summaryrefslogtreecommitdiff
path: root/util/libreboot-utils/lib
diff options
context:
space:
mode:
authorLeah Rowe <leah@libreboot.org>2026-09-07 08:12:24 +0100
committerLeah Rowe <leah@libreboot.org>2026-09-07 08:12:24 +0100
commit123639e3db0757fb3370516f7eaf50cbfae4d026 (patch)
tree2fefd5b712f2935949bd447038cfb867f49f6342 /util/libreboot-utils/lib
parent01cb422c9771c7daa00c6f832c3294d59802a635 (diff)
delete util/libreboot-utils (unused code)
this was an intense audit of nvmutil that somehow evolved into writing a new, hardened implementation of mktemp. it all works, a few memory bugs to solve on bsd, but i don't see the point in keeping it. mktemp is fine, and nvmutil already works. lbutils implemented atomic writes and integrity checking, in a manner completely overengineered for what it was actually doing (modifying a few bytes in 8KB GbE files) just delete it. i'll bring it back if i ever finish the code. i don't want to leave dead/unfinished code in the tree. Signed-off-by: Leah Rowe <leah@libreboot.org>
Diffstat (limited to 'util/libreboot-utils/lib')
-rw-r--r--util/libreboot-utils/lib/checksum.c108
-rw-r--r--util/libreboot-utils/lib/command.c521
-rw-r--r--util/libreboot-utils/lib/file.c817
-rw-r--r--util/libreboot-utils/lib/io.c563
-rw-r--r--util/libreboot-utils/lib/mkhtemp.c914
-rw-r--r--util/libreboot-utils/lib/num.c116
-rw-r--r--util/libreboot-utils/lib/rand.c200
-rw-r--r--util/libreboot-utils/lib/state.c164
-rw-r--r--util/libreboot-utils/lib/string.c643
-rw-r--r--util/libreboot-utils/lib/usage.c30
-rw-r--r--util/libreboot-utils/lib/word.c68
11 files changed, 0 insertions, 4144 deletions
diff --git a/util/libreboot-utils/lib/checksum.c b/util/libreboot-utils/lib/checksum.c
deleted file mode 100644
index f71bcb4f..00000000
--- a/util/libreboot-utils/lib/checksum.c
+++ /dev/null
@@ -1,108 +0,0 @@
-/* SPDX-License-Identifier: MIT
- * Copyright (c) 2022-2026 Leah Rowe <leah@libreboot.org>
- *
- * Functions related to GbE NVM checksums.
- */
-
-#include <sys/types.h>
-#include <sys/stat.h>
-
-#include <errno.h>
-#include <limits.h>
-#include <stddef.h>
-#include <stdlib.h>
-
-#include "../include/common.h"
-
-void
-read_checksums(void)
-{
- struct xstate *x = xstatus();
- struct commands *cmd = &x->cmd[x->i];
- struct xfile *f = &x->f;
-
- size_t _p;
- size_t _skip_part;
-
- unsigned char _num_invalid;
- unsigned char _max_invalid;
-
- f->part_valid[0] = 0;
- f->part_valid[1] = 0;
-
- if (!cmd->chksum_read)
- return;
-
- _num_invalid = 0;
- _max_invalid = 2;
-
- if (cmd->arg_part)
- _max_invalid = 1;
-
- /* Skip verification on this part,
- * but only when arg_part is set.
- */
- _skip_part = f->part ^ 1;
-
- for (_p = 0; _p < 2; _p++) {
-
- /* Only verify a part if it was *read*
- */
- if (cmd->arg_part && (_p == _skip_part))
- continue;
-
- f->part_valid[_p] = good_checksum(_p);
- if (!f->part_valid[_p])
- ++_num_invalid;
- }
-
- if (_num_invalid >= _max_invalid) {
-
- if (_max_invalid == 1)
- exitf("%s: part %lu has a bad checksum",
- f->fname, (size_t)f->part);
-
- exitf("%s: No valid checksum found in file",
- f->fname);
- }
-}
-
-int
-good_checksum(size_t partnum)
-{
- unsigned short expected_checksum;
- unsigned short actual_checksum;
-
- expected_checksum =
- calculated_checksum(partnum);
-
- actual_checksum =
- nvm_word(NVM_CHECKSUM_WORD, partnum);
-
- if (expected_checksum == actual_checksum) {
- return 1;
- } else {
- return 0;
- }
-}
-
-void
-set_checksum(size_t p)
-{
- check_bin(p, "part number");
- set_nvm_word(NVM_CHECKSUM_WORD, p, calculated_checksum(p));
-}
-
-unsigned short
-calculated_checksum(size_t p)
-{
- size_t c;
- unsigned int val16;
-
- val16 = 0;
-
- for (c = 0; c < NVM_CHECKSUM_WORD; c++)
- val16 += (unsigned int)nvm_word(c, p);
-
- return (unsigned short)((NVM_CHECKSUM - val16) & 0xffff);
-}
diff --git a/util/libreboot-utils/lib/command.c b/util/libreboot-utils/lib/command.c
deleted file mode 100644
index 3bdc4191..00000000
--- a/util/libreboot-utils/lib/command.c
+++ /dev/null
@@ -1,521 +0,0 @@
-/* SPDX-License-Identifier: MIT
- * Copyright (c) 2022-2026 Leah Rowe <leah@libreboot.org>
- */
-
-#include <sys/types.h>
-#include <sys/stat.h>
-
-#include <errno.h>
-#include <fcntl.h>
-#include <limits.h>
-#include <stdio.h>
-#include <stddef.h>
-#include <string.h>
-#include <unistd.h>
-
-#include "../include/common.h"
-
-void
-sanitize_command_list(void)
-{
- struct xstate *x = xstatus();
-
- size_t c;
- size_t num_commands;
-
- num_commands = items(x->cmd);
-
- for (c = 0; c < num_commands; c++)
- sanitize_command_index(c);
-}
-
-void
-sanitize_command_index(size_t c)
-{
- struct xstate *x = xstatus();
- struct commands *cmd = &x->cmd[c];
-
- int _flag;
- size_t gbe_rw_size;
-
- size_t rval;
-
- check_command_num(c);
-
- if (cmd->argc < 3)
- exitf("cmd index %lu: argc below 3, %d",
- (size_t)c, cmd->argc);
-
- if (cmd->str == NULL)
- exitf("cmd index %lu: NULL str",
- (size_t)c);
-
- if (*cmd->str == '\0')
- exitf("cmd index %lu: empty str",
- (size_t)c);
-
- if (slen(cmd->str, MAX_CMD_LEN +1, &rval) > MAX_CMD_LEN) {
- exitf("cmd index %lu: str too long: %s",
- (size_t)c, cmd->str);
- }
-
- if (cmd->run == NULL)
- exitf("cmd index %lu: cmd ptr null",
- (size_t)c);
-
- check_bin(cmd->arg_part, "cmd.arg_part");
- check_bin(cmd->chksum_read, "cmd.chksum_read");
- check_bin(cmd->chksum_write, "cmd.chksum_write");
-
- gbe_rw_size = cmd->rw_size;
-
- switch (gbe_rw_size) {
- case GBE_PART_SIZE:
- case NVM_SIZE:
- break;
- default:
- exitf("Unsupported rw_size: %lu",
- (size_t)gbe_rw_size);
- }
-
- if (gbe_rw_size > GBE_PART_SIZE)
- exitf("rw_size larger than GbE part: %lu",
- (size_t)gbe_rw_size);
-
- _flag = (cmd->flags & O_ACCMODE);
-
- if (_flag != O_RDONLY &&
- _flag != O_RDWR)
- exitf("invalid cmd.flags setting");
-}
-
-void
-set_cmd(int argc, char *argv[])
-{
- struct xstate *x = xstatus();
- const char *cmd;
-
- int rval;
-
- size_t c;
-
- for (c = 0; c < items(x->cmd); c++) {
-
- cmd = x->cmd[c].str;
-
- if (scmp(argv[2], cmd, MAX_CMD_LEN, &rval))
- continue; /* not the right command */
-
- /* valid command found */
- if (argc >= x->cmd[c].argc) {
- x->no_cmd = 0;
- x->i = c; /* set command */
-
- return;
- }
-
- exitf(
- "Too few args on command '%s'", cmd);
- }
-
-
- x->no_cmd = 1;
-}
-
-void
-set_cmd_args(int argc, char *argv[])
-{
- struct xstate *x = xstatus();
- size_t i = x->i;
- struct commands *cmd = &x->cmd[i];
- struct xfile *f = &x->f;
-
- if (!valid_command(i) || argc < 3)
- usage();
-
- if (x->no_cmd)
- usage();
-
- /* Maintainer bug
- */
- if (cmd->arg_part && argc < 4)
- exitf(
- "arg_part set for command that needs argc4");
-
- if (cmd->arg_part && i == CMD_SETMAC)
- exitf(
- "arg_part set on CMD_SETMAC");
-
- if (i == CMD_SETMAC) {
-
- if (argc >= 4)
- x->mac.str = argv[3];
- else
- x->mac.str = x->mac.rmac;
-
- } else if (cmd->arg_part) {
-
- f->part = conv_argv_part_num(argv[3]);
- }
-}
-
-size_t
-conv_argv_part_num(const char *part_str)
-{
- unsigned char ch;
-
- if (part_str[0] == '\0' || part_str[1] != '\0')
- exitf("Partnum string '%s' wrong length", part_str);
-
- /* char signedness is implementation-defined
- */
- ch = (unsigned char)part_str[0];
- if (ch < '0' || ch > '1')
- exitf("Bad part number (%c)", ch);
-
- return (size_t)(ch - '0');
-}
-
-void
-check_command_num(size_t c)
-{
- if (!valid_command(c))
- exitf("Invalid run_cmd arg: %lu",
- (size_t)c);
-}
-
-unsigned char
-valid_command(size_t c)
-{
- struct xstate *x = xstatus();
- struct commands *cmd;
-
- if (c >= items(x->cmd))
- return 0;
-
- cmd = &x->cmd[c];
-
- if (c != cmd->chk)
- exitf(
- "Invalid cmd chk value (%lu) vs arg: %lu",
- cmd->chk, c);
-
- return 1;
-}
-
-void
-cmd_helper_setmac(void)
-{
- struct xstate *x = xstatus();
- struct macaddr *mac = &x->mac;
-
- size_t partnum;
-
- check_cmd(cmd_helper_setmac, "setmac");
-
- printf("MAC address to be written: %s\n", mac->str);
- parse_mac_string();
-
- for (partnum = 0; partnum < 2; partnum++)
- write_mac_part(partnum);
-}
-
-void
-parse_mac_string(void)
-{
- struct xstate *x = xstatus();
- struct macaddr *mac = &x->mac;
-
- size_t mac_byte;
-
- size_t rval;
-
- if (slen(x->mac.str, 18, &rval) != 17)
- exitf("MAC address is the wrong length");
-
- memset(mac->mac_buf, 0, sizeof(mac->mac_buf));
-
- for (mac_byte = 0; mac_byte < 6; mac_byte++)
- set_mac_byte(mac_byte);
-
- if ((mac->mac_buf[0] | mac->mac_buf[1] | mac->mac_buf[2]) == 0)
- exitf("Must not specify all-zeroes MAC address");
-
- if (mac->mac_buf[0] & 1)
- exitf("Must not specify multicast MAC address");
-}
-
-void
-set_mac_byte(size_t mac_byte_pos)
-{
- struct xstate *x = xstatus();
- struct macaddr *mac = &x->mac;
-
- char separator;
-
- size_t mac_str_pos;
- size_t mac_nib_pos;
-
- mac_str_pos = mac_byte_pos * 3;
-
- if (mac_str_pos < 15) {
- if ((separator = mac->str[mac_str_pos + 2]) != ':')
- exitf("Invalid MAC address separator '%c'",
- separator);
- }
-
- for (mac_nib_pos = 0; mac_nib_pos < 2; mac_nib_pos++)
- set_mac_nib(mac_str_pos, mac_byte_pos, mac_nib_pos);
-}
-
-void
-set_mac_nib(size_t mac_str_pos,
- size_t mac_byte_pos, size_t mac_nib_pos)
-{
- struct xstate *x = xstatus();
- struct macaddr *mac = &x->mac;
-
- char mac_ch;
- unsigned short hex_num;
-
- mac_ch = mac->str[mac_str_pos + mac_nib_pos];
-
- if ((hex_num = hextonum(mac_ch)) > 15) {
- if (hex_num >= 17)
- exitf("Randomisation failure");
- else
- exitf("Invalid character '%c'",
- mac->str[mac_str_pos + mac_nib_pos]);
- }
-
- /* If random, ensure that local/unicast bits are set.
- */
- if ((mac_byte_pos == 0) && (mac_nib_pos == 1) &&
- ((mac_ch | 0x20) == 'x' ||
- (mac_ch == '?')))
- hex_num = (hex_num & 0xE) | 2; /* local, unicast */
-
- /* MAC words stored big endian in-file, little-endian
- * logically, so we reverse the order.
- */
- mac->mac_buf[mac_byte_pos >> 1] |= hex_num <<
- (((mac_byte_pos & 1) << 3) /* left or right byte? */
- | ((mac_nib_pos ^ 1) << 2)); /* left or right nib? */
-}
-
-void
-write_mac_part(size_t partnum)
-{
- struct xstate *x = xstatus();
- struct xfile *f = &x->f;
- struct macaddr *mac = &x->mac;
-
- size_t w;
-
- check_bin(partnum, "part number");
- if (!f->part_valid[partnum])
- return;
-
- for (w = 0; w < 3; w++)
- set_nvm_word(w, partnum, mac->mac_buf[w]);
-
- printf("Wrote MAC address to part %lu: ",
- (size_t)partnum);
- print_mac_from_nvm(partnum);
-}
-
-void
-cmd_helper_dump(void)
-{
- struct xstate *x = xstatus();
- struct xfile *f = &x->f;
-
- size_t p;
-
- check_cmd(cmd_helper_dump, "dump");
-
- f->part_valid[0] = good_checksum(0);
- f->part_valid[1] = good_checksum(1);
-
- for (p = 0; p < 2; p++) {
-
- if (!f->part_valid[p]) {
-
- fprintf(stderr,
- "BAD checksum %04x in part %lu (expected %04x)\n",
- nvm_word(NVM_CHECKSUM_WORD, p),
- (size_t)p,
- calculated_checksum(p));
- }
-
- printf("MAC (part %lu): ",
- (size_t)p);
-
- print_mac_from_nvm(p);
- spew_hex(f->buf + (p * GBE_PART_SIZE), NVM_SIZE);
- }
-}
-
-void
-print_mac_from_nvm(size_t partnum)
-{
- size_t c;
- unsigned short val16;
-
- for (c = 0; c < 3; c++) {
-
- val16 = nvm_word(c, partnum);
-
- printf("%02x:%02x",
- (unsigned int)(val16 & 0xff),
- (unsigned int)(val16 >> 8));
-
- if (c == 2)
- printf("\n");
- else
- printf(":");
- }
-}
-
-void
-cmd_helper_swap(void)
-{
- struct xstate *x = xstatus();
- struct xfile *f = &x->f;
-
- check_cmd(cmd_helper_swap, "swap");
-
- memcpy(
- f->buf + (size_t)GBE_WORK_SIZE,
- f->buf,
- GBE_PART_SIZE);
-
- memcpy(
- f->buf,
- f->buf + (size_t)GBE_PART_SIZE,
- GBE_PART_SIZE);
-
- memcpy(
- f->buf + (size_t)GBE_PART_SIZE,
- f->buf + (size_t)GBE_WORK_SIZE,
- GBE_PART_SIZE);
-
- set_part_modified(0);
- set_part_modified(1);
-}
-
-void
-cmd_helper_copy(void)
-{
- struct xstate *x = xstatus();
- struct xfile *f = &x->f;
-
- check_cmd(cmd_helper_copy, "copy");
-
- memcpy(
- f->buf + (size_t)((f->part ^ 1) * GBE_PART_SIZE),
- f->buf + (size_t)(f->part * GBE_PART_SIZE),
- GBE_PART_SIZE);
-
- set_part_modified(f->part ^ 1);
-}
-
-void
-cmd_helper_cat(void)
-{
- struct xstate *x = xstatus();
-
- check_cmd(cmd_helper_cat, "cat");
-
- x->cat = 0;
- cat(0);
-}
-
-void
-cmd_helper_cat16(void)
-{
- struct xstate *x = xstatus();
-
- check_cmd(cmd_helper_cat16, "cat16");
-
- x->cat = 1;
- cat(1);
-}
-
-void
-cmd_helper_cat128(void)
-{
- struct xstate *x = xstatus();
-
- check_cmd(cmd_helper_cat128, "cat128");
-
- x->cat = 15;
- cat(15);
-}
-
-void
-cat(size_t nff)
-{
- struct xstate *x = xstatus();
- struct xfile *f = &x->f;
-
- size_t p;
- size_t ff;
-
- p = 0;
- ff = 0;
-
- if ((size_t)x->cat != nff) {
-
- exitf("erroneous call to cat");
- }
-
- fflush(NULL);
-
- memset(f->pad, 0xff, GBE_PART_SIZE);
-
- for (p = 0; p < 2; p++) {
-
- cat_buf(f->bufcmp +
- (size_t)(p * (f->gbe_file_size >> 1)));
-
- for (ff = 0; ff < nff; ff++) {
-
- cat_buf(f->pad);
- }
- }
-}
-
-void
-cat_buf(unsigned char *b)
-{
- if (b == NULL)
- exitf("null pointer in cat command");
-
- if (rw_exact(STDOUT_FILENO, b,
- GBE_PART_SIZE, 0, IO_WRITE) < 0)
- exitf("stdout: cat");
-}
-void
-check_cmd(void (*fn)(void),
- const char *name)
-{
- struct xstate *x = xstatus();
- size_t i = x->i;
-
- if (x->cmd[i].run != fn)
- exitf("Running %s, but cmd %s is set",
- name, x->cmd[i].str);
-
- /* prevent second command
- */
- for (i = 0; i < items(x->cmd); i++)
- x->cmd[i].run = cmd_helper_err;
-}
-
-void
-cmd_helper_err(void)
-{
- exitf(
- "Erroneously running command twice");
-}
diff --git a/util/libreboot-utils/lib/file.c b/util/libreboot-utils/lib/file.c
deleted file mode 100644
index 0385ebbb..00000000
--- a/util/libreboot-utils/lib/file.c
+++ /dev/null
@@ -1,817 +0,0 @@
-/* SPDX-License-Identifier: MIT
- * Copyright (c) 2026 Leah Rowe <leah@libreboot.org>
- *
- * Pathless i/o, and some stuff you
- * probably never saw in userspace.
- *
- * Be nice to the demon.
- */
-
-/*
-TODO: putting it here just so it's somewhere:
-PATH_MAX is not reliable as a limit for paths,
-because the real length depends on mount point,
-and specific file systems.
-more correct usage example:
-long max = pathconf("/", _PC_PATH_MAX);
- */
-
-/* for openat2: */
-#ifdef __linux__
-#if !defined(USE_OPENAT) || \
- ((USE_OPENAT) < 1) /* if 1: use openat, not openat2 */
-#ifndef _GNU_SOURCE
-#define _GNU_SOURCE 1
-#endif
-#include <linux/openat2.h>
-#include <sys/syscall.h>
-#endif
-#endif
-
-#include <sys/types.h>
-#include <sys/stat.h>
-
-#include <errno.h>
-#include <fcntl.h>
-#include <stdio.h>
-#include <stdlib.h>
-#include <string.h>
-#include <unistd.h>
-
-#include "../include/common.h"
-
-/* check that a file changed
- */
-
-int
-same_file(int fd, struct stat *st_old,
- int check_size)
-{
- struct stat st;
- int saved_errno = errno;
- int rval = 0;
- errno = 0;
-
- if (if_err(st_old == NULL, EFAULT) ||
- if_err(fd < 0, EBADF) ||
- (rval = fstat(fd, &st)) < 0 ||
- (rval = fd_verify_regular(fd, st_old, &st)) < 0 ||
- if_err(check_size && st.st_size != st_old->st_size, ESTALE))
- return with_fallback_errno(ESTALE);
-
- reset_caller_errno(rval);
- return 0;
-}
-
-int
-fsync_dir(const char *path)
-{
- int saved_errno = errno;
- size_t pathlen = 0;
- char *dirbuf = NULL;
- int dirfd = -1;
- char *slash = NULL;
- struct stat st = {0};
- int rval = 0;
- errno = 0;
-
- if (if_err(slen(path, PATH_MAX, &pathlen) == 0, EINVAL))
- goto err_fsync_dir;
-
- memcpy(smalloc(&dirbuf, pathlen + 1),
- path, pathlen + 1);
- slash = strrchr(dirbuf, '/');
-
- if (slash != NULL) {
- *slash = '\0';
- if (*dirbuf == '\0') {
- dirbuf[0] = '/';
- dirbuf[1] = '\0';
- }
- } else {
- dirbuf[0] = '.';
- dirbuf[1] = '\0';
- }
-
- dirfd = fs_open(dirbuf,
- O_RDONLY | O_CLOEXEC | O_NOCTTY
-#ifdef O_DIRECTORY
- | O_DIRECTORY
-#endif
-#ifdef O_NOFOLLOW
- | O_NOFOLLOW
-#endif
-);
-
- if (if_err_sys(dirfd < 0) ||
- if_err_sys((rval = fstat(dirfd, &st)) < 0) ||
- if_err(!S_ISDIR(st.st_mode), ENOTDIR)
- ||
- if_err_sys((rval = fsync_on_eintr(dirfd)) == -1))
- goto err_fsync_dir;
-
- xclose(&dirfd);
- free_and_set_null(&dirbuf);
-
- reset_caller_errno(rval);
- return 0;
-
-err_fsync_dir:
- free_and_set_null(&dirbuf);
- xclose(&dirfd);
-
- return with_fallback_errno(EIO);
-}
-
-/* rw_exact() - Read perfectly or die
- *
- * Read/write, and absolutely insist on an
- * absolute read; e.g. if 100 bytes are
- * requested, this MUST return 100.
- *
- * This function will never return zero.
- * It will only return below (error),
- * or above (success). On error, -1 is
- * returned and errno is set accordingly.
- *
- * Zero-byte returns are not allowed.
- * It will re-spin a finite number of
- * times upon zero-return, to recover,
- * otherwise it will return an error.
- */
-
-ssize_t
-rw_exact(int fd, unsigned char *mem, size_t nrw,
- off_t off, int rw_type)
-{
- int saved_errno = errno;
- ssize_t rval = 0;
- ssize_t rc = 0;
- size_t nrw_cur;
- off_t off_cur;
- void *mem_cur;
- errno = 0;
-
- if (io_args(fd, mem, nrw, off, rw_type) == -1)
- goto err_rw_exact;
-
- while (1) {
-
- /* Prevent theoretical overflow */
- if (if_err(rval >= 0 && (size_t)rval > (nrw - (size_t)rc),
- EOVERFLOW))
- goto err_rw_exact;
-
- rc += rval;
- if ((size_t)rc >= nrw)
- break;
-
- mem_cur = (void *)(mem + (size_t)rc);
- nrw_cur = (size_t)(nrw - (size_t)rc);
-
- if (if_err(off < 0, EOVERFLOW))
- goto err_rw_exact;
-
- off_cur = off + (off_t)rc;
-
- if ((rval = rw(fd, mem_cur, nrw_cur, off_cur, rw_type)) <= 0)
- goto err_rw_exact;
- }
-
- if (if_err((size_t)rc != nrw, EIO) ||
- (rval = rw_over_nrw(rc, nrw)) < 0)
- goto err_rw_exact;
-
- reset_caller_errno(rval);
- return rval;
-
-err_rw_exact:
- return with_fallback_errno(EIO);
-}
-
-/**
- * rw() - read-write but with more
- * safety checks than barebones libc
- *
- * A fallback is provided for regular read/write.
- * rw_type can be IO_READ (read), IO_WRITE (write),
- * IO_PREAD (pread) or IO_PWRITE
- *
- * WARNING: this function allows zero-byte returns.
- * this is intentional, to mimic libc behaviour.
- * use rw_exact if you need to avoid this.
- * (ditto partial writes/reads)
- *
- */
-ssize_t
-rw(int fd, void *mem, size_t nrw,
- off_t off, int rw_type)
-{
- ssize_t rval = 0;
- ssize_t r = -1;
- int saved_errno = errno;
- errno = 0;
-
- if (io_args(fd, mem, nrw, off, rw_type) == -1 ||
- if_err(mem == NULL, EFAULT) ||
- if_err(fd < 0, EBADF) ||
- if_err(off < 0, EFAULT) ||
- if_err(nrw == 0, EINVAL))
- return with_fallback_errno(EIO);
-
- do {
- switch (rw_type) {
- case IO_READ:
- r = read(fd, mem, nrw);
- break;
- case IO_WRITE:
- r = write(fd, mem, nrw);
- break;
- case IO_PREAD:
- r = pread(fd, mem, nrw, off);
- break;
- case IO_PWRITE:
- r = pwrite(fd, mem, nrw, off);
- break;
- default:
- errno = EINVAL;
- break;
- }
-
- } while (rw_retry(saved_errno, r));
-
- if ((rval = rw_over_nrw(r, nrw)) < 0)
- return with_fallback_errno(EIO);
-
- reset_caller_errno(rval);
- return rval;
-}
-
-int
-io_args(int fd, void *mem, size_t nrw,
- off_t off, int rw_type)
-{
- int saved_errno = errno;
- errno = 0;
-
- if (if_err(mem == NULL, EFAULT) ||
- if_err(fd < 0, EBADF) ||
- if_err(off < 0, ERANGE) ||
- if_err(!nrw, EPERM) || /* TODO: toggle zero-byte check */
- if_err(nrw > (size_t)SSIZE_MAX, ERANGE) ||
- if_err(((size_t)off + nrw) < (size_t)off, ERANGE) ||
- if_err(rw_type > IO_PWRITE, EINVAL))
- goto err_io_args;
-
- reset_caller_errno(0);
- return 0;
-
-err_io_args:
- return with_fallback_errno(EINVAL);
-}
-
-int
-check_file(int fd, struct stat *st)
-{
- int saved_errno = errno;
- int rval = 0;
- errno = 0;
-
- if (if_err(fd < 0, EBADF) ||
- if_err(st == NULL, EFAULT) ||
- ((rval = fstat(fd, st)) == -1) ||
- if_err(!S_ISREG(st->st_mode), EBADF))
- goto err_is_file;
-
- reset_caller_errno(rval);
- return 0;
-
-err_is_file:
- return with_fallback_errno(EINVAL);
-}
-
-/* POSIX can say whatever it wants.
- * specification != implementation
- */
-ssize_t
-rw_over_nrw(ssize_t r, size_t nrw)
-{
- if (if_err(!nrw, EIO) ||
- (r == -1) ||
- if_err((size_t)r > SSIZE_MAX, ERANGE) ||
- if_err((size_t)r > nrw, ERANGE))
- return with_fallback_errno(EIO);
-
- return r;
-}
-
-/* two functions that reduce sloccount by
- * two hundred lines */
-int
-if_err(int condition, int errval)
-{
- if (!condition)
- return 0;
- if (errval)
- errno = errval;
- return 1;
-}
-int
-if_err_sys(int condition)
-{
- if (!condition)
- return 0;
- return 1;
-}
-
-int
-fs_rename_at(int olddirfd, const char *old,
- int newdirfd, const char *new)
-{
- if (if_err(new == NULL || old == NULL, EFAULT) ||
- if_err(olddirfd < 0 || newdirfd < 0, EBADF))
- return -1;
-
- return renameat(olddirfd, old, newdirfd, new);
-}
-
-/* secure open, based on relative path to root
- *
- * always a fixed fd for / see: rootfs()
- * and fs_resolve_at()
- */
-int
-fs_open(const char *path, int flags)
-{
- struct filesystem *fs;
-
- if (if_err(path == NULL, EFAULT) ||
- if_err(path[0] != '/', EINVAL) ||
- if_err_sys((fs = rootfs()) == NULL))
- return -1;
-
- return fs_resolve_at(fs->rootfd, path + 1, flags);
-}
-
-/* singleton function that returns a fixed descriptor of /
- * used throughout, for repeated integrity checks
- */
-struct filesystem *
-rootfs(void)
-{
- static struct filesystem global_fs;
- static int fs_initialised = 0;
-
- if (!fs_initialised) {
-
- global_fs.rootfd = -1;
-
- open_file_on_eintr("/", &global_fs.rootfd,
- O_RDONLY | O_DIRECTORY | O_CLOEXEC, 0400, NULL);
-
- if (global_fs.rootfd < 0)
- return NULL;
-
- fs_initialised = 1;
- }
-
- return &global_fs;
-}
-
-/* filesystem sandboxing in userspace
- * TODO:
- missing length bound check.
- potential CPU DoS on very long paths, spammed repeatedly.
- perhaps cap at MAX_PATH?
- */
-int
-fs_resolve_at(int dirfd, const char *path, int flags)
-{
- int nextfd = -1;
- int curfd;
- const char *p;
- char name[PATH_MAX];
- int saved_errno = errno;
- int r;
- int is_last;
- errno = 0;
-
- if (dirfd < 0 || path == NULL || *path == '\0') {
- errno = EINVAL;
- return -1;
- }
-
- p = path;
- curfd = dirfd; /* start here */
-
- for (;;) {
- r = fs_next_component(&p, name, sizeof(name));
- if (r < 0)
- goto err;
- if (r == 0)
- break;
-
- is_last = (*p == '\0');
-
- nextfd = fs_open_component(curfd, name, flags, is_last);
- if (nextfd < 0)
- goto err;
-
- /* close previous fd if not the original input */
- if (curfd != dirfd)
- xclose(&curfd);
-
- curfd = nextfd;
- nextfd = -1;
- }
-
- reset_caller_errno(0);
- return curfd;
-
-err:
- saved_errno = errno;
-
- if (nextfd >= 0)
- xclose(&nextfd);
-
- /* close curfd only if it's not the original */
- if (curfd != dirfd && curfd >= 0)
- xclose(&curfd);
-
- errno = saved_errno;
- return with_fallback_errno(EIO);
-}
-
-/* NOTE:
- rejects . and .. but not empty strings
- after normalisation. edge case:
- //////
-
- normalised implicitly, but might be good
- to add a defensive check regardless. code
- probably not exploitable in current state.
- */
-int
-fs_next_component(const char **p,
- char *name, size_t namesz)
-{
- const char *s = *p;
- size_t len = 0;
-
- while (*s == '/')
- s++;
-
- if (*s == '\0') {
- *p = s;
- return 0;
- }
-
- while (s[len] != '/' && s[len] != '\0')
- len++;
-
- if (len == 0 || len >= namesz ||
- len >= PATH_MAX) {
- errno = ENAMETOOLONG;
- return -1;
- }
-
- memcpy(name, s, len);
- name[len] = '\0';
-
- /* reject . and .. */
- if (if_err((name[0] == '.' && name[1] == '\0') ||
- (name[0] == '.' && name[1] == '.' && name[2] == '\0'), EPERM))
- goto err;
-
- *p = s + len;
- return 1;
-err:
- return with_fallback_errno(EPERM);
-}
-
-int
-fs_open_component(int dirfd, const char *name,
- int flags, int is_last)
-{
- int saved_errno = errno;
- int fd;
- struct stat st;
- errno = 0;
-
- fd = openat_on_eintr(dirfd, name,
- (is_last ? flags : (O_RDONLY | O_DIRECTORY)) |
- O_NOFOLLOW | O_CLOEXEC, (flags & O_CREAT) ? 0600 : 0);
-
- if (!is_last &&
- (if_err(fd < 0, EBADF) ||
- if_err_sys(fstat(fd, &st) < 0) ||
- if_err(!S_ISDIR(st.st_mode), ENOTDIR)))
- return with_fallback_errno(EIO);
-
- reset_caller_errno(fd);
- return fd;
-}
-
-int
-fs_dirname_basename(const char *path,
- char **dir, char **base,
- int allow_relative)
-{
- int saved_errno = errno;
- char *buf = NULL;
- char *slash;
- size_t len;
- const char *d = NULL;
- const char *b = NULL;
- errno = 0;
-
- if (if_err(path == NULL || dir == NULL || base == NULL, EFAULT))
- goto err;
-
- slen(path, PATH_MAX, &len);
- memcpy(smalloc(&buf, len + 1),
- path, len + 1);
-
- /* strip trailing slashes */
- while (len > 1 && buf[len - 1] == '/')
- buf[--len] = '\0';
-
- slash = strrchr(buf, '/');
-
- if (slash) {
-
- *slash = '\0';
- d = buf;
- b = slash + 1;
-
- if (*d == '\0')
- d = "/";
- } else if (allow_relative) {
-
- d = ".";
- b = buf;
- } else {
- free_and_set_null(&buf);
- goto err;
- }
-
- if (dup_pair(dir, d, base, b) < 0) {
- free_and_set_null(&buf);
- goto err;
- }
-
- free_and_set_null(&buf);
-
- reset_caller_errno(0);
- return 0;
-err:
- return with_fallback_errno(EINVAL);
-}
-
-/* TODO: why does this abort, but others
- e.g. open_file_on_eintr, don't???
- */
-void
-open_file_on_eintr(const char *path,
- int *fd, int flags, mode_t mode,
- struct stat *st)
-{
- int saved_errno = errno;
- int rval = 0;
- errno = 0;
-
- if (path == NULL)
- exitf("open_file_on_eintr: null path");
- if (fd == NULL)
- exitf("%s: open_file_on_eintr: null fd ptr", path);
- if (*fd >= 0)
- exitf(
- "%s: open_file_on_eintr: file already open", path);
-
- errno = 0;
- while (fs_retry(saved_errno,
- rval = open(path, flags, mode)));
-
- if (rval < 0)
- exitf(
- "%s: open_file_on_eintr: could not close", path);
-
- reset_caller_errno(rval);
- *fd = rval;
-
- /* we don't care about edge case behaviour here,
- even if the next operation sets errno on success,
- because the open() call is our main concern.
- however, we also must preserve the new errno,
- assuming it changed above under the same edge case */
-
- saved_errno = errno;
-
- if (st != NULL) {
- if (fstat(*fd, st) < 0)
- exitf("%s: stat", path);
-
- if (!S_ISREG(st->st_mode))
- exitf("%s: not a regular file", path);
- }
-
- if (lseek(*fd, 0, SEEK_CUR) == (off_t)-1)
- exitf("%s: file not seekable", path);
-
- errno = saved_errno; /* see previous comment */
-}
-
-
-#if defined(__linux__) && \
- (!defined(USE_OPENAT) || ((USE_OPENAT) < 1)) /* we use openat2 on linux */
-int
-openat_on_eintr(int dirfd, const char *path,
- int flags, mode_t mode)
-{
- struct open_how how = {
- .flags = (unsigned long long)flags,
- .mode = mode,
- .resolve =
- RESOLVE_BENEATH |
- RESOLVE_NO_SYMLINKS |
- RESOLVE_NO_MAGICLINKS
- };
- int saved_errno = errno;
- long rval = 0;
- errno = 0;
-
- if (if_err(dirfd < 0, EBADF) ||
- if_err(path == NULL, EFAULT))
- goto err;
-
- errno = 0;
- while (sys_retry(saved_errno,
- rval = syscall(SYS_openat2, dirfd, path, &how, sizeof(how))));
-
- if (rval == -1) /* avoid long->int UB for -1 */
- goto err;
-
- reset_caller_errno(rval);
- return (int)rval;
-err:
- return with_fallback_errno(EIO); /* -1 */
-}
-#else /* regular openat on non-linux e.g. openbsd */
-int
-openat_on_eintr(int dirfd, const char *path,
- int flags, mode_t mode)
-{
- int saved_errno = errno;
- int rval = 0;
- errno = 0;
-
- if (if_err(dirfd < 0, EBADF) ||
- if_err(path == NULL, EFAULT))
- return with_fallback_errno(EIO);
-
- while (fs_retry(saved_errno,
- rval = openat(dirfd, path, flags, mode)));
-
- reset_caller_errno(rval);
- return rval;
-}
-#endif
-
-int
-mkdirat_on_eintr(int dirfd,
- const char *path, mode_t mode)
-{
- int saved_errno = errno;
- int rval = 0;
- errno = 0;
-
- if (if_err(dirfd < 0, EBADF) ||
- if_err(path == NULL, EFAULT))
- return with_fallback_errno(EIO);
-
- while (fs_retry(saved_errno,
- rval = mkdirat(dirfd, path, mode)));
-
- reset_caller_errno(rval);
- return rval;
-}
-
-int
-fsync_on_eintr(int fd)
-{
- int saved_errno = errno;
- int rval = 0;
- errno = 0;
-
- if (if_err(fd < 0, EBADF))
- return with_fallback_errno(EIO);
-
- while (fs_retry(saved_errno,
- rval = fsync(fd)));
-
- reset_caller_errno(rval);
- return rval;
-}
-
-void
-xclose(int *fd)
-{
- int saved_errno = errno;
- int rval = 0;
-
- if (fd == NULL)
- exitf("xclose: null pointer");
- if (*fd < 0)
- return;
-
- /* nuance regarding EINTR on close():
- * EINTR can be set on error, but there's
- * no guarantee whether the fd is then still
- * open or closed. on some other commands, we
- * loop EINTR, but for close, we instead skip
- * aborting *if the errno is EINTR* - so don't
- * loop it, but do regard EINTR with rval -1
- * as essenitally a successful close()
- */
-
- /* because we don't want to mess with someone
- * elses file if that fd is then reassigned.
- * if the operation truly did fail, we ignore
- * it. just leave it flying in the wind */
-
- errno = 0;
- if ((rval = close(*fd)) < 0) {
- if (errno != EINTR)
- exitf("xclose: could not close");
-
- /* regard EINTR as a successful close */
- rval = 0;
- }
-
- *fd = -1;
-
- reset_caller_errno(rval);
-}
-
-/* unified eintr looping.
- * differently typed functions
- * to avoid potential UB
- *
- * ONE MACRO TO RULE THEM ALL:
- */
-#define fs_err_retry() \
- do { \
- if ((rval == -1) && \
- (errno == EINTR)) \
- return 1; \
- if (rval >= 0 && !errno) \
- errno = saved_errno; \
- return 0; \
- } while(0)
-/*
- * Regarding the errno logic above:
- * on success, it is permitted that
- * a syscall could still set errno.
- * We reset errno after storingit
- * for later preservation, in functions
- * that call *_retry() functions.
- *
- * They rely ultimately on this
- * macro for errno restoration. We
- * assume therefore that errno was
- * reset to zero before the retry
- * loop. If errno is then *set* on
- * success, we leave it alone. Otherwise,
- * we restore the caller's saved errno.
- *
- * This offers some consistency, while
- * complying with POSIX specification.
- */
-
-
-/* retry switch for functions that
- return long status e.g. linux syscall
- */
-int
-sys_retry(int saved_errno, long rval)
-{
- fs_err_retry();
-}
-
-/* retry switch for functions that
- return int status e.g. mkdirat
- */
-int
-fs_retry(int saved_errno, int rval)
-{
- fs_err_retry();
-}
-
-/* retry switch for functions that
- return rw count in ssize_t e.g. read()
- */
-int
-rw_retry(int saved_errno, ssize_t rval)
-{
- fs_err_retry();
-}
diff --git a/util/libreboot-utils/lib/io.c b/util/libreboot-utils/lib/io.c
deleted file mode 100644
index 6bfbbf51..00000000
--- a/util/libreboot-utils/lib/io.c
+++ /dev/null
@@ -1,563 +0,0 @@
-/* SPDX-License-Identifier: MIT
- * Copyright (c) 2026 Leah Rowe <leah@libreboot.org>
- *
- * I/O functions specific to nvmutil.
- */
-
-/* TODO: local tmpfiles not being deleted
- when flags==O_RDONLY e.g. dump command
- */
-
-#include <sys/types.h>
-#include <sys/stat.h>
-
-#include <errno.h>
-#include <fcntl.h>
-#include <limits.h>
-#include <stddef.h>
-#include <stdio.h>
-#include <stdlib.h>
-#include <string.h>
-#include <unistd.h>
-
-#include "../include/common.h"
-
-void
-open_gbe_file(void)
-{
- struct xstate *x = xstatus();
- struct commands *cmd = &x->cmd[x->i];
- struct xfile *f = &x->f;
- int saved_errno = errno;
- errno = 0;
-
- int _flags;
-
- f->gbe_fd = -1;
-
- open_file_on_eintr(f->fname, &f->gbe_fd,
- O_NOFOLLOW | O_CLOEXEC | O_NOCTTY,
- ((cmd->flags & O_ACCMODE) == O_RDONLY) ? 0400 : 0600,
- &f->gbe_st);
-
- if (f->gbe_st.st_nlink > 1)
- exitf(
- "%s: warning: file has multiple (%lu) hard links\n",
- f->fname, (size_t)f->gbe_st.st_nlink);
-
- if (f->gbe_st.st_nlink == 0)
- exitf("%s: file unlinked while open", f->fname);
-
- if ((_flags = fcntl(f->gbe_fd, F_GETFL)) == -1)
- exitf("%s: fcntl(F_GETFL)", f->fname);
-
- /* O_APPEND allows POSIX write() to ignore
- * the current write offset and write at EOF,
- * which would break positional read/write
- */
-
- if (_flags & O_APPEND)
- exitf("%s: O_APPEND flag", f->fname);
-
- f->gbe_file_size = f->gbe_st.st_size;
-
- switch (f->gbe_file_size) {
- case SIZE_8KB:
- case SIZE_16KB:
- case SIZE_128KB:
- break;
- default:
- exitf("File size must be 8KB, 16KB or 128KB");
- }
-
-/* currently fails (EBADF), locks are advisory anyway: */
-/*
- if (lock_file(f->gbe_fd, cmd->flags) == -1)
- exitf("%s: can't lock", f->fname);
-*/
-
- reset_caller_errno(0);
-}
-
-void
-copy_gbe(void)
-{
- struct xstate *x = xstatus();
- struct xfile *f = &x->f;
-
- read_file();
-
- if (f->gbe_file_size == SIZE_8KB)
- return;
-
- memcpy(f->buf + (size_t)GBE_PART_SIZE,
- f->buf + (size_t)(f->gbe_file_size >> 1),
- (size_t)GBE_PART_SIZE);
-}
-
-void
-read_file(void)
-{
- struct xstate *x = xstatus();
- struct xfile *f = &x->f;
-
- struct stat _st;
- ssize_t _r;
-
- /* read main file
- */
- _r = rw_exact(f->gbe_fd, f->buf, f->gbe_file_size,
- 0, IO_PREAD);
-
- if (_r < 0)
- exitf("%s: read failed", f->fname);
-
- /* copy to tmpfile
- */
- _r = rw_exact(f->tmp_fd, f->buf, f->gbe_file_size,
- 0, IO_PWRITE);
-
- if (_r < 0)
- exitf("%s: %s: copy failed",
- f->fname, f->tname);
-
- /* file size comparison
- */
- if (fstat(f->tmp_fd, &_st) == -1)
- exitf("%s: stat", f->tname);
-
- f->gbe_tmp_size = _st.st_size;
-
- if (f->gbe_tmp_size != f->gbe_file_size)
- exitf("%s: %s: not the same size",
- f->fname, f->tname);
-
- /* needs sync, for verification
- */
- if (fsync_on_eintr(f->tmp_fd) == -1)
- exitf("%s: fsync (tmpfile copy)", f->tname);
-
- _r = rw_exact(f->tmp_fd, f->bufcmp, f->gbe_file_size,
- 0, IO_PREAD);
-
- if (_r < 0)
- exitf("%s: read failed (cmp)", f->tname);
-
- if (vcmp(f->buf, f->bufcmp, f->gbe_file_size) != 0)
- exitf("%s: %s: read contents differ (pre-test)",
- f->fname, f->tname);
-}
-
-void
-write_gbe_file(void)
-{
- struct xstate *x = xstatus();
- struct commands *cmd = &x->cmd[x->i];
- struct xfile *f = &x->f;
-
- size_t p;
- unsigned char update_checksum;
-
- if ((cmd->flags & O_ACCMODE) == O_RDONLY)
- return;
-
- if (same_file(f->tmp_fd, &f->tmp_st, 0) < 0)
- exitf("%s: file inode/device changed", f->tname);
-
- if (same_file(f->gbe_fd, &f->gbe_st, 1) < 0)
- exitf("%s: file has changed", f->fname);
-
- update_checksum = cmd->chksum_write;
-
- for (p = 0; p < 2; p++) {
- if (!f->part_modified[p])
- continue;
-
- if (update_checksum)
- set_checksum(p);
-
- rw_gbe_file_part(p, IO_PWRITE, "pwrite");
- }
-}
-
-void
-rw_gbe_file_part(size_t p, int rw_type,
- const char *rw_type_str)
-{
- struct xstate *x = xstatus();
- struct commands *cmd = &x->cmd[x->i];
- struct xfile *f = &x->f;
-
- ssize_t rval;
-
- off_t file_offset;
-
- size_t gbe_rw_size;
- unsigned char *mem_offset;
-
- gbe_rw_size = cmd->rw_size;
-
- if (rw_type < IO_PREAD || rw_type > IO_PWRITE)
- exitf("%s: %s: part %lu: invalid rw_type, %d",
- f->fname, rw_type_str, (size_t)p, rw_type);
-
- mem_offset = gbe_mem_offset(p, rw_type_str);
- file_offset = (off_t)gbe_file_offset(p, rw_type_str);
-
- rval = rw_gbe_file_exact(f->tmp_fd, mem_offset,
- gbe_rw_size, file_offset, rw_type);
-
- if (rval == -1)
- exitf("%s: %s: part %lu",
- f->fname, rw_type_str, (size_t)p);
-
- if ((size_t)rval != gbe_rw_size)
- exitf("%s: partial %s: part %lu",
- f->fname, rw_type_str, (size_t)p);
-}
-
-void
-write_to_gbe_bin(void)
-{
- struct xstate *x = xstatus();
- struct commands *cmd = &x->cmd[x->i];
- struct xfile *f = &x->f;
-
- int saved_errno;
- int mv;
-
- if ((cmd->flags & O_ACCMODE) != O_RDWR)
- return;
-
- write_gbe_file();
-
- /* We may otherwise read from
- * cache, so we must sync.
- */
-
- if (fsync_on_eintr(f->tmp_fd) == -1)
- exitf("%s: fsync (pre-verification)",
- f->tname);
-
- check_written_part(0);
- check_written_part(1);
-
- report_io_err_rw();
-
- if (f->io_err_gbe)
- exitf("%s: bad write", f->fname);
-
- saved_errno = errno;
-
- xclose(&f->tmp_fd);
- xclose(&f->gbe_fd);
-
- errno = saved_errno;
-
- /* tmpfile written, now we
- * rename it back to the main file
- * (we do atomic writes)
- */
-
- f->tmp_fd = -1;
- f->gbe_fd = -1;
-
- if (!f->io_err_gbe_bin) {
-
- mv = gbe_mv();
-
- if (mv < 0) {
-
- f->io_err_gbe_bin = 1;
-
- fprintf(stderr, "%s: %s\n",
- f->fname, strerror(errno));
- } else {
-
- /* removed by rename
- */
- free_and_set_null(&f->tname);
- }
- }
-
- if (!f->io_err_gbe_bin)
- return;
-
- fprintf(stderr, "FAIL (rename): %s: skipping fsync\n",
- f->fname);
- if (errno)
- fprintf(stderr,
- "errno %d: %s\n", errno, strerror(errno));
-}
-
-void
-check_written_part(size_t p)
-{
- struct xstate *x = xstatus();
- struct commands *cmd = &x->cmd[x->i];
- struct xfile *f = &x->f;
-
- ssize_t rval;
-
- size_t gbe_rw_size;
-
- off_t file_offset;
- unsigned char *mem_offset;
-
- unsigned char *buf_restore;
-
- if (!f->part_modified[p])
- return;
-
- gbe_rw_size = cmd->rw_size;
-
- mem_offset = gbe_mem_offset(p, "pwrite");
- file_offset = (off_t)gbe_file_offset(p, "pwrite");
-
- memset(f->pad, 0xff, sizeof(f->pad));
-
- if (same_file(f->tmp_fd, &f->tmp_st, 0) < 0)
- exitf("%s: file inode/device changed", f->tname);
-
- if (same_file(f->gbe_fd, &f->gbe_st, 1) < 0)
- exitf("%s: file changed during write", f->fname);
-
- rval = rw_gbe_file_exact(f->tmp_fd, f->pad,
- gbe_rw_size, file_offset, IO_PREAD);
-
- if (rval == -1)
- f->rw_check_err_read[p] = f->io_err_gbe = 1;
- else if ((size_t)rval != gbe_rw_size)
- f->rw_check_partial_read[p] = f->io_err_gbe = 1;
- else if (vcmp(mem_offset, f->pad, gbe_rw_size) != 0)
- f->rw_check_bad_part[p] = f->io_err_gbe = 1;
-
- if (f->rw_check_err_read[p] ||
- f->rw_check_partial_read[p])
- return;
-
- /* We only load one part on-file, into memory but
- * always at offset zero, for post-write checks.
- * That's why we hardcode good_checksum(0)
- */
-
- buf_restore = f->buf;
-
- /* good_checksum works on f->buf
- * so let's change f->buf for now
- */
-
- f->buf = f->pad;
-
- if (good_checksum(0))
- f->post_rw_checksum[p] = 1;
-
- f->buf = buf_restore;
-}
-
-void
-report_io_err_rw(void)
-{
- struct xstate *x = xstatus();
- struct xfile *f = &x->f;
-
- size_t p;
-
- if (!f->io_err_gbe)
- return;
-
- for (p = 0; p < 2; p++) {
- if (!f->part_modified[p])
- continue;
-
- if (f->rw_check_err_read[p])
- fprintf(stderr,
- "%s: pread: p%lu (post-verification)\n",
- f->fname, (size_t)p);
- if (f->rw_check_partial_read[p])
- fprintf(stderr,
- "%s: partial pread: p%lu (post-verification)\n",
- f->fname, (size_t)p);
- if (f->rw_check_bad_part[p])
- fprintf(stderr,
- "%s: pwrite: corrupt write on p%lu\n",
- f->fname, (size_t)p);
-
- if (f->rw_check_err_read[p] ||
- f->rw_check_partial_read[p]) {
- fprintf(stderr,
- "%s: p%lu: skipped checksum verification "
- "(because read failed)\n",
- f->fname, (size_t)p);
-
- continue;
- }
-
- fprintf(stderr, "%s: ", f->fname);
-
- if (f->post_rw_checksum[p])
- fprintf(stderr, "GOOD");
- else
- fprintf(stderr, "BAD");
-
- fprintf(stderr, " checksum in p%lu on-disk.\n",
- (size_t)p);
-
- if (f->post_rw_checksum[p]) {
- fprintf(stderr,
- " This does NOT mean it's safe. it may be\n"
- " salvageable if you use the cat feature.\n");
- }
- }
-}
-
-int
-gbe_mv(void)
-{
- struct xstate *x = xstatus();
- struct xfile *f = &x->f;
-
- int rval;
-
- int saved_errno;
- int tmp_gbe_bin_exists;
-
- /* will be set 0 if it doesn't
- */
- tmp_gbe_bin_exists = 1;
-
- saved_errno = errno;
-
- rval = fs_rename_at(f->dirfd, f->tmpbase,
- f->dirfd, f->base);
-
- if (rval > -1)
- tmp_gbe_bin_exists = 0;
-
- if (f->gbe_fd > -1) {
- xclose(&f->gbe_fd);
-
- if (fsync_dir(f->fname) < 0) {
- f->io_err_gbe_bin = 1;
- rval = -1;
- }
- }
-
- xclose(&f->tmp_fd);
-
- /* before this function is called,
- * tmp_fd may have been moved
- */
- if (tmp_gbe_bin_exists) {
- if (unlink(f->tname) < 0)
- rval = -1;
- else
- tmp_gbe_bin_exists = 0;
- }
-
- if (rval >= 0)
- goto out;
-
- return with_fallback_errno(EIO);
-out:
- reset_caller_errno(rval);
- return rval;
-}
-
-/* This one is similar to gbe_file_offset,
- * but used to check Gbe bounds in memory,
- * and it is *also* used during file I/O.
- */
-unsigned char *
-gbe_mem_offset(size_t p, const char *f_op)
-{
- struct xstate *x = xstatus();
- struct xfile *f = &x->f;
-
- off_t gbe_off;
-
- gbe_off = gbe_x_offset(p, f_op, "mem",
- GBE_PART_SIZE, GBE_WORK_SIZE);
-
- return (unsigned char *)
- (f->buf + (size_t)gbe_off);
-}
-
-/* I/O operations filtered here. These operations must
- * only write from the 0th position or the half position
- * within the GbE file, and write 4KB of data.
- */
-off_t
-gbe_file_offset(size_t p, const char *f_op)
-{
- struct xstate *x = xstatus();
- struct xfile *f = &x->f;
-
- off_t gbe_file_half_size;
-
- gbe_file_half_size = f->gbe_file_size >> 1;
-
- return gbe_x_offset(p, f_op, "file",
- gbe_file_half_size, f->gbe_file_size);
-}
-
-off_t
-gbe_x_offset(size_t p, const char *f_op, const char *d_type,
- off_t nsize, off_t ncmp)
-{
- struct xstate *x = xstatus();
- struct xfile *f = &x->f;
-
- off_t off;
-
- check_bin(p, "part number");
-
- off = ((off_t)p) * (off_t)nsize;
-
- if (off > ncmp - GBE_PART_SIZE)
- exitf("%s: GbE %s %s out of bounds",
- f->fname, d_type, f_op);
-
- if (off != 0 && off != ncmp >> 1)
- exitf("%s: GbE %s %s at bad offset",
- f->fname, d_type, f_op);
-
- return off;
-}
-
-ssize_t
-rw_gbe_file_exact(int fd, unsigned char *mem, size_t nrw,
- off_t off, int rw_type)
-{
- struct xstate *x = xstatus();
- struct xfile *f = &x->f;
-
- ssize_t r;
-
- if (io_args(fd, mem, nrw, off, rw_type) == -1)
- return -1;
-
- if (mem != (void *)f->pad) {
- if (mem < f->buf)
- goto err_rw_gbe_file_exact;
-
- if ((size_t)(mem - f->buf) >= GBE_WORK_SIZE)
- goto err_rw_gbe_file_exact;
- }
-
- if (off < 0 || off >= f->gbe_file_size)
- goto err_rw_gbe_file_exact;
-
- if (nrw > (size_t)(f->gbe_file_size - off))
- goto err_rw_gbe_file_exact;
-
- if (nrw > (size_t)GBE_PART_SIZE)
- goto err_rw_gbe_file_exact;
-
- r = rw_exact(fd, mem, nrw, off, rw_type);
-
- return rw_over_nrw(r, nrw);
-
-err_rw_gbe_file_exact:
- return with_fallback_errno(EIO);
-}
diff --git a/util/libreboot-utils/lib/mkhtemp.c b/util/libreboot-utils/lib/mkhtemp.c
deleted file mode 100644
index d394ae73..00000000
--- a/util/libreboot-utils/lib/mkhtemp.c
+++ /dev/null
@@ -1,914 +0,0 @@
-/* SPDX-License-Identifier: MIT
- * Copyright (c) 2026 Leah Rowe <leah@libreboot.org>
- *
- * Hardened mktemp (be nice to the demon).
- */
-
-/* for openat2 / fast path: */
-#ifdef __linux__
-#if !defined(USE_OPENAT) || \
- ((USE_OPENAT) < 1) /* if 1: use openat, not openat2 */
-#ifndef _GNU_SOURCE
-#define _GNU_SOURCE 1
-#endif
-#include <sys/syscall.h>
-#include <linux/openat2.h>
-#ifndef O_TMPFILE
-#define O_TMPFILE 020000000
-#endif
-#ifndef AT_EMPTY_PATH
-#define AT_EMPTY_PATH 0x1000
-#endif
-#endif
-#endif
-
-#include <sys/types.h>
-#include <sys/stat.h>
-
-#include <errno.h>
-#include <fcntl.h>
-#include <stdio.h>
-#include <stdlib.h>
-#include <string.h>
-#include <unistd.h>
-
-#include "../include/common.h"
-
-/* note: tmpdir is an override of TMPDIR or /tmp or /var/tmp */
-int
-new_tmpfile(int *fd, char **path, char *tmpdir,
- const char *template)
-{
- return new_tmp_common(fd, path, MKHTEMP_FILE,
- tmpdir, template);
-}
-
-/* note: tmpdir is an override of TMPDIR or /tmp or /var/tmp */
-int
-new_tmpdir(int *fd, char **path, char *tmpdir,
- const char *template)
-{
- return new_tmp_common(fd, path, MKHTEMP_DIR,
- tmpdir, template);
-}
-
-int
-new_tmp_common(int *fd, char **path, int type,
- char *tmpdir, const char *template)
-{
- struct stat st;
-
- const char *templatestr;
-
- size_t dirlen;
- char *dest = NULL; /* final path (will be written into "path") */
- int saved_errno = errno;
- int dirfd = -1;
- const char *fname = NULL;
-
- struct stat st_dir_first;
-
- char *fail_dir = NULL;
-
- errno = 0;
-
- if (if_err(path == NULL || fd == NULL, EFAULT) ||
- if_err(*fd >= 0, EEXIST)) /* don't touch someone else's file */
- goto err;
-
- /* regarding **path:
- * the pointer (to the pointer)
- * must nott be null, but we don't
- * care about the pointer it points
- * to. you should expect it to be
- * replaced upon successful return
- *
- * (on error, it will not be touched)
- */
-
- *fd = -1;
-
- if (tmpdir == NULL) { /* no user override */
-#if defined(PERMIT_NON_STICKY_ALWAYS) && \
- ((PERMIT_NON_STICKY_ALWAYS) > 0)
- tmpdir = env_tmpdir(PERMIT_NON_STICKY_ALWAYS, &fail_dir, NULL);
-#else
- tmpdir = env_tmpdir(0, &fail_dir, NULL);
-#endif
- } else {
-
-#if defined(PERMIT_NON_STICKY_ALWAYS) && \
- ((PERMIT_NON_STICKY_ALWAYS) > 0)
- tmpdir = env_tmpdir(PERMIT_NON_STICKY_ALWAYS, &fail_dir,
- tmpdir);
-#else
- tmpdir = env_tmpdir(0, &fail_dir, tmpdir);
-#endif
- }
- if (if_err(tmpdir ==NULL || *tmpdir == '\0' || *tmpdir != '/', EINVAL))
- goto err;
-
- if (template != NULL)
- templatestr = template;
- else
- templatestr = "tmp.XXXXXXXXXX";
-
- /* may as well calculate in advance */
- dirlen = slen(tmpdir, PATH_MAX, &dirlen);
- /* full path: */
- dest = scatn(3, (const char *[]) { tmpdir, "/", templatestr },
- PATH_MAX, &dest);
-
- fname = dest + dirlen + 1;
-
- dirfd = fs_open(tmpdir,
- O_RDONLY | O_DIRECTORY);
- if (dirfd < 0)
- goto err;
-
- if (fstat(dirfd, &st_dir_first) < 0)
- goto err;
-
- *fd = mkhtemp(fd, &st, dest, dirfd,
- fname, &st_dir_first, type);
- if (*fd < 0)
- goto err;
-
- xclose(&dirfd);
-
- errno = saved_errno;
- *path = dest;
-
- reset_caller_errno(0);
- return 0;
-
-err:
- free_and_set_null(&dest);
-
- xclose(&dirfd);
- xclose(fd);
-
- /* where a TMPDIR isn't found, and we err,
- * we pass this back through for the
- * error message
- */
- if (fail_dir != NULL)
- *path = fail_dir;
-
- errno = saved_errno;
- return with_fallback_errno(EIO);
-}
-
-
-/* hardened TMPDIR parsing
- */
-
-char *
-env_tmpdir(int bypass_all_sticky_checks, char **tmpdir,
- char *override_tmpdir)
-{
- char *t = NULL;
- int allow_noworld_unsticky;
- int saved_errno = errno;
-
- static const char tmp[] = "/tmp";
- static const char vartmp[] = "/var/tmp";
-
- char *rval = NULL;
-
- errno = 0;
-
- /* tmpdir is a user override, if set */
- if (override_tmpdir == NULL)
- t = getenv("TMPDIR");
- else
- t = override_tmpdir;
-
- if (t != NULL && *t != '\0') {
-
- if (tmpdir_policy(t,
- &allow_noworld_unsticky) < 0)
- goto err;
-
- if (!world_writeable_and_sticky(t,
- allow_noworld_unsticky,
- bypass_all_sticky_checks))
- goto err;
-
- rval = NULL;
- if (t != NULL) {
- if (sdup(t, PATH_MAX, &rval) == NULL)
- goto err;
- }
- goto out;
- }
-
- allow_noworld_unsticky = 0;
-
- if (world_writeable_and_sticky(tmp, allow_noworld_unsticky,
- bypass_all_sticky_checks))
- rval = (char *)tmp;
- else if (world_writeable_and_sticky(vartmp,
- allow_noworld_unsticky, bypass_all_sticky_checks))
- rval = (char *)vartmp;
- else
- goto err;
-
-out:
- reset_caller_errno(0);
- if (tmpdir != NULL)
- *tmpdir = rval;
- return rval;
-err:
- if (tmpdir != NULL && t != NULL)
- *tmpdir = t;
- (void) with_fallback_errno(EPERM);
- return NULL;
-}
-
-int
-tmpdir_policy(const char *path,
- int *allow_noworld_unsticky)
-{
- int saved_errno = errno;
- int r;
- errno = 0;
-
- if (if_err(path == NULL ||
- allow_noworld_unsticky == NULL, EFAULT))
- goto err_tmpdir_policy;
-
- *allow_noworld_unsticky = 1;
-
- r = same_dir(path, "/tmp");
- if (r < 0)
- goto err_tmpdir_policy;
- if (r > 0)
- *allow_noworld_unsticky = 0;
-
- r = same_dir(path, "/var/tmp");
- if (r < 0)
- goto err_tmpdir_policy;
- if (r > 0)
- *allow_noworld_unsticky = 0;
-
- reset_caller_errno(0);
- return 0;
-
-err_tmpdir_policy:
- return with_fallback_errno(EPERM);
-}
-
-int
-same_dir(const char *a, const char *b)
-{
- int fd_a = -1;
- int fd_b = -1;
-
- struct stat st_a;
- struct stat st_b;
-
- int saved_errno = errno;
- int rval = 0; /* LOGICAL error, 0, if 0 is returned */
- errno = 0;
-
- /* optimisation: if both dirs
- are the same, we don't need
- to check anything. sehr schnell!
- */
- /* bonus: scmp checks null for us */
- if (!scmp(a, b, PATH_MAX, &rval))
- goto success_same_dir;
- else
- rval = 0; /* reset */
-
- if ((fd_a = fs_open(a, O_RDONLY | O_DIRECTORY | O_NOFOLLOW)) < 0 ||
- (fd_b = fs_open(b, O_RDONLY | O_DIRECTORY | O_NOFOLLOW)) < 0 ||
- fstat(fd_a, &st_a) < 0 ||
- fstat(fd_b, &st_b) < 0)
- goto err_same_dir;
-
- if (st_a.st_dev == st_b.st_dev &&
- st_a.st_ino == st_b.st_ino) {
-success_same_dir:
- rval = 1; /* SUCCESS */
- }
-
- xclose(&fd_a);
- xclose(&fd_b);
-
- /* we reset caller errno regardless
- * of success, so long as it's not
- * a syscall error
- */
- reset_caller_errno(0);
- return rval;
-
-err_same_dir:
- /* FAILURE (probably syscall) - returns -1
- */
- xclose(&fd_a);
- xclose(&fd_b);
-
- return with_fallback_errno(EIO); /* -1 */
-}
-
-/* bypass_all_sticky_checks: if set,
- disable stickiness checks (libc behaviour)
- (if not set: leah behaviour)
-
- allow_noworld_unsticky:
- allow non-sticky files if not world-writeable
- (still block non-sticky in standard TMPDIR)
-*/
-int
-world_writeable_and_sticky(
- const char *s,
- int allow_noworld_unsticky,
- int bypass_all_sticky_checks)
-{
- struct stat st;
- int dirfd = -1;
-
- int saved_errno = errno;
- errno = 0;
-
- if (if_err(s == NULL || *s == '\0', EINVAL) ||
- (dirfd = fs_open(s, O_RDONLY | O_DIRECTORY)) < 0 ||
- fstat(dirfd, &st) < 0 ||
- if_err(!S_ISDIR(st.st_mode), ENOTDIR))
- goto sticky_hell;
-
- /* *normal-**ish mode (libc):
- */
- if (bypass_all_sticky_checks)
- goto sticky_heaven; /* normal == no security */
-
- /* extremely not-libc mode:
- * only require stickiness on world-writeable dirs:
- */
- if (st.st_mode & S_IWOTH) { /* world writeable */
-
- if (if_err(!(st.st_mode & S_ISVTX), EPERM))
- goto sticky_hell; /* not sticky */
-
- goto sticky_heaven; /* sticky! */
- } else if (allow_noworld_unsticky) {
- goto sticky_heaven; /* sticky visa */
- } else {
- goto sticky_hell; /* visa denied */
- }
-
-sticky_heaven:
- if (faccessat(dirfd, ".", X_OK, AT_EACCESS) < 0)
- goto sticky_hell; /* down you go! */
-
- xclose(&dirfd);
- reset_caller_errno(0);
- return 1;
-
-sticky_hell:
- xclose(&dirfd);
- (void) with_fallback_errno(EPERM);
- return 0;
-}
-
-/* mk(h)temp - hardened mktemp.
- * like mkstemp, but (MUCH) harder.
- *
- * designed to resist TOCTOU attacks
- * e.g. directory race / symlink attack
- *
- * extremely strict and even implements
- * some limited userspace-level sandboxing,
- * similar in spirit to openbsd unveil,
- * though unveil is from kernel space.
- *
- * supports both files and directories.
- * file: type = MKHTEMP_FILE (0)
- * dir: type = MKHTEMP_DIR (1)
- *
- * DESIGN NOTES:
- *
- * caller is expected to handle
- * cleanup e.g. free(), on *st,
- * *template, *fname (all of the
- * pointers). ditto fd cleanup.
- *
- * some limited cleanup is
- * performed here, e.g. directory/file
- * cleanup on error in mkhtemp_try_create
- *
- * we only check if these are not NULL,
- * and the caller is expected to take
- * care; without too many conditions,
- * these functions are more flexible,
- * but some precauttions are taken:
- *
- * when used via the function new_tmpfile
- * or new_tmpdir, thtis is extremely strict,
- * much stricter than previous mktemp
- * variants. for example, it is much
- * stricter about stickiness on world
- * writeable directories, and it enforces
- * file ownership under hardened mode
- * (only lets you touch your own files/dirs)
- */
-/*
- TODO:
- some variables e.g. template vs suffix,
- assumes they match.
- we should test this explicitly,
- but the way this is called is
- currently safe - this would however
- be nice for future library use
- by outside projects.
- this whole code needs to be reorganised
-*/
-int
-mkhtemp(int *fd,
- struct stat *st,
- char *template,
- int dirfd,
- const char *fname,
- struct stat *st_dir_first,
- int type)
-{
- size_t template_len = 0;
- size_t xc = 0;
- size_t fname_len = 0;
-
- char *fname_copy = NULL;
- char *p;
-
- size_t retries;
-
- int saved_errno = errno;
-
- int r;
- char *end;
-
- errno = 0;
-
- if (if_err(fd == NULL || template == NULL || fname == NULL ||
- st_dir_first == NULL, EFAULT) ||
- if_err(*fd >= 0, EEXIST) ||
- if_err(dirfd < 0, EBADF))
- goto err;
-
- /* count X */
- for (end = template + slen(template, PATH_MAX, &template_len);
- end > template && *--end == 'X'; xc++);
-
- fname_len = slen(fname, PATH_MAX, &fname_len);
- if (if_err(strrchr(fname, '/') != NULL, EINVAL))
- goto err;
-
- if (if_err(xc < 3 || xc > template_len, EINVAL) ||
- if_err(fname_len > template_len, EOVERFLOW))
- goto err;
-
- if (if_err(vcmp(fname, template + template_len - fname_len,
- fname_len) != 0, EINVAL))
- goto err;
-
- /* fname_copy = templatestr region only; p points to trailing XXXXXX */
- memcpy(smalloc(&fname_copy, fname_len + 1),
- template + template_len - fname_len,
- fname_len + 1);
- p = fname_copy + fname_len - xc;
-
- for (retries = 0; retries < MKHTEMP_RETRY_MAX; retries++) {
-
- r = mkhtemp_try_create(dirfd,
- st_dir_first, fname_copy,
- p, xc, fd, st, type);
-
- if (r == 0)
- continue;
- if (r < 0)
- goto err;
-
- /* success: copy final name back */
- memcpy(template + template_len - fname_len,
- fname_copy, fname_len);
-
- errno = saved_errno;
- goto success;
- }
-
- errno = EEXIST;
-err:
- xclose(fd);
- free_and_set_null(&fname_copy);
-
- return with_fallback_errno(EIO);
-
-success:
- free_and_set_null(&fname_copy);
-
- reset_caller_errno(0);
- return *fd;
-}
-
-int
-mkhtemp_try_create(int dirfd,
- struct stat *st_dir_first,
- char *fname_copy,
- char *p,
- size_t xc,
- int *fd,
- struct stat *st,
- int type)
-{
- struct stat st_open;
- int saved_errno = errno;
- int rval = -1;
- char *rstr = NULL;
-
- int file_created = 0;
- int dir_created = 0;
-
- errno = 0;
-
- if (if_err(fd == NULL || st == NULL || p ==NULL || fname_copy ==NULL ||
- st_dir_first == NULL, EFAULT) ||
- if_err(*fd >= 0, EEXIST))
- goto err;
-
- /* TODO: potential infinite loop under entropy failure.
