Re: [PATCH v8 0/4] Various patches to improve Secure Boot support

Frediano Ziglio <[email protected]>
Newsgroups org.xenproject.lists.xen-devel
Message-ID <CAHt6W4f22gHSiWLz-qvWQT33jmM0_mnwKJCyKXqnG05rGBQs2g@mail.gmail.com>
On Wed, 19 Aug 2026 at 11:12, Jan Beulich <[email protected]> wrote:
>
> On 19.08.2026 12:03, Frediano Ziglio wrote:
> > On Sat, 8 Aug 2026 at 07:41, Frediano Ziglio <[email protected]> wrote:
> >>
> >> On Wed, 15 Jul 2026 at 07:22, Frediano Ziglio <[email protected]> wrote:
> >>>
> >>> These patches improve support for Secure boot.
> >>> UEFI CA memory mitigation requires memory pages to be not executable and
> >>> writable at the same time. So changing permissions and splitting some section
> >>> is required.
> >>> Remove multiboot pieces from EFI executable.
> >>>
> >>> Changes since v1:
> >>> - improved some comments;
> >>> - merged 2 pacthes removing multiboot support in x86 PE;
> >>> - removed a patch dealing with SBAT;
> >>> - other minor changes (see single patches).
> >>>
> >>> Changes since v2:
> >>> - improved some comments.
> >>>
> >>> Changes since v3:
> >>> - Added Acked-by;
> >>> - Improve commit message.
> >>>
> >>> Changes since v4:
> >>> - Messages updates;
> >>> - Clean some dependencies cause by code removal;
> >>> - Add small commit to remove a possibly unused string.
> >>>
> >>> Changes since v5:
> >>> - removed merged commit;
> >>> - remove more code/data from xen.efi output.
> >>>
> >>> Changes since v6:
> >>> - fix commit message.
> >>>
> >>> Changes since v7:
> >>> - added Acked-by, all commit are now acked.
> >>>
> >>> Frediano Ziglio (2):
> >>>   Align relevant sections to 4KB
> >>>   x86: Split .init section to satisfy UEFI CA memory mitigation
> >>>
> >>> Roger Pau Monné (2):
> >>>   x86/efi: discard multiboot and PVH support for PE binary
> >>>   x86/efi: avoid a relocation in efi_arch_post_exit_boot()
> >>>
> >>>  docs/hypervisor-guide/x86/how-xen-boots.rst |  6 -----
> >>>  xen/arch/x86/boot/head.S                    |  8 +++----
> >>>  xen/arch/x86/efi/efi-boot.h                 |  7 ++++--
> >>>  xen/arch/x86/xen.lds.S                      | 25 ++++++++++++---------
> >>>  xen/tools/combine_two_binaries.py           |  2 +-
> >>>  5 files changed, 25 insertions(+), 23 deletions(-)
> >>
> >> Ping
> >
> > Ping
>
> Andrew had indicated to me (apparently not to you?) that he'd like to
> massage the descriptions some while committing. Hence why I refrained
> from putting any of this in.
>
> Jan

I understand maybe we want better comments and explaining what's
missing/improvable could take more time than updating them directly,
but how many months does this require?
Especially after the changes had different acks.

Frediano
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.