git: b5f0e7f36afc - main - loader.efi: Be cautious about using GOPs

From: Warner Losh <imp_at_FreeBSD.org>
Date: Thu, 24 Sep 2026 07:24:18 UTC
The branch main has been updated by imp:

URL: https://cgit.FreeBSD.org/src/commit/?id=b5f0e7f36afc20bf17e9e955454b445d686cda06

commit b5f0e7f36afc20bf17e9e955454b445d686cda06
Author:     Warner Losh <imp@FreeBSD.org>
AuthorDate: 2026-09-24 07:22:16 +0000
Commit:     Warner Losh <imp@FreeBSD.org>
CommitDate: 2026-09-24 07:22:25 +0000

    loader.efi: Be cautious about using GOPs
    
    When we're searching for the EFI_GRAPHICS_OUTPUT_PROTOCOL_GUID (GOPs) to
    use, skip any whose Mode or Mode->Info pointers are NULL. The spec
    requires these to be non-null, however, some firmwares seem to fail to
    populate the Info when, for example, a monitor is not present. Work
    around these bugs by skipping any GOPs with bad pointers.
    
    PR: 288900
    Sponsored by:           Netflix
    Differential Revision:  https://reviews.freebsd.org/D59830
---
 stand/efi/loader/framebuffer.c | 9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

diff --git a/stand/efi/loader/framebuffer.c b/stand/efi/loader/framebuffer.c
index 632377613f58..6a95a1b98db4 100644
--- a/stand/efi/loader/framebuffer.c
+++ b/stand/efi/loader/framebuffer.c
@@ -632,7 +632,14 @@ efi_find_framebuffer(teken_gfx_t *gfx_state)
 			if (status != EFI_SUCCESS)
 				continue;
 
-			if (tgop->Mode->Info->PixelFormat == PixelBltOnly ||
+			/*
+			 * Some platforms half initialize the graphics protocol
+			 * here when no monitor present, even though spec says
+			 * they are non-optional. Windows and Linux don't access
+			 * Mode->Info generally, so such bugs can slip through.
+			 */
+			if (tgop->Mode == NULL || tgop->Mode->Info == NULL ||
+			    tgop->Mode->Info->PixelFormat == PixelBltOnly ||
 			    tgop->Mode->Info->PixelFormat >= PixelFormatMax)
 				continue;