Skip to content

hii: fail writes to questions without supported storage - #19

Open
dishendradeshmukh1986 wants to merge 1 commit into
linuxboot:mainfrom
dishendradeshmukh1986:fix/hii-missing-writable-storage
Open

dishendradeshmukh1986 wants to merge 1 commit into
linuxboot:mainfrom
dishendradeshmukh1986:fix/hii-missing-writable-storage

Conversation

@dishendradeshmukh1986

Copy link
Copy Markdown
Collaborator

Summary

  • Return an explicit error when a matched question has no supported
    writable VarStore.
  • Preserve normal writes for supported buffer and EFI VarStores.
  • Keep question-not-found handling separate from unsupported storage.
  • Add coverage for unresolved numeric and OneOf question storage.

Problem

Setting a matched question without supported storage returned success with
an empty response and changed nothing. Callers could mistake the unsupported
operation for a successful update.

Validation

cargo test --locked --lib --bins passed:

  • 50 library tests
  • 1 binary test

The combined write-safety series was also validated on an Arm64 UEFI
system using a real TPM Device EFI variable:

  1. Set and read back the new value.
  2. Reboot and confirm the value persisted.
  3. Restore the original value.
  4. Reboot and confirm the restored value persisted.
  5. Confirm the restored raw efivar matched the original byte-for-byte.

@xaionaro

xaionaro commented Oct 2, 2026

Copy link
Copy Markdown
Member

Could you resolve the merge conflict, please? :)

Validation found that setting a matched question without a supported
varstore returned success with an empty response and changed nothing.
This could make callers mistake an unsupported operation for success.

Return an explicit error naming the question when writable storage
cannot be resolved. Preserve the normal write path for supported
buffer and EFI varstores, and report success only after writing.

Add tests for unresolved storage and OneOf questions. Keep existing
question-not-found behaviour separate from this matched-question fix.

Signed-off-by: Dishendra Deshmukh <dishendra.deshmukh@arm.com>
Change-Id: I0861e2a8c7dca98c3b5edc965b494aaabc833286
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants