Re: [PATCH v8 0/4] Various patches to improve Secure Boot support
Frediano Ziglio <[email protected]> Sat, 8 Aug 2026 07:41:11 +0100
| Newsgroups | gmane.comp.emulators.xen.devel |
|---|---|
| Message-ID | <CAHt6W4cG_-=8MBJ+7dWQrLuC2Lf-fLOHDUyGwWDGQn6=9bO1Lw@mail.gmail.com> |
On Wed, 15 Jul 2026 at 07:22, Frediano Ziglio <[email protected]> wrote: > > These patches improve support for Secure boot. > UEFI CA memory mitigation requires memory pages to be not executable and > writable at the same time. So changing permissions and splitting some section > is required. > Remove multiboot pieces from EFI executable. > > Changes since v1: > - improved some comments; > - merged 2 pacthes removing multiboot support in x86 PE; > - removed a patch dealing with SBAT; > - other minor changes (see single patches). > > Changes since v2: > - improved some comments. > > Changes since v3: > - Added Acked-by; > - Improve commit message. > > Changes since v4: > - Messages updates; > - Clean some dependencies cause by code removal; > - Add small commit to remove a possibly unused string. > > Changes since v5: > - removed merged commit; > - remove more code/data from xen.efi output. > > Changes since v6: > - fix commit message. > > Changes since v7: > - added Acked-by, all commit are now acked. > > Frediano Ziglio (2): > Align relevant sections to 4KB > x86: Split .init section to satisfy UEFI CA memory mitigation > > Roger Pau Monné (2): > x86/efi: discard multiboot and PVH support for PE binary > x86/efi: avoid a relocation in efi_arch_post_exit_boot() > > docs/hypervisor-guide/x86/how-xen-boots.rst | 6 ----- > xen/arch/x86/boot/head.S | 8 +++---- > xen/arch/x86/efi/efi-boot.h | 7 ++++-- > xen/arch/x86/xen.lds.S | 25 ++++++++++++--------- > xen/tools/combine_two_binaries.py | 2 +- > 5 files changed, 25 insertions(+), 23 deletions(-) > Ping Frediano