From: Johannes Schneider <johannes.schneider@leica-geosystems.com>
To: barebox@lists.infradead.org
Cc: Marco Felsch <m.felsch@pengutronix.de>,
Johannes Schneider <johannes.schneider@leica-geosystems.com>
Subject: [PATCH v1 05/14] efi: loader: pe: add helpers for the image size and a named section
Date: Sun, 4 Oct 2026 01:19:38 +0000 [thread overview]
Message-ID: <20261004011958.3255011-6-johannes.schneider@leica-geosystems.com> (raw)
In-Reply-To: <20261004011958.3255011-1-johannes.schneider@leica-geosystems.com>
An EFI image may be read from a raw partition far larger than the
image. Add efi_pe_image_size(), which derives the size as written from
the section and certificate tables and needs only the headers;
efi_pe_file_size(), the same for a buffer holding the whole image; and
efi_pe_find_section() and efi_pe_find_next_section(), which return the
file data of the first or the next section of a name.
All of them parse untrusted images through efi_image_parse_header(). For
efi_pe_image_size() to work on a buffer holding only the headers, the
check that the certificate table lies within the buffer moves from
efi_image_parse_header() to efi_image_parse(), the only caller that
reads the table.
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Johannes Schneider <johannes.schneider@leica-geosystems.com>
---
efi/loader/pe.c | 116 +++++++++++++++++++++++++++++++++++++++-
include/efi/loader/pe.h | 7 +++
2 files changed, 121 insertions(+), 2 deletions(-)
diff --git a/efi/loader/pe.c b/efi/loader/pe.c
index 4b7874fe2a..827b50378c 100644
--- a/efi/loader/pe.c
+++ b/efi/loader/pe.c
@@ -507,8 +507,6 @@ static bool efi_image_parse_header(void *efi, size_t len,
return false;
if (!pe_range_ok(len, 0, *header_sizep))
return false;
- if (*authszp && !pe_range_ok(len, *authoffp, *authszp))
- return false;
if (!pe_range_ok(len, 0, csum_off) ||
!pe_range_ok(len, subsys_off, 0) ||
@@ -570,6 +568,8 @@ bool efi_image_parse(void *efi, size_t len, struct efi_image_regions **regp,
if (!efi_image_parse_header(efi, len, &nt, §ions, &header_size,
&align, &authoff, &authsz))
return false;
+ if (authsz && !pe_range_ok(len, authoff, authsz))
+ return false;
/*
* Count maximum number of regions to be digested.
@@ -780,6 +780,118 @@ static int fuzz_pe(const u8 *data, size_t size)
}
fuzz_test("pe", fuzz_pe);
+/**
+ * efi_pe_image_size() - size of a PE image as written to storage
+ * @efi: buffer holding at least the PE headers
+ * @len: size of @efi
+ *
+ * Return: the end of the last section or of the certificate table, whichever
+ * is further, which may lie beyond @len, or 0 if @efi holds no valid PE
+ * headers.
+ */
+size_t efi_pe_image_size(void *efi, size_t len)
+{
+ IMAGE_NT_HEADERS32 *nt;
+ IMAGE_SECTION_HEADER *sections;
+ u32 header_size, align, authoff, authsz;
+ size_t size, end;
+ int i;
+
+ if (!efi_image_parse_header(efi, len, &nt, §ions, &header_size,
+ &align, &authoff, &authsz))
+ return 0;
+
+ size = header_size;
+
+ for (i = 0; i < nt->FileHeader.sections; i++) {
+ if (check_add_overflow((size_t)sections[i].PointerToRawData,
+ (size_t)sections[i].SizeOfRawData, &end))
+ return 0;
+ size = max(size, end);
+ }
+
+ if (check_add_overflow((size_t)authoff, (size_t)authsz, &end))
+ return 0;
+
+ return max(size, end);
+}
+
+/**
+ * efi_pe_file_size() - size of a PE image held completely in a buffer
+ * @efi: buffer holding the image
+ * @len: size of @efi, possibly larger than the image
+ *
+ * Return: efi_pe_image_size(), or 0 if the image does not fit into @len.
+ */
+size_t efi_pe_file_size(void *efi, size_t len)
+{
+ size_t size = efi_pe_image_size(efi, len);
+
+ return size <= len ? size : 0;
+}
+
+/**
+ * efi_pe_find_next_section() - locate the next section of a name
+ * @efi: PE image
+ * @len: size of @efi
+ * @name: section name, at most 8 characters
+ * @size: returns the size of the section data
+ * @index: section table index to start at; set past the section found
+ *
+ * Return: pointer to the section data in @efi, or NULL if there is none.
