Re: [PATCH v8 0/4] Various patches to improve Secure Boot support

Frediano Ziglio <[email protected]> Sat, 8 Aug 2026 07:41:11 +0100
Newsgroups gmane.comp.emulators.xen.devel
Message-ID <CAHt6W4cG_-=8MBJ+7dWQrLuC2Lf-fLOHDUyGwWDGQn6=9bO1Lw@mail.gmail.com>
On Wed, 15 Jul 2026 at 07:22, Frediano Ziglio <[email protected]> wrote:
>
> These patches improve support for Secure boot.
> UEFI CA memory mitigation requires memory pages to be not executable and
> writable at the same time. So changing permissions and splitting some section
> is required.
> Remove multiboot pieces from EFI executable.
>
> Changes since v1:
> - improved some comments;
> - merged 2 pacthes removing multiboot support in x86 PE;
> - removed a patch dealing with SBAT;
> - other minor changes (see single patches).
>
> Changes since v2:
> - improved some comments.
>
> Changes since v3:
> - Added Acked-by;
> - Improve commit message.
>
> Changes since v4:
> - Messages updates;
> - Clean some dependencies cause by code removal;
> - Add small commit to remove a possibly unused string.
>
> Changes since v5:
> - removed merged commit;
> - remove more code/data from xen.efi output.
>
> Changes since v6:
> - fix commit message.
>
> Changes since v7:
> - added Acked-by, all commit are now acked.
>
> Frediano Ziglio (2):
>   Align relevant sections to 4KB
>   x86: Split .init section to satisfy UEFI CA memory mitigation
>
> Roger Pau Monné (2):
>   x86/efi: discard multiboot and PVH support for PE binary
>   x86/efi: avoid a relocation in efi_arch_post_exit_boot()
>
>  docs/hypervisor-guide/x86/how-xen-boots.rst |  6 -----
>  xen/arch/x86/boot/head.S                    |  8 +++----
>  xen/arch/x86/efi/efi-boot.h                 |  7 ++++--
>  xen/arch/x86/xen.lds.S                      | 25 ++++++++++++---------
>  xen/tools/combine_two_binaries.py           |  2 +-
>  5 files changed, 25 insertions(+), 23 deletions(-)
>

Ping

Frediano