chromeos: Reverse FMAP signature constant to avoid having it in .rodata

Even though coreboot always hardcodes the FMAP offset, the same is not
possible for all other tools that manipulate ROM images. Some need to
manually find the FMAP by searching for it's magic number (ASCII
"__FMAP__"). If we do something like 'memcmp(fmap_buffer, "__FMAP__",
...) in coreboot code, it has the unfortunate side effect that the
compiler will output that very same magic number as a constant in the
.rodata section to compare against. Other tools may mistake this for the
"real" FMAP location and get confused.

This patch reverses the constant defined in coreboot and changes the
only use of it correspondingly. It is not impossible but extremely
unlikely (at the current state of the art) that any compiler would be
clever enough to understand this pattern and optimize it back to a
straight memcmp() (GCC 4.9 definitely doesn't), so it should solve the
problem at least for another few years/decades.

BRANCH=veyron
BUG=chromium:447051
TEST=Made sure the new binaries actually contain "__PAMF__" in their
.rodata. Booted Pinky. Independently corrupted both the first and the
last byte of the FMAP signature with a hex editor and confirmed that
signature check fails in both cases.

Change-Id: I725652ef2a77f7f99884b46498428c3d68cd0945
Signed-off-by: Julius Werner <jwerner@chromium.org>
Reviewed-on: https://chromium-review.googlesource.com/240723
Reviewed-by: Daisuke Nojiri <dnojiri@chromium.org>
Reviewed-by: David Hendricks <dhendrix@chromium.org>
Reviewed-on: https://chromium-review.googlesource.com/242157
This commit is contained in:
Julius Werner 2015-01-14 13:12:10 -08:00 committed by ChromeOS Commit Bot
commit f4c8643b7c
2 changed files with 10 additions and 5 deletions

View file

@ -26,10 +26,15 @@
static int is_fmap_signature_valid(const struct fmap *fmap)
{
if (memcmp(fmap, FMAP_SIGNATURE, sizeof(FMAP_SIGNATURE) - 1)) {
printk(BIOS_ERR, "No FMAP found at %p.\n", fmap);
return 1;
}
const char reversed_sig[] = FMAP_REVERSED_SIGNATURE;
const char *p2 = reversed_sig + sizeof(FMAP_REVERSED_SIGNATURE) - 2;
const char *p1 = (char *)fmap;
while (p2 >= reversed_sig)
if (*p1++ != *p2--) {
printk(BIOS_ERR, "No FMAP found at %p.\n", fmap);
return 1;
}
printk(BIOS_DEBUG, "FMAP: Found \"%s\" version %d.%d at %p.\n",
fmap->name, fmap->ver_major, fmap->ver_minor, fmap);

View file

@ -38,7 +38,7 @@
#include <stdint.h>
#define FMAP_SIGNATURE "__FMAP__"
#define FMAP_REVERSED_SIGNATURE "__PAMF__" /* avoid magic number in .rodata */
#define FMAP_VER_MAJOR 1 /* this header's FMAP minor version */
#define FMAP_VER_MINOR 1 /* this header's FMAP minor version */
#define FMAP_STRLEN 32 /* maximum length for strings, */