mail archive of the barebox mailing list
 help / color / mirror / Atom feed
From: Johannes Schneider <johannes.schneider@leica-geosystems.com>
To: barebox@lists.infradead.org
Cc: Marco Felsch <m.felsch@pengutronix.de>,
	Johannes Schneider <johannes.schneider@leica-geosystems.com>
Subject: [PATCH v1 12/14] bootm: efi: boot signed EFI images when signed images are forced
Date: Sun,  4 Oct 2026 01:19:45 +0000	[thread overview]
Message-ID: <20261004011958.3255011-13-johannes.schneider@leica-geosystems.com> (raw)
In-Reply-To: <20261004011958.3255011-1-johannes.schneider@leica-geosystems.com>

With signed images forced, bootm refuses everything but FIT images. Let
EFI images through when Authenticode support is built in, and have the
EFI loader verify them against the "efi" keyring before loading:
mandatory with signed images forced or bootm.verify=signature, skipped
with bootm.verify=none, reported otherwise.

Not when barebox itself runs as EFI payload: its EFI application
handler passes the image to the firmware's LoadImage() and verifies
nothing itself.

An image booted this way is verified twice: here, so that barebox does
not parse anything of an image that is not authenticated, and again in
LoadImage(), which verifies every image a payload loads and cannot rely
on an earlier verdict. Skipping either would need the result of the
first carried over to the second, a shortcut that has to stay correct
as both paths change; the second verification costs 70 ms for a 30 MiB
UKI on an i.MX8MP.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Johannes Schneider <johannes.schneider@leica-geosystems.com>
---
 common/bootm.c     |  6 +++++-
 efi/loader/bootm.c | 29 +++++++++++++++++++++++++++++
 2 files changed, 34 insertions(+), 1 deletion(-)

diff --git a/common/bootm.c b/common/bootm.c
index 27da1a590b..c8fc5220a6 100644
--- a/common/bootm.c
+++ b/common/bootm.c
@@ -576,7 +576,11 @@ struct image_data *bootm_boot_prep(const struct bootm_data *bootm_data)
 		 */
 		data->oftree_file = NULL;
 		data->initrd_file = NULL;
-		if (data->image_type != filetype_fit) {
+		if (data->image_type == filetype_exe &&
+		    IS_ENABLED(CONFIG_EFI_LOADER_AUTHENTICODE) &&
+		    !efi_is_payload()) {
+			/* authenticated by the EFI loader before it runs */
+		} else if (data->image_type != filetype_fit) {
 			pr_err("Signed boot and image is no FIT image, aborting\n");
 			ret = -EINVAL;
 			goto err_out;
diff --git a/efi/loader/bootm.c b/efi/loader/bootm.c
index 8a83865458..fa12caf560 100644
--- a/efi/loader/bootm.c
+++ b/efi/loader/bootm.c
@@ -35,6 +35,7 @@
 #include <efi/error.h>
 #include <efi/initrd.h>
 #include <efi/devicepath.h>
+#include <efi/loader/authenticode.h>
 #include <efi/loader/pe.h>
 #include <loadable.h>
 
@@ -195,6 +196,30 @@ static efi_status_t efi_install_initrd(struct image_data *data,
 	return EFI_SUCCESS;
 }
 
+static int efi_loader_verify(struct image_data *data, void *efi, size_t size)
+{
+	bool required = bootm_signed_images_are_forced() ||
+			data->verify == BOOTM_VERIFY_SIGNATURE;
+	int ret;
+
+	if (!IS_ENABLED(CONFIG_EFI_LOADER_AUTHENTICODE)) {
+		if (required) {
+			pr_err("signed image required, but no Authenticode support\n");
+			return -EPERM;
+		}
+		return 0;
+	}
+
+	if (!required && data->verify == BOOTM_VERIFY_NONE)
+		return 0;
+
+	ret = efi_authenticode_verify(efi, size, EFI_AUTHENTICODE_KEYRING);
+	if (ret && required)
+		return -EPERM;
+
+	return 0;
+}
+
 /* The image may sit in a much larger partition: load only the image */
 static const struct resource *efi_load_os(struct image_data *data,
 					  resource_size_t start,
@@ -266,6 +291,10 @@ static int efi_loader_bootm(struct image_data *data)
 		return -EINVAL;
 	}
 
+	ret = efi_loader_verify(data, (void *)os_res->start, size);
+	if (ret)
+		return ret;
+
 	/* systemd-stub passes the load options on as kernel command line */
 	if (filetype_is_linux_efi_image(data->kernel_type) ||
 	    efi_pe_find_section((void *)os_res->start, size, ".linux",
-- 
2.43.0




  parent reply	other threads:[~2026-10-04  1:25 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-04  1:19 [PATCH v1 00/14] efi: loader: boot Authenticode-signed UKIs Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 01/14] mfd: hgs-efi: do not claim the name of the EFI loader's device Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 02/14] efi: loader: file: report EFI_UNSUPPORTED for volumes without a filesystem Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 03/14] efi: loader: bootm: free the devicetree after installing it Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 04/14] efi: loader: provide EFI_DT_FIXUP_PROTOCOL Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 05/14] efi: loader: pe: add helpers for the image size and a named section Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 06/14] efi: loader: bootm: load only the PE image, not the whole file Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 07/14] efi: loader: bootm: pass the kernel command line to UKIs Johannes Schneider
2026-10-05 17:18   ` Ahmad Fatoum
2026-10-04  1:19 ` [PATCH v1 08/14] efi: loader: verify Authenticode signatures against built-in keys Johannes Schneider
2026-10-05  5:33   ` Ahmad Fatoum
2026-10-05  5:45     ` SCHNEIDER Johannes
2026-10-09  0:07       ` SCHNEIDER Johannes
2026-10-04  1:19 ` [PATCH v1 09/14] efi: loader: authenticode: add a fuzz test Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 10/14] efi: loader: authenticate LoadImage() images when signing is forced Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 11/14] efi: loader: file: expose no filesystem when signed images are forced Johannes Schneider
2026-10-04  1:19 ` Johannes Schneider [this message]
2026-10-04  1:19 ` [PATCH v1 13/14] efi: loader: bootm: install a devicetree for matching UKI devicetrees Johannes Schneider
2026-10-04  1:19 ` [PATCH v1 14/14] efi: loader: bootm: apply overlays carried by a UKI Johannes Schneider

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261004011958.3255011-13-johannes.schneider@leica-geosystems.com \
    --to=johannes.schneider@leica-geosystems.com \
    --cc=barebox@lists.infradead.org \
    --cc=m.felsch@pengutronix.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox