From: Johannes Schneider <johannes.schneider@leica-geosystems.com>
To: barebox@lists.infradead.org
Cc: Marco Felsch <m.felsch@pengutronix.de>,
Johannes Schneider <johannes.schneider@leica-geosystems.com>
Subject: [PATCH v1 10/14] efi: loader: authenticate LoadImage() images when signing is forced
Date: Sun, 4 Oct 2026 01:19:43 +0000 [thread overview]
Message-ID: <20261004011958.3255011-11-johannes.schneider@leica-geosystems.com> (raw)
In-Reply-To: <20261004011958.3255011-1-johannes.schneider@leica-geosystems.com>
efi_image_authenticate() accepts every image, so with signed images
forced, a verified payload can still load unsigned images through
LoadImage(). systemd-stub does exactly that for the addons it finds next
to a UKI, PE files carrying .cmdline, .dtb and .initrd sections, without
shim through plain LoadImage(). An unsigned addon could thus replace
the kernel command line or devicetree of a signed UKI.
With signed images forced, verify images in LoadImage() against the
"efi" keyring, and have StartImage() refuse images that failed: as the
UEFI specification has it, LoadImage() still creates the handle when it
returns EFI_SECURITY_VIOLATION.
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Johannes Schneider <johannes.schneider@leica-geosystems.com>
---
efi/loader/Kconfig | 3 ++-
efi/loader/boot.c | 3 +++
efi/loader/pe.c | 7 ++++++-
include/efi/loader/authenticode.h | 11 +++++++++++
4 files changed, 22 insertions(+), 2 deletions(-)
diff --git a/efi/loader/Kconfig b/efi/loader/Kconfig
index 8345fccd1a..156123212b 100644
--- a/efi/loader/Kconfig
+++ b/efi/loader/Kconfig
@@ -33,7 +33,8 @@ config EFI_LOADER_AUTHENTICODE
image booted with bootm against the keys compiled into the "efi"
keyring (CONFIG_CRYPTO_PUBLIC_KEYS, keyring=efi). With signed images
forced, an EFI image then boots only if one of those keys verifies
- it, the same way a FIT image must carry a valid signature.
+ it, the same way a FIT image must carry a valid signature, and so
+ do the images an EFI payload loads through LoadImage().
X.509 certificates in the signature are not evaluated: trust is
anchored in the keyring. barebox does not report UEFI Secure Boot
diff --git a/efi/loader/boot.c b/efi/loader/boot.c
index 2d98c95b5c..3c9489e951 100644
--- a/efi/loader/boot.c
+++ b/efi/loader/boot.c
@@ -3098,6 +3098,9 @@ efi_status_t __efi_start_image(efi_handle_t image_handle,
if (image_obj->header.type != EFI_OBJECT_TYPE_LOADED_IMAGE)
return EFI_EXIT(EFI_INVALID_PARAMETER);
+ if (image_obj->auth_status != EFI_IMAGE_AUTH_PASSED)
+ return EFI_EXIT(EFI_SECURITY_VIOLATION);
+
ret = EFI_CALL(efi_open_protocol(image_handle, &efi_loaded_image_protocol_guid,
(void **)&info, NULL, NULL,
EFI_OPEN_PROTOCOL_GET_PROTOCOL));
diff --git a/efi/loader/pe.c b/efi/loader/pe.c
index 827b50378c..efec38b111 100644
--- a/efi/loader/pe.c
+++ b/efi/loader/pe.c
@@ -18,6 +18,8 @@
#include <efi/memory.h>
#include <efi/loader.h>
#include <efi/loader/pe.h>
+#include <efi/loader/authenticode.h>
+#include <bootm.h>
#include <efi/guid.h>
#include <efi/error.h>
#include <pe.h>
@@ -895,7 +897,10 @@ const void *efi_pe_find_section(void *efi, size_t len, const char *name,
#ifdef CONFIG_EFI_LOADER
static bool efi_image_authenticate(void *efi, size_t efi_size)
{
- return true;
+ if (!IS_ENABLED(CONFIG_BOOTM) || !bootm_signed_images_are_forced())
+ return true;
+
+ return !efi_authenticode_verify(efi, efi_size, EFI_AUTHENTICODE_KEYRING);
}
/**
diff --git a/include/efi/loader/authenticode.h b/include/efi/loader/authenticode.h
index 24c46ca7cf..df4fb7eab0 100644
--- a/include/efi/loader/authenticode.h
+++ b/include/efi/loader/authenticode.h
@@ -3,7 +3,18 @@
#define __EFI_LOADER_AUTHENTICODE_H
#include <linux/types.h>
+#include <linux/errno.h>
+#define EFI_AUTHENTICODE_KEYRING "efi"
+
+#ifdef CONFIG_EFI_AUTHENTICODE
int efi_authenticode_verify(void *efi, size_t len, const char *keyring);
+#else
+static inline int efi_authenticode_verify(void *efi, size_t len,
+ const char *keyring)
+{
+ return -ENOSYS;
+}
+#endif
#endif
--
2.43.0
next prev parent reply other threads:[~2026-10-04 1:21 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-04 1:19 [PATCH v1 00/14] efi: loader: boot Authenticode-signed UKIs Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 01/14] mfd: hgs-efi: do not claim the name of the EFI loader's device Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 02/14] efi: loader: file: report EFI_UNSUPPORTED for volumes without a filesystem Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 03/14] efi: loader: bootm: free the devicetree after installing it Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 04/14] efi: loader: provide EFI_DT_FIXUP_PROTOCOL Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 05/14] efi: loader: pe: add helpers for the image size and a named section Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 06/14] efi: loader: bootm: load only the PE image, not the whole file Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 07/14] efi: loader: bootm: pass the kernel command line to UKIs Johannes Schneider
2026-10-05 17:18 ` Ahmad Fatoum
2026-10-04 1:19 ` [PATCH v1 08/14] efi: loader: verify Authenticode signatures against built-in keys Johannes Schneider
2026-10-05 5:33 ` Ahmad Fatoum
2026-10-05 5:45 ` SCHNEIDER Johannes
2026-10-09 0:07 ` SCHNEIDER Johannes
2026-10-04 1:19 ` [PATCH v1 09/14] efi: loader: authenticode: add a fuzz test Johannes Schneider
2026-10-04 1:19 ` Johannes Schneider [this message]
2026-10-04 1:19 ` [PATCH v1 11/14] efi: loader: file: expose no filesystem when signed images are forced Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 12/14] bootm: efi: boot signed EFI images " Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 13/14] efi: loader: bootm: install a devicetree for matching UKI devicetrees Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 14/14] efi: loader: bootm: apply overlays carried by a UKI Johannes Schneider
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261004011958.3255011-11-johannes.schneider@leica-geosystems.com \
--to=johannes.schneider@leica-geosystems.com \
--cc=barebox@lists.infradead.org \
--cc=m.felsch@pengutronix.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox