fa/PaeuP7c8gqC/VAT 2dYCysljRrS0wmaLYrn86RVZJGiJiSNJkvANz5W+EbazOdUINTHBfGtEPi8VWdKiLlT9 N9qAiU0iHuwLfohhz3y4GYm7asIi6BH46GtJ3QjErBEy/hPQwdcFKDk/o28jgW92QxZ7 WZgxj7CTtwmx03F0CK5mO5Fvu+Jxk7+MlJYUIHnM84uPd+XjfrSz6mjcpG4+oOhEh/y/ aQLiX77N52880HhRlOsfPc1n8bUzjil2lKpF1rr6sNcESeihGWby0EIgkuUawg4zBD0z goGw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789570051; x=1790174851; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=GBPfJ5mOgmXCGpvBT7L71rofeWFO21wBMVUvFZChAjM=; b=2y9+UOvJ4iJ33Kz/kNGFAhv1JM3l4Tp6l2x404OTpJkA/PG0eYV8nCoPW8wEWYvtVe BM5vEV9L24F8h7LHfojIpNVbzkIq3STpiuX7WUKilr8c3D9sJZX14Bwr2lsQQYRKUbVJ DjTCXBfvb4O872LKSR/Y1y3urLYxSm47McVQwarTnM2krHQ+qwsRsnHedJCS0QIsGn1B Yy2JSp2WM19CxNEyfCx43fIpe9sf+kZ2YPSupe5lRHzJ+ExHEiWaWN3lAdjmuotIbTv0 P8/xgkJ+9fjgvITGOwJtxNBlrKGXK8PkLEAEym0YI02Ui8O3S0OSOuvNkLyl0DaKaDer r8yg== X-Gm-Message-State: AFuF++nPLhONZHGFVXeTHTRoh2O7SGQsxujdeSTJg1ELwFpOaMcKayre o1quyg2uKwbQqk20+06nzjiHDOe+OrqRmeCXZTELlF/cTIrwZC5O9zBJRbstDh+PkZLjjm1q0A= = X-Received: from edej18.prod.google.com ([2002:a05:6402:5692:b0:6a7:ee17:5c2b]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6402:400c:b0:6aa:f0e:a150 with SMTP id 4fb4d7f45d1cf-6aa2247ca1emr2169373a12.42.1789570050651; Wed, 16 Sep 2026 07:47:30 -0700 (PDT) Date: Wed, 16 Sep 2026 16:46:52 +0200 In-Reply-To: <20260916144647.2651379-11-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260916144647.2651379-11-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=6555; i=ardb@kernel.org; h=from:subject; bh=COS4mnBB6kmKQSlmrKytUWBFvUccXJP8C3EuJ+M7AW4=; b=owGbwMvMwCVmkMcZplerG8N4Wi2JIWvV6ru3ri1/k/HqYXoUHyNb19yfay9f6v570m/h2heWR 7kr5XusO0pZGMS4GGTFFFkEZv99t/P0RKla51myMHNYmUCGMHBxCsBE1rIy/Pep3vfp5jR76+1a WwpP2XOvybq2tTD68Mmk8IACztypr/4z/PfqXakXPWG24fv9bzSsvx+9tFfxwtETr7+wGF4PWvV vdRk7AA== X-Mailer: git-send-email 2.55.0.1032.g73a4cd73de-goog Message-ID: <20260916144647.2651379-15-ardb+git@google.com> Subject: [PATCH v3 4/9] efi/libstub: Use ucs2_string library for UTF-16 to UTF-8 conversion From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Vincent Mailhol Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ard Biesheuvel Don't rely on sprintf() with a wide string conversion modifier to convert the command line from UTF-16 to UTF-8. Instead, use the existing ucs2 string library routine that does the same. Note that while UEFI claims support for UTF-16, in practice it ignores surrogate pairs entirely, and so the simplified UCS-2 character set (where each character takes up exactly 2 bytes) is sufficient here. This removes the only user of sprintf() in the EFI stub, so drop that function as well. Since boot memory is plentiful on UEFI systems, just establish a worst case upper bound for the size of the buffer (which can never exceed COMMAND_LINE_SIZE), and allocate that first. Then, perform the conversion, and only fall back to processing the command line character by character if that resulted in truncation. This makes the common execution path much simpler. Note that this no longer truncates the command line at the first newline, but there is no evidence that this has ever been needed. Signed-off-by: Ard Biesheuvel Reviewed-by: Vincent Mailhol --- drivers/firmware/efi/libstub/Makefile | 3 +- drivers/firmware/efi/libstub/efi-stub-helper.c | 98 ++++++++------------ drivers/firmware/efi/libstub/vsprintf.c | 11 --- 3 files changed, 39 insertions(+), 73 deletions(-) diff --git a/drivers/firmware/efi/libstub/Makefile b/drivers/firmware/efi/l= ibstub/Makefile index 77a2b2d74f3f..12c0c7deb5cb 100644 --- a/drivers/firmware/efi/libstub/Makefile +++ b/drivers/firmware/efi/libstub/Makefile @@ -66,7 +66,8 @@ KBUILD_AFLAGS :=3D $(KBUILD_CFLAGS) -D__ASSEMBLY__ lib-y :=3D efi-stub-helper.o gop.o secureboot.o tpm.o \ file.o mem.o random.o randomalloc.o pci.o \ skip_spaces.o lib-cmdline.o lib-ctype.o \ - alignedmem.o printk.o vsprintf.o + alignedmem.o printk.o vsprintf.o \ + lib-ucs2_string.o =20 # include the stub's libfdt dependencies from lib/ when needed libfdt-deps :=3D fdt_rw.c fdt_ro.c fdt_wip.c fdt.c \ diff --git a/drivers/firmware/efi/libstub/efi-stub-helper.c b/drivers/firmw= are/efi/libstub/efi-stub-helper.c index f27f2e1f0019..3dc365492301 100644 --- a/drivers/firmware/efi/libstub/efi-stub-helper.c +++ b/drivers/firmware/efi/libstub/efi-stub-helper.c @@ -12,6 +12,7 @@ #include #include #include +#include #include #include =20 @@ -334,81 +335,56 @@ char *efi_convert_cmdline(efi_loaded_image_t *image) { const efi_char16_t *options =3D efi_table_attr(image, load_options); u32 options_size =3D efi_table_attr(image, load_options_size); - int options_bytes =3D 0, safe_options_bytes =3D 0; /* UTF-8 bytes */ - unsigned long cmdline_addr =3D 0; - const efi_char16_t *s2; - bool in_quote =3D false; + unsigned long options_chars =3D 0; + unsigned long cmdline_bytes; efi_status_t status; - u32 options_chars; + char *cmdline_addr; =20 if (options_size > 0) efi_measure_tagged_event((unsigned long)options, options_size, EFISTUB_EVT_LOAD_OPTIONS); =20 efi_apply_loadoptions_quirk((const void **)&options, &options_size); - options_chars =3D options_size / sizeof(efi_char16_t); - - if (options) { - s2 =3D options; - while (options_bytes < COMMAND_LINE_SIZE && options_chars--) { - efi_char16_t c =3D *s2++; - - if (c < 0x80) { - if (c =3D=3D L'\0' || c =3D=3D L'\n') - break; - if (c =3D=3D L'"') - in_quote =3D !in_quote; - else if (!in_quote && isspace((char)c)) - safe_options_bytes =3D options_bytes; - - options_bytes++; - continue; - } - - /* - * Get the number of UTF-8 bytes corresponding to a - * UTF-16 character. - * The first part handles everything in the BMP. - */ - options_bytes +=3D 2 + (c >=3D 0x800); - /* - * Add one more byte for valid surrogate pairs. Invalid - * surrogates will be replaced with 0xfffd and take up - * only 3 bytes. - */ - if ((c & 0xfc00) =3D=3D 0xd800) { - /* - * If the very last word is a high surrogate, - * we must ignore it since we can't access the - * low surrogate. - */ - if (!options_chars) { - options_bytes -=3D 3; - } else if ((*s2 & 0xfc00) =3D=3D 0xdc00) { - options_bytes++; - options_chars--; - s2++; - } - } - } - if (options_bytes >=3D COMMAND_LINE_SIZE) { - options_bytes =3D safe_options_bytes; - efi_err("Command line is too long: truncated to %d bytes\n", - options_bytes); - } - } + if (options) + options_chars =3D ucs2_strnlen(options, + options_size / sizeof(efi_char16_t)); =20 - options_bytes++; /* NUL termination */ + /* Each UCS-2 char takes up at most 3 UTF-8 bytes */ + cmdline_bytes =3D min(3 * options_chars, COMMAND_LINE_SIZE - 1) + 3; =20 - status =3D efi_bs_call(allocate_pool, EFI_LOADER_DATA, options_bytes, + status =3D efi_bs_call(allocate_pool, EFI_LOADER_DATA, cmdline_bytes, (void **)&cmdline_addr); if (status !=3D EFI_SUCCESS) return NULL; =20 - snprintf((char *)cmdline_addr, options_bytes, "%.*ls", - options_bytes - 1, options); + if (ucs2_as_utf8_l(cmdline_addr, options, options_chars, + cmdline_bytes) >=3D COMMAND_LINE_SIZE) { + /* + * The output fills up the entire buffer, and may have been + * truncated. Work backwards through the buffer to find a safe + * truncation point (i.e., a blank character not inside a + * quoted string). + */ + int safe_pos[2] =3D {}; + int in_quote =3D 0; + + for (int i =3D COMMAND_LINE_SIZE - 1; i >=3D 0; i--) { + char c =3D cmdline_addr[i]; + + if (!c) + return cmdline_addr; + else if (c =3D=3D '"') + in_quote ^=3D 1; + else if (!safe_pos[in_quote] && isspace(c)) + safe_pos[in_quote] =3D i; + } + + efi_err("Command line is too long: truncated to %d bytes\n", + safe_pos[in_quote]); + cmdline_addr[safe_pos[in_quote]] =3D '\0'; + } =20 - return (char *)cmdline_addr; + return cmdline_addr; } =20 /** diff --git a/drivers/firmware/efi/libstub/vsprintf.c b/drivers/firmware/efi= /libstub/vsprintf.c index 71c71c222346..dba136679172 100644 --- a/drivers/firmware/efi/libstub/vsprintf.c +++ b/drivers/firmware/efi/libstub/vsprintf.c @@ -551,14 +551,3 @@ int vsnprintf(char *buf, size_t size, const char *fmt,= va_list ap) =20 return pos; } - -int snprintf(char *buf, size_t size, const char *fmt, ...) -{ - va_list args; - int i; - - va_start(args, fmt); - i =3D vsnprintf(buf, size, fmt, args); - va_end(args); - return i; -} --=20 2.55.0.1032.g73a4cd73de-goog From nobody Fri Sep 25 04:38:15 2026 Received: from mail-wm1-f71.google.com (mail-wm1-f71.google.com [209.85.128.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 44F8E221FC6 for ; Wed, 16 Sep 2026 14:47:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.71 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789570056; cv=none; b=JPjHSver/o1vVEVj+iAKgoo/zURVqMf2ByGVblU7lmF271jdMsD+6j1/oZMXbVRaMx5Cp+58Hi9XViuy81M4FJHL7SfLLFlK/qqqG05iQVot1Tcfg4E5GZE/U1YIrsLQnf4amSExHXH5oIsE1hg/XeMGLyWCyQ46wrFBqARUlzQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789570056; c=relaxed/simple; bh=4M3XeYI8lfZyQ0kdxVKYo99uiVCoJeAAy1bxt0mFJPs=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=UBJPsZ3mB5aD6HVuqjN6GgxKNExZtnwWkTr08t3bpHuUJZbLW0S/T0mY9dGdDm3bira3kWKtuJrvUNwbpf6yUslnkwvcr+ChFtGWy+fwhbw5ilk4css54N/Ibjn24VLImBwvfk9RR64rZ0S5ce1qD58xY8rHA3cIrbvL/nVKGyQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=hBJF3vjR; arc=none smtp.client-ip=209.85.128.71 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="hBJF3vjR" Received: by mail-wm1-f71.google.com with SMTP id 5b1f17b1804b1-4994cf6cdb9so43761465e9.3 for ; Wed, 16 Sep 2026 07:47:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789570052; x=1790174852; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=X5xo/Tmz0T7aPKmXCPKRwoNwYrD0vFb3mWe6uQZFyqY=; b=hBJF3vjRNOcUWlJm44CO/ai4feMv7qKg25RwbyrxAa4TpdmOSUY+umQuTrCWCe5H6X FcMwT36yPADKtcfJYODnL2o2mqvKbzNTKsvDj0fLCUbuNbPnQai3tr37eIBXynORIyuW oPsVmdJr2LshAIcDX3YoEhhXBXnQ8k/otC0NfvM98IMdAvzSX2O/qGhAZF/mx6iOlrEs Rfj03lWk24yAM3eLpec5Ryi+GhSPbGJ25Kyliy3gz4KY/zPrViapwhP9ugFwG2PZi833 3OFtRJZb9byuYv5Eb4xw3uPc1q0nkx5ZlHRQn9BWuLsbokOSScUUV2NVygyq65yXiEd/ Zhqw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789570052; x=1790174852; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=X5xo/Tmz0T7aPKmXCPKRwoNwYrD0vFb3mWe6uQZFyqY=; b=GmKMH1uKy/yxJ4NpnGieZmKDh8Oa7ENnWZdd2GsUis2vf4lE5XIwA6yBsd6TSwoLJG QexfdRFTZnVK3P5J6MpU9PvZUZnnOW7iOCBpzVN79Bmrs9wyDGFsCzbT4T+4dCJCcDlv yzZqq6EXU4la/kV9ISKKazfPKwc95TkKXkKuMEssB6KbzsJTY8RbZEt6+SZWenU3IgDD XPTuotq0b0u3gCkuN+81Tgr2868qXJPmqnNV8T5sHeiJWNfWJ/EngfugYRzGjFiBGi4Y YD00ue5+xMn6+hq2G3zSHGL1aHiY8dIiAu8CjtIXXUsBVNfgXRJqzyclH1EVa+L7brY4 WnNA== X-Gm-Message-State: AFuF++mnIhcGh8aP9vD1E/Ys3UX+Xlxzh8eUXMMQ13KmxSDxDOiKefLP Z6sb+QtDhrgD0fhXjkvO+FwwkrOErq/ksRX/FBm+ga54Aqm9aXCcbUbvnwONd11YcFyvoj4dwg= = X-Received: from wmbhi10.prod.google.com ([2002:a05:600c:534a:b0:49e:661c:77f4]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:3b87:b0:49e:6c9b:4e94 with SMTP id 5b1f17b1804b1-49eb73308bemr44031795e9.28.1789570051918; Wed, 16 Sep 2026 07:47:31 -0700 (PDT) Date: Wed, 16 Sep 2026 16:46:53 +0200 In-Reply-To: <20260916144647.2651379-11-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260916144647.2651379-11-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=2274; i=ardb@kernel.org; h=from:subject; bh=dlXdLd0hhW7NlWGwnSX6SvP8+eAGOum46CB1gc4SNxc=; b=owGbwMvMwCVmkMcZplerG8N4Wi2JIWvV6nuhlcpndC5+UPqwZpVFuYsFq30/27SrRmt/2V4+o Z185rxSRykLgxgXg6yYIovA7L/vdp6eKFXrPEsWZg4rE8gQBi5OAZjIUg1GhnV7TZZtXR50v5TT qEym9q6KdwqP0d6HAe3Jv31WlU6Res3IMKH07bnb09Tm6257Mdmf5+qXGF/+R+btt/e99gqvr3s azQAA X-Mailer: git-send-email 2.55.0.1032.g73a4cd73de-goog Message-ID: <20260916144647.2651379-16-ardb+git@google.com> Subject: [PATCH v3 5/9] efi/libstub: Avoid efi_puts() for compile time constant strings From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Vincent Mailhol Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ard Biesheuvel efi_puts() performs a UTF-8 to UTF-16 conversion on its input, as the EFI console's native character set is UTF-16. This is pointless for compile time constant strings, since we can simply define those as UTF-16 to begin with. This takes slightly more space, but removes any runtime handling of those strings, simplifying the code. Note that efi_puts() also performs LF to CR-LF conversion, so this needs to be taken into account as well. Signed-off-by: Ard Biesheuvel Reviewed-by: Vincent Mailhol --- drivers/firmware/efi/libstub/gop.c | 6 +++--- drivers/firmware/efi/libstub/printk.c | 4 ++-- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/drivers/firmware/efi/libstub/gop.c b/drivers/firmware/efi/libs= tub/gop.c index 80dc8cfeb33e..6919e28ba92b 100644 --- a/drivers/firmware/efi/libstub/gop.c +++ b/drivers/firmware/efi/libstub/gop.c @@ -309,12 +309,12 @@ static u32 choose_mode_list(efi_graphics_output_proto= col_t *gop) efi_status_t status; =20 efi_printk("Available graphics modes are 0-%u\n", max_mode-1); - efi_puts(" * =3D current mode\n" - " - =3D unusable mode\n"); + efi_char16_puts(L" * =3D current mode\r\n" + " - =3D unusable mode\r\n"); =20 choose_mode(gop, match_list, (void *)cur_mode); =20 - efi_puts("\nPress any key to continue (or wait 10 seconds)\n"); + efi_char16_puts(L"\r\nPress any key to continue (or wait 10 seconds)\r\n"= ); status =3D efi_wait_for_key(10 * EFI_USEC_PER_SEC, &key); if (status !=3D EFI_SUCCESS && status !=3D EFI_TIMEOUT) { efi_err("Unable to read key, continuing in 10 seconds\n"); diff --git a/drivers/firmware/efi/libstub/printk.c b/drivers/firmware/efi/l= ibstub/printk.c index bc599212c05d..f36639886d00 100644 --- a/drivers/firmware/efi/libstub/printk.c +++ b/drivers/firmware/efi/libstub/printk.c @@ -136,7 +136,7 @@ int efi_printk(const char *fmt, ...) return 0; =20 if (loglevel >=3D 0) - efi_puts("EFI stub: "); + efi_char16_puts(L"EFI stub: "); =20 fmt =3D printk_skip_level(fmt); =20 @@ -146,7 +146,7 @@ int efi_printk(const char *fmt, ...) =20 efi_puts(printf_buf); if (printed >=3D sizeof(printf_buf)) { - efi_puts("[Message truncated]\n"); + efi_char16_puts(L"[Message truncated]\r\n"); return -1; } =20 --=20 2.55.0.1032.g73a4cd73de-goog From nobody Fri Sep 25 04:38:15 2026 Received: from mail-wr1-f71.google.com (mail-wr1-f71.google.com [209.85.221.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3F09736E473 for ; Wed, 16 Sep 2026 14:47:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.71 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789570057; cv=none; b=Yu138rwXUn+LxT4Kku4SxthK26EL5vdHYAAOnUcK54lDfUyeTZv1TMeo1/J0SHoVQZV9MT5ySOmHclgPc8VsfIXsBmm0r2239sIOpH6vtV2GDiILaKiHEATUhHZEj5h4JHQR70alktk4kb/a3BnnHHBhCf7mQn4cZ/VPArlVKt8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789570057; c=relaxed/simple; bh=RC7T2Rmxs3lTW7BX95UVBrLsNYd7YzAOK15o4EuF3gk=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=dTd56gZfPSXLrfrRS1tmi6yUomGDCssWgCr6/IDTBUB79DSlBoiWXUBH5fbelsm26sJ6CZrL5X5f5M3pZ1VCPOh7CLGtY2vXiC14/2O2vcq9oiuqVVKb0C+Q4IlozJ3PbJItx2vh8aGLGCEIBrmKyK41rNyMfNjMXBBzslg2puo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=V6GbdHiW; arc=none smtp.client-ip=209.85.221.71 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="V6GbdHiW" Received: by mail-wr1-f71.google.com with SMTP id ffacd0b85a97d-486f768517dso3102136f8f.1 for ; Wed, 16 Sep 2026 07:47:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789570053; x=1790174853; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=xYoVbSFON1AAEit9fkW19VQs/jjZSOyS/18YO9M94EE=; b=V6GbdHiWA3roOvYYGqTxfGcLgHsSX8dyDgc6kv1Z/yM2+6QDYUBYH7YybJ509aXdTA LvpauNX6qcdfaRPMemtrY9QPQVZuGLZlFWjrmBcfBOMgCMjH4+s/C1xECyN3AUpS04as qlRRmYo35sEnZUgcgKNRYQkq/Wl3tFWSMfKRBA1G/n9AWYWzp8fqQowl61WZd1izU4DN GHmd7/sFDQQEzW6oKDgk24aZ9CEUpP87p9/OgfYWs3HsvAoFRv8RK/mMNkPAg9kHpr0I n7bB58PVfGEE75R0sEsvu1za9HUpOd14BPqkzaQ4vO7Ycvqs11fw0fE+5VJH5cohv5XG RxlA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789570053; x=1790174853; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=xYoVbSFON1AAEit9fkW19VQs/jjZSOyS/18YO9M94EE=; b=APcKETVeEGh13t2sTH6E+LMFT4CKdloTsWk3AtAKgkfSJMCy89yBljS5Bb8hBuBptV 30r67+bOoEnj6ipH3UL12lGGi9hhyygIkTeWR5MlY5ShoUfguKBJr2Whuqwx2DWQ8bOW VfdQnp5cT/9it/KbmzfiYlaFDe4n3NMJfXsv1XekTA+vttPJFpnHkMnef8dqIsHiVzMe Bp29D5Bea0fH0feJeaUGTusBNBcH26FUETdE0khl2sEx/Jw/Jrx2L1hMyyhe482t/Gxu qVJkJC5TgjR3u4DA7lP56iQ3lls7GtY9NSet9o1WdOzIV/u8uDHZEyWOI4WjIstO2kuw MggQ== X-Gm-Message-State: AFuF++m7xNjXCIlkcL/3+Comsuff9KPaXA/MNjBMv5iAQ9HSwtXkGFIY BPBfD9FPB6ZQT0mcUxzu0zP+X9WUfxSk8IZAdOv8Q0FKNN4Z84N4GudD1YEe1Rig3VqzUbz9BQ= = X-Received: from wrwk16.prod.google.com ([2002:a5d:66d0:0:b0:483:3694:8d57]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:adf:e00a:0:20b0:487:bef:31cb with SMTP id ffacd0b85a97d-4870d05afb7mr6086738f8f.22.1789570053201; Wed, 16 Sep 2026 07:47:33 -0700 (PDT) Date: Wed, 16 Sep 2026 16:46:54 +0200 In-Reply-To: <20260916144647.2651379-11-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260916144647.2651379-11-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=9530; i=ardb@kernel.org; h=from:subject; bh=njHq+zVwhE6fZuDTSWDdHK03zgqP3QQxK8MBgkBFM+g=; b=owGbwMvMwCVmkMcZplerG8N4Wi2JIWvV6gc18htdHb4v4en22mD+su/O7g7OSq3znYorJt+Zz P/TYN7JjlIWBjEuBlkxRRaB2X/f7Tw9UarWeZYszBxWJpAhDFycAjAR5psM//0LdhXkBf6ef4jN aepEs4QVv62VHASTNCc+lVL3yt1/y4Lhf8Fj6YqtSRE8234xSv6uelnWdvKvwMmwmqBts4t17Uq O8QAA X-Mailer: git-send-email 2.55.0.1032.g73a4cd73de-goog Message-ID: <20260916144647.2651379-17-ardb+git@google.com> Subject: [PATCH v3 6/9] efi/libstub: Output UTF-16 directly from vsnprintf() From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Vincent Mailhol Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ard Biesheuvel The only remaining users of vsnprintf() in the EFI stub are the diagnostic printk()'s, which are emitted to the console and not recorded for posterity. The EFI console uses UTF-16 (or actually, UCS-2) natively, and so all non-UTF16 strings that are emitted need to be converted. Given the stub's vsnprintf() support for wide strings (using the %ls conversion modifier), which uses UTF-16 to UTF-8 conversion internally, the final conversion to UTF-16 needs to support not just plain ASCII but UTF-8 as well. This is all pointless, of course, and it makes more sense to use UTF-16 internally. This removes the need for UTF-16 to UTF-8 conversion in vsnprintf(), and given that all non-wide string inputs to vsnprintf() that exist in the stub today are compile time constant ASCII strings, the need to convert UTF-8 to UTF-16 disappears as well. So implement efi_vsnprintf() taking a const char *fmt as before, but outputting a efi_char16_t[] that can be passed to the EFI console directly, rather than via efi_puts(), leaving the latter unused and therefore removed. Note that efi_puts() performs LF to CR-LF conversion internally, so add this capability to efi_vsnprintf() as well. Signed-off-by: Ard Biesheuvel Reviewed-by: Vincent Mailhol --- drivers/firmware/efi/libstub/efistub.h | 5 +- drivers/firmware/efi/libstub/printk.c | 91 ++----------------- drivers/firmware/efi/libstub/vsprintf.c | 96 +++----------------- 3 files changed, 22 insertions(+), 170 deletions(-) diff --git a/drivers/firmware/efi/libstub/efistub.h b/drivers/firmware/efi/= libstub/efistub.h index fd91fc15ec81..36056c624782 100644 --- a/drivers/firmware/efi/libstub/efistub.h +++ b/drivers/firmware/efi/libstub/efistub.h @@ -1078,9 +1078,10 @@ efi_status_t check_platform_features(void); =20 void *get_efi_config_table(efi_guid_t guid); =20 -/* NOTE: These functions do not print a trailing newline after the string = */ void efi_char16_puts(efi_char16_t *); -void efi_puts(const char *str); + +int efi_vsnprintf(efi_char16_t *buf, size_t size, const char *fmt, va_list= ap, + bool crlf); =20 __printf(1, 2) int efi_printk(char const *fmt, ...); =20 diff --git a/drivers/firmware/efi/libstub/printk.c b/drivers/firmware/efi/l= ibstub/printk.c index f36639886d00..0a18cfe32528 100644 --- a/drivers/firmware/efi/libstub/printk.c +++ b/drivers/firmware/efi/libstub/printk.c @@ -23,98 +23,20 @@ void efi_char16_puts(efi_char16_t *str) output_string, str); } =20 -static -u32 utf8_to_utf32(const u8 **s8) -{ - u32 c32; - u8 c0, cx; - size_t clen, i; - - c0 =3D cx =3D *(*s8)++; - /* - * The position of the most-significant 0 bit gives us the length of - * a multi-octet encoding. - */ - for (clen =3D 0; cx & 0x80; ++clen) - cx <<=3D 1; - /* - * If the 0 bit is in position 8, this is a valid single-octet - * encoding. If the 0 bit is in position 7 or positions 1-3, the - * encoding is invalid. - * In either case, we just return the first octet. - */ - if (clen < 2 || clen > 4) - return c0; - /* Get the bits from the first octet. */ - c32 =3D cx >> clen--; - for (i =3D 0; i < clen; ++i) { - /* Trailing octets must have 10 in most significant bits. */ - cx =3D (*s8)[i] ^ 0x80; - if (cx & 0xc0) - return c0; - c32 =3D (c32 << 6) | cx; - } - /* - * Check for validity: - * - The character must be in the Unicode range. - * - It must not be a surrogate. - * - It must be encoded using the correct number of octets. - */ - if (c32 > 0x10ffff || - (c32 & 0xf800) =3D=3D 0xd800 || - clen !=3D (c32 >=3D 0x80) + (c32 >=3D 0x800) + (c32 >=3D 0x10000)) - return c0; - *s8 +=3D clen; - return c32; -} - -/** - * efi_puts() - Write a UTF-8 encoded string to the console - * @str: UTF-8 encoded string - */ -void efi_puts(const char *str) -{ - efi_char16_t buf[128]; - size_t pos =3D 0, lim =3D ARRAY_SIZE(buf); - const u8 *s8 =3D (const u8 *)str; - u32 c32; - - while (*s8) { - if (*s8 =3D=3D '\n') - buf[pos++] =3D L'\r'; - c32 =3D utf8_to_utf32(&s8); - if (c32 < 0x10000) { - /* Characters in plane 0 use a single word. */ - buf[pos++] =3D c32; - } else { - /* - * Characters in other planes encode into a surrogate - * pair. - */ - buf[pos++] =3D (0xd800 - (0x10000 >> 10)) + (c32 >> 10); - buf[pos++] =3D 0xdc00 + (c32 & 0x3ff); - } - if (*s8 =3D=3D '\0' || pos >=3D lim - 2) { - buf[pos] =3D L'\0'; - efi_char16_puts(buf); - pos =3D 0; - } - } -} - /** * efi_printk() - Print a kernel message * @fmt: format string * * The first letter of the format string is used to determine the logging = level * of the message. If the level is less then the current EFI logging level= , the - * message is suppressed. The message will be truncated to 255 bytes. + * message is suppressed. The message will be truncated to 255 characters + * (ignoring surrogates). * * Return: number of printed characters */ int efi_printk(const char *fmt, ...) { - char printf_buf[256]; + efi_char16_t printf_buf[256]; va_list args; int printed; int loglevel =3D printk_get_level(fmt); @@ -141,11 +63,12 @@ int efi_printk(const char *fmt, ...) fmt =3D printk_skip_level(fmt); =20 va_start(args, fmt); - printed =3D vsnprintf(printf_buf, sizeof(printf_buf), fmt, args); + printed =3D efi_vsnprintf(printf_buf, ARRAY_SIZE(printf_buf), fmt, args, + true); va_end(args); =20 - efi_puts(printf_buf); - if (printed >=3D sizeof(printf_buf)) { + efi_char16_puts(printf_buf); + if (printed >=3D ARRAY_SIZE(printf_buf)) { efi_char16_puts(L"[Message truncated]\r\n"); return -1; } diff --git a/drivers/firmware/efi/libstub/vsprintf.c b/drivers/firmware/efi= /libstub/vsprintf.c index dba136679172..bd32af6b4f4d 100644 --- a/drivers/firmware/efi/libstub/vsprintf.c +++ b/drivers/firmware/efi/libstub/vsprintf.c @@ -14,10 +14,14 @@ =20 #include #include +#include #include #include #include #include +#include + +#include "efistub.h" =20 static int skip_atoi(const char **s) @@ -239,58 +243,6 @@ char get_sign(long long *num, int flags) return 0; } =20 -static -size_t utf16s_utf8nlen(const u16 *s16, size_t maxlen) -{ - size_t len, clen; - - for (len =3D 0; len < maxlen && *s16; len +=3D clen) { - u16 c0 =3D *s16++; - - /* First, get the length for a BMP character */ - clen =3D 1 + (c0 >=3D 0x80) + (c0 >=3D 0x800); - if (len + clen > maxlen) - break; - /* - * If this is a high surrogate, and we're already at maxlen, we - * can't include the character if it's a valid surrogate pair. - * Avoid accessing one extra word just to check if it's valid - * or not. - */ - if ((c0 & 0xfc00) =3D=3D 0xd800) { - if (len + clen =3D=3D maxlen) - break; - if ((*s16 & 0xfc00) =3D=3D 0xdc00) { - ++s16; - ++clen; - } - } - } - - return len; -} - -static -u32 utf16_to_utf32(const u16 **s16) -{ - u16 c0, c1; - - c0 =3D *(*s16)++; - /* not a surrogate */ - if ((c0 & 0xf800) !=3D 0xd800) - return c0; - /* invalid: low surrogate instead of high */ - if (c0 & 0x0400) - return 0xfffd; - c1 =3D **s16; - /* invalid: missing low surrogate */ - if ((c1 & 0xfc00) !=3D 0xdc00) - return 0xfffd; - /* valid surrogate pair */ - ++(*s16); - return (0x10000 - (0xd800 << 10) - 0xdc00) + (c0 << 10) + c1; -} - #define PUTC(c) \ do { \ if (pos < size) \ @@ -298,7 +250,8 @@ do { \ ++pos; \ } while (0); =20 -int vsnprintf(char *buf, size_t size, const char *fmt, va_list ap) +int efi_vsnprintf(efi_char16_t *buf, size_t size, const char *fmt, va_list= ap, + bool crlf) { /* The maximum space required is to print a 64-bit number in octal */ char tmp[(sizeof(unsigned long long) * 8 + 2) / 3]; @@ -336,6 +289,8 @@ int vsnprintf(char *buf, size_t size, const char *fmt, = va_list ap) =20 for (pos =3D 0; *fmt; ++fmt) { if (*fmt !=3D '%' || *++fmt =3D=3D '%') { + if (crlf && *fmt =3D=3D '\n') + PUTC('\r'); PUTC(*fmt); continue; } @@ -400,7 +355,7 @@ int vsnprintf(char *buf, size_t size, const char *fmt, = va_list ap) else if (qualifier =3D=3D 'l') { wstring: flags |=3D WIDE; - precision =3D len =3D utf16s_utf8nlen((const u16 *)s, precision); + precision =3D len =3D ucs2_strnlen((const u16 *)s, precision); goto output; } precision =3D len =3D strnlen(s, precision); @@ -505,36 +460,9 @@ int vsnprintf(char *buf, size_t size, const char *fmt,= va_list ap) if (flags & WIDE) { const u16 *ws =3D (const u16 *)s; =20 - while (len-- > 0) { - u32 c32 =3D utf16_to_utf32(&ws); - u8 *s8; - size_t clen; - - if (c32 < 0x80) { - PUTC(c32); - continue; - } - - /* Number of trailing octets */ - clen =3D 1 + (c32 >=3D 0x800) + (c32 >=3D 0x10000); - - len -=3D clen; - s8 =3D (u8 *)&buf[pos]; - - /* Avoid writing partial character */ - PUTC('\0'); - pos +=3D clen; - if (pos >=3D size) - continue; - - /* Set high bits of leading octet */ - *s8 =3D (0xf00 >> 1) >> clen; - /* Write trailing octets in reverse order */ - for (s8 +=3D clen; clen; --clen, c32 >>=3D 6) - *s8-- =3D 0x80 | (c32 & 0x3f); - /* Set low bits of leading octet */ - *s8 |=3D c32; - } + if (pos < size) + memcpy(&buf[pos], ws, min(len, size - pos) * sizeof(*ws)); + pos +=3D len; } else { while (len-- > 0) PUTC(*s++); --=20 2.55.0.1032.g73a4cd73de-goog From nobody Fri Sep 25 04:38:15 2026 Received: from mail-lj1-f197.google.com (mail-lj1-f197.google.com [209.85.208.197]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0BBF9348C6F for ; Wed, 16 Sep 2026 14:54:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.197 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789570490; cv=none; b=Utd1qeKk5CtVZob8iXrKFFpQ9difE5R6AdUG19HynPEm8lI+EY/DUeWL9f6l4nEnhZnPQiXgAQQslgKxnswsCOw45vEyNUSsyObXaE+XIJ8jTQQK9XPONH/mwr3iKP8DVfxz9HGqBYSSNQs4Pjgb2cpVIDXsd2EQ36EvCguxrb8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789570490; c=relaxed/simple; bh=OuZ8FbKxnQyrbFX0fG6Hzht0V5w4fGRW+VAq0BseW9I=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=uWycWrkNUL+BDJIPfp9xkOBN8LxO4P/WiThzYPvXYtygic04U3b3Abtj1Pb0dCwazJM4GZekuS/oZXoczqeKr2v9QPPjKxkFO6fpH9i5Hv1QyQPh1BcCBfyOjNggnZa+kWXGys+fiuSY67DVmrto2rB2SAY61Skml8uV3z2w6pY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=nsD2hd6T; arc=none smtp.client-ip=209.85.208.197 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="nsD2hd6T" Received: by mail-lj1-f197.google.com with SMTP id 38308e7fff4ca-3a5a3189b6fso30664981fa.3 for ; Wed, 16 Sep 2026 07:54:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789570487; x=1790175287; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=n7++c8G2n+1RKQWflt7ZuCXFqKBOkqbx84bi5KofggA=; b=nsD2hd6T2A/qGWHiZHBWNnoPls5+4CWxrfIUT/7nvVw9sNjeR3bsJZB76a1tCRPrxS Lq8tWf5ZxTQteH+QEmki8/p61uCp5FynOPBIlcJPcJFOJB0D6v7Cf0eRwFFMmqKwQ352 ZzvgK+dNcmVBBM7A/SJYMEGglG8gnwNx16wcGQbFTbYViQo4mComRVj1dQVZKH0jdRVe n+yVrc7qxqE13tUU0k0QpvHOJ6WwGeWaV5CKFPrEv+m2OZnnVV+rSOSE0+AT4qOOMyPL CpY8gWsBCTTLPzLyQfhelLKzTjvLpAFqDBr1M13X1Jred6JYnMnX0wiGKDNPpMoGImBm iCpw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789570487; x=1790175287; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=n7++c8G2n+1RKQWflt7ZuCXFqKBOkqbx84bi5KofggA=; b=uKItonuLzOTR91z77LqFW02lvjoXzQWDo8kkqmys3qBs1JubkIsnj4yp+awg9Ye3Jq l7z1HsfyY/HvNPMo5URmlRZmqJM+vRlRKQeYeZGGv7c7FFInR5qYq/fwucSF21bx0Gy3 YJR0Vkn7TThWuF06XPz2vGLnIptTLIgWEuajY6NHtiOBDH69BV24R7EPfi16r1O3E/VN HdMv13pp0MWNrRjL5Yz/5LHDQxFgBJs5iqIIInE5rcsbN5m5/XW3CxwdOuT60LyUs13V 4mu8xjWE5WV96SDfMvv1WUFpE8S5o9UyXAMc82OHEtKF1HA0ei4LRL+gUlL/E8edniVX 63TA== X-Gm-Message-State: AFuF++kVfw0HuXYcRt0yt/TXPHmVIhk/NocZJ6reUwpQ56vx15o3oMIJ ldR8Xxgt8FwZGn8b5rp2H+xZ3Ujm0chmDafUfw+ob8YiUCge9AQNkd5bDCHruImGoHc03XZhJQ= = X-Received: from ejbmj23.prod.google.com ([2002:a17:906:af97:b0:c25:2b28:b647]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a17:907:6092:b0:c16:84dc:9607 with SMTP id a640c23a62f3a-c29e5333df7mr354716466b.19.1789570054133; Wed, 16 Sep 2026 07:47:34 -0700 (PDT) Date: Wed, 16 Sep 2026 16:46:55 +0200 In-Reply-To: <20260916144647.2651379-11-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260916144647.2651379-11-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=2858; i=ardb@kernel.org; h=from:subject; bh=BHh6avMxu3GGP3VARPK44z1/lEJAob47wThf/IcE9TQ=; b=owGbwMvMwCVmkMcZplerG8N4Wi2JIWvV6ocem/s3l94UfLzytF+Uy7KLBrWzpglLPaydfUHRx 33CpHuRHaUsDGJcDLJiiiwCs/++23l6olSt8yxZmDmsTCBDGLg4BWAiR7czMrw8weEyp7PdvC3d vf5vsODExa+1sso8RB4nq04Srk+6d4Dhr7ToUuHJp1tmt8YZreme7lyod3BWWZz7zG3s68yyd5w /xQ0A X-Mailer: git-send-email 2.55.0.1032.g73a4cd73de-goog Message-ID: <20260916144647.2651379-18-ardb+git@google.com> Subject: [PATCH v3 7/9] efi/libstub: Add support for printing human readable GUIDs From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Vincent Mailhol Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ard Biesheuvel Add support for the %pUl printk conversion specifier, which takes a pointer to a GUID and prints it in the usual format: aaaaaaaa-bbbb-cccc-dddd-dddddddddddd Co-developed-by: Vincent Mailhol Signed-off-by: Vincent Mailhol Signed-off-by: Ard Biesheuvel Reviewed-by: Vincent Mailhol --- drivers/firmware/efi/libstub/vsprintf.c | 39 +++++++++++++++++--- 1 file changed, 34 insertions(+), 5 deletions(-) diff --git a/drivers/firmware/efi/libstub/vsprintf.c b/drivers/firmware/efi= /libstub/vsprintf.c index bd32af6b4f4d..54b82ba798a2 100644 --- a/drivers/firmware/efi/libstub/vsprintf.c +++ b/drivers/firmware/efi/libstub/vsprintf.c @@ -113,6 +113,8 @@ char *put_dec(char *end, unsigned long long n) return p; } =20 +static const char digits[16] =3D "0123456789ABCDEF"; + static char *number(char *end, unsigned long long num, int base, char locase) { @@ -121,9 +123,6 @@ char *number(char *end, unsigned long long num, int bas= e, char locase) * produces same digits or (maybe lowercased) letters */ =20 - /* we are called with base 8, 10 or 16, only, thus don't need "G..." */ - static const char digits[16] =3D "0123456789ABCDEF"; /* "GHIJKLMNOPQRSTUV= WXYZ"; */ - switch (base) { case 10: if (num !=3D 0) @@ -144,6 +143,29 @@ char *number(char *end, unsigned long long num, int ba= se, char locase) return end; } =20 +static char *guid_to_str(const efi_guid_t *guid, char *out, char locase) +{ + static const u8 guid_index[UUID_SIZE] =3D { + 3, 2, 1, 0, 5, 4, 7, 6, 8, 9, 10, 11, 12, 13, 14, 15, + }; + + for (int i =3D 0, p =3D 0; i < ARRAY_SIZE(guid_index); i++) { + u8 byte =3D guid->b[guid_index[i]]; + + out[p++] =3D locase | digits[byte >> 4]; + out[p++] =3D locase | digits[byte & 0xf]; + + switch (i) { + case 3: + case 5: + case 7: + case 9: + out[p++] =3D '-'; + } + } + return out; +} + #define ZEROPAD 1 /* pad with zero */ #define SIGN 2 /* unsigned/signed long */ #define PLUS 4 /* show plus */ @@ -253,8 +275,7 @@ do { \ int efi_vsnprintf(efi_char16_t *buf, size_t size, const char *fmt, va_list= ap, bool crlf) { - /* The maximum space required is to print a 64-bit number in octal */ - char tmp[(sizeof(unsigned long long) * 8 + 2) / 3]; + char tmp[UUID_STRING_LEN]; char *tmp_end =3D &tmp[ARRAY_SIZE(tmp)]; long long num; int base; @@ -367,6 +388,14 @@ int efi_vsnprintf(efi_char16_t *buf, size_t size, cons= t char *fmt, va_list ap, break; =20 case 'p': + if (fmt[1] =3D=3D 'U' && (fmt[2] | 0x20) =3D=3D 'l') { + flags &=3D LEFT; + s =3D guid_to_str(va_arg(args, efi_guid_t *), tmp, fmt[2] & 0x20); + precision =3D len =3D UUID_STRING_LEN; + fmt +=3D 2; + goto output; + } + if (precision < 0) precision =3D 2 * sizeof(void *); fallthrough; --=20 2.55.0.1032.g73a4cd73de-goog From nobody Fri Sep 25 04:38:15 2026 Received: from mail-wm1-f69.google.com (mail-wm1-f69.google.com [209.85.128.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 21283331EB0 for ; Wed, 16 Sep 2026 14:47:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.69 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789570059; cv=none; b=LbTmIZom2ySEbusa183kPw4zTcsMEjFrI5WMR3k/rkzvP1ikHmLE1z06jHm2MyV+OlzGHPZZuOTA9F2ec8jdT+7rEefbZe/kNz47J5S9y9omkMHZMh5h7tQG22jARihQEqBrBKXXyn5M8HOmbBUX0xfNfPSE0vy7UKMN23gPPCc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789570059; c=relaxed/simple; bh=bIJT8uMDZTPbPgXrXoz9RnHI2oQQ5zLTI3zimM37reo=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=YD8c+vCgv1mSd0f8OWClwPSe5pSVaAHSTvoJM5GBahdjCdr8w4OO1dLlLqp1/eiOaxViDsFpmfbWpfRWycDoSbUgQytScXYYQsd0Fs+xEz0Lfc045aqXUpUniNBY08b/VRuq5UJIhc0N7dHDWp4I4ZV6demCQCnP0LIXmibLGL4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=NsKcyqb4; arc=none smtp.client-ip=209.85.128.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="NsKcyqb4" Received: by mail-wm1-f69.google.com with SMTP id 5b1f17b1804b1-495689bfcc8so47448345e9.1 for ; Wed, 16 Sep 2026 07:47:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789570055; x=1790174855; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=3jhe110S+2cKvT84ngsYWk0WnYvffWOvM3X507E5BdI=; b=NsKcyqb45ucdRr+VxafTi5RmAMutKZHZHAkD1d4Pi9aIX0IzgXnQAem162CSiLmzw9 /c1HL+RC8cn9hNomTFuleFwR8YsPVFZyR1MRbFOYqzcAr2YYY1KiQaZUf18XX1QkyuYG +vcZDuUcBmTurrMbFTeawTVsT15OyCWks/bQdYaYlDiXSw0+BcyNP9V8J7S3BD4LakJR //VH6tyW0g3i+NSa9IhNzYiZSxQLAeiA2gIvY4eWe/X9GdgnTnduuCyeX43pXNhimHs/ X4cgvYUJOSSnPK9V69hzUYIBZTfLyW9vpuxREbkhnmVmgINXLXNvpFXPTfasLwBEPffn fAXA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789570055; x=1790174855; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=3jhe110S+2cKvT84ngsYWk0WnYvffWOvM3X507E5BdI=; b=McW7aOljxSCR5C6y3D6M4WxWv6Ku8wsyxqhx01zH8gIw+yXORK4UaKBvb5TN4Tn1QY 4S09sJZvF2oBCX8VB/jTjVAysRTQ4fe5a8H4q4yONCWIe6RN5pM2bkuyy1pfK9hsA215 +E1dtRVHTk4atfvxmljWDqgpq8mkfx6b4N77+k112h1sD2UAJZF1rtbbibCZfDVdH9wr 97oMXuYuLrddfS/8vMQxrbWenyf8OsnOjYlILLW5Z4Ljb7cxIsx6y4WzMppu+8hDj2Zo nSo1duiAzCfY9EUh2f57TnD578konYuOL+uUhBpzJqGksGQfco0h4u8qxNdlh5f9SkKT q1pw== X-Gm-Message-State: AFuF++mi15s7nAP4skX2Bt/zqIITmN+Jc+BHRCCP6B34VWHlSqKh5GI6 XPQq++uEXNaN/6FPvI8okXOugeceEC0nDKw+VHriONNK4kOzMwVnJ8BqtW/tnJ3xzsj4eNH9Bw= = X-Received: from wmsm42.prod.google.com ([2002:a05:600c:3b2a:b0:49e:6640:5820]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:3547:b0:49c:f4e1:4c2d with SMTP id 5b1f17b1804b1-49eb732633bmr33661035e9.16.1789570055212; Wed, 16 Sep 2026 07:47:35 -0700 (PDT) Date: Wed, 16 Sep 2026 16:46:56 +0200 In-Reply-To: <20260916144647.2651379-11-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260916144647.2651379-11-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=1793; i=ardb@kernel.org; h=from:subject; bh=otson7pfhqSkY1QgbBEJDWS7yLkDvmJ6XHiMyvjC6Nk=; b=owGbwMvMwCVmkMcZplerG8N4Wi2JIWvV6keqHpt3XLg5//fp7Ed31t//tbBlenkyj6uSFs+2W 45HAt84d5SyMIhxMciKKbIIzP77bufpiVK1zrNkYeawMoEMYeDiFICJnFdlZNh35L792WdGd9d+ qfz97KbQd7X2nedWxJhJnc7h0ytjuF/F8D81Kvrj8yNbDYy3zTqwXjvGdJugWUftgey7F/yYvKe 5L+MFAA== X-Mailer: git-send-email 2.55.0.1032.g73a4cd73de-goog Message-ID: <20260916144647.2651379-19-ardb+git@google.com> Subject: [PATCH v3 8/9] efi/libstub: Add efi_snprintf() to construct wide strings From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Vincent Mailhol Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ard Biesheuvel The native EFI character set is UTF-16 (or in practice, UCS-2). Implement efi_snprintf() to construct UTF-16 strings using printf style templates. This will be used in a subsequent patch to set the LoaderDevicePartUUID EFI variable. Link: https://lore.kernel.org/all/20260903-efi_stub_bli-v2-1-dbf7ba915117@k= ernel.org/ Signed-off-by: Ard Biesheuvel Reviewed-by: Vincent Mailhol --- drivers/firmware/efi/libstub/efistub.h | 1 + drivers/firmware/efi/libstub/vsprintf.c | 11 +++++++++++ 2 files changed, 12 insertions(+) diff --git a/drivers/firmware/efi/libstub/efistub.h b/drivers/firmware/efi/= libstub/efistub.h index 36056c624782..880c1d0c464b 100644 --- a/drivers/firmware/efi/libstub/efistub.h +++ b/drivers/firmware/efi/libstub/efistub.h @@ -1084,6 +1084,7 @@ int efi_vsnprintf(efi_char16_t *buf, size_t size, con= st char *fmt, va_list ap, bool crlf); =20 __printf(1, 2) int efi_printk(char const *fmt, ...); +__printf(3, 4) int efi_snprintf(efi_char16_t *buf, size_t size, const char= *fmt, ...); =20 void efi_free(unsigned long size, unsigned long addr); DEFINE_FREE(efi_pool, void *, if (_T) efi_bs_call(free_pool, _T)); diff --git a/drivers/firmware/efi/libstub/vsprintf.c b/drivers/firmware/efi= /libstub/vsprintf.c index 54b82ba798a2..071c8b245b68 100644 --- a/drivers/firmware/efi/libstub/vsprintf.c +++ b/drivers/firmware/efi/libstub/vsprintf.c @@ -508,3 +508,14 @@ int efi_vsnprintf(efi_char16_t *buf, size_t size, cons= t char *fmt, va_list ap, =20 return pos; } + +int efi_snprintf(efi_char16_t *buf, size_t size, const char *fmt, ...) +{ + va_list args; + int i; + + va_start(args, fmt); + i =3D efi_vsnprintf(buf, size, fmt, args, false); + va_end(args); + return i; +} --=20 2.55.0.1032.g73a4cd73de-goog From nobody Fri Sep 25 04:38:15 2026 Received: from mail-wm1-f70.google.com (mail-wm1-f70.google.com [209.85.128.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 473F537A857 for ; Wed, 16 Sep 2026 14:47:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.70 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789570060; cv=none; b=BLQJI3DDyO0UYreFN9cjdmmTUlJS8HEd9DShU/AlP6x8hMcqaOJHXVRmzrKAyt6pJ0tyzjmkEqbs9k2Bp9fXwogltLsQfpD3yLYEZBmY3Ab4V8ymQKoAIZykKLCgXPR8+Byxh+8BJGvKuSDalCAu7eQjOFJFz1MKF+7w8zWKeNU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789570060; c=relaxed/simple; bh=Z/PHy8SqOY039ZfzHL4rdkKTKv2Tm1OexHtDCOj+1Zo=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=Rk3EZVg81DJ/M0a69vWlmHTnGmx/dUQ7StpILuAHM5cJKyEMAAaLRZYR1vVZjmo/fHqmR9QNJfB4SSARqiKDYTD/FckuqDRfdMtp2FPlpyCicVbxM6p90+9IYOpu60cZA/sYY3noOhfxk97dy9cxg+l4FfXWihdox9fzaK+nTHs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=cF5Erw+u; arc=none smtp.client-ip=209.85.128.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="cF5Erw+u" Received: by mail-wm1-f70.google.com with SMTP id 5b1f17b1804b1-49b0e6638e3so51384655e9.2 for ; Wed, 16 Sep 2026 07:47:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789570056; x=1790174856; darn=vger.kernel.org; h=content-transfer-encoding:content-type:cc:to:from:subject :message-id:references:mime-version:in-reply-to:date:from:to:cc :subject:date:message-id:reply-to:content-type; bh=ZM3fU71DKklu1u+zDqECfkv49Iwpg2mCdspvEHepLy4=; b=cF5Erw+umUYbkRqqX+ckgZPQExZ5ps3OIaRic/OBIDjNarU9ARTl1huomfuarlKq7v M6l8BLG4EybH1lnR60fYfg8xRbs6jR5f6bRVwD88MXNn7LegqYodWClTWyulS9gwgmae XCYndJHVMDhA4pDEjNscx99H+5coI92kYOnTdiPNJt7MGTLEp2LKNM2+G0Nu+zGf6fwu YU35UWQMrunMBPMcp8dsfOsY6QYrM/WZwoelTFO7Rjl/ubyhIp5wRrD+Sv7o1jQe1oGr UqgQxX8gmN0RI+Qfk+dIgS9kbGqIbpwFhep5ZveR3KgkkA15rTlTxPSB3yPQ2nfq/6n9 9jDQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789570056; x=1790174856; h=content-transfer-encoding:content-type:cc:to:from:subject :message-id:references:mime-version:in-reply-to:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=ZM3fU71DKklu1u+zDqECfkv49Iwpg2mCdspvEHepLy4=; b=CVCoFZ+1eKbwuX1AiH+9LutzqiW6KR08mhHzINH221mBnQzz0rcfbPdc10NUdknTWW qDKZ/Zg6LmtNI1AZc5pcCbM8ZRQGDtaSFMfWsyPQ5xTNunaCDfAGe4cSHz6ZHc+8/NYZ tYxoHhwxYPXZGSHJwTozdP6xAtMX/6CmEIzONecFo9zfybI3Jyc6t5ZEPm7blWX9uB0V yxc1UlSjqhhhLj4a0rV+beSgQ1q+AG8wfHd3CkZg/UnItoag3ZGC6s/C21CtuPvPMV5J KfOQGfkxJ8ij5JQhPI7VRh31HLxZzcbC5ntUTAmoDbFVp9Z1cf85RBg0/+ls///Xj1YW nWMA== X-Gm-Message-State: AFuF++kBF80rSZN5wIUAPGnovZUed0Zcz5A1RME9fbHiMruZE8tfxN6c JTbL7XrgtLxQcMzY3WWtbuxQWkl/nxbXPCNZH5uuJ8vGVLRb+RRGFRaapeZhKABFOIXC4EzvXA= = X-Received: from wmbf2.prod.google.com ([2002:a05:600c:5942:b0:499:4c8d:551f]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:8b58:b0:49c:fa21:e749 with SMTP id 5b1f17b1804b1-49eb733e3b5mr35778325e9.31.1789570056169; Wed, 16 Sep 2026 07:47:36 -0700 (PDT) Date: Wed, 16 Sep 2026 16:46:57 +0200 In-Reply-To: <20260916144647.2651379-11-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260916144647.2651379-11-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=8323; i=ardb@kernel.org; h=from:subject; bh=NfkFq12GKt3yz40ChbwrvQeuiqCTEPkRCNxLFhlu1HY=; b=owGbwMvMwCVmkMcZplerG8N4Wi2JIWvV6idLbji1b+ZnEToufergu00R0bPa5zzS2pO1/n8xX 9FEr+0GHaUsDGJcDLJiiiwCs/++23l6olSt8yxZmDmsTCBDGLg4BWAip+4y/NOvPpu746Dd90vf zpRv25uprXNpqbxQaPXk6+/untJf1DGb4Q+nT5l98nT5yYH3S5kvLjPfZ5S04Eb429OFoo5bP7x yd2YCAA== X-Mailer: git-send-email 2.55.0.1032.g73a4cd73de-goog Message-ID: <20260916144647.2651379-20-ardb+git@google.com> Subject: [PATCH v3 9/9] efi/libstub: add initial Boot Loader Interface support From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , Vincent Mailhol Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Vincent Mailhol The Boot Loader Interface (BLI) [1] defines EFI variables that expose boot loader state to the running OS. LoaderInfo identifies the boot loader, while LoaderDevicePartUUID records the GPT partition UUID of the partition containing it. LoaderDevicePartUUID is used, for example, by systemd-gpt-auto-generator [2] to identify the disk the boot loader was launched from and automatically detect and mount partitions on it. GRUB [3] and systemd-boot [4] populate these variables, but when the kernel is started directly by EFI firmware, there is no conventional external boot loader to provide them. In that case, because the EFI stub performs the boot loader role, it should provide the variables itself. Use LoaderInfo as a sentinel: if it is already set by an earlier boot stage or cannot be set, bail out. Otherwise, populate the other BLI variables. Parse the loaded image device path, extract the GUID signature from its GPT HD() node and publish it under the Linux loader entry vendor GUID as the volatile LoaderDevicePartUUID EFI variable. Install the efi_bli_set_variables() hook in both the generic efi-stub.c path and the x86-specific x86-stub.c path. [1] The Boot Loader Interface Link: https://systemd.io/BOOT_LOADER_INTERFACE/ [2] systemd-gpt-auto-generator Link: https://www.freedesktop.org/software/systemd/man/latest/systemd-gpt-a= uto-generator.html [3] GRUB -- =C2=A716.2 bli Link: https://www.gnu.org/software/grub/manual/grub/html_node/bli_005fmodul= e.html [4] systemd -- systemd-boot UEFI Boot Manager Link: https://github.com/systemd/systemd/blob/main/docs/BOOT.md?plain=3D1#L= 102 Signed-off-by: Vincent Mailhol [ardb: - constify 'image' pointer parameter - pass efi_guid_t* to efi_snprintf()] Signed-off-by: Ard Biesheuvel Reviewed-by: Vincent Mailhol --- drivers/firmware/efi/libstub/Makefile | 2 +- drivers/firmware/efi/libstub/bli.c | 87 ++++++++++++++++++++ drivers/firmware/efi/libstub/efi-stub.c | 1 + drivers/firmware/efi/libstub/efistub.h | 2 + drivers/firmware/efi/libstub/x86-stub.c | 1 + include/linux/efi.h | 22 +++++ 6 files changed, 114 insertions(+), 1 deletion(-) diff --git a/drivers/firmware/efi/libstub/Makefile b/drivers/firmware/efi/l= ibstub/Makefile index 12c0c7deb5cb..564773c89d14 100644 --- a/drivers/firmware/efi/libstub/Makefile +++ b/drivers/firmware/efi/libstub/Makefile @@ -66,7 +66,7 @@ KBUILD_AFLAGS :=3D $(KBUILD_CFLAGS) -D__ASSEMBLY__ lib-y :=3D efi-stub-helper.o gop.o secureboot.o tpm.o \ file.o mem.o random.o randomalloc.o pci.o \ skip_spaces.o lib-cmdline.o lib-ctype.o \ - alignedmem.o printk.o vsprintf.o \ + alignedmem.o printk.o vsprintf.o bli.o \ lib-ucs2_string.o =20 # include the stub's libfdt dependencies from lib/ when needed diff --git a/drivers/firmware/efi/libstub/bli.c b/drivers/firmware/efi/libs= tub/bli.c new file mode 100644 index 000000000000..b2407f63b743 --- /dev/null +++ b/drivers/firmware/efi/libstub/bli.c @@ -0,0 +1,87 @@ +// SPDX-License-Identifier: GPL-2.0 + +#include + +#include +#include +#include + +#include "efistub.h" + +static efi_guid_t loader_entry_guid =3D LINUX_EFI_LOADER_ENTRY_GUID; + +static const struct efi_hd_dev_path * +efi_bli_find_hd_node(const struct efi_dev_path *path) +{ + const struct efi_dev_path *node; + u16 node_len; + + for (node =3D path; + node->header.type !=3D EFI_DEV_END_PATH && + node->header.type !=3D EFI_DEV_END_PATH2; + node =3D (const void *)node + node_len) { + node_len =3D get_unaligned_le16(&node->header.length); + + if (node_len < sizeof(node->header)) + return NULL; + + if (node->header.type !=3D EFI_DEV_MEDIA || + node->header.sub_type !=3D EFI_DEV_MEDIA_HARD_DRIVE) + continue; + + if (node_len < sizeof(node->hd)) + return NULL; + + if (node->hd.partition_format !=3D EFI_HD_PARTITION_FORMAT_GPT || + node->hd.signature_type !=3D EFI_HD_SIGNATURE_TYPE_GUID) + continue; + + return &node->hd; + } + + return NULL; +} + +static void efi_bli_populate_loader_part_uuid(const efi_loaded_image_t *im= age) +{ + static efi_guid_t device_path_guid =3D EFI_DEVICE_PATH_PROTOCOL_GUID; + efi_char16_t partuuid[UUID_STRING_LEN + 1]; + const struct efi_hd_dev_path *hd_node; + const struct efi_dev_path *path; + + if (efi_bs_call(handle_protocol, efi_table_attr(image, device_handle), + &device_path_guid, (void **)&path) !=3D EFI_SUCCESS) + return; + + hd_node =3D efi_bli_find_hd_node(path); + if (!hd_node) + return; + + if (efi_snprintf(partuuid, ARRAY_SIZE(partuuid), "%pUl", + &hd_node->signature) !=3D UUID_STRING_LEN) + return; + + set_efi_var(L"LoaderDevicePartUUID", &loader_entry_guid, + EFI_VARIABLE_BOOTSERVICE_ACCESS | EFI_VARIABLE_RUNTIME_ACCESS, + sizeof(partuuid), partuuid); +} + +void efi_bli_set_variables(const efi_loaded_image_t *image) +{ + static efi_char16_t loader_info[] =3D L"Linux EFI stub " UTS_RELEASE; + unsigned long size =3D 0; + + if (!image) + return; + + if (get_efi_var(L"LoaderInfo", &loader_entry_guid, + NULL, &size, NULL) !=3D EFI_NOT_FOUND) + return; + + if (set_efi_var(L"LoaderInfo", &loader_entry_guid, + EFI_VARIABLE_BOOTSERVICE_ACCESS | EFI_VARIABLE_RUNTIME_ACCESS, + sizeof(loader_info), loader_info) !=3D EFI_SUCCESS) + return; + + efi_bli_populate_loader_part_uuid(image); +} diff --git a/drivers/firmware/efi/libstub/efi-stub.c b/drivers/firmware/efi= /libstub/efi-stub.c index 42d6073bcd06..2a95f4ea104a 100644 --- a/drivers/firmware/efi/libstub/efi-stub.c +++ b/drivers/firmware/efi/libstub/efi-stub.c @@ -165,6 +165,7 @@ efi_status_t efi_stub_common(efi_handle_t handle, dpy =3D setup_primary_display(); =20 efi_retrieve_eventlog(); + efi_bli_set_variables(image); =20 /* Ask the firmware to clear memory on unclean shutdown */ efi_enable_reset_attack_mitigation(); diff --git a/drivers/firmware/efi/libstub/efistub.h b/drivers/firmware/efi/= libstub/efistub.h index 880c1d0c464b..4f9e7ae28b6c 100644 --- a/drivers/firmware/efi/libstub/efistub.h +++ b/drivers/firmware/efi/libstub/efistub.h @@ -1072,6 +1072,8 @@ efi_status_t efi_random_alloc(unsigned long size, uns= igned long align, int memory_type, unsigned long alloc_min, unsigned long alloc_max); =20 +void efi_bli_set_variables(const efi_loaded_image_t *image); + efi_status_t efi_random_get_seed(void); =20 efi_status_t check_platform_features(void); diff --git a/drivers/firmware/efi/libstub/x86-stub.c b/drivers/firmware/efi= /libstub/x86-stub.c index cef32e2c82d8..b762f7f37f28 100644 --- a/drivers/firmware/efi/libstub/x86-stub.c +++ b/drivers/firmware/efi/libstub/x86-stub.c @@ -1014,6 +1014,7 @@ void __noreturn efi_stub_entry(efi_handle_t handle, efi_random_get_seed(); =20 efi_retrieve_eventlog(); + efi_bli_set_variables(image); =20 setup_graphics(boot_params); =20 diff --git a/include/linux/efi.h b/include/linux/efi.h index c35446a0b66f..ecb34be37a87 100644 --- a/include/linux/efi.h +++ b/include/linux/efi.h @@ -957,6 +957,17 @@ extern int efi_status_to_err(efi_status_t status); #define EFI_DEV_END_INSTANCE 0x01 #define EFI_DEV_END_ENTIRE 0xFF =20 +enum efi_hd_partition_format { + EFI_HD_PARTITION_FORMAT_MBR =3D 1, + EFI_HD_PARTITION_FORMAT_GPT, +}; + +enum efi_hd_signature_type { + EFI_HD_SIGNATURE_TYPE_NONE, + EFI_HD_SIGNATURE_TYPE_MBR, + EFI_HD_SIGNATURE_TYPE_GUID, +}; + struct efi_generic_dev_path { u8 type; u8 sub_type; @@ -988,6 +999,16 @@ struct efi_rel_offset_dev_path { u64 ending_offset; } __packed; =20 +struct efi_hd_dev_path { + struct efi_generic_dev_path header; + u32 partition_number; + u64 partition_start; + u64 partition_size; + efi_guid_t signature; + u8 partition_format; + u8 signature_type; +} __packed; + struct efi_mem_mapped_dev_path { struct efi_generic_dev_path header; u32 memory_type; @@ -1007,6 +1028,7 @@ struct efi_dev_path { struct efi_pci_dev_path pci; struct efi_vendor_dev_path vendor; struct efi_rel_offset_dev_path rel_offset; + struct efi_hd_dev_path hd; }; } __packed; =20 --=20 2.55.0.1032.g73a4cd73de-goog