Skip to content

Commit

Permalink
efi: Set image base address before jumping to the PE/COFF entry point
Browse files Browse the repository at this point in the history
Upstream GRUB uses the EFI LoadImage() and StartImage() to boot the Linux
kernel. But our custom EFI loader that supports Secure Boot instead uses
the EFI handover protocol (for x86) or jumping directly to the PE/COFF
entry point (for aarch64).

This is done to allow the bootloader to verify the images using the shim
lock protocol to avoid booting untrusted binaries.

Since the bootloader loads the kernel from the boot media instead of using
LoadImage(), it is responsible to set the Loaded Image base address before
booting the kernel.

Otherwise the kernel EFI stub will complain that it was not set correctly
and print the following warning message:

EFI stub: ERROR: FIRMWARE BUG: efi_loaded_image_t::image_base has bogus value

Resolves: rhbz#1825411

Signed-off-by: Javier Martinez Canillas <javierm@redhat.com>
  • Loading branch information
martinezjavier committed Apr 23, 2020
1 parent 91216d5 commit 1d5ef08
Showing 1 changed file with 12 additions and 0 deletions.
12 changes: 12 additions & 0 deletions grub-core/loader/efi/linux.c
Original file line number Diff line number Diff line change
Expand Up @@ -72,13 +72,25 @@ grub_err_t
grub_efi_linux_boot (void *kernel_addr, grub_off_t handover_offset,
void *kernel_params)
{
grub_efi_loaded_image_t *loaded_image = NULL;
handover_func hf;
int offset = 0;

#ifdef __x86_64__
offset = 512;
#endif

/*
* Since the EFI loader is not calling the LoadImage() and StartImage()
* services for loading the kernel and booting respectively, it has to
* set the Loaded Image base address.
*/
loaded_image = grub_efi_get_loaded_image (grub_efi_image_handle);
if (loaded_image)
loaded_image->image_base = kernel_addr;
else
grub_dprintf ("linux", "Loaded Image base address could not be set\n");

grub_dprintf ("linux", "kernel_addr: %p handover_offset: %p params: %p\n",
kernel_addr, (void *)(grub_efi_uintn_t)handover_offset, kernel_params);
hf = (handover_func)((char *)kernel_addr + handover_offset + offset);
Expand Down

0 comments on commit 1d5ef08

Please sign in to comment.