efivars_create() refuses to create variables outside the barebox vendor
GUID. That dates from when barebox was only an EFI payload: on somebody
else's firmware, whose NVRAM holds the platform's own state, a shell that
can create Boot#### or BootOrder under the global GUID is a liability,
and the payload only ever needs barebox-env-<guid> anyway.

The EFI loader took the same efivarfs over unchanged, where the argument
does not hold. The store is barebox' own in-memory buffer backed by a
file it writes itself, and everything the loader starts - the UEFI
Shell, GRUB, the OS - can already create variables under any GUID. Only
the barebox shell was held back:

  barebox:/ echo -o /efivarfs/Timeout-8be4df61-93ca-11d2-aa0d-00e098032b8c 5
  open: Operation not permitted

Lift the restriction when running as the loader, so board scripts can
set up global variables without going through /env/data/init.efivars.
The payload keeps confining itself to its own GUID.

Assisted-by: Claude:opus-5
Signed-off-by: Ahmad Fatoum <[email protected]>
---
 fs/efivarfs.c | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/fs/efivarfs.c b/fs/efivarfs.c
index a4d8cc8d0268..1f53c06d66d3 100644
--- a/fs/efivarfs.c
+++ b/fs/efivarfs.c
@@ -66,12 +66,17 @@ static int efivars_create(struct device *dev, const char 
*pathname,
        if (pathname[0] == '/')
                pathname++;
 
-       /* deny creating files with other vendor GUID than our own */
        ret = efivarfs_parse_filename(pathname, &vendor, &name);
        if (ret)
                return -ENOENT;
 
-       if (efi_guidcmp(vendor, EFI_BAREBOX_VENDOR_GUID))
+       /*
+        * As a payload, barebox is a guest on somebody else's firmware and
+        * confines itself to its own vendor GUID when creating variables.
+        * As the loader, the variable store is barebox' own and anything it
+        * boots may already create variables under any GUID.
+        */
+       if (!efi_is_loader() && efi_guidcmp(vendor, EFI_BAREBOX_VENDOR_GUID))
                return -EPERM;
 
        inode = xzalloc(sizeof(*inode));
-- 
2.47.3


Reply via email to