mail archive of the barebox mailing list
 help / color / mirror / Atom feed
* [PATCH] fs: efivarfs: allow creating variables under any GUID in loader mode
@ 2026-08-26  9:37 Ahmad Fatoum
  2026-08-28 12:52 ` Sascha Hauer
  0 siblings, 1 reply; 2+ messages in thread
From: Ahmad Fatoum @ 2026-08-26  9:37 UTC (permalink / raw)
  To: barebox; +Cc: Ahmad Fatoum

efivars_create() refuses to create variables outside the barebox vendor
GUID. That dates from when barebox was only an EFI payload: on somebody
else's firmware, whose NVRAM holds the platform's own state, a shell that
can create Boot#### or BootOrder under the global GUID is a liability,
and the payload only ever needs barebox-env-<guid> anyway.

The EFI loader took the same efivarfs over unchanged, where the argument
does not hold. The store is barebox' own in-memory buffer backed by a
file it writes itself, and everything the loader starts - the UEFI
Shell, GRUB, the OS - can already create variables under any GUID. Only
the barebox shell was held back:

  barebox:/ echo -o /efivarfs/Timeout-8be4df61-93ca-11d2-aa0d-00e098032b8c 5
  open: Operation not permitted

Lift the restriction when running as the loader, so board scripts can
set up global variables without going through /env/data/init.efivars.
The payload keeps confining itself to its own GUID.

Assisted-by: Claude:opus-5
Signed-off-by: Ahmad Fatoum <a.fatoum@pengutronix.de>
---
 fs/efivarfs.c | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/fs/efivarfs.c b/fs/efivarfs.c
index a4d8cc8d0268..1f53c06d66d3 100644
--- a/fs/efivarfs.c
+++ b/fs/efivarfs.c
@@ -66,12 +66,17 @@ static int efivars_create(struct device *dev, const char *pathname,
 	if (pathname[0] == '/')
 		pathname++;
 
-	/* deny creating files with other vendor GUID than our own */
 	ret = efivarfs_parse_filename(pathname, &vendor, &name);
 	if (ret)
 		return -ENOENT;
 
-	if (efi_guidcmp(vendor, EFI_BAREBOX_VENDOR_GUID))
+	/*
+	 * As a payload, barebox is a guest on somebody else's firmware and
+	 * confines itself to its own vendor GUID when creating variables.
+	 * As the loader, the variable store is barebox' own and anything it
+	 * boots may already create variables under any GUID.
+	 */
+	if (!efi_is_loader() && efi_guidcmp(vendor, EFI_BAREBOX_VENDOR_GUID))
 		return -EPERM;
 
 	inode = xzalloc(sizeof(*inode));
-- 
2.47.3




^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH] fs: efivarfs: allow creating variables under any GUID in loader mode
  2026-08-26  9:37 [PATCH] fs: efivarfs: allow creating variables under any GUID in loader mode Ahmad Fatoum
@ 2026-08-28 12:52 ` Sascha Hauer
  0 siblings, 0 replies; 2+ messages in thread
From: Sascha Hauer @ 2026-08-28 12:52 UTC (permalink / raw)
  To: barebox, Ahmad Fatoum


On Wed, 26 Aug 2026 11:37:13 +0200, Ahmad Fatoum wrote:
> efivars_create() refuses to create variables outside the barebox vendor
> GUID. That dates from when barebox was only an EFI payload: on somebody
> else's firmware, whose NVRAM holds the platform's own state, a shell that
> can create Boot#### or BootOrder under the global GUID is a liability,
> and the payload only ever needs barebox-env-<guid> anyway.
> 
> The EFI loader took the same efivarfs over unchanged, where the argument
> does not hold. The store is barebox' own in-memory buffer backed by a
> file it writes itself, and everything the loader starts - the UEFI
> Shell, GRUB, the OS - can already create variables under any GUID. Only
> the barebox shell was held back:
> 
> [...]

Applied, thanks!

[1/1] fs: efivarfs: allow creating variables under any GUID in loader mode
      https://git.pengutronix.de/cgit/barebox/commit/?id=97f6cf9c5acb (link may not be stable)

Best regards,
-- 
Sascha Hauer <s.hauer@pengutronix.de>




^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-08-28 12:53 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-26  9:37 [PATCH] fs: efivarfs: allow creating variables under any GUID in loader mode Ahmad Fatoum
2026-08-28 12:52 ` Sascha Hauer

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox