On 7/6/21 3:54 AM, Dov Murik wrote: > Newer kernels support efistub and therefore don't need all the legacy > stuff in X86QemuLoadImageLib, which are harder to secure. Specifically > the verification of kernel/initrd/cmdlien blobs will be added only to > the GenericQemuLoadImageLib implementation, so use that for SEV builds. > > Cc: Laszlo Ersek <ler...@redhat.com> > Cc: Ard Biesheuvel <ardb+tianoc...@kernel.org> > Cc: Jordan Justen <jordan.l.jus...@intel.com> > Cc: Ashish Kalra <ashish.ka...@amd.com> > Cc: Brijesh Singh <brijesh.si...@amd.com> > Cc: Erdem Aktas <erdemak...@google.com> > Cc: James Bottomley <j...@linux.ibm.com> > Cc: Jiewen Yao <jiewen....@intel.com> > Cc: Min Xu <min.m...@intel.com> > Cc: Tom Lendacky <thomas.lenda...@amd.com> > Ref: https://bugzilla.tianocore.org/show_bug.cgi?id=3457 > Signed-off-by: Dov Murik <dovmu...@linux.ibm.com>
Reviewed-by: Brijesh Singh <brijesh.si...@amd.com> thanks -=-=-=-=-=-=-=-=-=-=-=- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#77848): https://edk2.groups.io/g/devel/message/77848 Mute This Topic: https://groups.io/mt/84016358/21656 Group Owner: devel+ow...@edk2.groups.io Unsubscribe: https://edk2.groups.io/g/devel/unsub [arch...@mail-archive.com] -=-=-=-=-=-=-=-=-=-=-=-