audk/SecurityPkg
Laszlo Ersek 61a9fa589a SecurityPkg/DxeImageVerificationHandler: keep PE/COFF info status internal
The PeCoffLoaderGetImageInfo() function may return various error codes,
such as RETURN_INVALID_PARAMETER and RETURN_UNSUPPORTED.

Such error values should not be assigned to our "Status" variable in the
DxeImageVerificationHandler() function, because "Status" generally stands
for the main exit value of the function. And
SECURITY2_FILE_AUTHENTICATION_HANDLER functions are expected to return one
of EFI_SUCCESS, EFI_SECURITY_VIOLATION, and EFI_ACCESS_DENIED only.

Introduce the "PeCoffStatus" helper variable for keeping the return value
of PeCoffLoaderGetImageInfo() internal to the function. If
PeCoffLoaderGetImageInfo() fails, we'll jump to the "Done" label with
"Status" being EFI_ACCESS_DENIED, inherited from the top of the function.

Note that this is consistent with the subsequent PE/COFF Signature check,
where we jump to the "Done" label with "Status" having been re-set to
EFI_ACCESS_DENIED.

As a consequence, we can at once remove the

  Status = EFI_ACCESS_DENIED;

assignment right after the "PeCoffStatus" check.

This patch does not change the control flow in the function, it only
changes the "Status" outcome from API-incompatible error codes to
EFI_ACCESS_DENIED, under some circumstances.

Cc: Chao Zhang <chao.b.zhang@intel.com>
Cc: Jian J Wang <jian.j.wang@intel.com>
Cc: Jiewen Yao <jiewen.yao@intel.com>
Ref: https://bugzilla.tianocore.org/show_bug.cgi?id=2129
Signed-off-by: Laszlo Ersek <lersek@redhat.com>
Message-Id: <20200116190705.18816-4-lersek@redhat.com>
Reviewed-by: Michael D Kinney <michael.d.kinney@intel.com>
[lersek@redhat.com: push with Mike's R-b due to Chinese New Year
 Holiday: <https://edk2.groups.io/g/devel/message/53429>; msgid
 <d3fbb76dabed4e1987c512c328c82810@intel.com>]
2020-01-31 09:35:31 +00:00
..
FvReportPei SecurityPkg: Fix spelling errors 2019-10-23 10:23:23 -07:00
Hash2DxeCrypto SecurityPkg: Fix spelling errors 2019-10-23 10:23:23 -07:00
HddPassword SecurityPkg: Fix spelling errors 2019-10-23 10:23:23 -07:00
Include SecurityPkg/Guid: Add TCG 800-155 event GUID definition. 2020-01-06 06:23:19 +00:00
Library SecurityPkg/DxeImageVerificationHandler: keep PE/COFF info status internal 2020-01-31 09:35:31 +00:00
Pkcs7Verify/Pkcs7VerifyDxe SecurityPkg: Fix spelling errors 2019-10-23 10:23:23 -07:00
RandomNumberGenerator/RngDxe SecurityPkg: Fix spelling errors 2019-10-23 10:23:23 -07:00
Tcg SecurityPkg/Tcg2Pei: Add TCG PFP 105 support. 2020-01-06 06:23:19 +00:00
VariableAuthenticated/SecureBootConfigDxe SecurityPkg: Fix spelling errors 2019-10-23 10:23:23 -07:00
SecurityPkg.ci.yaml SecurityPkg: Add YAML files for CI builds 2019-11-11 13:02:30 -08:00
SecurityPkg.dec SecurityPkg/Guid: Add TCG 800-155 event GUID definition. 2020-01-06 06:23:19 +00:00
SecurityPkg.dsc SecurityPkg: Add YAML files for CI builds 2019-11-11 13:02:30 -08:00
SecurityPkg.uni SecurityPkg: Fix spelling errors 2019-10-23 10:23:23 -07:00
SecurityPkgExtra.uni SecurityPkg: Replace BSD License with BSD+Patent License 2019-04-09 10:58:23 -07:00