670 lines
		
	
	
		
			20 KiB
		
	
	
	
		
			Diff
		
	
	
	
	
	
			
		
		
	
	
			670 lines
		
	
	
		
			20 KiB
		
	
	
	
		
			Diff
		
	
	
	
	
	
| From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
 | ||
| From: Matthew Garrett <mjg@redhat.com>
 | ||
| Date: Mon, 1 Apr 2024 13:20:18 -0600
 | ||
| Subject: [PATCH] Add support for Linux EFI stub loading.
 | ||
| 
 | ||
| Also:
 | ||
| 
 | ||
| commit 71c843745f22f81e16d259e2e19c99bf3c1855c1
 | ||
| Author: Colin Watson <cjwatson@ubuntu.com>
 | ||
| Date:   Tue Oct 23 10:40:49 2012 -0400
 | ||
| 
 | ||
| Don't allow insmod when secure boot is enabled.
 | ||
| 
 | ||
| Hi,
 | ||
| 
 | ||
| Fedora's patch to forbid insmod in UEFI Secure Boot environments is fine
 | ||
| as far as it goes.  However, the insmod command is not the only way that
 | ||
| modules can be loaded.  In particular, the 'normal' command, which
 | ||
| implements the usual GRUB menu and the fully-featured command prompt,
 | ||
| will implicitly load commands not currently loaded into memory.  This
 | ||
| permits trivial Secure Boot violations by writing commands implementing
 | ||
| whatever you want to do and pointing $prefix at the malicious code.
 | ||
| 
 | ||
| I'm currently test-building this patch (replacing your current
 | ||
| grub-2.00-no-insmod-on-sb.patch), but this should be more correct.  It
 | ||
| moves the check into grub_dl_load_file.
 | ||
| ---
 | ||
|  grub-core/Makefile.core.def       |  16 +-
 | ||
|  grub-core/kern/dl.c               |  22 +++
 | ||
|  grub-core/kern/efi/mm.c           |  32 ++++
 | ||
|  grub-core/loader/efi/linux.c      |  47 ++++++
 | ||
|  grub-core/loader/i386/efi/linux.c | 335 ++++++++++++++++++++++++++++++++++++++
 | ||
|  grub-core/loader/i386/pc/linux.c  |  10 +-
 | ||
|  include/grub/efi/efi.h            |   3 +
 | ||
|  include/grub/efi/linux.h          |  31 ++++
 | ||
|  8 files changed, 485 insertions(+), 11 deletions(-)
 | ||
|  create mode 100644 grub-core/loader/i386/efi/linux.c
 | ||
|  create mode 100644 include/grub/efi/linux.h
 | ||
| 
 | ||
| diff --git a/grub-core/Makefile.core.def b/grub-core/Makefile.core.def
 | ||
| index a5a3ee31800..3f6e944d6a5 100644
 | ||
| --- a/grub-core/Makefile.core.def
 | ||
| +++ b/grub-core/Makefile.core.def
 | ||
| @@ -1831,12 +1831,6 @@ module = {
 | ||
|  };
 | ||
|  
 | ||
|  
 | ||
| -module = {
 | ||
| -  name = linux16;
 | ||
| -  common = loader/i386/pc/linux.c;
 | ||
| -  enable = x86;
 | ||
| -};
 | ||
| -
 | ||
|  module = {
 | ||
|    name = ntldr;
 | ||
|    i386_pc = loader/i386/pc/ntldr.c;
 | ||
| @@ -1892,10 +1886,9 @@ module = {
 | ||
|  
 | ||
|  module = {
 | ||
|    name = linux;
 | ||
| -  x86 = loader/i386/linux.c;
 | ||
|    i386_xen_pvh = loader/i386/linux.c;
 | ||
|    xen = loader/i386/xen.c;
 | ||
| -  i386_pc = lib/i386/pc/vesa_modes_table.c;
 | ||
| +  i386_pc = loader/i386/pc/linux.c;
 | ||
|    i386_xen_pvh = lib/i386/pc/vesa_modes_table.c;
 | ||
|    mips = loader/mips/linux.c;
 | ||
|    powerpc_ieee1275 = loader/powerpc/ieee1275/linux.c;
 | ||
| @@ -1908,11 +1901,14 @@ module = {
 | ||
|    loongarch64 = loader/efi/linux.c;
 | ||
|    riscv32 = loader/efi/linux.c;
 | ||
|    riscv64 = loader/efi/linux.c;
 | ||
| -  i386_efi = loader/efi/linux.c;
 | ||
| -  x86_64_efi = loader/efi/linux.c;
 | ||
| +  i386_efi = loader/i386/efi/linux.c;
 | ||
| +  x86_64_efi = loader/i386/efi/linux.c;
 | ||
|    emu = loader/emu/linux.c;
 | ||
| +  fdt = lib/fdt.c;
 | ||
|    common = loader/linux.c;
 | ||
|    common = lib/cmdline.c;
 | ||
| +  efi = loader/efi/linux.c;
 | ||
| +  efi = loader/i386/linux.c;
 | ||
|  };
 | ||
|  
 | ||
|  module = {
 | ||
| diff --git a/grub-core/kern/dl.c b/grub-core/kern/dl.c
 | ||
| index c55f0ecf931..d48d4131ba7 100644
 | ||
| --- a/grub-core/kern/dl.c
 | ||
| +++ b/grub-core/kern/dl.c
 | ||
| @@ -32,12 +32,21 @@
 | ||
|  #include <grub/env.h>
 | ||
|  #include <grub/cache.h>
 | ||
|  #include <grub/i18n.h>
 | ||
| +#include <grub/efi/sb.h>
 | ||
|  
 | ||
|  /* Platforms where modules are in a readonly area of memory.  */
 | ||
|  #if defined(GRUB_MACHINE_QEMU)
 | ||
|  #define GRUB_MODULES_MACHINE_READONLY
 | ||
|  #endif
 | ||
|  
 | ||
| +#ifdef GRUB_MACHINE_EMU
 | ||
| +#include <sys/mman.h>
 | ||
| +#endif
 | ||
| +
 | ||
| +#ifdef GRUB_MACHINE_EFI
 | ||
| +#include <grub/efi/efi.h>
 | ||
| +#endif
 | ||
| +
 | ||
|  
 | ||
|  
 | ||
|  #pragma GCC diagnostic ignored "-Wcast-align"
 | ||
| @@ -861,6 +870,19 @@ grub_dl_load_file (const char *filename)
 | ||
|    void *core = 0;
 | ||
|    grub_dl_t mod = 0;
 | ||
|  
 | ||
| +#ifdef GRUB_MACHINE_EFI
 | ||
| +  if (grub_efi_get_secureboot ())
 | ||
| +    {
 | ||
| +#if 0
 | ||
| +      /* This is an error, but grub2-mkconfig still generates a pile of
 | ||
| +       * insmod commands, so emitting it would be mostly just obnoxious. */
 | ||
| +      grub_error (GRUB_ERR_ACCESS_DENIED,
 | ||
| +		  "Secure Boot forbids loading module from %s", filename);
 | ||
| +#endif
 | ||
| +      return 0;
 | ||
| +    }
 | ||
| +#endif
 | ||
| +
 | ||
|    grub_boot_time ("Loading module %s", filename);
 | ||
|  
 | ||
|    file = grub_file_open (filename, GRUB_FILE_TYPE_GRUB_MODULE);
 | ||
| diff --git a/grub-core/kern/efi/mm.c b/grub-core/kern/efi/mm.c
 | ||
| index df443f434d4..fb9dbf52528 100644
 | ||
| --- a/grub-core/kern/efi/mm.c
 | ||
| +++ b/grub-core/kern/efi/mm.c
 | ||
| @@ -112,6 +112,38 @@ grub_efi_drop_alloc (grub_efi_physical_address_t address,
 | ||
|      }
 | ||
|  }
 | ||
|  
 | ||
| +/* Allocate pages below a specified address */
 | ||
| +void *
 | ||
| +grub_efi_allocate_pages_max (grub_efi_physical_address_t max,
 | ||
| +			     grub_efi_uintn_t pages)
 | ||
| +{
 | ||
| +  grub_efi_status_t status;
 | ||
| +  grub_efi_boot_services_t *b;
 | ||
| +  grub_efi_physical_address_t address = max;
 | ||
| +
 | ||
| +  if (max > 0xffffffff)
 | ||
| +    return 0;
 | ||
| +
 | ||
| +  b = grub_efi_system_table->boot_services;
 | ||
| +  status = b->allocate_pages (GRUB_EFI_ALLOCATE_MAX_ADDRESS, GRUB_EFI_LOADER_DATA, pages, &address);
 | ||
| +
 | ||
| +  if (status != GRUB_EFI_SUCCESS)
 | ||
| +    return 0;
 | ||
| +
 | ||
| +  if (address == 0)
 | ||
| +    {
 | ||
| +      /* Uggh, the address 0 was allocated... This is too annoying,
 | ||
| +	 so reallocate another one.  */
 | ||
| +      address = max;
 | ||
| +      status = b->allocate_pages (GRUB_EFI_ALLOCATE_MAX_ADDRESS, GRUB_EFI_LOADER_DATA, pages, &address);
 | ||
| +      grub_efi_free_pages (0, pages);
 | ||
| +      if (status != GRUB_EFI_SUCCESS)
 | ||
| +	return 0;
 | ||
| +    }
 | ||
| +
 | ||
| +  return (void *) ((grub_addr_t) address);
 | ||
| +}
 | ||
| +
 | ||
|  /* Allocate pages. Return the pointer to the first of allocated pages.  */
 | ||
|  void *
 | ||
|  grub_efi_allocate_pages_real (grub_efi_physical_address_t address,
 | ||
| diff --git a/grub-core/loader/efi/linux.c b/grub-core/loader/efi/linux.c
 | ||
| index bfbd95aeef0..925394d1767 100644
 | ||
| --- a/grub-core/loader/efi/linux.c
 | ||
| +++ b/grub-core/loader/efi/linux.c
 | ||
| @@ -25,10 +25,12 @@
 | ||
|  #include <grub/loader.h>
 | ||
|  #include <grub/mm.h>
 | ||
|  #include <grub/types.h>
 | ||
| +#include <grub/cpu/linux.h>
 | ||
|  #include <grub/efi/efi.h>
 | ||
|  #include <grub/efi/fdtload.h>
 | ||
|  #include <grub/efi/memory.h>
 | ||
|  #include <grub/efi/pe32.h>
 | ||
| +#include <grub/efi/linux.h>
 | ||
|  #include <grub/efi/sb.h>
 | ||
|  #include <grub/i18n.h>
 | ||
|  #include <grub/lib/cmdline.h>
 | ||
| @@ -87,6 +89,51 @@ static grub_efi_load_file2_t initrd_lf2 = {
 | ||
|    grub_efi_initrd_load_file2
 | ||
|  };
 | ||
|  
 | ||
| +#define SHIM_LOCK_GUID \
 | ||
| + { 0x605dab50, 0xe046, 0x4300, {0xab, 0xb6, 0x3d, 0xd8, 0x10, 0xdd, 0x8b, 0x23} }
 | ||
| +
 | ||
| +struct grub_efi_shim_lock
 | ||
| +{
 | ||
| +  grub_efi_status_t (*verify) (void *buffer, grub_uint32_t size);
 | ||
| +};
 | ||
| +typedef struct grub_efi_shim_lock grub_efi_shim_lock_t;
 | ||
| +
 | ||
| +grub_efi_boolean_t
 | ||
| +grub_linuxefi_secure_validate (void *data, grub_uint32_t size)
 | ||
| +{
 | ||
| +  grub_guid_t guid = SHIM_LOCK_GUID;
 | ||
| +  grub_efi_shim_lock_t *shim_lock;
 | ||
| +
 | ||
| +  shim_lock = grub_efi_locate_protocol(&guid, NULL);
 | ||
| +
 | ||
| +  if (!shim_lock)
 | ||
| +    return 1;
 | ||
| +
 | ||
| +  if (shim_lock->verify(data, size) == GRUB_EFI_SUCCESS)
 | ||
| +    return 1;
 | ||
| +
 | ||
| +  return 0;
 | ||
| +}
 | ||
| +
 | ||
| +#pragma GCC diagnostic push
 | ||
| +#pragma GCC diagnostic ignored "-Wcast-align"
 | ||
| +
 | ||
| +typedef void (*handover_func) (void *, grub_efi_system_table_t *, void *);
 | ||
| +
 | ||
| +grub_err_t
 | ||
| +grub_efi_linux_boot (void *kernel_address, grub_off_t offset,
 | ||
| +		     void *kernel_params)
 | ||
| +{
 | ||
| +  handover_func hf;
 | ||
| +
 | ||
| +  hf = (handover_func)((char *)kernel_address + offset);
 | ||
| +  hf (grub_efi_image_handle, grub_efi_system_table, kernel_params);
 | ||
| +
 | ||
| +  return GRUB_ERR_BUG;
 | ||
| +}
 | ||
| +
 | ||
| +#pragma GCC diagnostic pop
 | ||
| +
 | ||
|  grub_err_t
 | ||
|  grub_arch_efi_linux_load_image_header (grub_file_t file,
 | ||
|                                        struct linux_arch_kernel_header * lh)
 | ||
| diff --git a/grub-core/loader/i386/efi/linux.c b/grub-core/loader/i386/efi/linux.c
 | ||
| new file mode 100644
 | ||
| index 00000000000..9bfb4ab9e3e
 | ||
| --- /dev/null
 | ||
| +++ b/grub-core/loader/i386/efi/linux.c
 | ||
| @@ -0,0 +1,335 @@
 | ||
| +/*
 | ||
| + *  GRUB  --  GRand Unified Bootloader
 | ||
| + *  Copyright (C) 2012  Free Software Foundation, Inc.
 | ||
| + *
 | ||
| + *  GRUB is free software: you can redistribute it and/or modify
 | ||
| + *  it under the terms of the GNU General Public License as published by
 | ||
| + *  the Free Software Foundation, either version 3 of the License, or
 | ||
| + *  (at your option) any later version.
 | ||
| + *
 | ||
| + *  GRUB is distributed in the hope that it will be useful,
 | ||
| + *  but WITHOUT ANY WARRANTY; without even the implied warranty of
 | ||
| + *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 | ||
| + *  GNU General Public License for more details.
 | ||
| + *
 | ||
| + *  You should have received a copy of the GNU General Public License
 | ||
| + *  along with GRUB.  If not, see <http://www.gnu.org/licenses/>.
 | ||
| + */
 | ||
| +
 | ||
| +#include <grub/loader.h>
 | ||
| +#include <grub/file.h>
 | ||
| +#include <grub/err.h>
 | ||
| +#include <grub/types.h>
 | ||
| +#include <grub/mm.h>
 | ||
| +#include <grub/cpu/linux.h>
 | ||
| +#include <grub/command.h>
 | ||
| +#include <grub/i18n.h>
 | ||
| +#include <grub/lib/cmdline.h>
 | ||
| +#include <grub/efi/efi.h>
 | ||
| +#include <grub/efi/linux.h>
 | ||
| +
 | ||
| +GRUB_MOD_LICENSE ("GPLv3+");
 | ||
| +
 | ||
| +static grub_dl_t my_mod;
 | ||
| +static int loaded;
 | ||
| +static void *kernel_mem;
 | ||
| +static grub_uint64_t kernel_size;
 | ||
| +static grub_uint8_t *initrd_mem;
 | ||
| +static grub_uint32_t handover_offset;
 | ||
| +struct linux_kernel_params *params;
 | ||
| +static char *linux_cmdline;
 | ||
| +
 | ||
| +#define BYTES_TO_PAGES(bytes)   (((bytes) + 0xfff) >> 12)
 | ||
| +
 | ||
| +static grub_err_t
 | ||
| +grub_linuxefi_boot (void)
 | ||
| +{
 | ||
| +  int offset = 0;
 | ||
| +
 | ||
| +#ifdef __x86_64__
 | ||
| +  offset = 512;
 | ||
| +#endif
 | ||
| +  asm volatile ("cli");
 | ||
| +
 | ||
| +  return grub_efi_linux_boot ((char *)kernel_mem, handover_offset + offset,
 | ||
| +                              params);
 | ||
| +}
 | ||
| +
 | ||
| +static grub_err_t
 | ||
| +grub_linuxefi_unload (void)
 | ||
| +{
 | ||
| +  grub_dl_unref (my_mod);
 | ||
| +  loaded = 0;
 | ||
| +  if (initrd_mem)
 | ||
| +    grub_efi_free_pages ((grub_efi_physical_address_t)(grub_addr_t)initrd_mem,
 | ||
| +                         BYTES_TO_PAGES(params->ramdisk_size));
 | ||
| +  if (linux_cmdline)
 | ||
| +    grub_efi_free_pages ((grub_efi_physical_address_t)(grub_addr_t)
 | ||
| +                         linux_cmdline,
 | ||
| +                         BYTES_TO_PAGES(params->cmdline_size + 1));
 | ||
| +  if (kernel_mem)
 | ||
| +    grub_efi_free_pages ((grub_efi_physical_address_t)(grub_addr_t)kernel_mem,
 | ||
| +                         BYTES_TO_PAGES(kernel_size));
 | ||
| +  if (params)
 | ||
| +    grub_efi_free_pages ((grub_efi_physical_address_t)(grub_addr_t)params,
 | ||
| +                         BYTES_TO_PAGES(16384));
 | ||
| +  return GRUB_ERR_NONE;
 | ||
| +}
 | ||
| +
 | ||
| +static grub_err_t
 | ||
| +grub_cmd_initrd (grub_command_t cmd __attribute__ ((unused)),
 | ||
| +                 int argc, char *argv[])
 | ||
| +{
 | ||
| +  grub_file_t *files = 0;
 | ||
| +  int i, nfiles = 0;
 | ||
| +  grub_size_t size = 0;
 | ||
| +  grub_uint8_t *ptr;
 | ||
| +
 | ||
| +  if (argc == 0)
 | ||
| +    {
 | ||
| +      grub_error (GRUB_ERR_BAD_ARGUMENT, N_("filename expected"));
 | ||
| +      goto fail;
 | ||
| +    }
 | ||
| +
 | ||
| +  if (!loaded)
 | ||
| +    {
 | ||
| +      grub_error (GRUB_ERR_BAD_ARGUMENT, N_("you need to load the kernel first"));
 | ||
| +      goto fail;
 | ||
| +    }
 | ||
| +
 | ||
| +  files = grub_zalloc (argc * sizeof (files[0]));
 | ||
| +  if (!files)
 | ||
| +    goto fail;
 | ||
| +
 | ||
| +  for (i = 0; i < argc; i++)
 | ||
| +    {
 | ||
| +      files[i] = grub_file_open (argv[i], GRUB_FILE_TYPE_LINUX_INITRD | GRUB_FILE_TYPE_NO_DECOMPRESS);
 | ||
| +      if (! files[i])
 | ||
| +        goto fail;
 | ||
| +      nfiles++;
 | ||
| +      size += ALIGN_UP (grub_file_size (files[i]), 4);
 | ||
| +    }
 | ||
| +
 | ||
| +  initrd_mem = grub_efi_allocate_pages_max (0x3fffffff, BYTES_TO_PAGES(size));
 | ||
| +  if (!initrd_mem)
 | ||
| +    {
 | ||
| +      grub_error (GRUB_ERR_OUT_OF_MEMORY, N_("can't allocate initrd"));
 | ||
| +      goto fail;
 | ||
| +    }
 | ||
| +
 | ||
| +  params->ramdisk_size = size;
 | ||
| +  params->ramdisk_image = (grub_uint32_t)(grub_addr_t) initrd_mem;
 | ||
| +
 | ||
| +  ptr = initrd_mem;
 | ||
| +
 | ||
| +  for (i = 0; i < nfiles; i++)
 | ||
| +    {
 | ||
| +      grub_ssize_t cursize = grub_file_size (files[i]);
 | ||
| +      if (grub_file_read (files[i], ptr, cursize) != cursize)
 | ||
| +        {
 | ||
| +          if (!grub_errno)
 | ||
| +            grub_error (GRUB_ERR_FILE_READ_ERROR, N_("premature end of file %s"),
 | ||
| +                        argv[i]);
 | ||
| +          goto fail;
 | ||
| +        }
 | ||
| +      ptr += cursize;
 | ||
| +      grub_memset (ptr, 0, ALIGN_UP_OVERHEAD (cursize, 4));
 | ||
| +      ptr += ALIGN_UP_OVERHEAD (cursize, 4);
 | ||
| +    }
 | ||
| +
 | ||
| +  params->ramdisk_size = size;
 | ||
| +
 | ||
| + fail:
 | ||
| +  for (i = 0; i < nfiles; i++)
 | ||
| +    grub_file_close (files[i]);
 | ||
| +  grub_free (files);
 | ||
| +
 | ||
| +  if (initrd_mem && grub_errno)
 | ||
| +    grub_efi_free_pages ((grub_efi_physical_address_t)(grub_addr_t)initrd_mem,
 | ||
| +                         BYTES_TO_PAGES(size));
 | ||
| +
 | ||
| +  return grub_errno;
 | ||
| +}
 | ||
| +
 | ||
| +static grub_err_t
 | ||
| +grub_cmd_linux (grub_command_t cmd __attribute__ ((unused)),
 | ||
| +                int argc, char *argv[])
 | ||
| +{
 | ||
| +  grub_file_t file = 0;
 | ||
| +  struct linux_i386_kernel_header lh;
 | ||
| +  grub_ssize_t len, start, filelen;
 | ||
| +  void *kernel = NULL;
 | ||
| +
 | ||
| +  grub_dl_ref (my_mod);
 | ||
| +
 | ||
| +  if (argc == 0)
 | ||
| +    {
 | ||
| +      grub_error (GRUB_ERR_BAD_ARGUMENT, N_("filename expected"));
 | ||
| +      goto fail;
 | ||
| +    }
 | ||
| +
 | ||
| +  file = grub_file_open (argv[0], GRUB_FILE_TYPE_LINUX_KERNEL);
 | ||
| +  if (! file)
 | ||
| +    goto fail;
 | ||
| +
 | ||
| +  filelen = grub_file_size (file);
 | ||
| +
 | ||
| +  kernel = grub_malloc(filelen);
 | ||
| +
 | ||
| +  if (!kernel)
 | ||
| +    {
 | ||
| +      grub_error (GRUB_ERR_OUT_OF_MEMORY, N_("cannot allocate kernel buffer"));
 | ||
| +      goto fail;
 | ||
| +    }
 | ||
| +
 | ||
| +  if (grub_file_read (file, kernel, filelen) != filelen)
 | ||
| +    {
 | ||
| +      grub_error (GRUB_ERR_FILE_READ_ERROR, N_("Can't read kernel %s"), argv[0]);
 | ||
| +      goto fail;
 | ||
| +    }
 | ||
| +
 | ||
| +  if (! grub_linuxefi_secure_validate (kernel, filelen))
 | ||
| +    {
 | ||
| +      grub_error (GRUB_ERR_INVALID_COMMAND, N_("%s has invalid signature"),
 | ||
| +                  argv[0]);
 | ||
| +      goto fail;
 | ||
| +    }
 | ||
| +
 | ||
| +  params = grub_efi_allocate_pages_max (0x3fffffff, BYTES_TO_PAGES(16384));
 | ||
| +
 | ||
| +  if (! params)
 | ||
| +    {
 | ||
| +      grub_error (GRUB_ERR_OUT_OF_MEMORY, "cannot allocate kernel parameters");
 | ||
| +      goto fail;
 | ||
| +    }
 | ||
| +
 | ||
| +  grub_memset (params, 0, 16384);
 | ||
| +
 | ||
| +  grub_memcpy (&lh, kernel, sizeof (lh));
 | ||
| +
 | ||
| +  if (lh.boot_flag != grub_cpu_to_le16 (0xaa55))
 | ||
| +    {
 | ||
| +      grub_error (GRUB_ERR_BAD_OS, N_("invalid magic number"));
 | ||
| +      goto fail;
 | ||
| +    }
 | ||
| +
 | ||
| +  if (lh.setup_sects > GRUB_LINUX_MAX_SETUP_SECTS)
 | ||
| +    {
 | ||
| +      grub_error (GRUB_ERR_BAD_OS, N_("too many setup sectors"));
 | ||
| +      goto fail;
 | ||
| +    }
 | ||
| +
 | ||
| +  if (lh.version < grub_cpu_to_le16 (0x020b))
 | ||
| +    {
 | ||
| +      grub_error (GRUB_ERR_BAD_OS, N_("kernel too old"));
 | ||
| +      goto fail;
 | ||
| +    }
 | ||
| +
 | ||
| +  if (!lh.handover_offset)
 | ||
| +    {
 | ||
| +      grub_error (GRUB_ERR_BAD_OS, N_("kernel doesn't support EFI handover"));
 | ||
| +      goto fail;
 | ||
| +    }
 | ||
| +
 | ||
| +  grub_dprintf ("linux", "setting up cmdline\n");
 | ||
| +  linux_cmdline = grub_efi_allocate_pages_max(0x3fffffff,
 | ||
| +                                         BYTES_TO_PAGES(lh.cmdline_size + 1));
 | ||
| +
 | ||
| +  if (!linux_cmdline)
 | ||
| +    {
 | ||
| +      grub_error (GRUB_ERR_OUT_OF_MEMORY, N_("can't allocate cmdline"));
 | ||
| +      goto fail;
 | ||
| +    }
 | ||
| +
 | ||
| +  grub_memcpy (linux_cmdline, LINUX_IMAGE, sizeof (LINUX_IMAGE));
 | ||
| +  grub_create_loader_cmdline (argc, argv,
 | ||
| +                              linux_cmdline + sizeof (LINUX_IMAGE) - 1,
 | ||
| +                              lh.cmdline_size - (sizeof (LINUX_IMAGE) - 1),
 | ||
| +                              GRUB_VERIFY_KERNEL_CMDLINE);
 | ||
| +
 | ||
| +  lh.cmd_line_ptr = (grub_uint32_t)(grub_addr_t)linux_cmdline;
 | ||
| +
 | ||
| +  handover_offset = lh.handover_offset;
 | ||
| +
 | ||
| +  start = (lh.setup_sects + 1) * 512;
 | ||
| +  len = grub_file_size(file) - start;
 | ||
| +
 | ||
| +  kernel_mem = grub_efi_allocate_pages_max(lh.pref_address,
 | ||
| +                                           BYTES_TO_PAGES(lh.init_size));
 | ||
| +
 | ||
| +  if (!kernel_mem)
 | ||
| +    kernel_mem = grub_efi_allocate_pages_max(0x3fffffff,
 | ||
| +                                             BYTES_TO_PAGES(lh.init_size));
 | ||
| +
 | ||
| +  if (!kernel_mem)
 | ||
| +    {
 | ||
| +      grub_error (GRUB_ERR_OUT_OF_MEMORY, N_("can't allocate kernel"));
 | ||
| +      goto fail;
 | ||
| +    }
 | ||
| +
 | ||
| +  grub_memcpy (kernel_mem, (char *)kernel + start, len);
 | ||
| +  grub_loader_set (grub_linuxefi_boot, grub_linuxefi_unload, 0);
 | ||
| +  loaded=1;
 | ||
| +
 | ||
| +  lh.code32_start = (grub_uint32_t)(grub_uint64_t) kernel_mem;
 | ||
| +  grub_memcpy (params, &lh, 2 * 512);
 | ||
| +
 | ||
| +  params->type_of_loader = 0x21;
 | ||
| +
 | ||
| + fail:
 | ||
| +
 | ||
| +  if (file)
 | ||
| +    grub_file_close (file);
 | ||
| +
 | ||
| +  if (kernel)
 | ||
| +    grub_free (kernel);
 | ||
| +
 | ||
| +  if (grub_errno != GRUB_ERR_NONE)
 | ||
| +    {
 | ||
| +      grub_dl_unref (my_mod);
 | ||
| +      loaded = 0;
 | ||
| +    }
 | ||
| +
 | ||
| +  if (linux_cmdline && !loaded)
 | ||
| +    grub_efi_free_pages ((grub_efi_physical_address_t)(grub_addr_t)
 | ||
| +                         linux_cmdline,
 | ||
| +                         BYTES_TO_PAGES(lh.cmdline_size + 1));
 | ||
| +
 | ||
| +  if (kernel_mem && !loaded)
 | ||
| +    grub_efi_free_pages ((grub_efi_physical_address_t)(grub_addr_t)kernel_mem,
 | ||
| +                         BYTES_TO_PAGES(kernel_size));
 | ||
| +
 | ||
| +  if (params && !loaded)
 | ||
| +    grub_efi_free_pages ((grub_efi_physical_address_t)(grub_addr_t)params,
 | ||
| +                         BYTES_TO_PAGES(16384));
 | ||
| +
 | ||
| +  return grub_errno;
 | ||
| +}
 | ||
| +
 | ||
| +static grub_command_t cmd_linux, cmd_initrd;
 | ||
| +static grub_command_t cmd_linuxefi, cmd_initrdefi;
 | ||
| +
 | ||
| +GRUB_MOD_INIT(linux)
 | ||
| +{
 | ||
| +  cmd_linux =
 | ||
| +    grub_register_command ("linux", grub_cmd_linux,
 | ||
| +                           0, N_("Load Linux."));
 | ||
| +  cmd_linuxefi =
 | ||
| +    grub_register_command ("linuxefi", grub_cmd_linux,
 | ||
| +                           0, N_("Load Linux."));
 | ||
| +  cmd_initrd =
 | ||
| +    grub_register_command ("initrd", grub_cmd_initrd,
 | ||
| +                           0, N_("Load initrd."));
 | ||
| +  cmd_initrdefi =
 | ||
| +    grub_register_command ("initrdefi", grub_cmd_initrd,
 | ||
| +                           0, N_("Load initrd."));
 | ||
| +  my_mod = mod;
 | ||
| +}
 | ||
| +
 | ||
| +GRUB_MOD_FINI(linux)
 | ||
| +{
 | ||
| +  grub_unregister_command (cmd_linux);
 | ||
| +  grub_unregister_command (cmd_linuxefi);
 | ||
| +  grub_unregister_command (cmd_initrd);
 | ||
| +  grub_unregister_command (cmd_initrdefi);
 | ||
| +}
 | ||
| diff --git a/grub-core/loader/i386/pc/linux.c b/grub-core/loader/i386/pc/linux.c
 | ||
| index 600530a742b..8593d74737f 100644
 | ||
| --- a/grub-core/loader/i386/pc/linux.c
 | ||
| +++ b/grub-core/loader/i386/pc/linux.c
 | ||
| @@ -483,14 +483,20 @@ grub_cmd_initrd (grub_command_t cmd __attribute__ ((unused)),
 | ||
|    return grub_errno;
 | ||
|  }
 | ||
|  
 | ||
| -static grub_command_t cmd_linux, cmd_initrd;
 | ||
| +static grub_command_t cmd_linux, cmd_linux16, cmd_initrd, cmd_initrd16;
 | ||
|  
 | ||
|  GRUB_MOD_INIT(linux16)
 | ||
|  {
 | ||
|    cmd_linux =
 | ||
| +    grub_register_command ("linux", grub_cmd_linux,
