diff options
| -rw-r--r-- | test/py/tests/test_efi_secboot/conftest.py | 8 | ||||
| -rw-r--r-- | test/py/tests/test_efi_secboot/test_authvar.py | 47 |
2 files changed, 55 insertions, 0 deletions
diff --git a/test/py/tests/test_efi_secboot/conftest.py b/test/py/tests/test_efi_secboot/conftest.py index 76b8f9fa0a3..0755497d46d 100644 --- a/test/py/tests/test_efi_secboot/conftest.py +++ b/test/py/tests/test_efi_secboot/conftest.py @@ -96,6 +96,14 @@ def efi_boot_env(request, ubman): check_call('cd %s; %ssign-efi-sig-list -t "2020-04-05" -c KEK.crt -k KEK.key dbx db.esl dbx_db.auth' % (mnt_point, EFITOOLS_PATH), shell=True) + # dbt (with TEST_db certificate) + check_call('cd %s; %ssign-efi-sig-list -t "2020-04-05" -c KEK.crt -k KEK.key dbt db.esl dbt.auth' + % (mnt_point, EFITOOLS_PATH), + shell=True) + # dbr (with TEST_db certificate) + check_call('cd %s; %ssign-efi-sig-list -t "2020-04-05" -c KEK.crt -k KEK.key dbr db.esl dbr.auth' + % (mnt_point, EFITOOLS_PATH), + shell=True) # Copy image check_call('cp %s/lib/efi_loader/helloworld.efi %s' % diff --git a/test/py/tests/test_efi_secboot/test_authvar.py b/test/py/tests/test_efi_secboot/test_authvar.py index 7b45f8fb814..a41e9eb9204 100644 --- a/test/py/tests/test_efi_secboot/test_authvar.py +++ b/test/py/tests/test_efi_secboot/test_authvar.py @@ -279,3 +279,50 @@ class TestEfiAuthVar(object): output = ubman.run_command( 'printenv -e SetupMode') assert '00000000: 01' in output + + def test_efi_var_auth6(self, ubman, efi_boot_env): + """ + Test Case 6 - Default GUID of signature database variables + """ + ubman.restart_uboot() + disk_img = efi_boot_env + with ubman.log.section('Test Case 6a'): + # Test Case 6a, install signature database variables in setup + # mode without -guid + output = ubman.run_command_list([ + 'host bind 0 %s' % disk_img, + 'printenv -e SetupMode']) + assert '00000000: 01' in ''.join(output) + + for var in ('db', 'dbx', 'dbt', 'dbr'): + output = ubman.run_command_list([ + 'fatload host 0:1 4000000 %s.auth' % var, + 'setenv -e -nv -bs -rt -at -i 4000000:$filesize %s' % var, + 'printenv -e -n -guid d719b2cb-3d3a-4596-a3bc-dad00e67656f %s' % var]) + assert 'Failed to set EFI variable' not in ''.join(output) + assert '%s:' % var in ''.join(output) + + with ubman.log.section('Test Case 6b'): + # Test Case 6b, variables must not exist under the global + # variable GUID + for var in ('db', 'dbx', 'dbt', 'dbr'): + output = ubman.run_command( + 'printenv -e -n -guid 8be4df61-93ca-11d2-aa0d-00e098032b8c %s' % var) + assert '\"%s\" not defined' % var in output + + with ubman.log.section('Test Case 6c'): + # Test Case 6c, PK and KEK get the global variable GUID by + # default. Enrolling PK leaves setup mode, so this must come + # after the signature database enrollment above. + for var in ('PK', 'KEK'): + output = ubman.run_command_list([ + 'fatload host 0:1 4000000 %s.auth' % var, + 'setenv -e -nv -bs -rt -at -i 4000000:$filesize %s' % var, + 'printenv -e -n -guid 8be4df61-93ca-11d2-aa0d-00e098032b8c %s' % var]) + assert 'Failed to set EFI variable' not in ''.join(output) + assert '%s:' % var in ''.join(output) + + for var in ('PK', 'KEK'): + output = ubman.run_command( + 'printenv -e -n -guid d719b2cb-3d3a-4596-a3bc-dad00e67656f %s' % var) + assert '\"%s\" not defined' % var in output |
