1 // SPDX-License-Identifier: GPL-2.0
3 * Helper functions used by the EFI stub on multiple
4 * architectures. This should be #included by the EFI stub
5 * implementation files.
7 * Copyright 2011 Intel Corporation; author Matt Fleming
10 #include <linux/efi.h>
16 * Some firmware implementations have problems reading files in one go.
17 * A read chunk size of 1MB seems to work for most platforms.
19 * Unfortunately, reading files in chunks triggers *other* bugs on some
20 * platforms, so we provide a way to disable this workaround, which can
21 * be done by passing "efi=nochunk" on the EFI boot stub command line.
23 * If you experience issues with initrd images being corrupt it's worth
24 * trying efi=nochunk, but chunking is enabled by default because there
25 * are far more machines that require the workaround than those that
26 * break with it enabled.
28 #define EFI_READ_CHUNK_SIZE (1024 * 1024)
30 static unsigned long __chunk_size
= EFI_READ_CHUNK_SIZE
;
32 static int __section(.data
) __nokaslr
;
33 static int __section(.data
) __quiet
;
34 static int __section(.data
) __novamap
;
36 int __pure
nokaslr(void)
40 int __pure
is_quiet(void)
44 int __pure
novamap(void)
49 #define EFI_MMAP_NR_SLACK_SLOTS 8
52 efi_file_handle_t
*handle
;
56 void efi_printk(efi_system_table_t
*sys_table_arg
, char *str
)
60 for (s8
= str
; *s8
; s8
++) {
61 efi_char16_t ch
[2] = { 0 };
65 efi_char16_t nl
[2] = { '\r', 0 };
66 efi_char16_printk(sys_table_arg
, nl
);
69 efi_char16_printk(sys_table_arg
, ch
);
73 static inline bool mmap_has_headroom(unsigned long buff_size
,
74 unsigned long map_size
,
75 unsigned long desc_size
)
77 unsigned long slack
= buff_size
- map_size
;
79 return slack
/ desc_size
>= EFI_MMAP_NR_SLACK_SLOTS
;
82 efi_status_t
efi_get_memory_map(efi_system_table_t
*sys_table_arg
,
83 struct efi_boot_memmap
*map
)
85 efi_memory_desc_t
*m
= NULL
;
90 *map
->desc_size
= sizeof(*m
);
91 *map
->map_size
= *map
->desc_size
* 32;
92 *map
->buff_size
= *map
->map_size
;
94 status
= efi_call_early(allocate_pool
, EFI_LOADER_DATA
,
95 *map
->map_size
, (void **)&m
);
96 if (status
!= EFI_SUCCESS
)
101 status
= efi_call_early(get_memory_map
, map
->map_size
, m
,
102 &key
, map
->desc_size
, &desc_version
);
103 if (status
== EFI_BUFFER_TOO_SMALL
||
104 !mmap_has_headroom(*map
->buff_size
, *map
->map_size
,
106 efi_call_early(free_pool
, m
);
108 * Make sure there is some entries of headroom so that the
109 * buffer can be reused for a new map after allocations are
110 * no longer permitted. Its unlikely that the map will grow to
111 * exceed this headroom once we are ready to trigger
114 *map
->map_size
+= *map
->desc_size
* EFI_MMAP_NR_SLACK_SLOTS
;
115 *map
->buff_size
= *map
->map_size
;
119 if (status
!= EFI_SUCCESS
)
120 efi_call_early(free_pool
, m
);
122 if (map
->key_ptr
&& status
== EFI_SUCCESS
)
124 if (map
->desc_ver
&& status
== EFI_SUCCESS
)
125 *map
->desc_ver
= desc_version
;
133 unsigned long get_dram_base(efi_system_table_t
*sys_table_arg
)
136 unsigned long map_size
, buff_size
;
137 unsigned long membase
= EFI_ERROR
;
138 struct efi_memory_map map
;
139 efi_memory_desc_t
*md
;
140 struct efi_boot_memmap boot_map
;
142 boot_map
.map
= (efi_memory_desc_t
**)&map
.map
;
143 boot_map
.map_size
= &map_size
;
144 boot_map
.desc_size
= &map
.desc_size
;
145 boot_map
.desc_ver
= NULL
;
146 boot_map
.key_ptr
= NULL
;
147 boot_map
.buff_size
= &buff_size
;
149 status
= efi_get_memory_map(sys_table_arg
, &boot_map
);
150 if (status
!= EFI_SUCCESS
)
153 map
.map_end
= map
.map
+ map_size
;
155 for_each_efi_memory_desc_in_map(&map
, md
) {
156 if (md
->attribute
& EFI_MEMORY_WB
) {
157 if (membase
> md
->phys_addr
)
158 membase
= md
->phys_addr
;
162 efi_call_early(free_pool
, map
.map
);
168 * Allocate at the highest possible address that is not above 'max'.
170 efi_status_t
efi_high_alloc(efi_system_table_t
*sys_table_arg
,
171 unsigned long size
, unsigned long align
,
172 unsigned long *addr
, unsigned long max
)
174 unsigned long map_size
, desc_size
, buff_size
;
175 efi_memory_desc_t
*map
;
177 unsigned long nr_pages
;
180 struct efi_boot_memmap boot_map
;
183 boot_map
.map_size
= &map_size
;
184 boot_map
.desc_size
= &desc_size
;
185 boot_map
.desc_ver
= NULL
;
186 boot_map
.key_ptr
= NULL
;
187 boot_map
.buff_size
= &buff_size
;
189 status
= efi_get_memory_map(sys_table_arg
, &boot_map
);
190 if (status
!= EFI_SUCCESS
)
194 * Enforce minimum alignment that EFI or Linux requires when
195 * requesting a specific address. We are doing page-based (or
196 * larger) allocations, and both the address and size must meet
197 * alignment constraints.
199 if (align
< EFI_ALLOC_ALIGN
)
200 align
= EFI_ALLOC_ALIGN
;
202 size
= round_up(size
, EFI_ALLOC_ALIGN
);
203 nr_pages
= size
/ EFI_PAGE_SIZE
;
205 for (i
= 0; i
< map_size
/ desc_size
; i
++) {
206 efi_memory_desc_t
*desc
;
207 unsigned long m
= (unsigned long)map
;
210 desc
= efi_early_memdesc_ptr(m
, desc_size
, i
);
211 if (desc
->type
!= EFI_CONVENTIONAL_MEMORY
)
214 if (desc
->num_pages
< nr_pages
)
217 start
= desc
->phys_addr
;
218 end
= start
+ desc
->num_pages
* EFI_PAGE_SIZE
;
223 if ((start
+ size
) > end
)
226 if (round_down(end
- size
, align
) < start
)
229 start
= round_down(end
- size
, align
);
232 * Don't allocate at 0x0. It will confuse code that
233 * checks pointers against NULL.
238 if (start
> max_addr
)
243 status
= EFI_NOT_FOUND
;
245 status
= efi_call_early(allocate_pages
,
246 EFI_ALLOCATE_ADDRESS
, EFI_LOADER_DATA
,
247 nr_pages
, &max_addr
);
248 if (status
!= EFI_SUCCESS
) {
257 efi_call_early(free_pool
, map
);
263 * Allocate at the lowest possible address.
265 efi_status_t
efi_low_alloc(efi_system_table_t
*sys_table_arg
,
266 unsigned long size
, unsigned long align
,
269 unsigned long map_size
, desc_size
, buff_size
;
270 efi_memory_desc_t
*map
;
272 unsigned long nr_pages
;
274 struct efi_boot_memmap boot_map
;
277 boot_map
.map_size
= &map_size
;
278 boot_map
.desc_size
= &desc_size
;
279 boot_map
.desc_ver
= NULL
;
280 boot_map
.key_ptr
= NULL
;
281 boot_map
.buff_size
= &buff_size
;
283 status
= efi_get_memory_map(sys_table_arg
, &boot_map
);
284 if (status
!= EFI_SUCCESS
)
288 * Enforce minimum alignment that EFI or Linux requires when
289 * requesting a specific address. We are doing page-based (or
290 * larger) allocations, and both the address and size must meet
291 * alignment constraints.
293 if (align
< EFI_ALLOC_ALIGN
)
294 align
= EFI_ALLOC_ALIGN
;
296 size
= round_up(size
, EFI_ALLOC_ALIGN
);
297 nr_pages
= size
/ EFI_PAGE_SIZE
;
298 for (i
= 0; i
< map_size
/ desc_size
; i
++) {
299 efi_memory_desc_t
*desc
;
300 unsigned long m
= (unsigned long)map
;
303 desc
= efi_early_memdesc_ptr(m
, desc_size
, i
);
305 if (desc
->type
!= EFI_CONVENTIONAL_MEMORY
)
308 if (desc
->num_pages
< nr_pages
)
311 start
= desc
->phys_addr
;
312 end
= start
+ desc
->num_pages
* EFI_PAGE_SIZE
;
315 * Don't allocate at 0x0. It will confuse code that
316 * checks pointers against NULL. Skip the first 8
317 * bytes so we start at a nice even number.
322 start
= round_up(start
, align
);
323 if ((start
+ size
) > end
)
326 status
= efi_call_early(allocate_pages
,
327 EFI_ALLOCATE_ADDRESS
, EFI_LOADER_DATA
,
329 if (status
== EFI_SUCCESS
) {
335 if (i
== map_size
/ desc_size
)
336 status
= EFI_NOT_FOUND
;
338 efi_call_early(free_pool
, map
);
343 void efi_free(efi_system_table_t
*sys_table_arg
, unsigned long size
,
346 unsigned long nr_pages
;
351 nr_pages
= round_up(size
, EFI_ALLOC_ALIGN
) / EFI_PAGE_SIZE
;
352 efi_call_early(free_pages
, addr
, nr_pages
);
355 static efi_status_t
efi_file_size(efi_system_table_t
*sys_table_arg
, void *__fh
,
356 efi_char16_t
*filename_16
, void **handle
,
359 efi_file_handle_t
*h
, *fh
= __fh
;
360 efi_file_info_t
*info
;
362 efi_guid_t info_guid
= EFI_FILE_INFO_ID
;
363 unsigned long info_sz
;
365 status
= efi_call_proto(efi_file_handle
, open
, fh
, &h
, filename_16
,
366 EFI_FILE_MODE_READ
, (u64
)0);
367 if (status
!= EFI_SUCCESS
) {
368 efi_printk(sys_table_arg
, "Failed to open file: ");
369 efi_char16_printk(sys_table_arg
, filename_16
);
370 efi_printk(sys_table_arg
, "\n");
377 status
= efi_call_proto(efi_file_handle
, get_info
, h
, &info_guid
,
379 if (status
!= EFI_BUFFER_TOO_SMALL
) {
380 efi_printk(sys_table_arg
, "Failed to get file info size\n");
385 status
= efi_call_early(allocate_pool
, EFI_LOADER_DATA
,
386 info_sz
, (void **)&info
);
387 if (status
!= EFI_SUCCESS
) {
388 efi_printk(sys_table_arg
, "Failed to alloc mem for file info\n");
392 status
= efi_call_proto(efi_file_handle
, get_info
, h
, &info_guid
,
394 if (status
== EFI_BUFFER_TOO_SMALL
) {
395 efi_call_early(free_pool
, info
);
399 *file_sz
= info
->file_size
;
400 efi_call_early(free_pool
, info
);
402 if (status
!= EFI_SUCCESS
)
403 efi_printk(sys_table_arg
, "Failed to get initrd info\n");
408 static efi_status_t
efi_file_read(void *handle
, unsigned long *size
, void *addr
)
410 return efi_call_proto(efi_file_handle
, read
, handle
, size
, addr
);
413 static efi_status_t
efi_file_close(void *handle
)
415 return efi_call_proto(efi_file_handle
, close
, handle
);
418 static efi_status_t
efi_open_volume(efi_system_table_t
*sys_table_arg
,
419 efi_loaded_image_t
*image
,
420 efi_file_handle_t
**__fh
)
422 efi_file_io_interface_t
*io
;
423 efi_file_handle_t
*fh
;
424 efi_guid_t fs_proto
= EFI_FILE_SYSTEM_GUID
;
426 void *handle
= (void *)(unsigned long)efi_table_attr(efi_loaded_image
,
430 status
= efi_call_early(handle_protocol
, handle
,
431 &fs_proto
, (void **)&io
);
432 if (status
!= EFI_SUCCESS
) {
433 efi_printk(sys_table_arg
, "Failed to handle fs_proto\n");
437 status
= efi_call_proto(efi_file_io_interface
, open_volume
, io
, &fh
);
438 if (status
!= EFI_SUCCESS
)
439 efi_printk(sys_table_arg
, "Failed to open volume\n");
447 * Parse the ASCII string 'cmdline' for EFI options, denoted by the efi=
448 * option, e.g. efi=nochunk.
450 * It should be noted that efi= is parsed in two very different
451 * environments, first in the early boot environment of the EFI boot
452 * stub, and subsequently during the kernel boot.
454 efi_status_t
efi_parse_options(char const *cmdline
)
458 str
= strstr(cmdline
, "nokaslr");
459 if (str
== cmdline
|| (str
&& str
> cmdline
&& *(str
- 1) == ' '))
462 str
= strstr(cmdline
, "quiet");
463 if (str
== cmdline
|| (str
&& str
> cmdline
&& *(str
- 1) == ' '))
467 * If no EFI parameters were specified on the cmdline we've got
470 str
= strstr(cmdline
, "efi=");
474 /* Skip ahead to first argument */
475 str
+= strlen("efi=");
478 * Remember, because efi= is also used by the kernel we need to
479 * skip over arguments we don't understand.
481 while (*str
&& *str
!= ' ') {
482 if (!strncmp(str
, "nochunk", 7)) {
483 str
+= strlen("nochunk");
487 if (!strncmp(str
, "novamap", 7)) {
488 str
+= strlen("novamap");
492 /* Group words together, delimited by "," */
493 while (*str
&& *str
!= ' ' && *str
!= ',')
504 * Check the cmdline for a LILO-style file= arguments.
506 * We only support loading a file from the same filesystem as
509 efi_status_t
handle_cmdline_files(efi_system_table_t
*sys_table_arg
,
510 efi_loaded_image_t
*image
,
511 char *cmd_line
, char *option_string
,
512 unsigned long max_addr
,
513 unsigned long *load_addr
,
514 unsigned long *load_size
)
516 struct file_info
*files
;
517 unsigned long file_addr
;
519 efi_file_handle_t
*fh
= NULL
;
530 j
= 0; /* See close_handles */
532 if (!load_addr
|| !load_size
)
533 return EFI_INVALID_PARAMETER
;
541 for (nr_files
= 0; *str
; nr_files
++) {
542 str
= strstr(str
, option_string
);
546 str
+= strlen(option_string
);
548 /* Skip any leading slashes */
549 while (*str
== '/' || *str
== '\\')
552 while (*str
&& *str
!= ' ' && *str
!= '\n')
559 status
= efi_call_early(allocate_pool
, EFI_LOADER_DATA
,
560 nr_files
* sizeof(*files
), (void **)&files
);
561 if (status
!= EFI_SUCCESS
) {
562 pr_efi_err(sys_table_arg
, "Failed to alloc mem for file handle list\n");
567 for (i
= 0; i
< nr_files
; i
++) {
568 struct file_info
*file
;
569 efi_char16_t filename_16
[256];
572 str
= strstr(str
, option_string
);
576 str
+= strlen(option_string
);
581 /* Skip any leading slashes */
582 while (*str
== '/' || *str
== '\\')
585 while (*str
&& *str
!= ' ' && *str
!= '\n') {
586 if ((u8
*)p
>= (u8
*)filename_16
+ sizeof(filename_16
))
599 /* Only open the volume once. */
601 status
= efi_open_volume(sys_table_arg
, image
, &fh
);
602 if (status
!= EFI_SUCCESS
)
606 status
= efi_file_size(sys_table_arg
, fh
, filename_16
,
607 (void **)&file
->handle
, &file
->size
);
608 if (status
!= EFI_SUCCESS
)
611 file_size_total
+= file
->size
;
614 if (file_size_total
) {
618 * Multiple files need to be at consecutive addresses in memory,
619 * so allocate enough memory for all the files. This is used
620 * for loading multiple files.
622 status
= efi_high_alloc(sys_table_arg
, file_size_total
, 0x1000,
623 &file_addr
, max_addr
);
624 if (status
!= EFI_SUCCESS
) {
625 pr_efi_err(sys_table_arg
, "Failed to alloc highmem for files\n");
629 /* We've run out of free low memory. */
630 if (file_addr
> max_addr
) {
631 pr_efi_err(sys_table_arg
, "We've run out of free low memory\n");
632 status
= EFI_INVALID_PARAMETER
;
633 goto free_file_total
;
637 for (j
= 0; j
< nr_files
; j
++) {
640 size
= files
[j
].size
;
642 unsigned long chunksize
;
644 if (IS_ENABLED(CONFIG_X86
) && size
> __chunk_size
)
645 chunksize
= __chunk_size
;
649 status
= efi_file_read(files
[j
].handle
,
652 if (status
!= EFI_SUCCESS
) {
653 pr_efi_err(sys_table_arg
, "Failed to read file\n");
654 goto free_file_total
;
660 efi_file_close(files
[j
].handle
);
665 efi_call_early(free_pool
, files
);
667 *load_addr
= file_addr
;
668 *load_size
= file_size_total
;
673 efi_free(sys_table_arg
, file_size_total
, file_addr
);
676 for (k
= j
; k
< i
; k
++)
677 efi_file_close(files
[k
].handle
);
679 efi_call_early(free_pool
, files
);
687 * Relocate a kernel image, either compressed or uncompressed.
688 * In the ARM64 case, all kernel images are currently
689 * uncompressed, and as such when we relocate it we need to
690 * allocate additional space for the BSS segment. Any low
691 * memory that this function should avoid needs to be
692 * unavailable in the EFI memory map, as if the preferred
693 * address is not available the lowest available address will
696 efi_status_t
efi_relocate_kernel(efi_system_table_t
*sys_table_arg
,
697 unsigned long *image_addr
,
698 unsigned long image_size
,
699 unsigned long alloc_size
,
700 unsigned long preferred_addr
,
701 unsigned long alignment
)
703 unsigned long cur_image_addr
;
704 unsigned long new_addr
= 0;
706 unsigned long nr_pages
;
707 efi_physical_addr_t efi_addr
= preferred_addr
;
709 if (!image_addr
|| !image_size
|| !alloc_size
)
710 return EFI_INVALID_PARAMETER
;
711 if (alloc_size
< image_size
)
712 return EFI_INVALID_PARAMETER
;
714 cur_image_addr
= *image_addr
;
717 * The EFI firmware loader could have placed the kernel image
718 * anywhere in memory, but the kernel has restrictions on the
719 * max physical address it can run at. Some architectures
720 * also have a prefered address, so first try to relocate
721 * to the preferred address. If that fails, allocate as low
722 * as possible while respecting the required alignment.
724 nr_pages
= round_up(alloc_size
, EFI_ALLOC_ALIGN
) / EFI_PAGE_SIZE
;
725 status
= efi_call_early(allocate_pages
,
726 EFI_ALLOCATE_ADDRESS
, EFI_LOADER_DATA
,
727 nr_pages
, &efi_addr
);
730 * If preferred address allocation failed allocate as low as
733 if (status
!= EFI_SUCCESS
) {
734 status
= efi_low_alloc(sys_table_arg
, alloc_size
, alignment
,
737 if (status
!= EFI_SUCCESS
) {
738 pr_efi_err(sys_table_arg
, "Failed to allocate usable memory for kernel.\n");
743 * We know source/dest won't overlap since both memory ranges
744 * have been allocated by UEFI, so we can safely use memcpy.
746 memcpy((void *)new_addr
, (void *)cur_image_addr
, image_size
);
748 /* Return the new address of the relocated image. */
749 *image_addr
= new_addr
;
755 * Get the number of UTF-8 bytes corresponding to an UTF-16 character.
756 * This overestimates for surrogates, but that is okay.
758 static int efi_utf8_bytes(u16 c
)
760 return 1 + (c
>= 0x80) + (c
>= 0x800);
764 * Convert an UTF-16 string, not necessarily null terminated, to UTF-8.
766 static u8
*efi_utf16_to_utf8(u8
*dst
, const u16
*src
, int n
)
772 if (n
&& c
>= 0xd800 && c
<= 0xdbff &&
773 *src
>= 0xdc00 && *src
<= 0xdfff) {
774 c
= 0x10000 + ((c
& 0x3ff) << 10) + (*src
& 0x3ff);
778 if (c
>= 0xd800 && c
<= 0xdfff)
779 c
= 0xfffd; /* Unmatched surrogate */
785 *dst
++ = 0xc0 + (c
>> 6);
789 *dst
++ = 0xe0 + (c
>> 12);
792 *dst
++ = 0xf0 + (c
>> 18);
793 *dst
++ = 0x80 + ((c
>> 12) & 0x3f);
795 *dst
++ = 0x80 + ((c
>> 6) & 0x3f);
797 *dst
++ = 0x80 + (c
& 0x3f);
803 #ifndef MAX_CMDLINE_ADDRESS
804 #define MAX_CMDLINE_ADDRESS ULONG_MAX
808 * Convert the unicode UEFI command line to ASCII to pass to kernel.
809 * Size of memory allocated return in *cmd_line_len.
810 * Returns NULL on error.
812 char *efi_convert_cmdline(efi_system_table_t
*sys_table_arg
,
813 efi_loaded_image_t
*image
,
818 unsigned long cmdline_addr
= 0;
819 int load_options_chars
= image
->load_options_size
/ 2; /* UTF-16 */
820 const u16
*options
= image
->load_options
;
821 int options_bytes
= 0; /* UTF-8 bytes */
822 int options_chars
= 0; /* UTF-16 chars */
828 while (*s2
&& *s2
!= '\n'
829 && options_chars
< load_options_chars
) {
830 options_bytes
+= efi_utf8_bytes(*s2
++);
835 if (!options_chars
) {
836 /* No command line options, so return empty string*/
840 options_bytes
++; /* NUL termination */
842 status
= efi_high_alloc(sys_table_arg
, options_bytes
, 0,
843 &cmdline_addr
, MAX_CMDLINE_ADDRESS
);
844 if (status
!= EFI_SUCCESS
)
847 s1
= (u8
*)cmdline_addr
;
848 s2
= (const u16
*)options
;
850 s1
= efi_utf16_to_utf8(s1
, s2
, options_chars
);
853 *cmd_line_len
= options_bytes
;
854 return (char *)cmdline_addr
;
858 * Handle calling ExitBootServices according to the requirements set out by the
859 * spec. Obtains the current memory map, and returns that info after calling
860 * ExitBootServices. The client must specify a function to perform any
861 * processing of the memory map data prior to ExitBootServices. A client
862 * specific structure may be passed to the function via priv. The client
863 * function may be called multiple times.
865 efi_status_t
efi_exit_boot_services(efi_system_table_t
*sys_table_arg
,
867 struct efi_boot_memmap
*map
,
869 efi_exit_boot_map_processing priv_func
)
873 status
= efi_get_memory_map(sys_table_arg
, map
);
875 if (status
!= EFI_SUCCESS
)
878 status
= priv_func(sys_table_arg
, map
, priv
);
879 if (status
!= EFI_SUCCESS
)
882 status
= efi_call_early(exit_boot_services
, handle
, *map
->key_ptr
);
884 if (status
== EFI_INVALID_PARAMETER
) {
886 * The memory map changed between efi_get_memory_map() and
887 * exit_boot_services(). Per the UEFI Spec v2.6, Section 6.4:
888 * EFI_BOOT_SERVICES.ExitBootServices we need to get the
889 * updated map, and try again. The spec implies one retry
890 * should be sufficent, which is confirmed against the EDK2
891 * implementation. Per the spec, we can only invoke
892 * get_memory_map() and exit_boot_services() - we cannot alloc
893 * so efi_get_memory_map() cannot be used, and we must reuse
894 * the buffer. For all practical purposes, the headroom in the
895 * buffer should account for any changes in the map so the call
896 * to get_memory_map() is expected to succeed here.
898 *map
->map_size
= *map
->buff_size
;
899 status
= efi_call_early(get_memory_map
,
906 /* exit_boot_services() was called, thus cannot free */
907 if (status
!= EFI_SUCCESS
)
910 status
= priv_func(sys_table_arg
, map
, priv
);
911 /* exit_boot_services() was called, thus cannot free */
912 if (status
!= EFI_SUCCESS
)
915 status
= efi_call_early(exit_boot_services
, handle
, *map
->key_ptr
);
918 /* exit_boot_services() was called, thus cannot free */
919 if (status
!= EFI_SUCCESS
)
925 efi_call_early(free_pool
, *map
->map
);