blob: a7590702f86a09cfb3ba98676305daf3081481b0 [file] [log] [blame]
Patrick Rudolph1ab8ad62021-04-21 10:02:55 +02001/* SPDX-License-Identifier: GPL-2.0-only */
2
3#include <stdint.h>
4#include <stdlib.h>
5#include <string.h>
6#include <console/console.h>
7
8#include <vendorcode/intel/edk2/UDK2017/MdePkg/Include/Uefi/UefiBaseType.h>
9#include <vendorcode/intel/edk2/UDK2017/MdePkg/Include/Uefi/UefiMultiPhase.h>
10#include <vendorcode/intel/edk2/UDK2017/MdePkg/Include/Pi/PiFirmwareVolume.h>
11#include <vendorcode/intel/edk2/UDK2017/MdeModulePkg/Include/Guid/VariableFormat.h>
Patrick Rudolph1ab8ad62021-04-21 10:02:55 +020012
13#include "efivars.h"
14
15#define PREFIX "EFIVARS: "
16
17static const EFI_GUID EfiVariableGuid = {
18 0xddcf3616, 0x3275, 0x4164, { 0x98, 0xb6, 0xfe, 0x85, 0x70, 0x7f, 0xfe, 0x7d } };
19static const EFI_GUID EfiAuthenticatedVariableGuid = {
20 0xaaf32c78, 0x947b, 0x439a, { 0xa1, 0x80, 0x2e, 0x14, 0x4e, 0xc3, 0x77, 0x92 } };
21static const EFI_GUID EfiSystemNvDataFvGuid = {
22 0xfff12b8d, 0x7696, 0x4c8b, { 0xa9, 0x85, 0x27, 0x47, 0x07, 0x5b, 0x4f, 0x50 } };
23
24static void print_guid(int log_level, const EFI_GUID *g)
25{
26 printk(log_level, "GUID: %08x-%04x-%04x-%02x%02x%02x%02x%02x%02x%02x%02x",
27 g->Data1, g->Data2, g->Data3, g->Data4[0], g->Data4[1], g->Data4[2],
28 g->Data4[3], g->Data4[4], g->Data4[5], g->Data4[6], g->Data4[7]);
Patrick Rudolph1ab8ad62021-04-21 10:02:55 +020029}
30
31static bool compare_guid(const EFI_GUID *a, const EFI_GUID *b)
32{
33 return memcmp(a, b, sizeof(*a)) == 0;
34}
35
36/* Reads the CHAR16 string from rdev at offset and prints it */
37static enum cb_err rdev_print_wchar(int log_level, struct region_device *rdev, size_t offset)
38{
39 CHAR16 c;
40 int i = 0;
41
42 /* Convert ASCII to UTF-16 */
43 do {
44 if (rdev_readat(rdev, &c, offset + i * sizeof(c), sizeof(c)) != sizeof(c))
45 return CB_EFI_ACCESS_ERROR;
46 if (c < 0x80)
47 printk(log_level, "%c", (char)c);
48 else
49 printk(log_level, "\\u%04x", c);
50
51 i++;
52 } while (c);
53 return CB_SUCCESS;
54}
55
56/* Convert an ASCII string to UTF-16 and write it to the rdev starting at offset. */
57static enum cb_err rdev_write_wchar(struct region_device *rdev, size_t offset, const char *msg)
58{
59 size_t i;
60 CHAR16 c;
61
62 /* Convert ASCII to UTF-16 */
63 for (i = 0; i < strlen(msg) + 1; i++) {
64 c = msg[i];
65
66 if (rdev_writeat(rdev, &c, offset + i * sizeof(c), sizeof(c)) != sizeof(c))
67 return CB_EFI_ACCESS_ERROR;
68 }
69 return CB_SUCCESS;
70}
71
72/* Read an UTF-16 string from rdev at offset and compare it to ASCII string */
73static int rdev_strcmp_wchar_ascii(struct region_device *rdev, size_t offset, const char *msg)
74{
75 size_t i;
76 CHAR16 c;
77 int r;
78
79 i = 0;
80 /* Compare UTF-16 and ASCII */
81 while (1) {