 | ||
| +			   0, N_("Load Linux."));
 | ||
| +  cmd_linux16 =
 | ||
|      grub_register_command ("linux16", grub_cmd_linux,
 | ||
|  			   0, N_("Load Linux."));
 | ||
|    cmd_initrd =
 | ||
| +    grub_register_command ("initrd", grub_cmd_initrd,
 | ||
| +			   0, N_("Load initrd."));
 | ||
| +  cmd_initrd16 =
 | ||
|      grub_register_command ("initrd16", grub_cmd_initrd,
 | ||
|  			   0, N_("Load initrd."));
 | ||
|    my_mod = mod;
 | ||
| @@ -499,5 +505,7 @@ GRUB_MOD_INIT(linux16)
 | ||
|  GRUB_MOD_FINI(linux16)
 | ||
|  {
 | ||
|    grub_unregister_command (cmd_linux);
 | ||
| +  grub_unregister_command (cmd_linux16);
 | ||
|    grub_unregister_command (cmd_initrd);
 | ||
| +  grub_unregister_command (cmd_initrd16);
 | ||
|  }
 | ||
| diff --git a/include/grub/efi/efi.h b/include/grub/efi/efi.h
 | ||
| index 3670eddc52b..83ddbe26e57 100644
 | ||
| --- a/include/grub/efi/efi.h
 | ||
| +++ b/include/grub/efi/efi.h
 | ||
| @@ -75,6 +75,9 @@ EXPORT_FUNC(grub_efi_allocate_fixed) (grub_efi_physical_address_t address,
 | ||
|  				      grub_efi_uintn_t pages);
 | ||
|  void *
 | ||
|  EXPORT_FUNC(grub_efi_allocate_any_pages) (grub_efi_uintn_t pages);
 | ||
| +void *
 | ||
| +EXPORT_FUNC(grub_efi_allocate_pages_max) (grub_efi_physical_address_t max,
 | ||
| +					  grub_efi_uintn_t pages);
 | ||
|  void EXPORT_FUNC(grub_efi_free_pages) (grub_efi_physical_address_t address,
 | ||
|  				       grub_efi_uintn_t pages);
 | ||
|  grub_efi_uintn_t EXPORT_FUNC(grub_efi_find_mmap_size) (void);
 | ||
| diff --git a/include/grub/efi/linux.h b/include/grub/efi/linux.h
 | ||
| new file mode 100644
 | ||
| index 00000000000..d224daafa4f
 | ||
| --- /dev/null
 | ||
| +++ b/include/grub/efi/linux.h
 | ||
| @@ -0,0 +1,31 @@
 | ||
| +/*
 | ||
| + *  GRUB  --  GRand Unified Bootloader
 | ||
| + *  Copyright (C) 2014  Free Software Foundation, Inc.
 | ||
| + *
 | ||
| + *  GRUB is free software: you can redistribute it and/or modify
 | ||
| + *  it under the terms of the GNU General Public License as published by
 | ||
| + *  the Free Software Foundation, either version 3 of the License, or
 | ||
| + *  (at your option) any later version.
 | ||
| + *
 | ||
| + *  GRUB is distributed in the hope that it will be useful,
 | ||
| + *  but WITHOUT ANY WARRANTY; without even the implied warranty of
 | ||
| + *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 | ||
| + *  GNU General Public License for more details.
 | ||
| + *
 | ||
| + *  You should have received a copy of the GNU General Public License
 | ||
| + *  along with GRUB.  If not, see <http://www.gnu.org/licenses/>.
 | ||
| + */
 | ||
| +#ifndef GRUB_EFI_LINUX_HEADER
 | ||
| +#define GRUB_EFI_LINUX_HEADER	1
 | ||
| +
 | ||
| +#include <grub/efi/api.h>
 | ||
| +#include <grub/err.h>
 | ||
| +#include <grub/symbol.h>
 | ||
| +
 | ||
| +grub_efi_boolean_t
 | ||
| +EXPORT_FUNC(grub_linuxefi_secure_validate) (void *data, grub_uint32_t size);
 | ||
| +grub_err_t
 | ||
| +EXPORT_FUNC(grub_efi_linux_boot) (void *kernel_address, grub_off_t offset,
 | ||
| +                                  void *kernel_param);
 | ||
| +
 | ||
| +#endif /* ! GRUB_EFI_LINUX_HEADER */
 |