Skip to content

Commit 9928041

Browse files
committed
efi: Add missing __nocfi annotations to runtime wrappers
The EFI runtime wrappers are a sandbox for calling into EFI runtime services, which are invoked using indirect calls. When running with kCFI enabled, the compiler will require the target of any indirect call to be type annotated. Given that the EFI runtime services prototypes and calling convention are governed by the EFI spec, not the Linux kernel, adding such type annotations for firmware routines is infeasible, and so the compiler must be informed that prototype validation should be omitted. Add the __nocfi annotation at the appropriate places in the EFI runtime wrapper code to achieve this. Note that this currently only affects 32-bit ARM, given that other architectures that support both kCFI and EFI use an asm wrapper to call EFI runtime services, and this hides the indirect call from the compiler. Fixes: 1a4fec4 ("ARM: 9392/2: Support CLANG CFI") Reviewed-by: Linus Walleij <[email protected]> Tested-by: Nathan Chancellor <[email protected]> Signed-off-by: Ard Biesheuvel <[email protected]>
1 parent 290be0a commit 9928041

File tree

1 file changed

+6
-7
lines changed

1 file changed

+6
-7
lines changed

drivers/firmware/efi/runtime-wrappers.c

Lines changed: 6 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -213,7 +213,7 @@ extern struct semaphore __efi_uv_runtime_lock __alias(efi_runtime_lock);
213213
* Calls the appropriate efi_runtime_service() with the appropriate
214214
* arguments.
215215
*/
216-
static void efi_call_rts(struct work_struct *work)
216+
static void __nocfi efi_call_rts(struct work_struct *work)
217217
{
218218
const union efi_rts_args *args = efi_rts_work.args;
219219
efi_status_t status = EFI_NOT_FOUND;
@@ -435,7 +435,7 @@ static efi_status_t virt_efi_set_variable(efi_char16_t *name,
435435
return status;
436436
}
437437

438-
static efi_status_t
438+
static efi_status_t __nocfi
439439
virt_efi_set_variable_nb(efi_char16_t *name, efi_guid_t *vendor, u32 attr,
440440
unsigned long data_size, void *data)
441441
{
@@ -469,7 +469,7 @@ static efi_status_t virt_efi_query_variable_info(u32 attr,
469469
return status;
470470
}
471471

472-
static efi_status_t
472+
static efi_status_t __nocfi
473473
virt_efi_query_variable_info_nb(u32 attr, u64 *storage_space,
474474
u64 *remaining_space, u64 *max_variable_size)
475475
{
@@ -499,10 +499,9 @@ static efi_status_t virt_efi_get_next_high_mono_count(u32 *count)
499499
return status;
500500
}
501501

502-
static void virt_efi_reset_system(int reset_type,
503-
efi_status_t status,
504-
unsigned long data_size,
505-
efi_char16_t *data)
502+
static void __nocfi
503+
virt_efi_reset_system(int reset_type, efi_status_t status,
504+
unsigned long data_size, efi_char16_t *data)
506505
{
507506
if (down_trylock(&efi_runtime_lock)) {
508507
pr_warn("failed to invoke the reset_system() runtime service:\n"

0 commit comments

Comments
 (0)