mail archive of the barebox mailing list
 help / color / mirror / Atom feed
From: Johannes Schneider <johannes.schneider@leica-geosystems.com>
To: barebox@lists.infradead.org
Cc: Marco Felsch <m.felsch@pengutronix.de>,
	Johannes Schneider <johannes.schneider@leica-geosystems.com>
Subject: [PATCH v1 09/14] efi: loader: authenticode: add a fuzz test
Date: Sun,  4 Oct 2026 01:19:42 +0000	[thread overview]
Message-ID: <20261004011958.3255011-10-johannes.schneider@leica-geosystems.com> (raw)
In-Reply-To: <20261004011958.3255011-1-johannes.schneider@leica-geosystems.com>

authenticode_parse() walks the DER of a PKCS#7 signature taken from the
image before anything about the image is verified. Fuzz it, and the
digest of the signed attributes it hands on, the way the PE parser is
fuzzed.

As EFI_PE_PARSER does for the PE parser, a separate EFI_AUTHENTICODE
builds the verifier without the EFI loader under COMPILE_TEST;
EFI_LOADER_AUTHENTICODE selects it. The libfuzzer configuration enables
it.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Johannes Schneider <johannes.schneider@leica-geosystems.com>
---
 common/boards/configs/libfuzzer.config |  1 +
 efi/Kconfig                            | 11 +++++++++++
 efi/loader/Kconfig                     |  2 +-
 efi/loader/Makefile                    |  2 +-
 efi/loader/authenticode.c              | 13 +++++++++++++
 5 files changed, 27 insertions(+), 2 deletions(-)

diff --git a/common/boards/configs/libfuzzer.config b/common/boards/configs/libfuzzer.config
index f0a298559f..40c90d644a 100644
--- a/common/boards/configs/libfuzzer.config
+++ b/common/boards/configs/libfuzzer.config
@@ -16,6 +16,7 @@ CONFIG_DEBUG_MEMLEAK=y
 CONFIG_TEST=y
 CONFIG_COMPILE_TEST=y
 CONFIG_EFI_PE_PARSER=y
+CONFIG_EFI_AUTHENTICODE=y
 CONFIG_JWT=y
 CONFIG_FUZZ=y
 CONFIG_FUZZ_EXTERNAL=y
diff --git a/efi/Kconfig b/efi/Kconfig
index e3f3941831..6c8d6b9de4 100644
--- a/efi/Kconfig
+++ b/efi/Kconfig
@@ -12,6 +12,17 @@ config EFI_PE_PARSER
 	  This can be enabled without the full EFI loader to compile-test and
 	  fuzz PE image parsing.
 
+config EFI_AUTHENTICODE
+	bool "Authenticode signature verifier" if COMPILE_TEST
+	depends on CRYPTO_BUILTIN_KEYS && HAVE_DIGEST_SHA256
+	select CRYPTO_RSA
+	select EFI_PE_PARSER
+	help
+	  Build the Authenticode (PKCS#7) verifier used by the EFI loader.
+
+	  This can be enabled without the full EFI loader to compile-test and
+	  fuzz the parsing of Authenticode signatures.
+
 config EFI_PAYLOAD
 	bool "barebox as EFI payload/app (consumer)"
 	depends on HAVE_EFI_PAYLOAD || COMPILE_TEST
diff --git a/efi/loader/Kconfig b/efi/loader/Kconfig
index 4099da0689..8345fccd1a 100644
--- a/efi/loader/Kconfig
+++ b/efi/loader/Kconfig
@@ -27,7 +27,7 @@ config EFI_LOADER_SECURE_BOOT
 config EFI_LOADER_AUTHENTICODE
 	bool "Verify Authenticode signatures of booted EFI images"
 	depends on CRYPTO_BUILTIN_KEYS && HAVE_DIGEST_SHA256
-	select CRYPTO_RSA
+	select EFI_AUTHENTICODE
 	help
 	  Verify the Authenticode (PKCS#7, SHA-256, RSA) signature of an EFI
 	  image booted with bootm against the keys compiled into the "efi"
diff --git a/efi/loader/Makefile b/efi/loader/Makefile
index 775014dc22..f590fb278a 100644
--- a/efi/loader/Makefile
+++ b/efi/loader/Makefile
@@ -1,6 +1,7 @@
 # SPDX-License-Identifier: GPL-2.0
 
 obj-$(CONFIG_EFI_PE_PARSER) += pe.o
+obj-$(CONFIG_EFI_AUTHENTICODE) += authenticode.o
 
 ifeq ($(CONFIG_EFI_LOADER),y)
 
@@ -14,7 +15,6 @@ obj-y += boot.o
 obj-y += runtime.o
 obj-y += setup.o
 obj-y += watchdog.o
-obj-$(CONFIG_EFI_LOADER_AUTHENTICODE) += authenticode.o
 obj-y += loadopts.o
 obj-y += efi_var_common.o
 obj-y += efi_variable.o
diff --git a/efi/loader/authenticode.c b/efi/loader/authenticode.c
index 36e5a46fc6..ef2ea895e1 100644
--- a/efi/loader/authenticode.c
+++ b/efi/loader/authenticode.c
@@ -15,6 +15,7 @@
 #include <efi/loader/authenticode.h>
 #include <efi/error.h>
 #include <pe.h>
+#include <fuzz.h>
 
 struct der {
 	const u8 *p;
@@ -340,6 +341,18 @@ static int sha256_attrs(const struct authenticode *a, u8 *out)
 	return ret;
 }
 
+static int fuzz_authenticode(const u8 *data, size_t size)
+{
+	struct authenticode a = {};
+	u8 hash[SHA256_DIGEST_SIZE];
+
+	if (!authenticode_parse(&a, data, size))
+		sha256_attrs(&a, hash);
+
+	return 0;
+}
+fuzz_test("authenticode", fuzz_authenticode);
+
 /**
  * efi_authenticode_verify() - verify a PE image's Authenticode signature
  * @efi:	PE image
-- 
2.43.0




  parent reply	other threads:[~2026-10-04  1:25 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-04  1:19 [PATCH v1 00/14] efi: loader: boot Authenticode-signed UKIs Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 01/14] mfd: hgs-efi: do not claim the name of the EFI loader's device Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 02/14] efi: loader: file: report EFI_UNSUPPORTED for volumes without a filesystem Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 03/14] efi: loader: bootm: free the devicetree after installing it Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 04/14] efi: loader: provide EFI_DT_FIXUP_PROTOCOL Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 05/14] efi: loader: pe: add helpers for the image size and a named section Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 06/14] efi: loader: bootm: load only the PE image, not the whole file Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 07/14] efi: loader: bootm: pass the kernel command line to UKIs Johannes Schneider
2026-10-05 17:18   ` Ahmad Fatoum
2026-10-04  1:19 ` [PATCH v1 08/14] efi: loader: verify Authenticode signatures against built-in keys Johannes Schneider
2026-10-05  5:33   ` Ahmad Fatoum
2026-10-05  5:45     ` SCHNEIDER Johannes
2026-10-09  0:07       ` SCHNEIDER Johannes
2026-10-04  1:19 ` Johannes Schneider [this message]
2026-10-04  1:19 ` [PATCH v1 10/14] efi: loader: authenticate LoadImage() images when signing is forced Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 11/14] efi: loader: file: expose no filesystem when signed images are forced Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 12/14] bootm: efi: boot signed EFI images " Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 13/14] efi: loader: bootm: install a devicetree for matching UKI devicetrees Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 14/14] efi: loader: bootm: apply overlays carried by a UKI Johannes Schneider

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261004011958.3255011-10-johannes.schneider@leica-geosystems.com \
    --to=johannes.schneider@leica-geosystems.com \
    --cc=barebox@lists.infradead.org \
    --cc=m.felsch@pengutronix.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox