From 7d0e15b8913f3a180405fba5ce1529df540b04aa Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 7 Sep 2022 23:56:11 +0000 Subject: [PATCH 01/10] Sync with rawhide at 2.06-56 minus gettext changes Signed-off-by: Robbie Harwood --- ...file-show-which-file-filters-get-run.patch | 4 +- ...i-make-the-default-arena-most-of-ram.patch | 73 ------------------- ...ed-array-positions-for-our-allocatio.patch | 0 ...tion-policy-for-kernel-vs-initrd-mem.patch | 0 ...-initrd-within-the-bounds-expressed-.patch | 0 ...ER_-CODE-DATA-for-kernel-and-initrd-.patch | 0 ...e-etc-kernel-cmdline-during-mkconfig.patch | 0 ...sh-don-t-dup-rhgb-quiet-check-mtimes.patch | 0 0277-Try-reserving-less-ram.patch | 34 --------- ...=> 0277-squish-give-up-on-rhgb-quiet.patch | 0 ...write-etc-kernel-cmdline-if-writable.patch | 0 ...5-implement-vec5-for-cas-negotiation.patch | 70 ++++++++++++++++++ ...scfg-Don-t-root-device-in-emu-builds.patch | 27 +++++++ grub.patches | 20 ++--- grub2.spec | 5 +- 15 files changed, 113 insertions(+), 120 deletions(-) delete mode 100644 0271-efi-make-the-default-arena-most-of-ram.patch rename 0272-efi-use-enumerated-array-positions-for-our-allocatio.patch => 0271-efi-use-enumerated-array-positions-for-our-allocatio.patch (100%) rename 0273-efi-split-allocation-policy-for-kernel-vs-initrd-mem.patch => 0272-efi-split-allocation-policy-for-kernel-vs-initrd-mem.patch (100%) rename 0274-efi-allocate-the-initrd-within-the-bounds-expressed-.patch => 0273-efi-allocate-the-initrd-within-the-bounds-expressed-.patch (100%) rename 0275-efi-use-EFI_LOADER_-CODE-DATA-for-kernel-and-initrd-.patch => 0274-efi-use-EFI_LOADER_-CODE-DATA-for-kernel-and-initrd-.patch (100%) rename 0276-BLS-create-etc-kernel-cmdline-during-mkconfig.patch => 0275-BLS-create-etc-kernel-cmdline-during-mkconfig.patch (100%) rename 0278-squish-don-t-dup-rhgb-quiet-check-mtimes.patch => 0276-squish-don-t-dup-rhgb-quiet-check-mtimes.patch (100%) delete mode 100644 0277-Try-reserving-less-ram.patch rename 0279-squish-give-up-on-rhgb-quiet.patch => 0277-squish-give-up-on-rhgb-quiet.patch (100%) rename 0280-squish-BLS-only-write-etc-kernel-cmdline-if-writable.patch => 0278-squish-BLS-only-write-etc-kernel-cmdline-if-writable.patch (100%) create mode 100644 0279-ieee1275-implement-vec5-for-cas-negotiation.patch create mode 100644 0280-blscfg-Don-t-root-device-in-emu-builds.patch diff --git a/0270-Make-debug-file-show-which-file-filters-get-run.patch b/0270-Make-debug-file-show-which-file-filters-get-run.patch index 12062a31..4ac32cb4 100644 --- a/0270-Make-debug-file-show-which-file-filters-get-run.patch +++ b/0270-Make-debug-file-show-which-file-filters-get-run.patch @@ -15,14 +15,14 @@ Signed-off-by: Peter Jones 1 file changed, 11 insertions(+) diff --git a/grub-core/kern/file.c b/grub-core/kern/file.c -index ed69fc0f0f..3f175630ea 100644 +index ed69fc0f0f..20a4c839aa 100644 --- a/grub-core/kern/file.c +++ b/grub-core/kern/file.c @@ -30,6 +30,14 @@ void (*EXPORT_VAR (grub_grubnet_fini)) (void); grub_file_filter_t grub_file_filters[GRUB_FILE_FILTER_MAX]; -+static char *filter_names[] = { ++static const char *filter_names[] = { + [GRUB_FILE_FILTER_VERIFY] = "GRUB_FILE_FILTER_VERIFY", + [GRUB_FILE_FILTER_GZIO] = "GRUB_FILE_FILTER_GZIO", + [GRUB_FILE_FILTER_XZIO] = "GRUB_FILE_FILTER_XZIO", diff --git a/0271-efi-make-the-default-arena-most-of-ram.patch b/0271-efi-make-the-default-arena-most-of-ram.patch deleted file mode 100644 index 49143703..00000000 --- a/0271-efi-make-the-default-arena-most-of-ram.patch +++ /dev/null @@ -1,73 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Fri, 29 Jul 2022 15:57:57 -0400 -Subject: [PATCH] efi: make the default arena most of ram - -Currently when populating the initial memory arena on EFI systems, we -count the available regions below GRUB_EFI_MAX_ALLOCATION_ADDRESS from -the EFI memory map and then allocates one quarter of that for our arena. - -Because many systems come up without IOMMUs, we currently set -GRUB_EFI_MAX_ALLOCATION_ADDRESS to 0x7fffffff, i.e. all addresses -allocated must be below 2G[0]. Due to firmware and other -considerations, this makes the most memory we can possibly have in our -arena 512M. - -Because our EFI loader doesn't get kernel and initrd memory from grub's -allocator, but rather reserves it directly from UEFI and then simply -marks those as allocated if they're within grub's arena, it was -historically possible to have initrds that are larger than 512M, because -we could use any memory region below 4G, without concern for grub's -choice of arena size. - -Unfortunately, when we switched to using the "verifiers" API (and thus -the file_filter_t API) to do measurement of kernel and initrd, this -introduced a pattern that allocates the entire file when we call -grub_file_open(), and buffers it to pass to the filter. This results in -needing to have enough space for the initramfs in the grub arena. - -This is bad. - -Since it's unlikely you're going to do anything *other* than loading a -kernel and initramfs that takes much of the available free memory from -UEFI, this patch introduces a workaround by changing the amount we give -to the arena be three quarters of the available memory, rather than one -quarter, thus changing our theoretical initrd limit to 1.5G. In -practice, it may still be smaller than that depending on allocation -fragmentation, but generally it will be most of it. - -Note that this doesn't fix the underlying flaw, which is that there is -no safe way to do the validation correctly using the "verifiers" system -with the current file API without buffering the whole file before -grub_file_read() is ever called, and thus you can't set an allocation -policy for the initial buffer of the file at all, so unless we raise the -allocation limit to >4G, it can't be allocated in the big region. - -[0] I'm not sure there was a good reason not to pick 4G, but even if we - had, at least one common firmware routes the first 2G of physical - RAM to 0x0, and any additional memory starting at 0x100000000. - -Related: rhbz#2112134 - -Signed-off-by: Peter Jones ---- - grub-core/kern/efi/mm.c | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/grub-core/kern/efi/mm.c b/grub-core/kern/efi/mm.c -index e460b072e6..150e412ee7 100644 ---- a/grub-core/kern/efi/mm.c -+++ b/grub-core/kern/efi/mm.c -@@ -737,10 +737,10 @@ grub_efi_mm_init (void) - filtered_memory_map_end = filter_memory_map (memory_map, filtered_memory_map, - desc_size, memory_map_end); - -- /* By default, request a quarter of the available memory. */ -+ /* By default, request three quarters of the available memory. */ - total_pages = get_total_pages (filtered_memory_map, desc_size, - filtered_memory_map_end); -- required_pages = (total_pages >> 2); -+ required_pages = (total_pages >> 1) + (total_pages >> 2); - if (required_pages < BYTES_TO_PAGES (MIN_HEAP_SIZE)) - required_pages = BYTES_TO_PAGES (MIN_HEAP_SIZE); - else if (required_pages > BYTES_TO_PAGES (MAX_HEAP_SIZE)) diff --git a/0272-efi-use-enumerated-array-positions-for-our-allocatio.patch b/0271-efi-use-enumerated-array-positions-for-our-allocatio.patch similarity index 100% rename from 0272-efi-use-enumerated-array-positions-for-our-allocatio.patch rename to 0271-efi-use-enumerated-array-positions-for-our-allocatio.patch diff --git a/0273-efi-split-allocation-policy-for-kernel-vs-initrd-mem.patch b/0272-efi-split-allocation-policy-for-kernel-vs-initrd-mem.patch similarity index 100% rename from 0273-efi-split-allocation-policy-for-kernel-vs-initrd-mem.patch rename to 0272-efi-split-allocation-policy-for-kernel-vs-initrd-mem.patch diff --git a/0274-efi-allocate-the-initrd-within-the-bounds-expressed-.patch b/0273-efi-allocate-the-initrd-within-the-bounds-expressed-.patch similarity index 100% rename from 0274-efi-allocate-the-initrd-within-the-bounds-expressed-.patch rename to 0273-efi-allocate-the-initrd-within-the-bounds-expressed-.patch diff --git a/0275-efi-use-EFI_LOADER_-CODE-DATA-for-kernel-and-initrd-.patch b/0274-efi-use-EFI_LOADER_-CODE-DATA-for-kernel-and-initrd-.patch similarity index 100% rename from 0275-efi-use-EFI_LOADER_-CODE-DATA-for-kernel-and-initrd-.patch rename to 0274-efi-use-EFI_LOADER_-CODE-DATA-for-kernel-and-initrd-.patch diff --git a/0276-BLS-create-etc-kernel-cmdline-during-mkconfig.patch b/0275-BLS-create-etc-kernel-cmdline-during-mkconfig.patch similarity index 100% rename from 0276-BLS-create-etc-kernel-cmdline-during-mkconfig.patch rename to 0275-BLS-create-etc-kernel-cmdline-during-mkconfig.patch diff --git a/0278-squish-don-t-dup-rhgb-quiet-check-mtimes.patch b/0276-squish-don-t-dup-rhgb-quiet-check-mtimes.patch similarity index 100% rename from 0278-squish-don-t-dup-rhgb-quiet-check-mtimes.patch rename to 0276-squish-don-t-dup-rhgb-quiet-check-mtimes.patch diff --git a/0277-Try-reserving-less-ram.patch b/0277-Try-reserving-less-ram.patch deleted file mode 100644 index 46fb871f..00000000 --- a/0277-Try-reserving-less-ram.patch +++ /dev/null @@ -1,34 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 8 Aug 2022 11:23:59 -0400 -Subject: [PATCH] Try reserving less ram... - -In 005a0aaaad2a00a1fa1e60d94cc4fd5407c22e7d, we switched from reserving -one quarter of the available free memory to three quarters. Apparently -this has some unfortunate side-affects for some workloads, and has -negatively effected chainloading[0] as well as Fedora CoreOS[1]. - -This patch changes it to reserve /half/ of available memory, in hopes -that this is a working compromise. - -[0] https://bugzilla.redhat.com/show_bug.cgi?id=2115202 -[1] https://github.com/coreos/fedora-coreos-tracker/issues/1271 - -Signed-off-by: Peter Jones ---- - grub-core/kern/efi/mm.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/grub-core/kern/efi/mm.c b/grub-core/kern/efi/mm.c -index 150e412ee7..b4e012f5e7 100644 ---- a/grub-core/kern/efi/mm.c -+++ b/grub-core/kern/efi/mm.c -@@ -740,7 +740,7 @@ grub_efi_mm_init (void) - /* By default, request three quarters of the available memory. */ - total_pages = get_total_pages (filtered_memory_map, desc_size, - filtered_memory_map_end); -- required_pages = (total_pages >> 1) + (total_pages >> 2); -+ required_pages = (total_pages >> 1); - if (required_pages < BYTES_TO_PAGES (MIN_HEAP_SIZE)) - required_pages = BYTES_TO_PAGES (MIN_HEAP_SIZE); - else if (required_pages > BYTES_TO_PAGES (MAX_HEAP_SIZE)) diff --git a/0279-squish-give-up-on-rhgb-quiet.patch b/0277-squish-give-up-on-rhgb-quiet.patch similarity index 100% rename from 0279-squish-give-up-on-rhgb-quiet.patch rename to 0277-squish-give-up-on-rhgb-quiet.patch diff --git a/0280-squish-BLS-only-write-etc-kernel-cmdline-if-writable.patch b/0278-squish-BLS-only-write-etc-kernel-cmdline-if-writable.patch similarity index 100% rename from 0280-squish-BLS-only-write-etc-kernel-cmdline-if-writable.patch rename to 0278-squish-BLS-only-write-etc-kernel-cmdline-if-writable.patch diff --git a/0279-ieee1275-implement-vec5-for-cas-negotiation.patch b/0279-ieee1275-implement-vec5-for-cas-negotiation.patch new file mode 100644 index 00000000..2749d10c --- /dev/null +++ b/0279-ieee1275-implement-vec5-for-cas-negotiation.patch @@ -0,0 +1,70 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Diego Domingos +Date: Thu, 25 Aug 2022 11:37:56 -0400 +Subject: [PATCH] ieee1275: implement vec5 for cas negotiation + +As a legacy support, if the vector 5 is not implemented, Power +Hypervisor will consider the max CPUs as 64 instead 256 currently +supported during client-architecture-support negotiation. + +This patch implements the vector 5 and set the MAX CPUs to 256 while +setting the others values to 0 (default). + +Signed-off-by: Diego Domingos +Signed-off-by: Robbie Harwood +--- + grub-core/kern/ieee1275/init.c | 20 +++++++++++++++++++- + 1 file changed, 19 insertions(+), 1 deletion(-) + +diff --git a/grub-core/kern/ieee1275/init.c b/grub-core/kern/ieee1275/init.c +index ef55107467..6a51c9efab 100644 +--- a/grub-core/kern/ieee1275/init.c ++++ b/grub-core/kern/ieee1275/init.c +@@ -311,6 +311,18 @@ struct option_vector2 { + grub_uint8_t max_pft_size; + } __attribute__((packed)); + ++struct option_vector5 { ++ grub_uint8_t byte1; ++ grub_uint8_t byte2; ++ grub_uint8_t byte3; ++ grub_uint8_t cmo; ++ grub_uint8_t associativity; ++ grub_uint8_t bin_opts; ++ grub_uint8_t micro_checkpoint; ++ grub_uint8_t reserved0; ++ grub_uint32_t max_cpus; ++} __attribute__((packed)); ++ + struct pvr_entry { + grub_uint32_t mask; + grub_uint32_t entry; +@@ -329,6 +341,8 @@ struct cas_vector { + grub_uint16_t vec3; + grub_uint8_t vec4_size; + grub_uint16_t vec4; ++ grub_uint8_t vec5_size; ++ struct option_vector5 vec5; + } __attribute__((packed)); + + /* Call ibm,client-architecture-support to try to get more RMA. +@@ -349,7 +363,7 @@ grub_ieee1275_ibm_cas (void) + } args; + struct cas_vector vector = { + .pvr_list = { { 0x00000000, 0xffffffff } }, /* any processor */ +- .num_vecs = 4 - 1, ++ .num_vecs = 5 - 1, + .vec1_size = 0, + .vec1 = 0x80, /* ignore */ + .vec2_size = 1 + sizeof(struct option_vector2) - 2, +@@ -360,6 +374,10 @@ grub_ieee1275_ibm_cas (void) + .vec3 = 0x00e0, // ask for FP + VMX + DFP but don't halt if unsatisfied + .vec4_size = 2 - 1, + .vec4 = 0x0001, // set required minimum capacity % to the lowest value ++ .vec5_size = 1 + sizeof(struct option_vector5) - 2, ++ .vec5 = { ++ 0, 0, 0, 0, 0, 0, 0, 0, 256 ++ } + }; + + INIT_IEEE1275_COMMON (&args.common, "call-method", 3, 2); diff --git a/0280-blscfg-Don-t-root-device-in-emu-builds.patch b/0280-blscfg-Don-t-root-device-in-emu-builds.patch new file mode 100644 index 00000000..3fe8baf2 --- /dev/null +++ b/0280-blscfg-Don-t-root-device-in-emu-builds.patch @@ -0,0 +1,27 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 25 Aug 2022 17:57:55 -0400 +Subject: [PATCH] blscfg: Don't root device in emu builds + +Otherwise, we end up looking for kernel/initrd in /boot/boot which +doesn't work at all. Non-emu builds need to be looking in +($root)/boot/, which is what this is for. + +Signed-off-by: Robbie Harwood +--- + grub-core/commands/blscfg.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/grub-core/commands/blscfg.c b/grub-core/commands/blscfg.c +index e907a6a5d2..dbd0899acf 100644 +--- a/grub-core/commands/blscfg.c ++++ b/grub-core/commands/blscfg.c +@@ -41,7 +41,7 @@ GRUB_MOD_LICENSE ("GPLv3+"); + + #define GRUB_BLS_CONFIG_PATH "/loader/entries/" + #ifdef GRUB_MACHINE_EMU +-#define GRUB_BOOT_DEVICE "/boot" ++#define GRUB_BOOT_DEVICE "" + #else + #define GRUB_BOOT_DEVICE "($root)" + #endif diff --git a/grub.patches b/grub.patches index b0acec4a..5bd36301 100644 --- a/grub.patches +++ b/grub.patches @@ -268,13 +268,13 @@ Patch0267: 0267-grub-probe-document-the-behavior-of-multiple-v.patch Patch0268: 0268-grub_fs_probe-dprint-errors-from-filesystems.patch Patch0269: 0269-fs-fat-don-t-error-when-mtime-is-0.patch Patch0270: 0270-Make-debug-file-show-which-file-filters-get-run.patch -Patch0271: 0271-efi-make-the-default-arena-most-of-ram.patch -Patch0272: 0272-efi-use-enumerated-array-positions-for-our-allocatio.patch -Patch0273: 0273-efi-split-allocation-policy-for-kernel-vs-initrd-mem.patch -Patch0274: 0274-efi-allocate-the-initrd-within-the-bounds-expressed-.patch -Patch0275: 0275-efi-use-EFI_LOADER_-CODE-DATA-for-kernel-and-initrd-.patch -Patch0276: 0276-BLS-create-etc-kernel-cmdline-during-mkconfig.patch -Patch0277: 0277-Try-reserving-less-ram.patch -Patch0278: 0278-squish-don-t-dup-rhgb-quiet-check-mtimes.patch -Patch0279: 0279-squish-give-up-on-rhgb-quiet.patch -Patch0280: 0280-squish-BLS-only-write-etc-kernel-cmdline-if-writable.patch +Patch0271: 0271-efi-use-enumerated-array-positions-for-our-allocatio.patch +Patch0272: 0272-efi-split-allocation-policy-for-kernel-vs-initrd-mem.patch +Patch0273: 0273-efi-allocate-the-initrd-within-the-bounds-expressed-.patch +Patch0274: 0274-efi-use-EFI_LOADER_-CODE-DATA-for-kernel-and-initrd-.patch +Patch0275: 0275-BLS-create-etc-kernel-cmdline-during-mkconfig.patch +Patch0276: 0276-squish-don-t-dup-rhgb-quiet-check-mtimes.patch +Patch0277: 0277-squish-give-up-on-rhgb-quiet.patch +Patch0278: 0278-squish-BLS-only-write-etc-kernel-cmdline-if-writable.patch +Patch0279: 0279-ieee1275-implement-vec5-for-cas-negotiation.patch +Patch0280: 0280-blscfg-Don-t-root-device-in-emu-builds.patch diff --git a/grub2.spec b/grub2.spec index b9e4543a..03350389 100644 --- a/grub2.spec +++ b/grub2.spec @@ -17,7 +17,7 @@ Name: grub2 Epoch: 1 Version: 2.06 -Release: 52%{?dist} +Release: 53%{?dist} Summary: Bootloader with support for Linux, Multiboot and more License: GPLv3+ URL: http://www.gnu.org/software/grub/ @@ -530,6 +530,9 @@ mv ${EFI_HOME}/grub.cfg.stb ${EFI_HOME}/grub.cfg %endif %changelog +* Wed Sep 07 2022 Robbie Harwood - 2.06-53 +- Sync with rawhide at 2.06-56 minus gettext changes + * Wed Aug 17 2022 Robbie Harwood - 2.06-52 - Handle ostree's non-writable /etc/kernel From ee3e6f65f0264b99024f58b02dae02c8056b5a3a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 12 Oct 2022 18:13:31 +0000 Subject: [PATCH 02/10] x86-efi: Fix an incorrect array size in kernel allocation Signed-off-by: Robbie Harwood --- ...ncorrect-array-size-in-kernel-alloca.patch | 36 +++++++++++++++++++ grub.patches | 1 + grub2.spec | 5 ++- 3 files changed, 41 insertions(+), 1 deletion(-) create mode 100644 0281-x86-efi-Fix-an-incorrect-array-size-in-kernel-alloca.patch diff --git a/0281-x86-efi-Fix-an-incorrect-array-size-in-kernel-alloca.patch b/0281-x86-efi-Fix-an-incorrect-array-size-in-kernel-alloca.patch new file mode 100644 index 00000000..00797503 --- /dev/null +++ b/0281-x86-efi-Fix-an-incorrect-array-size-in-kernel-alloca.patch @@ -0,0 +1,36 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Tue, 11 Oct 2022 17:00:50 -0400 +Subject: [PATCH] x86-efi: Fix an incorrect array size in kernel allocation + +In 81a6ebf62bbe166ddc968463df2e8bd481bf697c ("efi: split allocation +policy for kernel vs initrd memories."), I introduced a split in the +kernel allocator to allow for different dynamic policies for the kernel +and the initrd allocations. + +Unfortunately, that change increased the size of the policy data used to +make decisions, but did not change the size of the temporary storage we +use to back it up and restore. This results in some of .data getting +clobbered at runtime, and hilarity ensues. + +This patch makes the size of the backup storage be based on the size of +the initial policy data. + +Signed-off-by: Peter Jones +--- + grub-core/loader/i386/efi/linux.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/grub-core/loader/i386/efi/linux.c b/grub-core/loader/i386/efi/linux.c +index ac5ef50bdb..9854b0defa 100644 +--- a/grub-core/loader/i386/efi/linux.c ++++ b/grub-core/loader/i386/efi/linux.c +@@ -92,7 +92,7 @@ static struct allocation_choice max_addresses[] = + { INITRD_MEM, GRUB_EFI_MAX_ALLOCATION_ADDRESS, GRUB_EFI_ALLOCATE_MAX_ADDRESS }, + { NO_MEM, 0, 0 } + }; +-static struct allocation_choice saved_addresses[4]; ++static struct allocation_choice saved_addresses[sizeof(max_addresses) / sizeof(max_addresses[0])]; + + #define save_addresses() grub_memcpy(saved_addresses, max_addresses, sizeof(max_addresses)) + #define restore_addresses() grub_memcpy(max_addresses, saved_addresses, sizeof(max_addresses)) diff --git a/grub.patches b/grub.patches index 5bd36301..ce6f6c7d 100644 --- a/grub.patches +++ b/grub.patches @@ -278,3 +278,4 @@ Patch0277: 0277-squish-give-up-on-rhgb-quiet.patch Patch0278: 0278-squish-BLS-only-write-etc-kernel-cmdline-if-writable.patch Patch0279: 0279-ieee1275-implement-vec5-for-cas-negotiation.patch Patch0280: 0280-blscfg-Don-t-root-device-in-emu-builds.patch +Patch0281: 0281-x86-efi-Fix-an-incorrect-array-size-in-kernel-alloca.patch diff --git a/grub2.spec b/grub2.spec index 03350389..4f0e4a31 100644 --- a/grub2.spec +++ b/grub2.spec @@ -17,7 +17,7 @@ Name: grub2 Epoch: 1 Version: 2.06 -Release: 53%{?dist} +Release: 54%{?dist} Summary: Bootloader with support for Linux, Multiboot and more License: GPLv3+ URL: http://www.gnu.org/software/grub/ @@ -530,6 +530,9 @@ mv ${EFI_HOME}/grub.cfg.stb ${EFI_HOME}/grub.cfg %endif %changelog +* Wed Oct 12 2022 Robbie Harwood - 2.06-54 +- x86-efi: Fix an incorrect array size in kernel allocation + * Wed Sep 07 2022 Robbie Harwood - 2.06-53 - Sync with rawhide at 2.06-56 minus gettext changes From 445c9bcb9d145db4bceeed4cf64ce46ecb54b913 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Nov 2022 18:09:20 +0000 Subject: [PATCH 03/10] Font fixes (CVE-2022-2601 batch) Signed-off-by: Robbie Harwood --- ...hs-exceeds-font-max_glyph_width-or-f.patch | 32 +++++ ...erflow-in-grub_font_get_glyph_intern.patch | 111 ++++++++++++++++++ ...-integer-overflows-in-grub_font_cons.patch | 80 +++++++++++++ 0285-font-Remove-grub_font_dup_glyph.patch | 41 +++++++ ...nteger-overflow-in-ensure_comb_space.patch | 47 ++++++++ ...nt-Fix-integer-overflow-in-BMP-index.patch | 64 ++++++++++ ...-underflow-in-binary-search-of-char-.patch | 84 +++++++++++++ ...b-Enforce-verification-of-font-files.patch | 53 +++++++++ 0290-fbutil-Fix-integer-overflow.patch | 84 +++++++++++++ ...ix-an-integer-underflow-in-blit_comb.patch | 90 ++++++++++++++ ..._font_blit_glyph-and-grub_font_blit_.patch | 74 ++++++++++++ ...l_font-to-glyphs-in-ascii_font_glyph.patch | 35 ++++++ ...ix-an-integer-overflow-in-grub_unico.patch | 54 +++++++++ grub.patches | 13 ++ grub2.spec | 5 +- 15 files changed, 866 insertions(+), 1 deletion(-) create mode 100644 0282-font-Reject-glyphs-exceeds-font-max_glyph_width-or-f.patch create mode 100644 0283-font-Fix-size-overflow-in-grub_font_get_glyph_intern.patch create mode 100644 0284-font-Fix-several-integer-overflows-in-grub_font_cons.patch create mode 100644 0285-font-Remove-grub_font_dup_glyph.patch create mode 100644 0286-font-Fix-integer-overflow-in-ensure_comb_space.patch create mode 100644 0287-font-Fix-integer-overflow-in-BMP-index.patch create mode 100644 0288-font-Fix-integer-underflow-in-binary-search-of-char-.patch create mode 100644 0289-kern-efi-sb-Enforce-verification-of-font-files.patch create mode 100644 0290-fbutil-Fix-integer-overflow.patch create mode 100644 0291-font-Fix-an-integer-underflow-in-blit_comb.patch create mode 100644 0292-font-Harden-grub_font_blit_glyph-and-grub_font_blit_.patch create mode 100644 0293-font-Assign-null_font-to-glyphs-in-ascii_font_glyph.patch create mode 100644 0294-normal-charset-Fix-an-integer-overflow-in-grub_unico.patch diff --git a/0282-font-Reject-glyphs-exceeds-font-max_glyph_width-or-f.patch b/0282-font-Reject-glyphs-exceeds-font-max_glyph_width-or-f.patch new file mode 100644 index 00000000..e264b099 --- /dev/null +++ b/0282-font-Reject-glyphs-exceeds-font-max_glyph_width-or-f.patch @@ -0,0 +1,32 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Zhang Boyang +Date: Wed, 3 Aug 2022 19:45:33 +0800 +Subject: [PATCH] font: Reject glyphs exceeds font->max_glyph_width or + font->max_glyph_height + +Check glyph's width and height against limits specified in font's +metadata. Reject the glyph (and font) if such limits are exceeded. + +Signed-off-by: Zhang Boyang +Reviewed-by: Daniel Kiper +(cherry picked from commit 5760fcfd466cc757540ea0d591bad6a08caeaa16) +(cherry picked from commit 3b410ef4bb95e607cadeba2193fa90ae9bddb98d) +--- + grub-core/font/font.c | 4 +++- + 1 file changed, 3 insertions(+), 1 deletion(-) + +diff --git a/grub-core/font/font.c b/grub-core/font/font.c +index d09bb38d89..2f09a4a55b 100644 +--- a/grub-core/font/font.c ++++ b/grub-core/font/font.c +@@ -760,7 +760,9 @@ grub_font_get_glyph_internal (grub_font_t font, grub_uint32_t code) + || read_be_uint16 (font->file, &height) != 0 + || read_be_int16 (font->file, &xoff) != 0 + || read_be_int16 (font->file, &yoff) != 0 +- || read_be_int16 (font->file, &dwidth) != 0) ++ || read_be_int16 (font->file, &dwidth) != 0 ++ || width > font->max_char_width ++ || height > font->max_char_height) + { + remove_font (font); + return 0; diff --git a/0283-font-Fix-size-overflow-in-grub_font_get_glyph_intern.patch b/0283-font-Fix-size-overflow-in-grub_font_get_glyph_intern.patch new file mode 100644 index 00000000..7ec23ab8 --- /dev/null +++ b/0283-font-Fix-size-overflow-in-grub_font_get_glyph_intern.patch @@ -0,0 +1,111 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Zhang Boyang +Date: Fri, 5 Aug 2022 00:51:20 +0800 +Subject: [PATCH] font: Fix size overflow in grub_font_get_glyph_internal() + +The length of memory allocation and file read may overflow. This patch +fixes the problem by using safemath macros. + +There is a lot of code repetition like "(x * y + 7) / 8". It is unsafe +if overflow happens. This patch introduces grub_video_bitmap_calc_1bpp_bufsz(). +It is safe replacement for such code. It has safemath-like prototype. + +This patch also introduces grub_cast(value, pointer), it casts value to +typeof(*pointer) then store the value to *pointer. It returns true when +overflow occurs or false if there is no overflow. The semantics of arguments +and return value are designed to be consistent with other safemath macros. + +Signed-off-by: Zhang Boyang +Reviewed-by: Daniel Kiper +(cherry picked from commit 941d10ad6f1dcbd12fb613002249e29ba035f985) +(cherry picked from commit 6bca9693878bdf61dd62b8c784862a48e75f569a) +--- + grub-core/font/font.c | 17 +++++++++++++---- + include/grub/bitmap.h | 18 ++++++++++++++++++ + include/grub/safemath.h | 2 ++ + 3 files changed, 33 insertions(+), 4 deletions(-) + +diff --git a/grub-core/font/font.c b/grub-core/font/font.c +index 2f09a4a55b..6a3fbebbd8 100644 +--- a/grub-core/font/font.c ++++ b/grub-core/font/font.c +@@ -739,7 +739,8 @@ grub_font_get_glyph_internal (grub_font_t font, grub_uint32_t code) + grub_int16_t xoff; + grub_int16_t yoff; + grub_int16_t dwidth; +- int len; ++ grub_ssize_t len; ++ grub_size_t sz; + + if (index_entry->glyph) + /* Return cached glyph. */ +@@ -768,9 +769,17 @@ grub_font_get_glyph_internal (grub_font_t font, grub_uint32_t code) + return 0; + } + +- len = (width * height + 7) / 8; +- glyph = grub_malloc (sizeof (struct grub_font_glyph) + len); +- if (!glyph) ++ /* Calculate real struct size of current glyph. */ ++ if (grub_video_bitmap_calc_1bpp_bufsz (width, height, &len) || ++ grub_add (sizeof (struct grub_font_glyph), len, &sz)) ++ { ++ remove_font (font); ++ return 0; ++ } ++ ++ /* Allocate and initialize the glyph struct. */ ++ glyph = grub_malloc (sz); ++ if (glyph == NULL) + { + remove_font (font); + return 0; +diff --git a/include/grub/bitmap.h b/include/grub/bitmap.h +index 5728f8ca3a..0d9603f619 100644 +--- a/include/grub/bitmap.h ++++ b/include/grub/bitmap.h +@@ -23,6 +23,7 @@ + #include + #include + #include ++#include + + struct grub_video_bitmap + { +@@ -79,6 +80,23 @@ grub_video_bitmap_get_height (struct grub_video_bitmap *bitmap) + return bitmap->mode_info.height; + } + ++/* ++ * Calculate and store the size of data buffer of 1bit bitmap in result. ++ * Equivalent to "*result = (width * height + 7) / 8" if no overflow occurs. ++ * Return true when overflow occurs or false if there is no overflow. ++ * This function is intentionally implemented as a macro instead of ++ * an inline function. Although a bit awkward, it preserves data types for ++ * safemath macros and reduces macro side effects as much as possible. ++ * ++ * XXX: Will report false overflow if width * height > UINT64_MAX. ++ */ ++#define grub_video_bitmap_calc_1bpp_bufsz(width, height, result) \ ++({ \ ++ grub_uint64_t _bitmap_pixels; \ ++ grub_mul ((width), (height), &_bitmap_pixels) ? 1 : \ ++ grub_cast (_bitmap_pixels / GRUB_CHAR_BIT + !!(_bitmap_pixels % GRUB_CHAR_BIT), (result)); \ ++}) ++ + void EXPORT_FUNC (grub_video_bitmap_get_mode_info) (struct grub_video_bitmap *bitmap, + struct grub_video_mode_info *mode_info); + +diff --git a/include/grub/safemath.h b/include/grub/safemath.h +index c17b89bba1..bb0f826de1 100644 +--- a/include/grub/safemath.h ++++ b/include/grub/safemath.h +@@ -30,6 +30,8 @@ + #define grub_sub(a, b, res) __builtin_sub_overflow(a, b, res) + #define grub_mul(a, b, res) __builtin_mul_overflow(a, b, res) + ++#define grub_cast(a, res) grub_add ((a), 0, (res)) ++ + #else + #error gcc 5.1 or newer or clang 3.8 or newer is required + #endif diff --git a/0284-font-Fix-several-integer-overflows-in-grub_font_cons.patch b/0284-font-Fix-several-integer-overflows-in-grub_font_cons.patch new file mode 100644 index 00000000..fcc1d3c3 --- /dev/null +++ b/0284-font-Fix-several-integer-overflows-in-grub_font_cons.patch @@ -0,0 +1,80 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Zhang Boyang +Date: Fri, 5 Aug 2022 01:58:27 +0800 +Subject: [PATCH] font: Fix several integer overflows in + grub_font_construct_glyph() + +This patch fixes several integer overflows in grub_font_construct_glyph(). +Glyphs of invalid size, zero or leading to an overflow, are rejected. +The inconsistency between "glyph" and "max_glyph_size" when grub_malloc() +returns NULL is fixed too. + +Fixes: CVE-2022-2601 + +Reported-by: Zhang Boyang +Signed-off-by: Zhang Boyang +Reviewed-by: Daniel Kiper +(cherry picked from commit b1805f251b31a9d3cfae5c3572ddfa630145dbbf) +(cherry picked from commit b91eb9bd6c724339b7d7bb4765b9d36f1ee88b84) +--- + grub-core/font/font.c | 29 +++++++++++++++++------------ + 1 file changed, 17 insertions(+), 12 deletions(-) + +diff --git a/grub-core/font/font.c b/grub-core/font/font.c +index 6a3fbebbd8..1fa181d4ca 100644 +--- a/grub-core/font/font.c ++++ b/grub-core/font/font.c +@@ -1517,6 +1517,7 @@ grub_font_construct_glyph (grub_font_t hinted_font, + struct grub_video_signed_rect bounds; + static struct grub_font_glyph *glyph = 0; + static grub_size_t max_glyph_size = 0; ++ grub_size_t cur_glyph_size; + + ensure_comb_space (glyph_id); + +@@ -1533,29 +1534,33 @@ grub_font_construct_glyph (grub_font_t hinted_font, + if (!glyph_id->ncomb && !glyph_id->attributes) + return main_glyph; + +- if (max_glyph_size < sizeof (*glyph) + (bounds.width * bounds.height + GRUB_CHAR_BIT - 1) / GRUB_CHAR_BIT) ++ if (grub_video_bitmap_calc_1bpp_bufsz (bounds.width, bounds.height, &cur_glyph_size) || ++ grub_add (sizeof (*glyph), cur_glyph_size, &cur_glyph_size)) ++ return main_glyph; ++ ++ if (max_glyph_size < cur_glyph_size) + { + grub_free (glyph); +- max_glyph_size = (sizeof (*glyph) + (bounds.width * bounds.height + GRUB_CHAR_BIT - 1) / GRUB_CHAR_BIT) * 2; +- if (max_glyph_size < 8) +- max_glyph_size = 8; +- glyph = grub_malloc (max_glyph_size); ++ if (grub_mul (cur_glyph_size, 2, &max_glyph_size)) ++ max_glyph_size = 0; ++ glyph = max_glyph_size > 0 ? grub_malloc (max_glyph_size) : NULL; + } + if (!glyph) + { ++ max_glyph_size = 0; + grub_errno = GRUB_ERR_NONE; + return main_glyph; + } + +- grub_memset (glyph, 0, sizeof (*glyph) +- + (bounds.width * bounds.height +- + GRUB_CHAR_BIT - 1) / GRUB_CHAR_BIT); ++ grub_memset (glyph, 0, cur_glyph_size); + + glyph->font = main_glyph->font; +- glyph->width = bounds.width; +- glyph->height = bounds.height; +- glyph->offset_x = bounds.x; +- glyph->offset_y = bounds.y; ++ if (bounds.width == 0 || bounds.height == 0 || ++ grub_cast (bounds.width, &glyph->width) || ++ grub_cast (bounds.height, &glyph->height) || ++ grub_cast (bounds.x, &glyph->offset_x) || ++ grub_cast (bounds.y, &glyph->offset_y)) ++ return main_glyph; + + if (glyph_id->attributes & GRUB_UNICODE_GLYPH_ATTRIBUTE_MIRROR) + grub_font_blit_glyph_mirror (glyph, main_glyph, diff --git a/0285-font-Remove-grub_font_dup_glyph.patch b/0285-font-Remove-grub_font_dup_glyph.patch new file mode 100644 index 00000000..a3493f6b --- /dev/null +++ b/0285-font-Remove-grub_font_dup_glyph.patch @@ -0,0 +1,41 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Zhang Boyang +Date: Fri, 5 Aug 2022 02:13:29 +0800 +Subject: [PATCH] font: Remove grub_font_dup_glyph() + +Remove grub_font_dup_glyph() since nobody is using it since 2013, and +I'm too lazy to fix the integer overflow problem in it. + +Signed-off-by: Zhang Boyang +Reviewed-by: Daniel Kiper +(cherry picked from commit 25ad31c19c331aaa2dbd9bd2b2e2655de5766a9d) +(cherry picked from commit ad950e1e033318bb50222ed268a6dcfb97389035) +--- + grub-core/font/font.c | 14 -------------- + 1 file changed, 14 deletions(-) + +diff --git a/grub-core/font/font.c b/grub-core/font/font.c +index 1fa181d4ca..a115a63b0c 100644 +--- a/grub-core/font/font.c ++++ b/grub-core/font/font.c +@@ -1055,20 +1055,6 @@ grub_font_get_glyph_with_fallback (grub_font_t font, grub_uint32_t code) + return best_glyph; + } + +-#if 0 +-static struct grub_font_glyph * +-grub_font_dup_glyph (struct grub_font_glyph *glyph) +-{ +- static struct grub_font_glyph *ret; +- ret = grub_malloc (sizeof (*ret) + (glyph->width * glyph->height + 7) / 8); +- if (!ret) +- return NULL; +- grub_memcpy (ret, glyph, sizeof (*ret) +- + (glyph->width * glyph->height + 7) / 8); +- return ret; +-} +-#endif +- + /* FIXME: suboptimal. */ + static void + grub_font_blit_glyph (struct grub_font_glyph *target, diff --git a/0286-font-Fix-integer-overflow-in-ensure_comb_space.patch b/0286-font-Fix-integer-overflow-in-ensure_comb_space.patch new file mode 100644 index 00000000..af5eedbb --- /dev/null +++ b/0286-font-Fix-integer-overflow-in-ensure_comb_space.patch @@ -0,0 +1,47 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Zhang Boyang +Date: Fri, 5 Aug 2022 02:27:05 +0800 +Subject: [PATCH] font: Fix integer overflow in ensure_comb_space() + +In fact it can't overflow at all because glyph_id->ncomb is only 8-bit +wide. But let's keep safe if somebody changes the width of glyph_id->ncomb +in the future. This patch also fixes the inconsistency between +render_max_comb_glyphs and render_combining_glyphs when grub_malloc() +returns NULL. + +Signed-off-by: Zhang Boyang +Reviewed-by: Daniel Kiper +(cherry picked from commit b2740b7e4a03bb8331d48b54b119afea76bb9d5f) +(cherry picked from commit f66ea1e60c347408e92b6695d5105c7e0f24d568) +--- + grub-core/font/font.c | 14 +++++++++----- + 1 file changed, 9 insertions(+), 5 deletions(-) + +diff --git a/grub-core/font/font.c b/grub-core/font/font.c +index a115a63b0c..d0e6340404 100644 +--- a/grub-core/font/font.c ++++ b/grub-core/font/font.c +@@ -1468,14 +1468,18 @@ ensure_comb_space (const struct grub_unicode_glyph *glyph_id) + if (glyph_id->ncomb <= render_max_comb_glyphs) + return; + +- render_max_comb_glyphs = 2 * glyph_id->ncomb; +- if (render_max_comb_glyphs < 8) ++ if (grub_mul (glyph_id->ncomb, 2, &render_max_comb_glyphs)) ++ render_max_comb_glyphs = 0; ++ if (render_max_comb_glyphs > 0 && render_max_comb_glyphs < 8) + render_max_comb_glyphs = 8; + grub_free (render_combining_glyphs); +- render_combining_glyphs = grub_malloc (render_max_comb_glyphs +- * sizeof (render_combining_glyphs[0])); ++ render_combining_glyphs = (render_max_comb_glyphs > 0) ? ++ grub_calloc (render_max_comb_glyphs, sizeof (render_combining_glyphs[0])) : NULL; + if (!render_combining_glyphs) +- grub_errno = 0; ++ { ++ render_max_comb_glyphs = 0; ++ grub_errno = GRUB_ERR_NONE; ++ } + } + + int diff --git a/0287-font-Fix-integer-overflow-in-BMP-index.patch b/0287-font-Fix-integer-overflow-in-BMP-index.patch new file mode 100644 index 00000000..bb227490 --- /dev/null +++ b/0287-font-Fix-integer-overflow-in-BMP-index.patch @@ -0,0 +1,64 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Zhang Boyang +Date: Mon, 15 Aug 2022 02:04:58 +0800 +Subject: [PATCH] font: Fix integer overflow in BMP index + +The BMP index (font->bmp_idx) is designed as a reverse lookup table of +char entries (font->char_index), in order to speed up lookups for BMP +chars (i.e. code < 0x10000). The values in BMP index are the subscripts +of the corresponding char entries, stored in grub_uint16_t, while 0xffff +means not found. + +This patch fixes the problem of large subscript truncated to grub_uint16_t, +leading BMP index to return wrong char entry or report false miss. The +code now checks for bounds and uses BMP index as a hint, and fallbacks +to binary-search if necessary. + +On the occasion add a comment about BMP index is initialized to 0xffff. + +Signed-off-by: Zhang Boyang +Reviewed-by: Daniel Kiper +(cherry picked from commit afda8b60ba0712abe01ae1e64c5f7a067a0e6492) +(cherry picked from commit 6d90568929e11739b56f09ebbce9185ca9c23519) +--- + grub-core/font/font.c | 13 +++++++++---- + 1 file changed, 9 insertions(+), 4 deletions(-) + +diff --git a/grub-core/font/font.c b/grub-core/font/font.c +index d0e6340404..b208a28717 100644 +--- a/grub-core/font/font.c ++++ b/grub-core/font/font.c +@@ -300,6 +300,8 @@ load_font_index (grub_file_t file, grub_uint32_t sect_length, struct + font->bmp_idx = grub_malloc (0x10000 * sizeof (grub_uint16_t)); + if (!font->bmp_idx) + return 1; ++ ++ /* Init the BMP index array to 0xffff. */ + grub_memset (font->bmp_idx, 0xff, 0x10000 * sizeof (grub_uint16_t)); + + +@@ -328,7 +330,7 @@ load_font_index (grub_file_t file, grub_uint32_t sect_length, struct + return 1; + } + +- if (entry->code < 0x10000) ++ if (entry->code < 0x10000 && i < 0xffff) + font->bmp_idx[entry->code] = i; + + last_code = entry->code; +@@ -696,9 +698,12 @@ find_glyph (const grub_font_t font, grub_uint32_t code) + /* Use BMP index if possible. */ + if (code < 0x10000 && font->bmp_idx) + { +- if (font->bmp_idx[code] == 0xffff) +- return 0; +- return &table[font->bmp_idx[code]]; ++ if (font->bmp_idx[code] < 0xffff) ++ return &table[font->bmp_idx[code]]; ++ /* ++ * When we are here then lookup in BMP index result in miss, ++ * fallthough to binary-search. ++ */ + } + + /* Do a binary search in `char_index', which is ordered by code point. */ diff --git a/0288-font-Fix-integer-underflow-in-binary-search-of-char-.patch b/0288-font-Fix-integer-underflow-in-binary-search-of-char-.patch new file mode 100644 index 00000000..5c25e091 --- /dev/null +++ b/0288-font-Fix-integer-underflow-in-binary-search-of-char-.patch @@ -0,0 +1,84 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Zhang Boyang +Date: Sun, 14 Aug 2022 18:09:38 +0800 +Subject: [PATCH] font: Fix integer underflow in binary search of char index + +If search target is less than all entries in font->index then "hi" +variable is set to -1, which translates to SIZE_MAX and leads to errors. + +This patch fixes the problem by replacing the entire binary search code +with the libstdc++'s std::lower_bound() implementation. + +Signed-off-by: Zhang Boyang +Reviewed-by: Daniel Kiper +(cherry picked from commit c140a086838e7c9af87842036f891b8393a8c4bc) +(cherry picked from commit e110997335b1744464ea232d57a7d86e16ca8dee) +--- + grub-core/font/font.c | 40 ++++++++++++++++++++++------------------ + 1 file changed, 22 insertions(+), 18 deletions(-) + +diff --git a/grub-core/font/font.c b/grub-core/font/font.c +index b208a28717..193dfec045 100644 +--- a/grub-core/font/font.c ++++ b/grub-core/font/font.c +@@ -688,12 +688,12 @@ read_be_int16 (grub_file_t file, grub_int16_t * value) + static inline struct char_index_entry * + find_glyph (const grub_font_t font, grub_uint32_t code) + { +- struct char_index_entry *table; +- grub_size_t lo; +- grub_size_t hi; +- grub_size_t mid; ++ struct char_index_entry *table, *first, *end; ++ grub_size_t len; + + table = font->char_index; ++ if (table == NULL) ++ return NULL; + + /* Use BMP index if possible. */ + if (code < 0x10000 && font->bmp_idx) +@@ -706,25 +706,29 @@ find_glyph (const grub_font_t font, grub_uint32_t code) + */ + } + +- /* Do a binary search in `char_index', which is ordered by code point. */ +- lo = 0; +- hi = font->num_chars - 1; ++ /* ++ * Do a binary search in char_index which is ordered by code point. ++ * The code below is the same as libstdc++'s std::lower_bound(). ++ */ ++ first = table; ++ len = font->num_chars; ++ end = first + len; + +- if (!table) +- return 0; +- +- while (lo <= hi) ++ while (len > 0) + { +- mid = lo + (hi - lo) / 2; +- if (code < table[mid].code) +- hi = mid - 1; +- else if (code > table[mid].code) +- lo = mid + 1; ++ grub_size_t half = len >> 1; ++ struct char_index_entry *middle = first + half; ++ ++ if (middle->code < code) ++ { ++ first = middle + 1; ++ len = len - half - 1; ++ } + else +- return &table[mid]; ++ len = half; + } + +- return 0; ++ return (first < end && first->code == code) ? first : NULL; + } + + /* Get a glyph for the Unicode character CODE in FONT. The glyph is loaded diff --git a/0289-kern-efi-sb-Enforce-verification-of-font-files.patch b/0289-kern-efi-sb-Enforce-verification-of-font-files.patch new file mode 100644 index 00000000..42fea351 --- /dev/null +++ b/0289-kern-efi-sb-Enforce-verification-of-font-files.patch @@ -0,0 +1,53 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Zhang Boyang +Date: Sun, 14 Aug 2022 15:51:54 +0800 +Subject: [PATCH] kern/efi/sb: Enforce verification of font files + +As a mitigation and hardening measure enforce verification of font +files. Then only trusted font files can be load. This will reduce the +attack surface at cost of losing the ability of end-users to customize +fonts if e.g. UEFI Secure Boot is enabled. Vendors can always customize +fonts because they have ability to pack fonts into their GRUB bundles. + +This goal is achieved by: + + * Removing GRUB_FILE_TYPE_FONT from shim lock verifier's + skip-verification list. + + * Adding GRUB_FILE_TYPE_FONT to lockdown verifier's defer-auth list, + so font files must be verified by a verifier before they can be loaded. + +Suggested-by: Daniel Kiper +Signed-off-by: Zhang Boyang +Reviewed-by: Daniel Kiper +(cherry picked from commit 630deb8c0d8b02b670ced4b7030414bcf17aa080) +(cherry picked from commit 37257e0ee45b9029b62f4046c983481d063b821d) +--- + grub-core/kern/efi/sb.c | 1 - + grub-core/kern/lockdown.c | 1 + + 2 files changed, 1 insertion(+), 1 deletion(-) + +diff --git a/grub-core/kern/efi/sb.c b/grub-core/kern/efi/sb.c +index 89c4bb3fd1..db42c2539f 100644 +--- a/grub-core/kern/efi/sb.c ++++ b/grub-core/kern/efi/sb.c +@@ -145,7 +145,6 @@ shim_lock_verifier_init (grub_file_t io __attribute__ ((unused)), + case GRUB_FILE_TYPE_PRINT_BLOCKLIST: + case GRUB_FILE_TYPE_TESTLOAD: + case GRUB_FILE_TYPE_GET_SIZE: +- case GRUB_FILE_TYPE_FONT: + case GRUB_FILE_TYPE_ZFS_ENCRYPTION_KEY: + case GRUB_FILE_TYPE_CAT: + case GRUB_FILE_TYPE_HEXCAT: +diff --git a/grub-core/kern/lockdown.c b/grub-core/kern/lockdown.c +index 0bc70fd42d..af6d493cd3 100644 +--- a/grub-core/kern/lockdown.c ++++ b/grub-core/kern/lockdown.c +@@ -51,6 +51,7 @@ lockdown_verifier_init (grub_file_t io __attribute__ ((unused)), + case GRUB_FILE_TYPE_EFI_CHAINLOADED_IMAGE: + case GRUB_FILE_TYPE_ACPI_TABLE: + case GRUB_FILE_TYPE_DEVICE_TREE_IMAGE: ++ case GRUB_FILE_TYPE_FONT: + *flags = GRUB_VERIFY_FLAGS_DEFER_AUTH; + + /* Fall through. */ diff --git a/0290-fbutil-Fix-integer-overflow.patch b/0290-fbutil-Fix-integer-overflow.patch new file mode 100644 index 00000000..f8e82e57 --- /dev/null +++ b/0290-fbutil-Fix-integer-overflow.patch @@ -0,0 +1,84 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Zhang Boyang +Date: Tue, 6 Sep 2022 03:03:21 +0800 +Subject: [PATCH] fbutil: Fix integer overflow + +Expressions like u64 = u32 * u32 are unsafe because their products are +truncated to u32 even if left hand side is u64. This patch fixes all +problems like that one in fbutil. + +To get right result not only left hand side have to be u64 but it's also +necessary to cast at least one of the operands of all leaf operators of +right hand side to u64, e.g. u64 = u32 * u32 + u32 * u32 should be +u64 = (u64)u32 * u32 + (u64)u32 * u32. + +For 1-bit bitmaps grub_uint64_t have to be used. It's safe because any +combination of values in (grub_uint64_t)u32 * u32 + u32 expression will +not overflow grub_uint64_t. + +Other expressions like ptr + u32 * u32 + u32 * u32 are also vulnerable. +They should be ptr + (grub_addr_t)u32 * u32 + (grub_addr_t)u32 * u32. + +This patch also adds a comment to grub_video_fb_get_video_ptr() which +says it's arguments must be valid and no sanity check is performed +(like its siblings in grub-core/video/fb/fbutil.c). + +Signed-off-by: Zhang Boyang +Reviewed-by: Daniel Kiper +(cherry picked from commit 50a11a81bc842c58962244a2dc86bbd31a426e12) +(cherry picked from commit 8fa75d647362c938c4cc302cf5945b31fb92c078) +--- + grub-core/video/fb/fbutil.c | 4 ++-- + include/grub/fbutil.h | 13 +++++++++---- + 2 files changed, 11 insertions(+), 6 deletions(-) + +diff --git a/grub-core/video/fb/fbutil.c b/grub-core/video/fb/fbutil.c +index b98bb51fe8..25ef39f47d 100644 +--- a/grub-core/video/fb/fbutil.c ++++ b/grub-core/video/fb/fbutil.c +@@ -67,7 +67,7 @@ get_pixel (struct grub_video_fbblit_info *source, + case 1: + if (source->mode_info->blit_format == GRUB_VIDEO_BLIT_FORMAT_1BIT_PACKED) + { +- int bit_index = y * source->mode_info->width + x; ++ grub_uint64_t bit_index = (grub_uint64_t) y * source->mode_info->width + x; + grub_uint8_t *ptr = source->data + bit_index / 8; + int bit_pos = 7 - bit_index % 8; + color = (*ptr >> bit_pos) & 0x01; +@@ -138,7 +138,7 @@ set_pixel (struct grub_video_fbblit_info *source, + case 1: + if (source->mode_info->blit_format == GRUB_VIDEO_BLIT_FORMAT_1BIT_PACKED) + { +- int bit_index = y * source->mode_info->width + x; ++ grub_uint64_t bit_index = (grub_uint64_t) y * source->mode_info->width + x; + grub_uint8_t *ptr = source->data + bit_index / 8; + int bit_pos = 7 - bit_index % 8; + *ptr = (*ptr & ~(1 << bit_pos)) | ((color & 0x01) << bit_pos); +diff --git a/include/grub/fbutil.h b/include/grub/fbutil.h +index 4205eb917f..78a1ab3b45 100644 +--- a/include/grub/fbutil.h ++++ b/include/grub/fbutil.h +@@ -31,14 +31,19 @@ struct grub_video_fbblit_info + grub_uint8_t *data; + }; + +-/* Don't use for 1-bit bitmaps, addressing needs to be done at the bit level +- and it doesn't make sense, in general, to ask for a pointer +- to a particular pixel's data. */ ++/* ++ * Don't use for 1-bit bitmaps, addressing needs to be done at the bit level ++ * and it doesn't make sense, in general, to ask for a pointer ++ * to a particular pixel's data. ++ * ++ * This function assumes that bounds checking has been done in previous phase ++ * and they are opted out in here. ++ */ + static inline void * + grub_video_fb_get_video_ptr (struct grub_video_fbblit_info *source, + unsigned int x, unsigned int y) + { +- return source->data + y * source->mode_info->pitch + x * source->mode_info->bytes_per_pixel; ++ return source->data + (grub_addr_t) y * source->mode_info->pitch + (grub_addr_t) x * source->mode_info->bytes_per_pixel; + } + + /* Advance pointer by VAL bytes. If there is no unaligned access available, diff --git a/0291-font-Fix-an-integer-underflow-in-blit_comb.patch b/0291-font-Fix-an-integer-underflow-in-blit_comb.patch new file mode 100644 index 00000000..b8a0e9e3 --- /dev/null +++ b/0291-font-Fix-an-integer-underflow-in-blit_comb.patch @@ -0,0 +1,90 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Zhang Boyang +Date: Mon, 24 Oct 2022 08:05:35 +0800 +Subject: [PATCH] font: Fix an integer underflow in blit_comb() + +The expression (ctx.bounds.height - combining_glyphs[i]->height) / 2 may +evaluate to a very big invalid value even if both ctx.bounds.height and +combining_glyphs[i]->height are small integers. For example, if +ctx.bounds.height is 10 and combining_glyphs[i]->height is 12, this +expression evaluates to 2147483647 (expected -1). This is because +coordinates are allowed to be negative but ctx.bounds.height is an +unsigned int. So, the subtraction operates on unsigned ints and +underflows to a very big value. The division makes things even worse. +The quotient is still an invalid value even if converted back to int. + +This patch fixes the problem by casting ctx.bounds.height to int. As +a result the subtraction will operate on int and grub_uint16_t which +will be promoted to an int. So, the underflow will no longer happen. Other +uses of ctx.bounds.height (and ctx.bounds.width) are also casted to int, +to ensure coordinates are always calculated on signed integers. + +Fixes: CVE-2022-3775 + +Reported-by: Daniel Axtens +Signed-off-by: Zhang Boyang +Reviewed-by: Daniel Kiper +(cherry picked from commit 6d2668dea3774ed74c4cd1eadd146f1b846bc3d4) +(cherry picked from commit 05e532fb707bbf79aa4e1efbde4d208d7da89d6b) +--- + grub-core/font/font.c | 16 ++++++++-------- + 1 file changed, 8 insertions(+), 8 deletions(-) + +diff --git a/grub-core/font/font.c b/grub-core/font/font.c +index 193dfec045..12a5f0d08c 100644 +--- a/grub-core/font/font.c ++++ b/grub-core/font/font.c +@@ -1203,12 +1203,12 @@ blit_comb (const struct grub_unicode_glyph *glyph_id, + ctx.bounds.height = main_glyph->height; + + above_rightx = main_glyph->offset_x + main_glyph->width; +- above_righty = ctx.bounds.y + ctx.bounds.height; ++ above_righty = ctx.bounds.y + (int) ctx.bounds.height; + + above_leftx = main_glyph->offset_x; +- above_lefty = ctx.bounds.y + ctx.bounds.height; ++ above_lefty = ctx.bounds.y + (int) ctx.bounds.height; + +- below_rightx = ctx.bounds.x + ctx.bounds.width; ++ below_rightx = ctx.bounds.x + (int) ctx.bounds.width; + below_righty = ctx.bounds.y; + + comb = grub_unicode_get_comb (glyph_id); +@@ -1221,7 +1221,7 @@ blit_comb (const struct grub_unicode_glyph *glyph_id, + + if (!combining_glyphs[i]) + continue; +- targetx = (ctx.bounds.width - combining_glyphs[i]->width) / 2 + ctx.bounds.x; ++ targetx = ((int) ctx.bounds.width - combining_glyphs[i]->width) / 2 + ctx.bounds.x; + /* CGJ is to avoid diacritics reordering. */ + if (comb[i].code + == GRUB_UNICODE_COMBINING_GRAPHEME_JOINER) +@@ -1231,8 +1231,8 @@ blit_comb (const struct grub_unicode_glyph *glyph_id, + case GRUB_UNICODE_COMB_OVERLAY: + do_blit (combining_glyphs[i], + targetx, +- (ctx.bounds.height - combining_glyphs[i]->height) / 2 +- - (ctx.bounds.height + ctx.bounds.y), &ctx); ++ ((int) ctx.bounds.height - combining_glyphs[i]->height) / 2 ++ - ((int) ctx.bounds.height + ctx.bounds.y), &ctx); + if (min_devwidth < combining_glyphs[i]->width) + min_devwidth = combining_glyphs[i]->width; + break; +@@ -1305,7 +1305,7 @@ blit_comb (const struct grub_unicode_glyph *glyph_id, + /* Fallthrough. */ + case GRUB_UNICODE_STACK_ATTACHED_ABOVE: + do_blit (combining_glyphs[i], targetx, +- -(ctx.bounds.height + ctx.bounds.y + space ++ -((int) ctx.bounds.height + ctx.bounds.y + space + + combining_glyphs[i]->height), &ctx); + if (min_devwidth < combining_glyphs[i]->width) + min_devwidth = combining_glyphs[i]->width; +@@ -1313,7 +1313,7 @@ blit_comb (const struct grub_unicode_glyph *glyph_id, + + case GRUB_UNICODE_COMB_HEBREW_DAGESH: + do_blit (combining_glyphs[i], targetx, +- -(ctx.bounds.height / 2 + ctx.bounds.y ++ -((int) ctx.bounds.height / 2 + ctx.bounds.y + + combining_glyphs[i]->height / 2), &ctx); + if (min_devwidth < combining_glyphs[i]->width) + min_devwidth = combining_glyphs[i]->width; diff --git a/0292-font-Harden-grub_font_blit_glyph-and-grub_font_blit_.patch b/0292-font-Harden-grub_font_blit_glyph-and-grub_font_blit_.patch new file mode 100644 index 00000000..307572cb --- /dev/null +++ b/0292-font-Harden-grub_font_blit_glyph-and-grub_font_blit_.patch @@ -0,0 +1,74 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Zhang Boyang +Date: Mon, 24 Oct 2022 07:15:41 +0800 +Subject: [PATCH] font: Harden grub_font_blit_glyph() and + grub_font_blit_glyph_mirror() + +As a mitigation and hardening measure add sanity checks to +grub_font_blit_glyph() and grub_font_blit_glyph_mirror(). This patch +makes these two functions do nothing if target blitting area isn't fully +contained in target bitmap. Therefore, if complex calculations in caller +overflows and malicious coordinates are given, we are still safe because +any coordinates which result in out-of-bound-write are rejected. However, +this patch only checks for invalid coordinates, and doesn't provide any +protection against invalid source glyph or destination glyph, e.g. +mismatch between glyph size and buffer size. + +This hardening measure is designed to mitigate possible overflows in +blit_comb(). If overflow occurs, it may return invalid bounding box +during dry run and call grub_font_blit_glyph() with malicious +coordinates during actual blitting. However, we are still safe because +the scratch glyph itself is valid, although its size makes no sense, and +any invalid coordinates are rejected. + +It would be better to call grub_fatal() if illegal parameter is detected. +However, doing this may end up in a dangerous recursion because grub_fatal() +would print messages to the screen and we are in the progress of drawing +characters on the screen. + +Reported-by: Daniel Axtens +Signed-off-by: Zhang Boyang +Reviewed-by: Daniel Kiper +(cherry picked from commit fcd7aa0c278f7cf3fb9f93f1a3966e1792339eb6) +(cherry picked from commit 1d37ec63a1c76a14fdf70f548eada92667b42ddb) +--- + grub-core/font/font.c | 14 ++++++++++++++ + 1 file changed, 14 insertions(+) + +diff --git a/grub-core/font/font.c b/grub-core/font/font.c +index 12a5f0d08c..29fbb94294 100644 +--- a/grub-core/font/font.c ++++ b/grub-core/font/font.c +@@ -1069,8 +1069,15 @@ static void + grub_font_blit_glyph (struct grub_font_glyph *target, + struct grub_font_glyph *src, unsigned dx, unsigned dy) + { ++ grub_uint16_t max_x, max_y; + unsigned src_bit, tgt_bit, src_byte, tgt_byte; + unsigned i, j; ++ ++ /* Harden against out-of-bound writes. */ ++ if ((grub_add (dx, src->width, &max_x) || max_x > target->width) || ++ (grub_add (dy, src->height, &max_y) || max_y > target->height)) ++ return; ++ + for (i = 0; i < src->height; i++) + { + src_bit = (src->width * i) % 8; +@@ -1102,9 +1109,16 @@ grub_font_blit_glyph_mirror (struct grub_font_glyph *target, + struct grub_font_glyph *src, + unsigned dx, unsigned dy) + { ++ grub_uint16_t max_x, max_y; + unsigned tgt_bit, src_byte, tgt_byte; + signed src_bit; + unsigned i, j; ++ ++ /* Harden against out-of-bound writes. */ ++ if ((grub_add (dx, src->width, &max_x) || max_x > target->width) || ++ (grub_add (dy, src->height, &max_y) || max_y > target->height)) ++ return; ++ + for (i = 0; i < src->height; i++) + { + src_bit = (src->width * i + src->width - 1) % 8; diff --git a/0293-font-Assign-null_font-to-glyphs-in-ascii_font_glyph.patch b/0293-font-Assign-null_font-to-glyphs-in-ascii_font_glyph.patch new file mode 100644 index 00000000..368b9d06 --- /dev/null +++ b/0293-font-Assign-null_font-to-glyphs-in-ascii_font_glyph.patch @@ -0,0 +1,35 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Zhang Boyang +Date: Fri, 28 Oct 2022 17:29:16 +0800 +Subject: [PATCH] font: Assign null_font to glyphs in ascii_font_glyph[] + +The calculations in blit_comb() need information from glyph's font, e.g. +grub_font_get_xheight(main_glyph->font). However, main_glyph->font is +NULL if main_glyph comes from ascii_font_glyph[]. Therefore +grub_font_get_*() crashes because of NULL pointer. + +There is already a solution, the null_font. So, assign it to those glyphs +in ascii_font_glyph[]. + +Reported-by: Daniel Axtens +Signed-off-by: Zhang Boyang +Reviewed-by: Daniel Kiper +(cherry picked from commit dd539d695482069d28b40f2d3821f710cdcf6ee6) +(cherry picked from commit 87526376857eaceae474c9797e3cee5b50597332) +--- + grub-core/font/font.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/grub-core/font/font.c b/grub-core/font/font.c +index 29fbb94294..e6616e610c 100644 +--- a/grub-core/font/font.c ++++ b/grub-core/font/font.c +@@ -137,7 +137,7 @@ ascii_glyph_lookup (grub_uint32_t code) + ascii_font_glyph[current]->offset_x = 0; + ascii_font_glyph[current]->offset_y = -2; + ascii_font_glyph[current]->device_width = 8; +- ascii_font_glyph[current]->font = NULL; ++ ascii_font_glyph[current]->font = &null_font; + + grub_memcpy (ascii_font_glyph[current]->bitmap, + &ascii_bitmaps[current * ASCII_BITMAP_SIZE], diff --git a/0294-normal-charset-Fix-an-integer-overflow-in-grub_unico.patch b/0294-normal-charset-Fix-an-integer-overflow-in-grub_unico.patch new file mode 100644 index 00000000..96f2f94d --- /dev/null +++ b/0294-normal-charset-Fix-an-integer-overflow-in-grub_unico.patch @@ -0,0 +1,54 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Zhang Boyang +Date: Fri, 28 Oct 2022 21:31:39 +0800 +Subject: [PATCH] normal/charset: Fix an integer overflow in + grub_unicode_aglomerate_comb() + +The out->ncomb is a bit-field of 8 bits. So, the max possible value is 255. +However, code in grub_unicode_aglomerate_comb() doesn't check for an +overflow when incrementing out->ncomb. If out->ncomb is already 255, +after incrementing it will get 0 instead of 256, and cause illegal +memory access in subsequent processing. + +This patch introduces GRUB_UNICODE_NCOMB_MAX to represent the max +acceptable value of ncomb. The code now checks for this limit and +ignores additional combining characters when limit is reached. + +Reported-by: Daniel Axtens +Signed-off-by: Zhang Boyang +Reviewed-by: Daniel Kiper +(cherry picked from commit da90d62316a3b105d2fbd7334d6521936bd6dcf6) +(cherry picked from commit 26fafec86000b5322837722a115279ef03922ca6) +--- + grub-core/normal/charset.c | 3 +++ + include/grub/unicode.h | 2 ++ + 2 files changed, 5 insertions(+) + +diff --git a/grub-core/normal/charset.c b/grub-core/normal/charset.c +index 7a5a7c153c..c243ca6dae 100644 +--- a/grub-core/normal/charset.c ++++ b/grub-core/normal/charset.c +@@ -472,6 +472,9 @@ grub_unicode_aglomerate_comb (const grub_uint32_t *in, grub_size_t inlen, + if (!haveout) + continue; + ++ if (out->ncomb == GRUB_UNICODE_NCOMB_MAX) ++ continue; ++ + if (comb_type == GRUB_UNICODE_COMB_MC + || comb_type == GRUB_UNICODE_COMB_ME + || comb_type == GRUB_UNICODE_COMB_MN) +diff --git a/include/grub/unicode.h b/include/grub/unicode.h +index 4de986a857..c4f6fca043 100644 +--- a/include/grub/unicode.h ++++ b/include/grub/unicode.h +@@ -147,7 +147,9 @@ struct grub_unicode_glyph + grub_uint8_t bidi_level:6; /* minimum: 6 */ + enum grub_bidi_type bidi_type:5; /* minimum: :5 */ + ++#define GRUB_UNICODE_NCOMB_MAX ((1 << 8) - 1) + unsigned ncomb:8; ++ + /* Hint by unicode subsystem how wide this character usually is. + Real width is determined by font. Set only in UTF-8 stream. */ + int estimated_width:8; diff --git a/grub.patches b/grub.patches index ce6f6c7d..3f26954f 100644 --- a/grub.patches +++ b/grub.patches @@ -279,3 +279,16 @@ Patch0278: 0278-squish-BLS-only-write-etc-kernel-cmdline-if-writable.patch Patch0279: 0279-ieee1275-implement-vec5-for-cas-negotiation.patch Patch0280: 0280-blscfg-Don-t-root-device-in-emu-builds.patch Patch0281: 0281-x86-efi-Fix-an-incorrect-array-size-in-kernel-alloca.patch +Patch0282: 0282-font-Reject-glyphs-exceeds-font-max_glyph_width-or-f.patch +Patch0283: 0283-font-Fix-size-overflow-in-grub_font_get_glyph_intern.patch +Patch0284: 0284-font-Fix-several-integer-overflows-in-grub_font_cons.patch +Patch0285: 0285-font-Remove-grub_font_dup_glyph.patch +Patch0286: 0286-font-Fix-integer-overflow-in-ensure_comb_space.patch +Patch0287: 0287-font-Fix-integer-overflow-in-BMP-index.patch +Patch0288: 0288-font-Fix-integer-underflow-in-binary-search-of-char-.patch +Patch0289: 0289-kern-efi-sb-Enforce-verification-of-font-files.patch +Patch0290: 0290-fbutil-Fix-integer-overflow.patch +Patch0291: 0291-font-Fix-an-integer-underflow-in-blit_comb.patch +Patch0292: 0292-font-Harden-grub_font_blit_glyph-and-grub_font_blit_.patch +Patch0293: 0293-font-Assign-null_font-to-glyphs-in-ascii_font_glyph.patch +Patch0294: 0294-normal-charset-Fix-an-integer-overflow-in-grub_unico.patch diff --git a/grub2.spec b/grub2.spec index 4f0e4a31..9188f92c 100644 --- a/grub2.spec +++ b/grub2.spec @@ -17,7 +17,7 @@ Name: grub2 Epoch: 1 Version: 2.06 -Release: 54%{?dist} +Release: 55%{?dist} Summary: Bootloader with support for Linux, Multiboot and more License: GPLv3+ URL: http://www.gnu.org/software/grub/ @@ -530,6 +530,9 @@ mv ${EFI_HOME}/grub.cfg.stb ${EFI_HOME}/grub.cfg %endif %changelog +* Tue Nov 15 2022 Robbie Harwood - 2.06-55 +- Font fixes (CVE-2022-2601 batch) + * Wed Oct 12 2022 Robbie Harwood - 2.06-54 - x86-efi: Fix an incorrect array size in kernel allocation From 27a1c2a3360aff2e1e03fb446c9e36a89fa00c77 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 22 Nov 2022 23:10:50 +0000 Subject: [PATCH 04/10] Bundle unicode.pf2 with images Resolves: #2143725 Resolves: #2144113 Signed-off-by: Robbie Harwood --- ...ening-fonts-from-the-bundled-memdisk.patch | 79 +++++++++++++++++++ grub.macros | 17 ++-- grub.patches | 1 + grub2.spec | 8 +- 4 files changed, 98 insertions(+), 7 deletions(-) create mode 100644 0295-font-Try-opening-fonts-from-the-bundled-memdisk.patch diff --git a/0295-font-Try-opening-fonts-from-the-bundled-memdisk.patch b/0295-font-Try-opening-fonts-from-the-bundled-memdisk.patch new file mode 100644 index 00000000..97d7e38f --- /dev/null +++ b/0295-font-Try-opening-fonts-from-the-bundled-memdisk.patch @@ -0,0 +1,79 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Chris Coulson +Date: Wed, 16 Nov 2022 14:40:04 +0000 +Subject: [PATCH] font: Try opening fonts from the bundled memdisk + +Signed-off-by: Robbie Harwood +(cherry picked from commit b77167c407b74d27d506f866f66d5204dc3785c7) +--- + grub-core/font/font.c | 48 +++++++++++++++++++++++++++++++----------------- + 1 file changed, 31 insertions(+), 17 deletions(-) + +diff --git a/grub-core/font/font.c b/grub-core/font/font.c +index e6616e610c..e421d1ae6f 100644 +--- a/grub-core/font/font.c ++++ b/grub-core/font/font.c +@@ -409,6 +409,27 @@ read_section_as_short (struct font_file_section *section, + return 0; + } + ++static grub_file_t ++try_open_from_prefix (const char *prefix, const char *filename) ++{ ++ grub_file_t file; ++ char *fullname, *ptr; ++ ++ fullname = grub_malloc (grub_strlen (prefix) + grub_strlen (filename) + 1 ++ + sizeof ("/fonts/") + sizeof (".pf2")); ++ if (!fullname) ++ return 0; ++ ptr = grub_stpcpy (fullname, prefix); ++ ptr = grub_stpcpy (ptr, "/fonts/"); ++ ptr = grub_stpcpy (ptr, filename); ++ ptr = grub_stpcpy (ptr, ".pf2"); ++ *ptr = 0; ++ ++ file = grub_buffile_open (fullname, GRUB_FILE_TYPE_FONT, 1024); ++ grub_free (fullname); ++ return file; ++} ++ + /* Load a font and add it to the beginning of the global font list. + Returns 0 upon success, nonzero upon failure. */ + grub_font_t +@@ -427,25 +448,18 @@ grub_font_load (const char *filename) + file = grub_buffile_open (filename, GRUB_FILE_TYPE_FONT, 1024); + else + { +- const char *prefix = grub_env_get ("prefix"); +- char *fullname, *ptr; +- if (!prefix) ++ file = try_open_from_prefix ("(memdisk)", filename); ++ if (!file) + { +- grub_error (GRUB_ERR_FILE_NOT_FOUND, N_("variable `%s' isn't set"), +- "prefix"); +- goto fail; ++ const char *prefix = grub_env_get ("prefix"); ++ if (!prefix) ++ { ++ grub_error (GRUB_ERR_FILE_NOT_FOUND, N_("variable `%s' isn't set"), ++ "prefix"); ++ goto fail; ++ } ++ file = try_open_from_prefix (prefix, filename); + } +- fullname = grub_malloc (grub_strlen (prefix) + grub_strlen (filename) + 1 +- + sizeof ("/fonts/") + sizeof (".pf2")); +- if (!fullname) +- goto fail; +- ptr = grub_stpcpy (fullname, prefix); +- ptr = grub_stpcpy (ptr, "/fonts/"); +- ptr = grub_stpcpy (ptr, filename); +- ptr = grub_stpcpy (ptr, ".pf2"); +- *ptr = 0; +- file = grub_buffile_open (fullname, GRUB_FILE_TYPE_FONT, 1024); +- grub_free (fullname); + } + if (!file) + goto fail; diff --git a/grub.macros b/grub.macros index 2ab40944..101fec80 100644 --- a/grub.macros +++ b/grub.macros @@ -383,11 +383,16 @@ rm -f %{1}.conf \ %ifarch x86_64 aarch64 %{arm} riscv64 %define mkimage() \ +mkdir -p memdisk/fonts \ +cp %{4}/unicode.pf2 memdisk/fonts \ +mksquashfs memdisk memdisk.squashfs -comp xz \ %{4}./grub-mkimage -O %{1} -o %{2}.orig \\\ -p /EFI/%{efi_vendor} -d grub-core ${GRUB_MODULES} \\\ + -m memdisk.squashfs \\\ --sbat %{4}./sbat.csv \ %{4}./grub-mkimage -O %{1} -o %{3}.orig \\\ -p /EFI/BOOT -d grub-core ${GRUB_MODULES} \\\ + -m memdisk.squashfs \\\ --sbat %{4}./sbat.csv \ %{expand:%%define ___pesign_client_cert %{?___pesign_client_cert}%{!?___pesign_client_cert:%{__pesign_client_cert}}} \ %{?__pesign_client_cert:%{expand:%%define __pesign_client_cert %{___pesign_client_cert}}} \ @@ -415,11 +420,15 @@ GRUB_MODULES=" all_video boot blscfg btrfs \\\ gfxmenu gfxterm gzio \\\ halt hfsplus http increment iso9660 jpeg \\\ loadenv loopback linux lvm lsefi lsefimmap luks \\\ - luks2 mdraid09 mdraid1x minicmd net \\\ + luks2 \\\ + memdisk \\\ + mdraid09 mdraid1x minicmd net \\\ normal part_apple part_msdos part_gpt \\\ password_pbkdf2 pgp png read reboot \\\ regexp search search_fs_uuid search_fs_file \\\ - search_label serial sleep syslinuxcfg test tftp \\\ + search_label serial sleep \\\ + squash4 \\\ + syslinuxcfg test tftp \\\ version video xfs zstd " \ GRUB_MODULES+=%{efi_modules} \ %{expand:%%{mkimage %{1} %{2} %{3} %{4}}} \ @@ -520,8 +529,6 @@ install -m 700 %{3} $RPM_BUILD_ROOT%{efi_esp_dir}/%{3} \ %ifarch %{arm} \ install -D -m 700 %{2} $RPM_BUILD_ROOT%{efi_esp_boot}/BOOTARM.EFI \ %endif \ -install -D -m 700 unicode.pf2 \\\ - ${RPM_BUILD_ROOT}/boot/grub2/fonts/unicode.pf2 \ ${RPM_BUILD_ROOT}/%{_bindir}/grub2-editenv \\\ ${RPM_BUILD_ROOT}/boot/grub2/grubenv create \ %{expand:%%do_install_protected_file grub2-%{package_arch}} \ @@ -619,7 +626,6 @@ ln -s ../boot/grub2/grub.cfg \\\ %ifarch %{arm} \ %attr(0700,root,root) %verify(not mtime) %{efi_esp_boot}/BOOTARM.EFI \ %endif \ -%attr(0700,root,root)/boot/grub2/fonts \ %dir %attr(0700,root,root)/boot/loader/entries \ %ghost %config(noreplace) %attr(0700,root,root)/boot/grub2/grub.cfg \ %ghost %config(noreplace) %verify(not mtime) %attr(0700,root,root)%{efi_esp_dir}/grub.cfg \ @@ -641,5 +647,4 @@ ln -s ../boot/grub2/grub.cfg \\\ %{expand:%%files %{1}-cdboot} \ %defattr(-,root,root,-) \ %attr(0700,root,root) %verify(not mtime) %{efi_esp_dir}/%{3} \ -%attr(0700,root,root)/boot/grub2/fonts \ %{nil} diff --git a/grub.patches b/grub.patches index 3f26954f..787f78e2 100644 --- a/grub.patches +++ b/grub.patches @@ -292,3 +292,4 @@ Patch0291: 0291-font-Fix-an-integer-underflow-in-blit_comb.patch Patch0292: 0292-font-Harden-grub_font_blit_glyph-and-grub_font_blit_.patch Patch0293: 0293-font-Assign-null_font-to-glyphs-in-ascii_font_glyph.patch Patch0294: 0294-normal-charset-Fix-an-integer-overflow-in-grub_unico.patch +Patch0295: 0295-font-Try-opening-fonts-from-the-bundled-memdisk.patch diff --git a/grub2.spec b/grub2.spec index 9188f92c..80ed3589 100644 --- a/grub2.spec +++ b/grub2.spec @@ -17,7 +17,7 @@ Name: grub2 Epoch: 1 Version: 2.06 -Release: 55%{?dist} +Release: 56%{?dist} Summary: Bootloader with support for Linux, Multiboot and more License: GPLv3+ URL: http://www.gnu.org/software/grub/ @@ -49,6 +49,7 @@ BuildRequires: freetype-devel gettext-devel git BuildRequires: texinfo BuildRequires: dejavu-sans-fonts BuildRequires: help2man +BuildRequires: squashfs-tools # For %%_userunitdir macro BuildRequires: systemd %ifarch %{efi_arch} @@ -530,6 +531,11 @@ mv ${EFI_HOME}/grub.cfg.stb ${EFI_HOME}/grub.cfg %endif %changelog +* Tue Nov 22 2022 Robbie Harwood - 2.06-56 +- Bundle unicode.pf2 with images +- Resolves: #2143725 +- Resolves: #2144113 + * Tue Nov 15 2022 Robbie Harwood - 2.06-55 - Font fixes (CVE-2022-2601 batch) From 8644ec255a4d6e9c0cd770956f3ffd2444490d96 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 23 Nov 2022 16:22:02 -0500 Subject: [PATCH 05/10] Bring back the font because everything is pain --- grub.macros | 4 ++++ grub2.spec | 5 ++++- 2 files changed, 8 insertions(+), 1 deletion(-) diff --git a/grub.macros b/grub.macros index 101fec80..687f87c3 100644 --- a/grub.macros +++ b/grub.macros @@ -529,6 +529,8 @@ install -m 700 %{3} $RPM_BUILD_ROOT%{efi_esp_dir}/%{3} \ %ifarch %{arm} \ install -D -m 700 %{2} $RPM_BUILD_ROOT%{efi_esp_boot}/BOOTARM.EFI \ %endif \ +install -D -m 700 unicode.pf2 \\\ + ${RPM_BUILD_ROOT}/boot/grub2/fonts/unicode.pf2 \ ${RPM_BUILD_ROOT}/%{_bindir}/grub2-editenv \\\ ${RPM_BUILD_ROOT}/boot/grub2/grubenv create \ %{expand:%%do_install_protected_file grub2-%{package_arch}} \ @@ -626,6 +628,7 @@ ln -s ../boot/grub2/grub.cfg \\\ %ifarch %{arm} \ %attr(0700,root,root) %verify(not mtime) %{efi_esp_boot}/BOOTARM.EFI \ %endif \ +%attr(0700,root,root)/boot/grub2/fonts \ %dir %attr(0700,root,root)/boot/loader/entries \ %ghost %config(noreplace) %attr(0700,root,root)/boot/grub2/grub.cfg \ %ghost %config(noreplace) %verify(not mtime) %attr(0700,root,root)%{efi_esp_dir}/grub.cfg \ @@ -647,4 +650,5 @@ ln -s ../boot/grub2/grub.cfg \\\ %{expand:%%files %{1}-cdboot} \ %defattr(-,root,root,-) \ %attr(0700,root,root) %verify(not mtime) %{efi_esp_dir}/%{3} \ +%attr(0700,root,root)/boot/grub2/fonts \ %{nil} diff --git a/grub2.spec b/grub2.spec index 80ed3589..c3e6efb8 100644 --- a/grub2.spec +++ b/grub2.spec @@ -17,7 +17,7 @@ Name: grub2 Epoch: 1 Version: 2.06 -Release: 56%{?dist} +Release: 57%{?dist} Summary: Bootloader with support for Linux, Multiboot and more License: GPLv3+ URL: http://www.gnu.org/software/grub/ @@ -531,6 +531,9 @@ mv ${EFI_HOME}/grub.cfg.stb ${EFI_HOME}/grub.cfg %endif %changelog +* Wed Nov 23 2022 Robbie Harwood - 2.06-57 +- Temporarily restore the font because everything is pain + * Tue Nov 22 2022 Robbie Harwood - 2.06-56 - Bundle unicode.pf2 with images - Resolves: #2143725 From 07531cb006650faffcbfbe58b4f219566af2760c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 14 Dec 2022 19:33:40 +0000 Subject: [PATCH 06/10] ppc64le: fix lpar cas5 Resolves: #2152547 Signed-off-by: Robbie Harwood --- 0296-Correction-in-vector-5-values.patch | 31 ++++++++++++++++++++++++ grub.patches | 1 + grub2.spec | 6 ++++- 3 files changed, 37 insertions(+), 1 deletion(-) create mode 100644 0296-Correction-in-vector-5-values.patch diff --git a/0296-Correction-in-vector-5-values.patch b/0296-Correction-in-vector-5-values.patch new file mode 100644 index 00000000..54dfc3d2 --- /dev/null +++ b/0296-Correction-in-vector-5-values.patch @@ -0,0 +1,31 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Avnish Chouhan +Date: Tue, 22 Nov 2022 08:01:47 -0500 +Subject: [PATCH] Correction in vector 5 values + +This patch is to update the vector 5 values which is troubling some +machines to bootup properly. Max out the values of all the properties of +Vector 5 (similar to vector 2) except max cpu property, which were set +as 0 earlier. + +Signed-off-by: Avnish Chouhan +[rharwood: rewrap comit message] +Signed-off-by: Robbie Harwood +(cherry picked from commit c2e640266247e3e0d3268f5ef20a734f5800f577) +--- + grub-core/kern/ieee1275/init.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/grub-core/kern/ieee1275/init.c b/grub-core/kern/ieee1275/init.c +index 6a51c9efab..28a3bd4621 100644 +--- a/grub-core/kern/ieee1275/init.c ++++ b/grub-core/kern/ieee1275/init.c +@@ -376,7 +376,7 @@ grub_ieee1275_ibm_cas (void) + .vec4 = 0x0001, // set required minimum capacity % to the lowest value + .vec5_size = 1 + sizeof(struct option_vector5) - 2, + .vec5 = { +- 0, 0, 0, 0, 0, 0, 0, 0, 256 ++ -1, -1, -1, -1, -1, -1, -1, -1, 256 + } + }; + diff --git a/grub.patches b/grub.patches index 787f78e2..b13a35e0 100644 --- a/grub.patches +++ b/grub.patches @@ -293,3 +293,4 @@ Patch0292: 0292-font-Harden-grub_font_blit_glyph-and-grub_font_blit_.patch Patch0293: 0293-font-Assign-null_font-to-glyphs-in-ascii_font_glyph.patch Patch0294: 0294-normal-charset-Fix-an-integer-overflow-in-grub_unico.patch Patch0295: 0295-font-Try-opening-fonts-from-the-bundled-memdisk.patch +Patch0296: 0296-Correction-in-vector-5-values.patch diff --git a/grub2.spec b/grub2.spec index c3e6efb8..a3c882d8 100644 --- a/grub2.spec +++ b/grub2.spec @@ -17,7 +17,7 @@ Name: grub2 Epoch: 1 Version: 2.06 -Release: 57%{?dist} +Release: 58%{?dist} Summary: Bootloader with support for Linux, Multiboot and more License: GPLv3+ URL: http://www.gnu.org/software/grub/ @@ -531,6 +531,10 @@ mv ${EFI_HOME}/grub.cfg.stb ${EFI_HOME}/grub.cfg %endif %changelog +* Wed Dec 14 2022 Robbie Harwood - 2.06-58 +- ppc64le: fix lpar cas5 +- Resolves: #2152547 + * Wed Nov 23 2022 Robbie Harwood - 2.06-57 - Temporarily restore the font because everything is pain From 860cf9444270a0e2c13e4af0600c01762a0a5930 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 21 Dec 2022 22:38:05 +0000 Subject: [PATCH 07/10] Fix prefix setting with memdisk creation for network boot Signed-off-by: Robbie Harwood --- grub.macros | 6 ++++-- grub2.spec | 5 ++++- 2 files changed, 8 insertions(+), 3 deletions(-) diff --git a/grub.macros b/grub.macros index 687f87c3..2e232cbe 100644 --- a/grub.macros +++ b/grub.macros @@ -387,12 +387,14 @@ mkdir -p memdisk/fonts \ cp %{4}/unicode.pf2 memdisk/fonts \ mksquashfs memdisk memdisk.squashfs -comp xz \ %{4}./grub-mkimage -O %{1} -o %{2}.orig \\\ - -p /EFI/%{efi_vendor} -d grub-core ${GRUB_MODULES} \\\ + -d grub-core ${GRUB_MODULES} \\\ -m memdisk.squashfs \\\ + -p /EFI/%{efi_vendor} \\\ --sbat %{4}./sbat.csv \ %{4}./grub-mkimage -O %{1} -o %{3}.orig \\\ - -p /EFI/BOOT -d grub-core ${GRUB_MODULES} \\\ + -d grub-core ${GRUB_MODULES} \\\ -m memdisk.squashfs \\\ + -p /EFI/BOOT \\\ --sbat %{4}./sbat.csv \ %{expand:%%define ___pesign_client_cert %{?___pesign_client_cert}%{!?___pesign_client_cert:%{__pesign_client_cert}}} \ %{?__pesign_client_cert:%{expand:%%define __pesign_client_cert %{___pesign_client_cert}}} \ diff --git a/grub2.spec b/grub2.spec index a3c882d8..2d587e36 100644 --- a/grub2.spec +++ b/grub2.spec @@ -17,7 +17,7 @@ Name: grub2 Epoch: 1 Version: 2.06 -Release: 58%{?dist} +Release: 59%{?dist} Summary: Bootloader with support for Linux, Multiboot and more License: GPLv3+ URL: http://www.gnu.org/software/grub/ @@ -531,6 +531,9 @@ mv ${EFI_HOME}/grub.cfg.stb ${EFI_HOME}/grub.cfg %endif %changelog +* Wed Dec 21 2022 Robbie Harwood - 2.06-59 +- Fix prefix setting with memdisk creation for network boot + * Wed Dec 14 2022 Robbie Harwood - 2.06-58 - ppc64le: fix lpar cas5 - Resolves: #2152547 From ff20c0ecb5b8d072040bb25ca6616c4d08e64da7 Mon Sep 17 00:00:00 2001 From: Prarit Bhargava Date: Sun, 4 Dec 2022 19:41:23 -0500 Subject: [PATCH 08/10] Allow for xz'd symvers file The Fedora/ARK kernel is moving to removing gzip as a dependency and replacing it with xz. Use xz instead of gz as an extension for the symvers file. Signed-off-by: Prarit Bhargava (cherry picked from commit 78d64adfbe3cd089df8e41166c3688f026acdad1) [rharwood: bump spec] Signed-off-by: Robbie Harwood --- 20-grub.install | 9 +++++++++ grub2.spec | 5 ++++- 2 files changed, 13 insertions(+), 1 deletion(-) diff --git a/20-grub.install b/20-grub.install index bc55a14b..bb0d5299 100755 --- a/20-grub.install +++ b/20-grub.install @@ -75,6 +75,7 @@ case "$COMMAND" in command -v restorecon &>/dev/null && \ restorecon "/boot/.${KERNEL_IMAGE##*/}-${KERNEL_VERSION}.hmac" fi + # OLD method using gzip'd file (will be deprecated and removed in the future) # symvers is symvers-.gz symlink, needs a special treatment i="$KERNEL_DIR/symvers.gz" if [[ -e "$i" ]]; then @@ -83,6 +84,14 @@ case "$COMMAND" in command -v restorecon &>/dev/null && \ restorecon "/boot/symvers-${KERNEL_VERSION}.gz" fi + # symvers is symvers-.bz symlink, needs a special treatment + i="$KERNEL_DIR/symvers.bz" + if [[ -e "$i" ]]; then + rm -f "/boot/symvers-${KERNEL_VERSION}.bz" + ln -s "$i" "/boot/symvers-${KERNEL_VERSION}.bz" + command -v restorecon &>/dev/null && \ + restorecon "/boot/symvers-${KERNEL_VERSION}.bz" + fi fi if [[ "x${GRUB_ENABLE_BLSCFG}" = "xtrue" ]] || [[ ! -f /sbin/new-kernel-pkg ]]; then diff --git a/grub2.spec b/grub2.spec index 2d587e36..a94b874a 100644 --- a/grub2.spec +++ b/grub2.spec @@ -17,7 +17,7 @@ Name: grub2 Epoch: 1 Version: 2.06 -Release: 59%{?dist} +Release: 60%{?dist} Summary: Bootloader with support for Linux, Multiboot and more License: GPLv3+ URL: http://www.gnu.org/software/grub/ @@ -531,6 +531,9 @@ mv ${EFI_HOME}/grub.cfg.stb ${EFI_HOME}/grub.cfg %endif %changelog +* Thu Jan 12 2023 Robbie Harwood - 2.06-60 +- Alllow for xz'd symvers.gz file + * Wed Dec 21 2022 Robbie Harwood - 2.06-59 - Fix prefix setting with memdisk creation for network boot From 1de51c25787db454971f035c6c123241a09f2fd7 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 12 Jan 2023 12:22:24 -0500 Subject: [PATCH 09/10] Fix SBAT for CVE changes Signed-off-by: Robbie Harwood --- grub2.spec | 5 ++++- sbat.csv.in | 2 +- 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/grub2.spec b/grub2.spec index a94b874a..67a3967c 100644 --- a/grub2.spec +++ b/grub2.spec @@ -17,7 +17,7 @@ Name: grub2 Epoch: 1 Version: 2.06 -Release: 60%{?dist} +Release: 61%{?dist} Summary: Bootloader with support for Linux, Multiboot and more License: GPLv3+ URL: http://www.gnu.org/software/grub/ @@ -531,6 +531,9 @@ mv ${EFI_HOME}/grub.cfg.stb ${EFI_HOME}/grub.cfg %endif %changelog +* Thu Jan 12 2023 Robbie Harwood - 2.06-61 +- Fix missing SBAT bump (sign) + * Thu Jan 12 2023 Robbie Harwood - 2.06-60 - Alllow for xz'd symvers.gz file diff --git a/sbat.csv.in b/sbat.csv.in index 55b3d10d..b338b5f5 100755 --- a/sbat.csv.in +++ b/sbat.csv.in @@ -1,3 +1,3 @@ sbat,1,SBAT Version,sbat,1,https://github.com/rhboot/shim/blob/main/SBAT.md -grub,2,Free Software Foundation,grub,@@VERSION@@,https//www.gnu.org/software/grub/ +grub,3,Free Software Foundation,grub,@@VERSION@@,https//www.gnu.org/software/grub/ grub.rh,2,Red Hat,grub2,@@VERSION_RELEASE@@,mailto:secalert@redhat.com From 159a618da58b4bca3d5e84ecea15d2c2ca4b2d3e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 27 Mar 2023 17:40:35 +0000 Subject: [PATCH 10/10] Backport arm compressed boot changes Resolves: #2181825 Signed-off-by: Robbie Harwood --- ...ux-Remove-magic-number-header-field-.patch | 44 +++++++++ 0298-Correct-BSS-zeroing-on-aarch64.patch | 96 +++++++++++++++++++ grub.patches | 2 + grub2.spec | 6 +- 4 files changed, 147 insertions(+), 1 deletion(-) create mode 100644 0297-loader-arm64-linux-Remove-magic-number-header-field-.patch create mode 100644 0298-Correct-BSS-zeroing-on-aarch64.patch diff --git a/0297-loader-arm64-linux-Remove-magic-number-header-field-.patch b/0297-loader-arm64-linux-Remove-magic-number-header-field-.patch new file mode 100644 index 00000000..89b3f8fb --- /dev/null +++ b/0297-loader-arm64-linux-Remove-magic-number-header-field-.patch @@ -0,0 +1,44 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Ard Biesheuvel +Date: Thu, 11 Aug 2022 16:51:57 +0200 +Subject: [PATCH] loader/arm64/linux: Remove magic number header field check + +The "ARM\x64" magic number in the file header identifies an image as one +that implements the bare metal boot protocol, allowing the loader to +simply move the file to a suitably aligned address in memory, with +sufficient headroom for the trailing .bss segment (the required memory +size is described in the header as well). + +Note of this matters for GRUB, as it only supports EFI boot. EFI does +not care about this magic number, and nor should GRUB: this prevents us +from booting other PE linux images, such as the generic EFI zboot +decompressor, which is a pure PE/COFF image, and does not implement the +bare metal boot protocol. + +So drop the magic number check. + +Signed-off-by: Ard Biesheuvel +Reviewed-by: Daniel Kiper +Resolves: rhbz#2125069 +Signed-off-by: Jeremy Linton +(cherry-picked from commit 69edb31205602c29293a8c6e67363bba2a4a1e66) +Signed-off-by: Robbie Harwood +(cherry picked from commit 62382eff5c44a07f8c176108807d446cbfdae609) +--- + grub-core/loader/arm64/linux.c | 3 --- + 1 file changed, 3 deletions(-) + +diff --git a/grub-core/loader/arm64/linux.c b/grub-core/loader/arm64/linux.c +index de85583487..489d0c7173 100644 +--- a/grub-core/loader/arm64/linux.c ++++ b/grub-core/loader/arm64/linux.c +@@ -55,9 +55,6 @@ static grub_addr_t initrd_end; + grub_err_t + grub_arch_efi_linux_check_image (struct linux_arch_kernel_header * lh) + { +- if (lh->magic != GRUB_LINUX_ARMXX_MAGIC_SIGNATURE) +- return grub_error(GRUB_ERR_BAD_OS, "invalid magic number"); +- + if ((lh->code0 & 0xffff) != GRUB_DOS_MAGIC) + return grub_error (GRUB_ERR_NOT_IMPLEMENTED_YET, + N_("plain image kernel not supported - rebuild with CONFIG_(U)EFI_STUB enabled")); diff --git a/0298-Correct-BSS-zeroing-on-aarch64.patch b/0298-Correct-BSS-zeroing-on-aarch64.patch new file mode 100644 index 00000000..b1e22653 --- /dev/null +++ b/0298-Correct-BSS-zeroing-on-aarch64.patch @@ -0,0 +1,96 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Jeremy Linton +Date: Tue, 6 Sep 2022 15:33:03 -0500 +Subject: [PATCH] Correct BSS zeroing on aarch64 + +The aarch64 loader doesn't use efi bootservices, and +therefor it has a very minimal loader which makes a lot +of assumptions about the kernel layout. With the ZBOOT +changes, the layout has changed a bit and we not should +really be parsing the PE sections to determine how much +data to copy, otherwise the BSS won't be setup properly. + +This code still makes a lot of assumptions about the +the kernel layout, so its far from ideal, but it works. + +Resolves: rhbz#2125069 + +Signed-off-by: Jeremy Linton +(cherry picked from commit 9752abcb38119b8fa52ba06e651e220c750e26c1) +--- + grub-core/loader/arm64/linux.c | 27 ++++++++++++++++++++++----- + 1 file changed, 22 insertions(+), 5 deletions(-) + +diff --git a/grub-core/loader/arm64/linux.c b/grub-core/loader/arm64/linux.c +index 489d0c7173..419f2201df 100644 +--- a/grub-core/loader/arm64/linux.c ++++ b/grub-core/loader/arm64/linux.c +@@ -316,10 +316,12 @@ grub_cmd_initrd (grub_command_t cmd __attribute__ ((unused)), + static grub_err_t + parse_pe_header (void *kernel, grub_uint64_t *total_size, + grub_uint32_t *entry_offset, +- grub_uint32_t *alignment) ++ grub_uint32_t *alignment,grub_uint32_t *code_size) + { + struct linux_arch_kernel_header *lh = kernel; + struct grub_armxx_linux_pe_header *pe; ++ grub_uint16_t i; ++ struct grub_pe32_section_table *sections; + + pe = (void *)((unsigned long)kernel + lh->hdr_offset); + +@@ -329,6 +331,19 @@ parse_pe_header (void *kernel, grub_uint64_t *total_size, + *total_size = pe->opt.image_size; + *entry_offset = pe->opt.entry_addr; + *alignment = pe->opt.section_alignment; ++ *code_size = pe->opt.section_alignment; ++ ++ sections = (struct grub_pe32_section_table *) ((char *)&pe->opt + ++ pe->coff.optional_header_size); ++ grub_dprintf ("linux", "num_sections : %d\n", pe->coff.num_sections ); ++ for (i = 0 ; i < pe->coff.num_sections; i++) ++ { ++ grub_dprintf ("linux", "raw_size : %lld\n", ++ (long long) sections[i].raw_data_size); ++ grub_dprintf ("linux", "virt_size : %lld\n", ++ (long long) sections[i].virtual_size); ++ *code_size += sections[i].raw_data_size; ++ } + + return GRUB_ERR_NONE; + } +@@ -341,6 +356,7 @@ grub_cmd_linux (grub_command_t cmd __attribute__ ((unused)), + grub_err_t err; + grub_off_t filelen; + grub_uint32_t align; ++ grub_uint32_t code_size; + void *kernel = NULL; + int nx_supported = 1; + +@@ -373,11 +389,12 @@ grub_cmd_linux (grub_command_t cmd __attribute__ ((unused)), + + if (grub_arch_efi_linux_check_image (kernel) != GRUB_ERR_NONE) + goto fail; +- if (parse_pe_header (kernel, &kernel_size, &handover_offset, &align) != GRUB_ERR_NONE) ++ if (parse_pe_header (kernel, &kernel_size, &handover_offset, &align, &code_size) != GRUB_ERR_NONE) + goto fail; + grub_dprintf ("linux", "kernel mem size : %lld\n", (long long) kernel_size); + grub_dprintf ("linux", "kernel entry offset : %d\n", handover_offset); + grub_dprintf ("linux", "kernel alignment : 0x%x\n", align); ++ grub_dprintf ("linux", "kernel size : 0x%x\n", code_size); + + err = grub_efi_check_nx_image_support((grub_addr_t)kernel, filelen, &nx_supported); + if (err != GRUB_ERR_NONE) +@@ -396,9 +413,9 @@ grub_cmd_linux (grub_command_t cmd __attribute__ ((unused)), + kernel_addr = (void *)ALIGN_UP((grub_uint64_t)kernel_alloc_addr, align); + + grub_dprintf ("linux", "kernel @ %p\n", kernel_addr); +- grub_memcpy (kernel_addr, kernel, grub_min(filelen, kernel_size)); +- if (kernel_size > filelen) +- grub_memset ((char *)kernel_addr + filelen, 0, kernel_size - filelen); ++ grub_memcpy (kernel_addr, kernel, grub_min(code_size, kernel_size)); ++ if (kernel_size > code_size) ++ grub_memset ((char *)kernel_addr + code_size, 0, kernel_size - code_size); + grub_free(kernel); + kernel = NULL; + diff --git a/grub.patches b/grub.patches index b13a35e0..15bf2b13 100644 --- a/grub.patches +++ b/grub.patches @@ -294,3 +294,5 @@ Patch0293: 0293-font-Assign-null_font-to-glyphs-in-ascii_font_glyph.patch Patch0294: 0294-normal-charset-Fix-an-integer-overflow-in-grub_unico.patch Patch0295: 0295-font-Try-opening-fonts-from-the-bundled-memdisk.patch Patch0296: 0296-Correction-in-vector-5-values.patch +Patch0297: 0297-loader-arm64-linux-Remove-magic-number-header-field-.patch +Patch0298: 0298-Correct-BSS-zeroing-on-aarch64.patch diff --git a/grub2.spec b/grub2.spec index 67a3967c..8298ef0e 100644 --- a/grub2.spec +++ b/grub2.spec @@ -17,7 +17,7 @@ Name: grub2 Epoch: 1 Version: 2.06 -Release: 61%{?dist} +Release: 62%{?dist} Summary: Bootloader with support for Linux, Multiboot and more License: GPLv3+ URL: http://www.gnu.org/software/grub/ @@ -531,6 +531,10 @@ mv ${EFI_HOME}/grub.cfg.stb ${EFI_HOME}/grub.cfg %endif %changelog +* Mon Mar 27 2023 Robbie Harwood - 2.06-62 +- Backport arm compressed boot changes +- Resolves: #2181825 + * Thu Jan 12 2023 Robbie Harwood - 2.06-61 - Fix missing SBAT bump (sign)