- * if attacker has control of rand - TODO: maybe add timeout
- */
- memcpy(p, rstr = rchars(xc), xc);
- free_and_set_null(&rstr);
-
- if (if_err_sys(fd_verify_dir_identity(dirfd, st_dir_first) < 0))
- goto err;
-
- if (type == MKHTEMP_FILE) {
-#if defined(__linux__) && \
- (!defined(USE_OPENAT) || ((USE_OPENAT) < 1))
- /* try O_TMPFILE fast path */
- if (mkhtemp_tmpfile_linux(dirfd,
- st_dir_first, fname_copy,
- p, xc, fd, st) >= 0) {
-
- errno = saved_errno;
- rval = 1;
- goto out;
- }
-#endif
-
- *fd = openat_on_eintr(dirfd, fname_copy,
- O_RDWR | O_CREAT | O_EXCL |
- O_NOFOLLOW | O_CLOEXEC | O_NOCTTY, 0600);
-
- /* O_CREAT and O_EXCL guarantees creation upon success
- */
- if (*fd >= 0)
- file_created = 1;
-
- } else { /* dir: MKHTEMP_DIR */
-
- if (mkdirat_on_eintr(dirfd, fname_copy, 0700) < 0)
- goto err;
-
- /* ^ NOTE: opening the directory here
- will never set errno=EEXIST,
- since we're not creating it */
-
- dir_created = 1;
-
- /* do it again (mitigate directory race) */
- if (fd_verify_dir_identity(dirfd, st_dir_first) < 0)
- goto err;
-
- if ((*fd = openat_on_eintr(dirfd, fname_copy,
- O_RDONLY | O_DIRECTORY | O_CLOEXEC, 0)) < 0)
- goto err;
-
- if (if_err_sys(fstat(*fd, &st_open) < 0) ||
- if_err(!S_ISDIR(st_open.st_mode), ENOTDIR))
- goto err;
-
- /* NOTE: pointless to check nlink here (only just opened) */
- if (fd_verify_dir_identity(dirfd, st_dir_first) < 0)
- goto err;
-
- }
-
- /* NOTE: openat_on_eintr and mkdirat_on_eintr
- * already handled EINTR/EAGAIN looping
- */
-
- if (*fd < 0) {
- if (errno == EEXIST) {
-
- rval = 0;
- goto out;
- }
- goto err;
- }
-
- if (fstat(*fd, &st_open) < 0)
- goto err;
-
- if (type == MKHTEMP_FILE) {
-
- if (fd_verify_dir_identity(dirfd, st_dir_first) < 0)
- goto err;
-
- if (secure_file(fd, st, &st_open,
- O_APPEND, 1, 1, 0600) < 0) /* WARNING: only once */
- goto err;
-
- } else { /* dir: MKHTEMP_DIR */
-
- if (fd_verify_identity(*fd, &st_open, st_dir_first) < 0)
- goto err;
-
- if (if_err(!S_ISDIR(st_open.st_mode), ENOTDIR) ||
- if_err_sys(is_owner(&st_open) < 0) ||
- if_err(st_open.st_mode & (S_IWGRP | S_IWOTH), EPERM))
- goto err;
- }
-
- rval = 1;
-
-out:
- reset_caller_errno(0);
- return rval;
-err:
- xclose(fd);
-
- if (file_created)
- (void) unlinkat(dirfd, fname_copy, 0);
- if (dir_created)
- (void) unlinkat(dirfd, fname_copy, AT_REMOVEDIR);
-
- return with_fallback_errno(EPERM);
-}
-
-/* linux has its own special hardening
- available specifically for tmpfiles,
- which eliminates many race conditions.
-
- we still use openat() on bsd, which is
- still ok with our other mitigations
- */
-#if defined(__linux__) && \
- (!defined(USE_OPENAT) || ((USE_OPENAT) < 1))
-int
-mkhtemp_tmpfile_linux(int dirfd,
- struct stat *st_dir_first,
- char *fname_copy,
- char *p,
- size_t xc,
- int *fd,
- struct stat *st)
-{
- int saved_errno = errno;
- int tmpfd = -1;
- size_t retries;
- int linked = 0;
- char *rstr = NULL;
- errno = 0;
-
- if (if_err(fd == NULL || st == NULL ||
- fname_copy == NULL || p == NULL ||
- st_dir_first == NULL, EFAULT))
- goto err;
-
- /* create unnamed tmpfile */
- tmpfd = openat_on_eintr(dirfd, ".",
- O_TMPFILE | O_RDWR | O_CLOEXEC, 0600);
-
- if (tmpfd < 0)
- goto err;
-
- if (fd_verify_dir_identity(dirfd, st_dir_first) < 0)
- goto err;
-
- for (retries = 0; retries < MKHTEMP_RETRY_MAX; retries++) {
-
- memcpy(p, rstr = rchars(xc), xc);
- free_and_set_null(&rstr);
-
- if (fd_verify_dir_identity(dirfd,
- st_dir_first) < 0)
- goto err;
-
- if (linkat(tmpfd, "", dirfd,
- fname_copy, AT_EMPTY_PATH) == -1) {
-
- if (errno == EEXIST)
- continue; /* retry on collision */
- else
- goto err;
- }
-
- linked = 1; /* file created */
-
- /* TODO: potential fd leak here.
- * probably should only set *fd on successful
- * return from this function (see below)
- */
- if (fd_verify_dir_identity(dirfd, st_dir_first) < 0 ||
- fstat(*fd = tmpfd, st) < 0 ||
- secure_file(fd, st, st, O_APPEND, 1, 1, 0600) < 0)
- goto err;
-
- goto out;
- }
-
- if (!errno)
- errno = EEXIST;
-err:
- if (linked)
- (void) unlinkat(dirfd, fname_copy, 0);
-
- xclose(&tmpfd);
- return with_fallback_errno(EIO);
-out:
- reset_caller_errno(0);
- return 0;
-}
-#endif
-
-/* WARNING: **ONCE** per file.
- *
- * some of these checks will trip up
- * if you do them twice; all of them
- * only need to be done once anyway.
- */
-int secure_file(int *fd,
- struct stat *st,
- struct stat *expected,
- int bad_flags,
- int check_seek,
- int do_lock,
- mode_t mode)
-{
- int flags = -1;
- struct stat st_now;
- int saved_errno = errno;
- errno = 0;
-
- if (if_err(fd == NULL || st == NULL, EFAULT) ||
- if_err(*fd < 0, EBADF))
- goto err_demons;
-
- if ((flags = fcntl(*fd, F_GETFL)) == -1)
- goto err_demons;
-
- if (if_err(bad_flags > 0 && (flags & bad_flags), EPERM))
- goto err_demons;
-
- if (expected != NULL) {
- if (fd_verify_regular(*fd, expected, st) < 0)
- goto err_demons;
- } else if (if_err_sys(fstat(*fd, &st_now) == -1) ||
- if_err(!S_ISREG(st_now.st_mode), EBADF)) {
- goto err_demons; /***********/
- } else /* ( >:3 ) */
- *st = st_now; /* /| |\ */ /* don't let him out */
- /* / \ */
- if (check_seek) { /***********/
- if (lseek(*fd, 0, SEEK_CUR) == (off_t)-1)
- goto err_demons;
- } /* don't release the demon! */
-
- if (if_err(st->st_nlink != 1, ELOOP) ||
- if_err(st->st_uid != geteuid() && geteuid() != 0, EPERM) ||
- if_err_sys(is_owner(st) < 0) ||
- if_err(st->st_mode & (S_IWGRP | S_IWOTH), EPERM))
- goto err_demons;
-
- if (do_lock) {
- if (lock_file(*fd, flags) == -1)
- goto err_demons;
-
- /* TODO: why would this be NULL? audit
- * to find out. we should always verify! */
- if (expected != NULL)
- if (fd_verify_identity(*fd, expected, &st_now) < 0)
- goto err_demons;
- }
-
- if (fchmod(*fd, mode) == -1)
- goto err_demons;
-
- reset_caller_errno(0);
- return 0;
-
-err_demons:
- return with_fallback_errno(EIO);
-}
-
-int
-fd_verify_regular(int fd,
- const struct stat *expected,
- struct stat *out)
-{
- int saved_errno = errno;
- errno = 0;
-
- if (if_err_sys(fd_verify_identity(fd, expected, out) < 0) ||
- if_err(!S_ISREG(out->st_mode), EBADF)) {
- return with_fallback_errno(EIO);
- } else {
- reset_caller_errno(0);
- return 0; /* regular file */
- }
-}
-
-int
-fd_verify_identity(int fd,
- const struct stat *expected,
- struct stat *out)
-{
- struct stat st_now;
- int saved_errno = errno;
- errno = 0;
-
-if( if_err(fd < 0 || expected == NULL, EFAULT) ||
- if_err_sys(fstat(fd, &st_now)) ||
- if_err(st_now.st_dev != expected->st_dev ||
- st_now.st_ino != expected->st_ino, ESTALE))
- return with_fallback_errno(EIO);
-
- if (out != NULL)
- *out = st_now;
-
- reset_caller_errno(0);
- return 0;
-}
-
-int
-fd_verify_dir_identity(int fd,
- const struct stat *expected)
-{
- struct stat st_now;
- int saved_errno = errno;
- errno = 0;
-
- if (if_err(fd < 0 || expected == NULL, EFAULT) ||
- if_err_sys(fstat(fd, &st_now) < 0) ||
- if_err(st_now.st_dev != expected->st_dev, ESTALE) ||
- if_err(st_now.st_ino != expected->st_ino, ESTALE) ||
- if_err(!S_ISDIR(st_now.st_mode), ENOTDIR))
- goto err;
-
- reset_caller_errno(0);
- return 0;
-err:
- return with_fallback_errno(EIO);
-}
-
-int
-is_owner(struct stat *st)
-{
- int saved_errno = errno;
- errno = 0;
-
- if (if_err(st == NULL, EFAULT) ||
- if_err(st->st_uid != geteuid() /* someone else's file */
-#if defined(ALLOW_ROOT_OVERRIDE) && ((ALLOW_ROOT_OVERRIDE) > 0)
- && geteuid() != 0 /* override for root */
-#endif
- , EPERM)) return with_fallback_errno(EIO);
-
- reset_caller_errno(0);
- return 0;
-}
-
-int
-lock_file(int fd, int flags)
-{
- struct flock fl;
- int saved_errno = errno;
- int fcntl_rval = -1;
- errno = 0;
-
- if (if_err(fd < 0, EBADF) ||
- if_err(flags < 0, EINVAL))
- goto err_lock_file;
-
- memset(&fl, 0, sizeof(fl));
-
- if ((flags & O_ACCMODE) == O_RDONLY)
- fl.l_type = F_RDLCK;
- else
- fl.l_type = F_WRLCK;
-
- fl.l_whence = SEEK_SET;
-
- if ((fcntl_rval = fcntl(fd, F_SETLK, &fl)) == -1)
- goto err_lock_file;
-
- reset_caller_errno(0);
- return 0;
-
-err_lock_file:
- return with_fallback_errno(EIO);
-}
diff --git a/util/libreboot-utils/lib/num.c b/util/libreboot-utils/lib/num.c
deleted file mode 100644
index ce5e420d..00000000
--- a/util/libreboot-utils/lib/num.c
+++ /dev/null
@@ -1,116 +0,0 @@
-/* SPDX-License-Identifier: MIT
- * Copyright (c) 2026 Leah Rowe <leah@libreboot.org>
- *
- * Non-randomisation-related numerical functions.
- * For rand functions, see: rand.c
- */
-
-#ifdef __OpenBSD__
-#include <sys/param.h>
-#endif
-#include <sys/types.h>
-
-#include <errno.h>
-#if !((defined(__OpenBSD__) && (OpenBSD) >= 201) || \
- defined(__FreeBSD__) || \
- defined(__NetBSD__) || defined(__APPLE__))
-#include <fcntl.h> /* if not arc4random: /dev/urandom */
-#endif
-#include <ctype.h>
-#include <limits.h>
-#include <stddef.h>
-#include <stdio.h>
-#include <string.h>
-#include <unistd.h>
-
-#include "../include/common.h"
-
-unsigned short
-hextonum(char ch_s)
-{
- unsigned char ch;
-
- ch = (unsigned char)ch_s;
-
- if ((unsigned int)(ch - '0') <= 9)
- return ch - '0';
-
- ch |= 0x20;
-
- if ((unsigned int)(ch - 'a') <= 5)
- return ch - 'a' + 10;
-
- if (ch == '?' || ch == 'x') /* random */
- return (short)rsize(16); /* <-- with rejection sampling! */
-
- return 16;
-}
-
-/* basically hexdump -C */
-/*
- TODO: optimise this
- write a full util for hexdump
- how to optimise:
- don't call print tens of thousands of times!
- convert the numbers manually, and cache everything
- in a BUFSIZ sized buffer, with everything properly
- aligned. i worked out that i could fit 79 rows
- in a 8KB buffer (1264 bytes of numbers represented
- as strings in hex)
- this depends on the OS, and would be calculated at
- runtime.
- then:
- don't use printf. just write it to stdout (basically
- a simple cat implementation)
-*/
-void
-spew_hex(const void *data, size_t len)
-{
- const unsigned char *buf = (const unsigned char *)data;
- unsigned char c;
- size_t i;
- size_t j;
-
- if (buf == NULL ||
- len == 0)
- return;
-
- for (i = 0; i < len; i += 16) {
-
- if (len <= 4294967296) /* below 4GB */
- printf("%08zx ", i);
- else
- printf("%16zu ", i);
-
- for (j = 0; j < 16; j++) {
-
- if (i + j < len)
- printf("%02x ", buf[i + j]);
- else
- printf(" ");
-
- if (j == 7)
- printf(" ");
- }
-
- printf(" |");
-
- for (j = 0; j < 16 && i + j < len; j++) {
-
- c = buf[i + j];
- printf("%c", isprint(c) ? c : '.');
- }
-
- printf("|\n");
- }
-
- printf("%08zx\n", len);
-}
-
-void
-check_bin(size_t a, const char *a_name)
-{
- if (a > 1)
- exitf("%s must be 0 or 1, but is %lu",
- a_name, (size_t)a);
-}
diff --git a/util/libreboot-utils/lib/rand.c b/util/libreboot-utils/lib/rand.c
deleted file mode 100644
index bf090b43..00000000
--- a/util/libreboot-utils/lib/rand.c
+++ /dev/null
@@ -1,200 +0,0 @@
-/* SPDX-License-Identifier: MIT
- * Copyright (c) 2026 Leah Rowe <leah@libreboot.org>
- *
- * Random number generation
- */
-
-#if defined(USE_ARC4) && \
- ((USE_ARC4) > 0)
-#define _DEFAULT_SOURCE 1 /* for arc4random on *linux* */
- /* (not needed on bsd - on bsd,
- it is used automatically unless
- overridden with USE_URANDOM */
-#elif defined(USE_URANDOM) && \
- ((USE_URANDOM) > 0)
-#include <fcntl.h> /* if not arc4random: /dev/urandom */
-#elif defined(__linux__) && \
- !(defined(USE_ARC4) && ((USE_ARC4) > 0))
-#ifndef _GNU_SOURCE
-#define _GNU_SOURCE 1
-#endif
-#include <sys/syscall.h>
-#include <sys/random.h>
-#endif
-
-#ifdef __OpenBSD__
-#include <sys/param.h>
-#endif
-#include <sys/types.h>
-
-#include <errno.h>
-#include <fcntl.h>
-#include <limits.h>
-#include <stddef.h>
-#include <string.h>
-#include <unistd.h>
-#include <stdlib.h>
-#include <string.h>
-#include <stdint.h>
-#include <stdio.h>
-
-#include "../include/common.h"
-
-/* Regarding Linux getrandom/urandom:
- *
- * For maximum security guarantee, we *only*
- * use getrandom via syscall, or /dev/urandom;
- * use of urandom is ill advised. This is why
- * we use the syscall, in case the libc version
- * of getrandom() might defer to /dev/urandom
- *
- * We *abort* on error, for both /dev/urandom
- * and getrandom(), because the BSD arc4random
- * never returns with error; therefore, for the
- * most parity in terms of behaviour, we abort,
- * because otherwise the function would have two
- * return modes: always successful (BSD), or only
- * sometimes (Linux). The BSD arc4random could
- * theoretically abort; it is extremely unlikely
- * there, and just so on Linux, hence this design.
- *
- * This is important, because cryptographic code
- * for example must not rely on weak randomness.
- * We must therefore treat broken randomness as
- * though the world is broken, and burn accordingly.
- *
- * Similarly, any invalid input (NULL, zero bytes
- * requested) are treated as fatal errors; again,
- * cryptographic code must be reliable. If your
- * code erroneously requested zero bytes, you might
- * then end up with a non-randomised buffer, where
- * you likely intended otherwise.
- *
- * In other words: call rset() correctly, or your
- * program dies, and rset will behave correctly,
- * or your program dies.
- */
-
-/* random string generator, with
- * rejection sampling. NOTE: only
- * uses ASCII-safe characters, for
- * printing on a unix terminal
- *
- * you still shouldn't use this for
- * password generation; open diceware
- * passphrases are better for that
- *
- * NOTE: the generated strings must
- * ALSO be safe for file/directory names
- * on unix-like os e.g. linux/bsd
- */
-char *
-rchars(size_t n) /* emulates spkmodem-decode */
-{
- static char ch[] =
- "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789";
-
- char *s = NULL;
- size_t i;
-
- smalloc(&s, n + 1);
- for (i = 0; i < n; i++)
- s[i] = ch[rsize(sizeof(ch) - 1)];
-
- *(s + n) = '\0';
- return s;
-}
-
-size_t
-rsize(size_t n)
-{
- size_t rval = SIZE_MAX;
- if (!n)
- exitf("rsize: division by zero");
-
- /* rejection sampling (clamp rand to eliminate modulo bias) */
- for (; rval >= SIZE_MAX - (SIZE_MAX % n); rset(&rval, sizeof(rval)));
-
- return rval % n;
-}
-
-void *
-rmalloc(size_t n)
-{
- void *buf = NULL;
- rset(vmalloc(&buf, n), n);
- return buf; /* basically malloc() but with rand */
-}
-
-void
-rset(void *buf, size_t n)
-{
- int saved_errno = errno;
- errno = 0;
-
- if (if_err(buf == NULL, EFAULT))
- goto err;
-
- if (n == 0)
- exitf("rset: zero-byte request");
-
-/* on linux, getrandom is recommended,
- but you can pass -DUSE_ARC4=1 to use arc4random.
- useful for portability testing from linux.
- */
-#if (defined(USE_ARC4) && ((USE_ARC4) > 0)) || \
- ((defined(__OpenBSD__) || defined(__FreeBSD__) || \
- defined(__NetBSD__) || defined(__APPLE__) || \
- defined(__DragonFly__)) && !(defined(USE_URANDOM) && \
- ((USE_URANDOM) > 0)))
-
- arc4random_buf(buf, n);
-#else
- size_t off = 0;
-
-retry_rand: {
-
-#if defined(USE_URANDOM) && \
- ((USE_URANDOM) > 0)
- ssize_t rval;
- int fd = -1;
-
- open_file_on_eintr("/dev/urandom", &fd, O_RDONLY, 0400, NULL);
-
- while (rw_retry(saved_errno,
- rval = rw(fd, (unsigned char *)buf + off, n - off, 0, IO_READ)));
-#elif defined(__linux__)
- long rval;
- while (sys_retry(saved_errno,
- rval = syscall(SYS_getrandom,
- (unsigned char *)buf + off, n - off, 0)));
-#else
-#error Unsupported operating system (possibly unsecure randomisation)
-#endif
-
- if (rval < 0 || /* syscall fehler */
- rval == 0) { /* prevent infinite loop on fatal err */
-#if defined(USE_URANDOM) && \
- ((USE_URANDOM) > 0)
- xclose(&fd);
-#endif
- goto err;
- }
-
- if ((off += (size_t)rval) < n)
- goto retry_rand;
-
-#if defined(USE_URANDOM) && \
- ((USE_URANDOM) > 0)
- xclose(&fd);
-#endif
-}
-
-#endif
- reset_caller_errno(0);
- return;
-err:
- (void) with_fallback_errno(ECANCELED);
- exitf("Randomisierungsfehler");
- exit(EXIT_FAILURE);
-}
diff --git a/util/libreboot-utils/lib/state.c b/util/libreboot-utils/lib/state.c
deleted file mode 100644
index 78e15134..00000000
--- a/util/libreboot-utils/lib/state.c
+++ /dev/null
@@ -1,164 +0,0 @@
-/* SPDX-License-Identifier: MIT
- * Copyright (c) 2022-2026 Leah Rowe <leah@libreboot.org>
- *
- * State machine (singleton) for nvmutil data.
- */
-
-#ifndef _XOPEN_SOURCE
-#define _XOPEN_SOURCE 700
-#endif
-
-#include <sys/types.h>
-#include <sys/stat.h>
-
-#include <errno.h>
-#include <fcntl.h>
-#include <limits.h>
-#include <stdarg.h>
-#include <stddef.h>
-#include <stdio.h>
-#include <stdlib.h>
-#include <string.h>
-#include <unistd.h>
-
-#include "../include/common.h"
-
-struct xstate *
-xstart(int argc, char *argv[])
-{
- static int first_run = 1;
- static char *dir = NULL;
- static char *base = NULL;
- char *realdir = NULL;
- char *tmpdir = NULL;
- char *tmpbase_local = NULL;
-
- static struct xstate us = {
- {
- /* be careful when modifying xstate. you
- * must set everything precisely */
- {
- CMD_DUMP, "dump", cmd_helper_dump, ARGC_3,
- ARG_NOPART,
- SKIP_CHECKSUM_READ, SKIP_CHECKSUM_WRITE,
- NVM_SIZE, O_RDONLY
- }, {
- CMD_SETMAC, "setmac", cmd_helper_setmac, ARGC_3,
- ARG_NOPART,
- CHECKSUM_READ, CHECKSUM_WRITE,
- NVM_SIZE, O_RDWR
- }, {
- CMD_SWAP, "swap", cmd_helper_swap, ARGC_3,
- ARG_NOPART,
- CHECKSUM_READ, SKIP_CHECKSUM_WRITE,
- GBE_PART_SIZE, O_RDWR
- }, {
- CMD_COPY, "copy", cmd_helper_copy, ARGC_4,
- ARG_PART,
- CHECKSUM_READ, SKIP_CHECKSUM_WRITE,
- GBE_PART_SIZE, O_RDWR
- }, {
- CMD_CAT, "cat", cmd_helper_cat, ARGC_3,
- ARG_NOPART,
- CHECKSUM_READ, SKIP_CHECKSUM_WRITE,
- GBE_PART_SIZE, O_RDONLY
- }, {
- CMD_CAT16, "cat16", cmd_helper_cat16, ARGC_3,
- ARG_NOPART,
- CHECKSUM_READ, SKIP_CHECKSUM_WRITE,
- GBE_PART_SIZE, O_RDONLY
- }, {
- CMD_CAT128, "cat128", cmd_helper_cat128, ARGC_3,
- ARG_NOPART,
- CHECKSUM_READ, SKIP_CHECKSUM_WRITE,
- GBE_PART_SIZE, O_RDONLY
- }
- },
-
- /* ->mac */
- {NULL, "xx:xx:xx:xx:xx:xx", {0, 0, 0}}, /* .str, .rmac, .mac_buf */
-
- /* .f */
- {0},
-
- /* ->i (index to cmd[]) */
- 0,
-
- /* .no_cmd (set 0 when a command is found) */
- 1,
-
- /* .cat (cat helpers set this) */
- -1
-
- };
-
- if (!first_run)
- return &us;
-
- if (argc < 3)
- exitf("xstart: Too few arguments");
- if (argv == NULL)
- exitf("xstart: NULL argv");
-
- first_run = 0;
-
- us.f.buf = us.f.real_buf;
-
- us.f.fname = argv[1];
-
- us.f.tmp_fd = -1;
- us.f.tname = NULL;
-
- if ((realdir = realpath(us.f.fname, NULL)) == NULL)
- exitf("xstart: can't get realpath of %s",
- us.f.fname);
-
- if (fs_dirname_basename(realdir, &dir, &base, 0) < 0)
- exitf("xstart: don't know CWD of %s",
- us.f.fname);
-
- sdup(base, PATH_MAX, &us.f.base);
-
- us.f.dirfd = fs_open(dir,
- O_RDONLY | O_DIRECTORY);
- if (us.f.dirfd < 0)
- exitf("%s: open dir", dir);
-
- if (new_tmpfile(&us.f.tmp_fd, &us.f.tname, dir, ".gbe.XXXXXXXXXX") < 0)
- exitf("%s", us.f.tname);
-
- if (fs_dirname_basename(us.f.tname,
- &tmpdir, &tmpbase_local, 0) < 0)
- exitf("tmp basename");
-
- sdup(tmpbase_local, PATH_MAX, &us.f.tmpbase);
-
- free_and_set_null(&tmpdir);
-
- if (us.f.tname == NULL)
- exitf("x->f.tname null");
- if (*us.f.tname == '\0')
- exitf("x->f.tname empty");
-
- if (fstat(us.f.tmp_fd, &us.f.tmp_st) < 0)
- exitf("%s: stat", us.f.tname);
-
- memset(us.f.real_buf, 0, sizeof(us.f.real_buf));
- memset(us.f.bufcmp, 0, sizeof(us.f.bufcmp));
-
- /* for good measure */
- memset(us.f.pad, 0, sizeof(us.f.pad));
-
- return &us;
-}
-
-struct xstate *
-xstatus(void)
-{
- struct xstate *x = xstart(0, NULL);
-
- if (x == NULL)
- exitf("NULL pointer to xstate");
-
- return x;
-}
diff --git a/util/libreboot-utils/lib/string.c b/util/libreboot-utils/lib/string.c
deleted file mode 100644
index 7388cf35..00000000
--- a/util/libreboot-utils/lib/string.c
+++ /dev/null
@@ -1,643 +0,0 @@
-/* SPDX-License-Identifier: MIT
- * Copyright (c) 2026 Leah Rowe <leah@libreboot.org>
- *
- * String functions
- */
-
-#include <sys/types.h>
-#include <sys/stat.h>
-
-#include <errno.h>
-#include <stdarg.h>
-#include <stddef.h>
-#include <stdio.h>
-#include <string.h>
-#include <stdlib.h>
-#include <unistd.h>
-#include <limits.h>
-#include <stdint.h>
-
-#include "../include/common.h"
-
-/* for null detection inside
- * word-optimised string functions
- */
-#define ff ((size_t)-1 / 0xFF)
-#define high ((ff) * 0x80)
-/* NOTE:
- * do not assume that a match means
- * both words have null at the same
- * location. see how this is handled
- * e.g. in scmp.
- */
-#define zeroes(x) (((x) - (ff)) & ~(x) & (high))
-
-size_t
-page_remain(const void *p)
-{
- /* calling sysconf repeatedly
- * is folly. cache it (static)
- */
- static size_t pagesz = 0;
- if (!pagesz)
- pagesz = (size_t)pagesize();
-
- return pagesz - ((uintptr_t)p & (pagesz - 1));
-}
-
-long
-pagesize(void)
-{
- static long rval = 0;
- static int set = 0;
- int saved_errno = 0;
-
- if (!set) {
- if ((rval = sysconf(_SC_PAGESIZE)) < 0)
- exitf("could not determine page size");
- set = 1;
- }
-
- reset_caller_errno(0);
- return rval;
-}
-
-void
-free_and_set_null(char **buf)
-{
- if (buf == NULL)
- exitf(
- "null ptr (to ptr for freeing) in free_and_set_null");
-
- if (*buf == NULL)
- return;
-
- free(*buf);
- *buf = NULL;
-}
-
-/* safe(ish) malloc.
-
- use this and free_and_set_null()
- in your program, to reduce the
- chance of use after frees!
-
- if you use these functions in the
- intended way, you will greatly reduce
- the number of bugs in your code
- */
-char *
-smalloc(char **buf, size_t size)
-{
- return (char *)vmalloc((void **)buf, size);
-}
-void *
-vmalloc(void **buf, size_t size)
-{
- int saved_errno = errno;
- void *rval = NULL;
- errno = 0;
-
- if (size >= SIZE_MAX - 1)
- exitf("integer overflow in vmalloc");
- if (buf == NULL)
- exitf("Bad pointer passed to vmalloc");
-
- /* lots of programs will
- * re-initialise a buffer
- * that was allocated, without
- * freeing or NULLing it. this
- * is here intentionally, to
- * force the programmer to behave
- */
- if (*buf != NULL)
- exitf("Non-null pointer given to vmalloc");
-
- if (!size)
- exitf(
- "Tried to vmalloc(0) and that is very bad. Fix it now");
-
- if ((rval = malloc(size)) == NULL)
- exitf("malloc fail in vmalloc");
-
- reset_caller_errno(0);
- return *buf = rval;
-}
-
-/* strict word-based strcmp */
-int
-scmp(const char *a,
- const char *b,
- size_t maxlen,
- int *rval)
-{
- size_t i = 0;
- size_t j;
- size_t wa;
- size_t wb;
- int saved_errno = errno;
- errno = 0;
-
- if (if_err(a == NULL || b == NULL || rval == NULL, EFAULT))
- goto err;
-
- for ( ; ((uintptr_t)(a + i) % sizeof(size_t)) != 0; i++) {
-
- if (if_err(i >= maxlen, EOVERFLOW))
- goto err;
- else if (!ccmp(a, b, i, rval))
- goto out;
- }
-
- for ( ; i + sizeof(size_t) <= maxlen;
- i += sizeof(size_t)) {
-
- /* prevent crossing page boundary on word check */
- if (page_remain(a + i) < sizeof(size_t) ||
- page_remain(b + i) < sizeof(size_t))
- break;
-
- memcpy(&wa, a + i, sizeof(size_t));
- memcpy(&wb, b + i, sizeof(size_t));
-
- if (wa != wb)
- for (j = 0; j < sizeof(size_t); j++)
- if (!ccmp(a, b, i + j, rval))
- goto out;
-
- if (!zeroes(wa))
- continue;
-
- *rval = 0;
- goto out;
- }
-
- for ( ; i < maxlen; i++)
- if (!ccmp(a, b, i, rval))
- goto out;
-
-err:
- (void) with_fallback_errno(EFAULT);
- if (rval != NULL)
- *rval = -1;
-
- exitf("scmp");
- return -1;
-out:
- reset_caller_errno(0);
- return *rval;
-}
-
-int ccmp(const char *a, const char *b,
- size_t i, int *rval)
-{
- unsigned char ac;
- unsigned char bc;
-
- if (if_err(a == NULL || b == NULL || rval == NULL, EFAULT))
- exitf("ccmp");
-
- ac = (unsigned char)a[i];
- bc = (unsigned char)b[i];
-
- if (ac != bc) {
- *rval = ac - bc;
- return 0;
- } else if (ac == '\0') {
- *rval = 0;
- return 0;
- }
-
- return 1;
-}
-
-/* strict word-based strlen */
-size_t
-slen(const char *s,
- size_t maxlen,
- size_t *rval)
-{
- int saved_errno = errno;
- size_t i = 0;
- size_t w;
- size_t j;
- errno = 0;
-
- if (if_err(s == NULL || rval == NULL, EFAULT))
- goto err;
-
- for ( ; ((uintptr_t)(s + i) % sizeof(size_t)) != 0; i++) {
-
- if (if_err(i >= maxlen, EOVERFLOW))
- goto err;
- if (s[i] == '\0') {
- *rval = i;
- goto out;
- }
- }
-
- for ( ; i + sizeof(size_t) <= maxlen;
- i += sizeof(size_t)) {
-
- memcpy(&w, s + i, sizeof(size_t));
- if (!zeroes(w))
- continue;
-
- for (j = 0; j < sizeof(size_t); j++) {
- if (s[i + j] == '\0') {
- *rval = i + j;
- goto out;
- }
- }
- }
-
- for ( ; i < maxlen; i++) {
- if (s[i] == '\0') {
- *rval = i;
- goto out;
- }
- }
-
-err:
- (void) with_fallback_errno(EFAULT);
- if (rval != NULL)
- *rval = 0;
-
- exitf("slen"); /* abort */
- return 0; /* gcc15 is happy */
-out:
- reset_caller_errno(0);
- return *rval;
-}
-
-int
-dup_pair(char **dir, const char *d,
- char **base, const char *b)
-{
- char *dtmp = NULL;
- char *btmp = NULL;
-
- if (d && sdup(d, PATH_MAX, &dtmp) == NULL)
- return -1;
-
- if (b && sdup(b, PATH_MAX, &btmp) == NULL) {
- free(dtmp);
- return -1;
- }
-
- *dir = dtmp;
- *base = btmp;
-
- return 0;
-}
-
-/* strict word-based strdup */
-char *
-sdup(const char *s,
- size_t max, char **dest)
-{
- size_t j;
- size_t w;
- size_t i = 0;
- char *out = NULL;
- int saved_errno = errno;
- errno = 0;
-
- if (if_err(dest == NULL || *dest != NULL || s == NULL, EFAULT))
- goto err;
-
- out = smalloc(dest, max);
-
- for ( ; ((uintptr_t)(s + i) % sizeof(size_t)) != 0; i++) {
-
- if (if_err(i >= max, EOVERFLOW))
- goto err;
-
- out[i] = s[i];
- if (s[i] == '\0') {
- *dest = out;
- goto out;
- }
- }
-
- for ( ; i + sizeof(size_t) <= max; i += sizeof(size_t)) {
-
- if (page_remain(s + i) < sizeof(size_t))
- break;
-
- memcpy(&w, s + i, sizeof(size_t));
- if (!zeroes(w)) {
- memcpy(out + i, &w, sizeof(size_t));
- continue;
- }
-
- for (j = 0; j < sizeof(size_t); j++) {
-
- out[i + j] = s[i + j];
- if (s[i + j] == '\0') {
- *dest = out;
- goto out;
- }
- }
- }
-
- for ( ; i < max; i++) {
-
- out[i] = s[i];
- if (s[i] == '\0') {
- *dest = out;
- goto out;
- }
- }
-
-err:
- free_and_set_null(&out);
- if (dest != NULL)
- *dest = NULL;
-
- (void) with_fallback_errno(EFAULT);
- exitf("sdup");
-
- return NULL;
-out:
- reset_caller_errno(0);
- return *dest;
-}
-
-/* concatenate N number of strings */
-char *
-scatn(ssize_t sc, const char **sv,
- size_t max, char **rval)
-{
- int saved_errno = errno;
- char *final = NULL;
- char *rcur = NULL;
- char *rtmp = NULL;
- ssize_t i;
- errno = 0;
-
- if (if_err(sc < 2, EINVAL) ||
- if_err(sv == NULL, EFAULT) ||
- if_err(rval == NULL || *rval != NULL, EFAULT))
- goto err;
-
- for (i = 0; i < sc; i++) {
-
- if (if_err(sv[i] == NULL, EFAULT))
- goto err;
- else if (i == 0) {
- (void) sdup(sv[0], max, &final);
- continue;
- }
-
- rtmp = NULL;
- scat(final, sv[i], max, &rtmp);
-
- free_and_set_null(&final);
- final = rtmp;
- rtmp = NULL;
- }
-
- reset_caller_errno(0);
- *rval = final;
- return *rval;
-err:
- free_and_set_null(&rcur);
- free_and_set_null(&rtmp);
- free_and_set_null(&final);
-
- (void) with_fallback_errno(EFAULT);
-
- exitf("scatn");
- return NULL;
-}
-
-/* strict strcat */
-char *
-scat(const char *s1, const char *s2,
- size_t n, char **dest)
-{
- size_t size1;
- size_t size2;
- char *rval = NULL;
- int saved_errno = errno;
- errno = 0;
-
- if (if_err(dest == NULL || *dest != NULL, EFAULT))
- goto err;
-
- slen(s1, n, &size1);
- slen(s2, n, &size2);
-
- if (if_err(size1
- > SIZE_MAX - size2 - 1, EOVERFLOW))
- goto err;
-
- smalloc(&rval, size1 + size2 + 1);
-
- memcpy(rval, s1, size1);
- memcpy(rval + size1, s2, size2);
- *(rval + size1 + size2) = '\0';
-
- reset_caller_errno(0);
- *dest = rval;
- return *dest;
-err:
- (void) with_fallback_errno(EINVAL);
- if (dest != NULL)
- *dest = NULL;
- exitf("scat");
-
- return NULL;
-}
-
-/* strict split/de-cat - off is where
- 2nd buffer will start from */
-void
-dcat(const char *s, size_t n,
- size_t off, char **dest1,
- char **dest2)
-{
- size_t size;
- char *rval1 = NULL;
- char *rval2 = NULL;
- int saved_errno = errno;
- errno = 0;
-
- if (if_err(dest1 == NULL || dest2 == NULL, EFAULT))
- goto err;
-
- if (if_err(slen(s, n, &size) >= SIZE_MAX - 1, EOVERFLOW) ||
- if_err(off >= size, EOVERFLOW))
- goto err;
-
- memcpy(smalloc(&rval1, off + 1),
- s, off);
- *(rval1 + off) = '\0';
-
- memcpy(smalloc(&rval2, size - off +1),
- s + off, size - off);
- *(rval2 + size - off) = '\0';
-
- *dest1 = rval1;
- *dest2 = rval2;
-
- reset_caller_errno(0);
- return;
-
-err:
- *dest1 = *dest2 = NULL;
-
- free_and_set_null(&rval1);
- free_and_set_null(&rval2);
-
- (void) with_fallback_errno(EINVAL);
- exitf("dcat");
-}
-
-/* because no libc reimagination is complete
- * without a reimplementation of memcmp. and
- * no safe one is complete without null checks.
- */
-int
-vcmp(const void *s1, const void *s2, size_t n)
-{
- int saved_errno = errno;
- size_t i = 0;
- size_t a;
- size_t b;
-
- const unsigned char *x;
- const unsigned char *y;
- errno = 0;
-
- if (if_err(s1 == NULL || s2 == NULL, EFAULT))
- exitf("vcmp: null input");
-
- x = s1;
- y = s2;
-
- for ( ; i + sizeof(size_t) <= n; i += sizeof(size_t)) {
-
- memcpy(&a, x + i, sizeof(size_t));
- memcpy(&b, y + i, sizeof(size_t));
-
- if (a != b)
- break;
- }
-
- for ( ; i < n; i++)
- if (x[i] != y[i])
- return (int)x[i] - (int)y[i];
-
- reset_caller_errno(0);
- return 0;
-}
-
-/* on functions that return with errno,
- * i sometimes have a default fallback,
- * which is set if errno wasn't changed,
- * under error condition.
- */
-int
-with_fallback_errno(int fallback)
-{
- if (!errno)
- errno = fallback;
- return -1;
-}
-
-/* the one for nvmutil state is in state.c */
-/* this one just exits */
-void
-exitf(const char *msg, ...)
-{
- va_list args;
- int saved_errno = errno;
-
- func_t err_cleanup = errhook(NULL);
- err_cleanup();
- reset_caller_errno(0);
- saved_errno = errno;
-
- if (!errno)
- saved_errno = errno = ECANCELED;
-
- fprintf(stderr, "%s: ", lbgetprogname());
-
- va_start(args, msg);
- vfprintf(stderr, msg, args);
- va_end(args);
-
- errno = saved_errno;
- fprintf(stderr, ": %s\n", strerror(errno));
-
- exit(EXIT_FAILURE);
-}
-
-/* the err function will
- * call this upon exit, and
- * cleanup will be performed
- * e.g. you might want to
- * close some files, depending
- * on your program.
- * see: exitf()
- */
-func_t errhook(func_t ptr)
-{
- static int set = 0;
- static func_t hook = NULL;
-
- if (!set) {
- set = 1;
-
- if (ptr == NULL)
- hook = no_op;
- else
- hook = ptr;
- }
-
- return hook;
-}
-
-void
-no_op(void)
-{
- return;
-}
-
-const char *
-lbgetprogname(void)
-{
- char *name = lbsetprogname(NULL);
- char *p = NULL;
- if (name)
- p = strrchr(name, '/');
- if (p)
- return p + 1;
- else if (name)
- return name;
- else
- return "libreboot-utils";
-}
-
-/* singleton. if string not null,
- sets the string. after set,
- will not set anymore. either
- way, returns the string
- */
-char *
-lbsetprogname(char *argv0)
-{
- static char *progname = NULL;
- static int set = 0;
-
- if (!set) {
- if (argv0 == NULL)
- return "libreboot-utils";
- (void) sdup(argv0, PATH_MAX, &progname);
- set = 1;
- }
-
- return progname;
-}
diff --git a/util/libreboot-utils/lib/usage.c b/util/libreboot-utils/lib/usage.c
deleted file mode 100644
index 4ade2f9e..00000000
--- a/util/libreboot-utils/lib/usage.c
+++ /dev/null
@@ -1,30 +0,0 @@
-/* SPDX-License-Identifier: MIT
- * Copyright (c) 2023 Riku Viitanen <riku.viitanen@protonmail.com>
- * Copyright (c) 2026 Leah Rowe <leah@libreboot.org>
- */
-
-#include <errno.h>
-#include <stdio.h>
-
-#include "../include/common.h"
-
-void
-usage(void)
-{
- const char *util = lbgetprogname();
-
- fprintf(stderr,
- "Modify Intel GbE NVM images e.g. set MAC\n"
- "USAGE:\n"
- "\t%s FILE dump\n"
- "\t%s FILE setmac [MAC]\n"
- "\t%s FILE swap\n"
- "\t%s FILE copy 0|1\n"
- "\t%s FILE cat\n"
- "\t%s FILE cat16\n"
- "\t%s FILE cat128\n",
- util, util, util, util,
- util, util, util);
-
- exitf("Too few arguments");
-}
diff --git a/util/libreboot-utils/lib/word.c b/util/libreboot-utils/lib/word.c
deleted file mode 100644
index 45ac3d48..00000000
--- a/util/libreboot-utils/lib/word.c
+++ /dev/null
@@ -1,68 +0,0 @@
-/* SPDX-License-Identifier: MIT
- * Copyright (c) 2022-2026 Leah Rowe <leah@libreboot.org>
- *
- * Manipulate Intel GbE NVM words, which are 16-bit little
- * endian in the files (MAC address words are big endian).
- */
-
-#include <sys/types.h>
-
-#include <errno.h>
-#include <stddef.h>
-
-#include "../include/common.h"
-
-unsigned short
-nvm_word(size_t pos16, size_t p)
-{
- struct xstate *x = xstatus();
- struct xfile *f = &x->f;
-
- size_t pos;
-
- check_nvm_bound(pos16, p);
- pos = (pos16 << 1) + (p * GBE_PART_SIZE);
-
- return (unsigned short)f->buf[pos] |
- ((unsigned short)f->buf[pos + 1] << 8);
-}
-
-void
-set_nvm_word(size_t pos16, size_t p, unsigned short val16)
-{
- struct xstate *x = xstatus();
- struct xfile *f = &x->f;
-
- size_t pos;
-
- check_nvm_bound(pos16, p);
- pos = (pos16 << 1) + (p * GBE_PART_SIZE);
-
- f->buf[pos] = (unsigned char)(val16 & 0xff);
- f->buf[pos + 1] = (unsigned char)(val16 >> 8);
-
- set_part_modified(p);
-}
-
-void
-set_part_modified(size_t p)
-{
- struct xstate *x = xstatus();
- struct xfile *f = &x->f;
-
- check_bin(p, "part number");
- f->part_modified[p] = 1;
-}
-
-void
-check_nvm_bound(size_t c, size_t p)
-{
- /* Block out of bound NVM access
- */
-
- check_bin(p, "part number");
-
- if (c >= NVM_WORDS)
- exitf("check_nvm_bound: out of bounds %lu",
- (size_t)c);
-}