efivars_create() refuses to create variables outside the barebox vendor GUID. That dates from when barebox was only an EFI payload: on somebody else's firmware, whose NVRAM holds the platform's own state, a shell that can create Boot#### or BootOrder under the global GUID is a liability, and the payload only ever needs barebox-env-<guid> anyway.
The EFI loader took the same efivarfs over unchanged, where the argument does not hold. The store is barebox' own in-memory buffer backed by a file it writes itself, and everything the loader starts - the UEFI Shell, GRUB, the OS - can already create variables under any GUID. Only the barebox shell was held back: barebox:/ echo -o /efivarfs/Timeout-8be4df61-93ca-11d2-aa0d-00e098032b8c 5 open: Operation not permitted Lift the restriction when running as the loader, so board scripts can set up global variables without going through /env/data/init.efivars. The payload keeps confining itself to its own GUID. Assisted-by: Claude:opus-5 Signed-off-by: Ahmad Fatoum <[email protected]> --- fs/efivarfs.c | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/fs/efivarfs.c b/fs/efivarfs.c index a4d8cc8d0268..1f53c06d66d3 100644 --- a/fs/efivarfs.c +++ b/fs/efivarfs.c @@ -66,12 +66,17 @@ static int efivars_create(struct device *dev, const char *pathname, if (pathname[0] == '/') pathname++; - /* deny creating files with other vendor GUID than our own */ ret = efivarfs_parse_filename(pathname, &vendor, &name); if (ret) return -ENOENT; - if (efi_guidcmp(vendor, EFI_BAREBOX_VENDOR_GUID)) + /* + * As a payload, barebox is a guest on somebody else's firmware and + * confines itself to its own vendor GUID when creating variables. + * As the loader, the variable store is barebox' own and anything it + * boots may already create variables under any GUID. + */ + if (!efi_is_loader() && efi_guidcmp(vendor, EFI_BAREBOX_VENDOR_GUID)) return -EPERM; inode = xzalloc(sizeof(*inode)); -- 2.47.3