82 if (rdev_readat(rdev, &c, offset + i * sizeof(c), sizeof(c)) != sizeof(c))
83 return CB_EFI_ACCESS_ERROR;
84 if ((r = (c - msg[i])) != 0 || !c)
85 break;
86
87 i++;
88 }
89 return r;
90}
91
92/* Compare an rdev region and a data buffer */
93static int rdev_memcmp(struct region_device *rdev, size_t offset, uint8_t *data, size_t size)
94{
95 uint8_t buf[16];
96 size_t i;
97 int r;
98
99 i = 0;
100 while (size >= sizeof(buf)) {
101 if (rdev_readat(rdev, buf, offset + i, sizeof(buf)) != sizeof(buf))
102 return CB_EFI_ACCESS_ERROR;
103 r = memcmp(buf, data + i, sizeof(buf));
104 if (r != 0)
105 return r;
106 i += sizeof(buf);
107 size -= sizeof(buf);
108 }
109 while (size > 0) {
110 if (rdev_readat(rdev, buf, offset + i, 1) != 1)
111 return CB_EFI_ACCESS_ERROR;
112 r = buf[0] - data[i];
113 if (r != 0)
114 return r;
115 i++;
116 size--;
117 }
118 return 0;
119}
120
121
122static enum cb_err validate_fv_header(const struct region_device *rdev,
123 EFI_FIRMWARE_VOLUME_HEADER *fw_vol_hdr)
124{
125 uint16_t checksum, data;
126 size_t i;
127
128 if (rdev_readat(rdev, fw_vol_hdr, 0, sizeof(*fw_vol_hdr)) != sizeof(*fw_vol_hdr))
129 return CB_EFI_ACCESS_ERROR;
130
131 /*
132 * Verify the header revision, header signature, length
133 * Length of FvBlock cannot be 2**64-1
134 * HeaderLength cannot be an odd number
135 */
136 if ((fw_vol_hdr->Revision != EFI_FVH_REVISION)
137 || (fw_vol_hdr->Signature != EFI_FVH_SIGNATURE)
138 || (fw_vol_hdr->FvLength > region_device_sz(rdev))
139 || (fw_vol_hdr->HeaderLength > region_device_sz(rdev))
140 || (fw_vol_hdr->HeaderLength & 1)) {
141 printk(BIOS_WARNING, PREFIX "No Firmware Volume header present\n");
142 return CB_EFI_FVH_INVALID;
143 }
144
145 /* Check the Firmware Volume Guid */
146 if (!compare_guid(&fw_vol_hdr->FileSystemGuid, &EfiSystemNvDataFvGuid)) {
147 printk(BIOS_WARNING, PREFIX "Firmware Volume Guid non-compatible\n");
148 return CB_EFI_FVH_INVALID;
149 }
150
151 /* Verify the header checksum */
152 checksum = 0;
153 for (i = 0; i < fw_vol_hdr->HeaderLength; i += 2) {
154 if (rdev_readat(rdev, &data, i, sizeof(data)) != sizeof(data))
155 return CB_EFI_ACCESS_ERROR;
156 checksum = (uint16_t)(checksum + data); /* intentionally overflows */
157 }
158 if (checksum != 0) {
159 printk(BIOS_WARNING, PREFIX "FV checksum is invalid: 0x%X\n", checksum);
160 return CB_EFI_CHECKSUM_INVALID;
161 }
162
163 printk(BIOS_SPEW, PREFIX "UEFI FV with size %lld found\n", fw_vol_hdr->FvLength);
164
165 return CB_SUCCESS;
Patrick Rudolph1ab8ad62021-04-21 10:02:55 +0200166}
167
168static enum cb_err
169validate_variable_store_header(const EFI_FIRMWARE_VOLUME_HEADER *fv_hdr,
170 struct region_device *rdev,
171 bool *auth_format)
172{
173 VARIABLE_STORE_HEADER hdr;
174 size_t length;
175
176 if (rdev_readat(rdev, &hdr, fv_hdr->HeaderLength, sizeof(hdr)) != sizeof(hdr))
177 return CB_EFI_ACCESS_ERROR;
178
179 /* Check the Variable Store Guid */
180 if (!compare_guid(&hdr.Signature, &EfiVariableGuid) &&
181 !compare_guid(&hdr.Signature, &EfiAuthenticatedVariableGuid)) {
182 printk(BIOS_WARNING, PREFIX "Variable Store Guid non-compatible\n");
183 return CB_EFI_VS_CORRUPTED_INVALID;
184 }
185
186 *auth_format = compare_guid(&hdr.Signature, &EfiAuthenticatedVariableGuid);
187
188 length = region_device_sz(rdev) - fv_hdr->HeaderLength;
189 if (hdr.Size > length) {
190 printk(BIOS_WARNING, PREFIX "Variable Store Length does not match\n");
191 return CB_EFI_VS_CORRUPTED_INVALID;
192 }
193
194 if (hdr.Format != VARIABLE_STORE_FORMATTED)
195 return CB_EFI_VS_NOT_FORMATTED_INVALID;
196
197 if (hdr.State != VARIABLE_STORE_HEALTHY)
198 return CB_EFI_VS_CORRUPTED_INVALID;
199
200 if (rdev_chain(rdev, rdev, fv_hdr->HeaderLength + sizeof(hdr), hdr.Size)) {
201 printk(BIOS_WARNING, PREFIX "rdev_chain failed\n");
202 return CB_EFI_ACCESS_ERROR;
203 }
204
205 printk(BIOS_SPEW, PREFIX "UEFI variable store with size %zu found\n",
206 region_device_sz(rdev));
207
208 return CB_SUCCESS;
209}
210
211struct efi_find_args {
212 const EFI_GUID *guid;
213 const char *name;
214 uint32_t *size;
215 void *data;
216};
217
218static bool match(struct region_device *rdev, VARIABLE_HEADER *hdr, size_t hdr_size,
219 const char *name, const EFI_GUID *guid)
220{
221 /* Only search for valid or in transition to be deleted variables */
222 if ((hdr->State != VAR_ADDED) &&
223 (hdr->State != (VAR_IN_DELETED_TRANSITION & VAR_ADDED)))
224 return false;
225
226 if ((!compare_guid(&hdr->VendorGuid, guid)) ||
227 !hdr->NameSize ||
228 !hdr->DataSize)
229 return false;
230
231 if (rdev_strcmp_wchar_ascii(rdev, hdr_size, name) != 0)
232 return false;
233
234 return true;
235}
236
237static
238enum cb_err find_and_copy(struct region_device *rdev, VARIABLE_HEADER *hdr, size_t hdr_size,
239 void *arg, bool *stop)
240{
241 struct efi_find_args *fa = (struct efi_find_args *)arg;
242
243 if (!match(rdev, hdr, hdr_size, fa->name, fa->guid))
244 return CB_SUCCESS;
245
246 *stop = true;
247 if (*(fa->size) < hdr->DataSize)
248 return CB_EFI_BUFFER_TOO_SMALL;
249
250 if (rdev_readat(rdev, fa->data, hdr_size + hdr->NameSize, hdr->DataSize) !=
251 hdr->DataSize)
252 return CB_EFI_ACCESS_ERROR;
253
254 *(fa->size) = hdr->DataSize;
255 return CB_SUCCESS;
256}
257
258struct efi_find_compare_args {
259 const EFI_GUID *guid;
260 const char *name;
261 uint32_t size;
262 void *data;
263 bool match;
264};
265
266static
267enum cb_err find_and_compare(struct region_device *rdev, VARIABLE_HEADER *hdr, size_t hdr_size,
268 void *arg, bool *stop)
269{
270 struct efi_find_compare_args *fa = (struct efi_find_compare_args *)arg;
271
272 if (!match(rdev, hdr, hdr_size, fa->name, fa->guid))
273 return CB_SUCCESS;
274
275 *stop = true;
276 if (fa->size != hdr->DataSize) {
277 fa->match = false;
278 return CB_SUCCESS;
279 }
280
281 fa->match = rdev_memcmp(rdev, hdr_size + hdr->NameSize, fa->data, hdr->DataSize) == 0;
282
283 return CB_SUCCESS;
284}
285
286static enum cb_err noop(struct region_device *rdev, VARIABLE_HEADER *hdr, size_t hdr_size,
287 void *arg, bool *stop)
288{
289 /* Does nothing. */
290 return CB_SUCCESS;
291}
292
293static enum cb_err print_var(struct region_device *rdev, VARIABLE_HEADER *hdr, size_t hdr_size,
294 void *arg, bool *stop)
295{
296 uint8_t buf[16];
297 size_t len, i;
298
299 printk(BIOS_DEBUG, "%08zx: Var ", region_device_offset(rdev));
300 print_guid(BIOS_DEBUG, &hdr->VendorGuid);
301
302 printk(BIOS_DEBUG, "-");
303
304 rdev_print_wchar(BIOS_DEBUG, rdev, hdr_size);
305
306 printk(BIOS_DEBUG, ", State %02x, Size %02x\n", hdr->State, hdr->DataSize);
307
308 if (hdr->DataSize && hdr->NameSize) {
309 len = sizeof(buf) < hdr->DataSize ? sizeof(buf) : hdr->DataSize;
310 if (rdev_readat(rdev, buf, hdr_size + hdr->NameSize, len) != len)
311 return CB_EFI_ACCESS_ERROR;
312 printk(BIOS_DEBUG, " Data: ");
313
314 for (i = 0; i < len; i++)
315 printk(BIOS_DEBUG, "0x%02x ", buf[i]);
316
317 if (hdr->DataSize > len)
318 printk(BIOS_DEBUG, "...");
319
320 printk(BIOS_DEBUG, "\n");
321 }
322
323 return CB_SUCCESS;
324}
325
326static enum cb_err walk_variables(struct region_device *rdev,
327 bool auth_format,
328 enum cb_err (*walker)(struct region_device *rdev,
329 VARIABLE_HEADER *hdr,
330 size_t hdr_size,
331 void *arg,
332 bool *stop),
333 void *walker_arg)
334{
335 AUTHENTICATED_VARIABLE_HEADER auth_hdr;
336 size_t header_size, var_size;
337 VARIABLE_HEADER hdr;
338 bool stop;
339 enum cb_err ret;
340
341 if (auth_format)
342 header_size = sizeof(AUTHENTICATED_VARIABLE_HEADER);
343 else
344 header_size = sizeof(VARIABLE_HEADER);
345
346 do {
347 if (auth_format) {
348 if (rdev_readat(rdev, &auth_hdr, 0, sizeof(auth_hdr))
349 != sizeof(auth_hdr))
350 return CB_EFI_ACCESS_ERROR;
351 hdr.Reserved = auth_hdr.Reserved;
352 hdr.StartId = auth_hdr.StartId;
353 hdr.State = auth_hdr.State;
354 hdr.Attributes = auth_hdr.Attributes;
355 hdr.NameSize = auth_hdr.NameSize;
356 hdr.DataSize = auth_hdr.DataSize;
357 memcpy(&hdr.VendorGuid, &auth_hdr.VendorGuid, sizeof(hdr.VendorGuid));
358 } else if (rdev_readat(rdev, &hdr, 0, sizeof(hdr)) != sizeof(hdr)) {
359 return CB_EFI_ACCESS_ERROR;
360 }
361 if (hdr.StartId != VARIABLE_DATA)
362 break;
363
364 if (hdr.State == UINT8_MAX ||
365 hdr.DataSize == UINT32_MAX ||
366 hdr.NameSize == UINT32_MAX ||
367 hdr.Attributes == UINT32_MAX) {
368 hdr.NameSize = 0;
369 hdr.DataSize = 0;
370 }
371
372 printk(BIOS_SPEW, "Found variable with state %02x and ", hdr.State);
373 print_guid(BIOS_SPEW, &hdr.VendorGuid);
374 printk(BIOS_SPEW, "\n");
375
376 stop = false;
377
378 ret = walker(rdev, &hdr, header_size, walker_arg, &stop);
379
380 if (ret != CB_SUCCESS || stop)
381 return ret;
382
383 var_size = ALIGN_UP(header_size + hdr.NameSize + hdr.DataSize,
384 HEADER_ALIGNMENT);
385 } while (!rdev_chain(rdev, rdev, var_size, region_device_sz(rdev) - var_size));
386
387 return CB_EFI_OPTION_NOT_FOUND;
388}
389
390static enum cb_err efi_fv_init(struct region_device *rdev, bool *auth_format)
391{
392 EFI_FIRMWARE_VOLUME_HEADER fv_hdr;
393 enum cb_err ret;
394
395 ret = validate_fv_header(rdev, &fv_hdr);
396 if (ret != CB_SUCCESS) {
397 printk(BIOS_WARNING, PREFIX "Failed to validate firmware header\n");
398
399 return ret;
400 }
401 ret = validate_variable_store_header(&fv_hdr, rdev, auth_format);
402 if (ret != CB_SUCCESS)
403 printk(BIOS_WARNING, PREFIX "Failed to validate variable store header\n");
404
405 return ret;
406}
407
408enum cb_err efi_fv_print_options(struct region_device *rdev)
409{
410 enum cb_err ret;
411 bool auth_format;
412
413 ret = efi_fv_init(rdev, &auth_format);
414 if (ret != CB_SUCCESS)
415 return ret;
416
417 return walk_variables(rdev, auth_format, print_var, NULL);
418}
419
420/*
421 * efi_fv_get_option
422 * - writes up to *size bytes into a buffer pointed to by *dest
423 * - rdev is the spi flash region to operate on
424 * - the FVH and variable store header must have been initialized by a third party
425 */
426enum cb_err efi_fv_get_option(struct region_device *rdev,
427 const EFI_GUID *guid,
428 const char *name,
429 void *dest,
430 uint32_t *size)
431{
432 struct efi_find_args args;
433 bool auth_format;
434 enum cb_err ret;
435
436 ret = efi_fv_init(rdev, &auth_format);
437 if (ret != CB_SUCCESS)
438 return ret;
439
440 args.guid = guid;
441 args.name = name;
442 args.size = size;
443 args.data = dest;
444
445 return walk_variables(rdev, auth_format, find_and_copy, &args);
446}
447
448static enum cb_err write_auth_hdr(struct region_device *rdev, const EFI_GUID *guid,
449 const char *name, void *data, size_t size)
450{
451 AUTHENTICATED_VARIABLE_HEADER auth_hdr;
452 size_t name_size, var_size;
453 enum cb_err ret;
454
455 name_size = (strlen(name) + 1) * sizeof(CHAR16);
456 var_size = name_size + size + sizeof(auth_hdr);
457
458 if (var_size > region_device_sz(rdev))
459 return CB_EFI_STORE_FULL;
460
461 /* Sanity check. flash must be blank */
462 if (rdev_readat(rdev, &auth_hdr, 0, sizeof(auth_hdr)) != sizeof(auth_hdr))
463 return CB_EFI_ACCESS_ERROR;
464
465 if (auth_hdr.StartId != UINT16_MAX ||
466 auth_hdr.State != UINT8_MAX ||
467 auth_hdr.DataSize != UINT32_MAX ||
468 auth_hdr.NameSize != UINT32_MAX ||
469 auth_hdr.Attributes != UINT32_MAX) {
470 return CB_EFI_ACCESS_ERROR;
471 }
472
473 memset(&auth_hdr, 0xff, sizeof(auth_hdr));
474
475 auth_hdr.StartId = VARIABLE_DATA;
476 auth_hdr.Attributes = EFI_VARIABLE_NON_VOLATILE|
477 EFI_VARIABLE_BOOTSERVICE_ACCESS|
478 EFI_VARIABLE_RUNTIME_ACCESS;
479 auth_hdr.NameSize = name_size;
480 auth_hdr.DataSize = size;
481 memcpy(&auth_hdr.VendorGuid, guid, sizeof(EFI_GUID));
482
483 /* Write header with no State */
484 if (rdev_writeat(rdev, &auth_hdr, 0, sizeof(auth_hdr)) != sizeof(auth_hdr))
485 return CB_EFI_ACCESS_ERROR;
486
487 /* Set header State to valid header */
488 auth_hdr.State = VAR_HEADER_VALID_ONLY;
489 if (rdev_writeat(rdev, &auth_hdr.State, offsetof(AUTHENTICATED_VARIABLE_HEADER, State),
490 sizeof(auth_hdr.State)) != sizeof(auth_hdr.State))
491 return CB_EFI_ACCESS_ERROR;
492
493 /* Write the name */
494 ret = rdev_write_wchar(rdev, sizeof(auth_hdr), name);
495 if (ret != CB_SUCCESS)
496 return ret;
497
498 /* Write the data */
499 if (rdev_writeat(rdev, data, sizeof(auth_hdr) + name_size, size) != size)
500 return CB_EFI_ACCESS_ERROR;
501
502 /* Set header State to valid data */
503 auth_hdr.State = VAR_ADDED;
504 if (rdev_writeat(rdev, &auth_hdr.State, offsetof(AUTHENTICATED_VARIABLE_HEADER, State),
505 sizeof(auth_hdr.State)) != sizeof(auth_hdr.State))
506 return CB_EFI_ACCESS_ERROR;
507
508 return CB_SUCCESS;
509}
510
511static enum cb_err write_hdr(struct region_device *rdev, const EFI_GUID *guid,
512 const char *name,
513 void *data,
514 size_t size)
515{
516 VARIABLE_HEADER hdr;
517 size_t name_size, var_size;
518 enum cb_err ret;
519
520 name_size = (strlen(name) + 1) * sizeof(CHAR16);
521 var_size = name_size + size + sizeof(hdr);
522 if (var_size > region_device_sz(rdev))
523 return CB_EFI_STORE_FULL;
524
525 /* Sanity check. flash must be blank */
526 if (rdev_readat(rdev, &hdr, 0, sizeof(hdr)) != sizeof(hdr))
527 return CB_EFI_ACCESS_ERROR;
528
529 if (hdr.StartId != UINT16_MAX ||
530 hdr.State != UINT8_MAX ||
531 hdr.DataSize != UINT32_MAX ||
532 hdr.NameSize != UINT32_MAX ||
533 hdr.Attributes != UINT32_MAX) {
534 return CB_EFI_ACCESS_ERROR;
535 }
536
537 memset(&hdr, 0xff, sizeof(hdr));
538
539 hdr.StartId = VARIABLE_DATA;
540 hdr.Attributes = EFI_VARIABLE_NON_VOLATILE|
541 EFI_VARIABLE_BOOTSERVICE_ACCESS|
542 EFI_VARIABLE_RUNTIME_ACCESS;
543 hdr.NameSize = name_size;
544 hdr.DataSize = size;
545 memcpy(&hdr.VendorGuid, guid, sizeof(EFI_GUID));
546
547 /* Write header with no State */
548 if (rdev_writeat(rdev, &hdr, 0, sizeof(hdr)) != sizeof(hdr))
549 return CB_EFI_ACCESS_ERROR;
550
551 /* Set header State to valid header */
552 hdr.State = VAR_HEADER_VALID_ONLY;
553 if (rdev_writeat(rdev, &hdr.State, offsetof(VARIABLE_HEADER, State),
554 sizeof(hdr.State)) != sizeof(hdr.State))
555 return CB_EFI_ACCESS_ERROR;
556
557 /* Write the name */
558 ret = rdev_write_wchar(rdev, sizeof(hdr), name);
559 if (ret != CB_SUCCESS)
560 return ret;
561
562 /* Write the data */
563 if (rdev_writeat(rdev, data, sizeof(hdr) + name_size, size) != size)
564 return CB_EFI_ACCESS_ERROR;
565
566 /* Set header State to valid data */
567 hdr.State = VAR_ADDED;
568 if (rdev_writeat(rdev, &hdr.State, offsetof(VARIABLE_HEADER, State),
569 sizeof(hdr.State)) != sizeof(hdr.State))
570 return CB_EFI_ACCESS_ERROR;
571
572 return CB_SUCCESS;
573}
574
575/*
576 * efi_fv_set_option
577 * - writes size bytes read from the buffer pointed to by *data
578 * - rdev is the spi flash region to operate on
579 * - the FVH and variable store header must have been initialized by a third party
580 */
581enum cb_err efi_fv_set_option(struct region_device *rdev,
582 const EFI_GUID *guid,
583 const char *name,
584 void *data,
585 uint32_t size)
586{
587 struct region_device rdev_old;
588 struct efi_find_compare_args args;
589 bool found_existing;
590 VARIABLE_HEADER hdr;
591 bool auth_format;
592 enum cb_err ret;
593
594 ret = efi_fv_init(rdev, &auth_format);
595 if (ret != CB_SUCCESS)
596 return ret;
597
598 /* Find existing variable */
599 args.guid = guid;
600 args.name = name;
601 args.size = size;
602 args.match = false;
603 args.data = data;
604
605 ret = walk_variables(rdev, auth_format, find_and_compare, &args);
606 found_existing = ret == CB_SUCCESS;
607
608 if (found_existing) {
609 printk(BIOS_ERR, "found existing variable %s, match =%d\n", name, args.match);
610
611 if (args.match)
612 return CB_SUCCESS;
613
614 rdev_old = *rdev;
615
616 /* Mark as to be deleted */
617 hdr.State = VAR_IN_DELETED_TRANSITION;
618 if (rdev_writeat(rdev, &hdr.State, offsetof(VARIABLE_HEADER, State),
619 sizeof(hdr.State)) != sizeof(hdr.State))
620 return CB_EFI_ACCESS_ERROR;
621 }
622
623 /* Walk to end of variable store */
624 ret = walk_variables(rdev, auth_format, noop, NULL);
625 if (ret != CB_EFI_OPTION_NOT_FOUND)
626 return ret;
627
628 /* Now append new variable:
629 * 1. Write the header without State field.
630 * 2. Write the State field and set it to HEADER_VALID.
631 * 3. Write data
632 * 4. Write the State field and set it to VAR_ADDED
633 */
634
635 if (auth_format)
636 ret = write_auth_hdr(rdev, guid, name, data, size);
637 else
638 ret = write_hdr(rdev, guid, name, data, size);
639 if (ret != CB_SUCCESS)
640 return ret;
641
642 if (found_existing) {
643 /* Mark old variable as deleted */
644 hdr.State = VAR_DELETED;
645 if (rdev_writeat(&rdev_old, &hdr.State, offsetof(VARIABLE_HEADER, State),
646 sizeof(hdr.State)) != sizeof(hdr.State))
647 return CB_EFI_ACCESS_ERROR;
648 }
649
650 return CB_SUCCESS;
651}