1From 508270838998f151a82e9c13e7cb8a470a2dc23d Mon Sep 17 00:00:00 2001 2From: Javier Martinez Canillas <javierm@redhat.com> 3Date: Wed, 24 Feb 2021 15:03:26 +0100 4Subject: [PATCH] gdb: Restrict GDB access when locked down 5 6The gdbstub* commands allow to start and control a GDB stub running on 7local host that can be used to connect from a remote debugger. Restrict 8this functionality when the GRUB is locked down. 9 10Signed-off-by: Javier Martinez Canillas <javierm@redhat.com> 11Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com> 12Signed-off-by: Stefan Sørensen <stefan.sorensen@spectralink.com> 13--- 14 grub-core/gdb/gdb.c | 32 ++++++++++++++++++-------------- 15 1 file changed, 18 insertions(+), 14 deletions(-) 16 17diff --git a/grub-core/gdb/gdb.c b/grub-core/gdb/gdb.c 18index 847a1e1..1818cb6 100644 19--- a/grub-core/gdb/gdb.c 20+++ b/grub-core/gdb/gdb.c 21@@ -75,20 +75,24 @@ static grub_command_t cmd, cmd_stop, cmd_break; 22 GRUB_MOD_INIT (gdb) 23 { 24 grub_gdb_idtinit (); 25- cmd = grub_register_command ("gdbstub", grub_cmd_gdbstub, 26- N_("PORT"), 27- /* TRANSLATORS: GDB stub is a small part of 28- GDB functionality running on local host 29- which allows remote debugger to 30- connect to it. */ 31- N_("Start GDB stub on given port")); 32- cmd_break = grub_register_command ("gdbstub_break", grub_cmd_gdb_break, 33- /* TRANSLATORS: this refers to triggering 34- a breakpoint so that the user will land 35- into GDB. */ 36- 0, N_("Break into GDB")); 37- cmd_stop = grub_register_command ("gdbstub_stop", grub_cmd_gdbstop, 38- 0, N_("Stop GDB stub")); 39+ cmd = grub_register_command_lockdown ("gdbstub", grub_cmd_gdbstub, 40+ N_("PORT"), 41+ /* 42+ * TRANSLATORS: GDB stub is a small part of 43+ * GDB functionality running on local host 44+ * which allows remote debugger to 45+ * connect to it. 46+ */ 47+ N_("Start GDB stub on given port")); 48+ cmd_break = grub_register_command_lockdown ("gdbstub_break", grub_cmd_gdb_break, 49+ /* 50+ * TRANSLATORS: this refers to triggering 51+ * a breakpoint so that the user will land 52+ * into GDB. 53+ */ 54+ 0, N_("Break into GDB")); 55+ cmd_stop = grub_register_command_lockdown ("gdbstub_stop", grub_cmd_gdbstop, 56+ 0, N_("Stop GDB stub")); 57 } 58 59 GRUB_MOD_FINI (gdb) 60-- 612.14.2 62 63