+ */
+const void *efi_pe_find_next_section(void *efi, size_t len, const char *name,
+ size_t *size, int *index)
+{
+ IMAGE_NT_HEADERS32 *nt;
+ IMAGE_SECTION_HEADER *sections;
+ u32 header_size, align, authoff, authsz;
+ size_t namelen = strlen(name), sz;
+ int i;
+
+ if (namelen > 8)
+ return NULL;
+
+ if (!efi_image_parse_header(efi, len, &nt, §ions, &header_size,
+ &align, &authoff, &authsz))
+ return NULL;
+
+ for (i = *index; i < nt->FileHeader.sections; i++) {
+ if (memcmp(sections[i].Name, name, namelen) ||
+ (namelen < 8 && sections[i].Name[namelen]))
+ continue;
+
+ sz = sections[i].Misc.VirtualSize ?: sections[i].SizeOfRawData;
+ sz = min_t(size_t, sz, sections[i].SizeOfRawData);
+ if (!pe_range_ok(len, sections[i].PointerToRawData, sz))
+ return NULL;
+
+ *size = sz;
+ *index = i + 1;
+ return efi + sections[i].PointerToRawData;
+ }
+
+ return NULL;
+}
+
+/**
+ * efi_pe_find_section() - locate a section's file data by name
+ * @efi: PE image
+ * @len: size of @efi
+ * @name: section name, at most 8 characters
+ * @size: returns the size of the section data
+ *
+ * Return: pointer to the first section's data in @efi, or NULL if there is
+ * none.
+ */
+const void *efi_pe_find_section(void *efi, size_t len, const char *name,
+ size_t *size)
+{
+ int index = 0;
+
+ return efi_pe_find_next_section(efi, len, name, size, &index);
+}
+
#ifdef CONFIG_EFI_LOADER
static bool efi_image_authenticate(void *efi, size_t efi_size)
{
diff --git a/include/efi/loader/pe.h b/include/efi/loader/pe.h
index b99f517cbf..2d2a19604f 100644
--- a/include/efi/loader/pe.h
+++ b/include/efi/loader/pe.h
@@ -73,6 +73,13 @@ void *efi_prepare_aligned_image(void *efi, u64 *efi_size);
bool efi_image_parse(void *efi, size_t len, struct efi_image_regions **regp,
struct _WIN_CERTIFICATE **auth, size_t *auth_len);
+size_t efi_pe_image_size(void *efi, size_t len);
+size_t efi_pe_file_size(void *efi, size_t len);
+const void *efi_pe_find_next_section(void *efi, size_t len, const char *name,
+ size_t *size, int *index);
+const void *efi_pe_find_section(void *efi, size_t len, const char *name,
+ size_t *size);
+
/* Check if a buffer contains a PE-COFF image */
efi_status_t efi_check_pe(void *buffer, size_t size, void **nt_header);
/* PE loader implementation */
--
2.43.0
next prev parent reply other threads:[~2026-10-04 1:25 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-04 1:19 [PATCH v1 00/14] efi: loader: boot Authenticode-signed UKIs Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 01/14] mfd: hgs-efi: do not claim the name of the EFI loader's device Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 02/14] efi: loader: file: report EFI_UNSUPPORTED for volumes without a filesystem Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 03/14] efi: loader: bootm: free the devicetree after installing it Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 04/14] efi: loader: provide EFI_DT_FIXUP_PROTOCOL Johannes Schneider
2026-10-04 1:19 ` Johannes Schneider [this message]
2026-10-04 1:19 ` [PATCH v1 06/14] efi: loader: bootm: load only the PE image, not the whole file Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 07/14] efi: loader: bootm: pass the kernel command line to UKIs Johannes Schneider
2026-10-05 17:18 ` Ahmad Fatoum
2026-10-04 1:19 ` [PATCH v1 08/14] efi: loader: verify Authenticode signatures against built-in keys Johannes Schneider
2026-10-05 5:33 ` Ahmad Fatoum
2026-10-05 5:45 ` SCHNEIDER Johannes
2026-10-09 0:07 ` SCHNEIDER Johannes
2026-10-04 1:19 ` [PATCH v1 09/14] efi: loader: authenticode: add a fuzz test Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 10/14] efi: loader: authenticate LoadImage() images when signing is forced Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 11/14] efi: loader: file: expose no filesystem when signed images are forced Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 12/14] bootm: efi: boot signed EFI images " Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 13/14] efi: loader: bootm: install a devicetree for matching UKI devicetrees Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 14/14] efi: loader: bootm: apply overlays carried by a UKI Johannes Schneider
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261004011958.3255011-6-johannes.schneider@leica-geosystems.com \
--to=johannes.schneider@leica-geosystems.com \
--cc=barebox@lists.infradead.org \
--cc=m.felsch@pengutronix.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox