Re: [PATCH 1/1] efi_leader: delete rng-seed if having EFI RNG protocol

2024-09-25 Thread Simon Glass
Hi Heinrich, On Sun, 22 Sept 2024 at 15:43, Heinrich Schuchardt wrote: > > On 20.09.24 17:58, Simon Glass wrote: > > Hi Ilias, > > > > On Fri, 20 Sept 2024 at 09:37, Ilias Apalodimas > > wrote: > >> > >> Hi Simon, > >> > >> On Fri, 20 Sept 2024 at 10:25, Simon Glass wrote: > >>> > >>> Hi Ilias,

Re: [PATCH 1/1] efi_leader: delete rng-seed if having EFI RNG protocol

2024-09-22 Thread Heinrich Schuchardt
On 20.09.24 17:58, Simon Glass wrote: Hi Ilias, On Fri, 20 Sept 2024 at 09:37, Ilias Apalodimas wrote: Hi Simon, On Fri, 20 Sept 2024 at 10:25, Simon Glass wrote: Hi Ilias, On Thu, 19 Sept 2024 at 17:51, Ilias Apalodimas wrote: On Thu, 19 Sept 2024 at 18:39, Simon Glass wrote: Hi,

Re: [PATCH 1/1] efi_leader: delete rng-seed if having EFI RNG protocol

2024-09-20 Thread Simon Glass
Hi Ilias, On Fri, 20 Sept 2024 at 09:37, Ilias Apalodimas wrote: > > Hi Simon, > > On Fri, 20 Sept 2024 at 10:25, Simon Glass wrote: > > > > Hi Ilias, > > > > On Thu, 19 Sept 2024 at 17:51, Ilias Apalodimas > > wrote: > > > > > > On Thu, 19 Sept 2024 at 18:39, Simon Glass wrote: > > > > > > >

Re: [PATCH 1/1] efi_leader: delete rng-seed if having EFI RNG protocol

2024-09-20 Thread Simon Glass
Hi Ilias, On Thu, 19 Sept 2024 at 17:51, Ilias Apalodimas wrote: > > On Thu, 19 Sept 2024 at 18:39, Simon Glass wrote: > > > > Hi, > > > > On Thu, 19 Sept 2024 at 17:37, Ilias Apalodimas > > wrote: > > > > > > On Thu, 19 Sept 2024 at 18:19, Simon Glass wrote: > > > > > > > > Hi, > > > > > > >

Re: [PATCH 1/1] efi_leader: delete rng-seed if having EFI RNG protocol

2024-09-20 Thread Ilias Apalodimas
Hi Simon, On Fri, 20 Sept 2024 at 10:25, Simon Glass wrote: > > Hi Ilias, > > On Thu, 19 Sept 2024 at 17:51, Ilias Apalodimas > wrote: > > > > On Thu, 19 Sept 2024 at 18:39, Simon Glass wrote: > > > > > > Hi, > > > > > > On Thu, 19 Sept 2024 at 17:37, Ilias Apalodimas > > > wrote: > > > > > >

Re: [PATCH 1/1] efi_leader: delete rng-seed if having EFI RNG protocol

2024-09-19 Thread Ilias Apalodimas
On Thu, 19 Sept 2024 at 18:39, Simon Glass wrote: > > Hi, > > On Thu, 19 Sept 2024 at 17:37, Ilias Apalodimas > wrote: > > > > On Thu, 19 Sept 2024 at 18:19, Simon Glass wrote: > > > > > > Hi, > > > > > > On Thu, 19 Sept 2024 at 17:13, Ilias Apalodimas > > > wrote: > > > > > > > > > > > > > > >

Re: [PATCH 1/1] efi_leader: delete rng-seed if having EFI RNG protocol

2024-09-19 Thread Simon Glass
Hi, On Thu, 19 Sept 2024 at 17:37, Ilias Apalodimas wrote: > > On Thu, 19 Sept 2024 at 18:19, Simon Glass wrote: > > > > Hi, > > > > On Thu, 19 Sept 2024 at 17:13, Ilias Apalodimas > > wrote: > > > > > > > > > > > > On Thu, Sep 19, 2024, 18:05 Heinrich Schuchardt > > > wrote: > > >> > > >> On

Re: [PATCH 1/1] efi_leader: delete rng-seed if having EFI RNG protocol

2024-09-19 Thread Ilias Apalodimas
On Thu, 19 Sept 2024 at 18:19, Simon Glass wrote: > > Hi, > > On Thu, 19 Sept 2024 at 17:13, Ilias Apalodimas > wrote: > > > > > > > > On Thu, Sep 19, 2024, 18:05 Heinrich Schuchardt > > wrote: > >> > >> On 19.09.24 17:00, Simon Glass wrote: > >> > Hi, > >> > > >> > On Thu, 19 Sept 2024 at 16:3

Re: [PATCH 1/1] efi_leader: delete rng-seed if having EFI RNG protocol

2024-09-19 Thread Heinrich Schuchardt
On 19.09.24 17:19, Simon Glass wrote: Hi, On Thu, 19 Sept 2024 at 17:13, Ilias Apalodimas wrote: On Thu, Sep 19, 2024, 18:05 Heinrich Schuchardt wrote: On 19.09.24 17:00, Simon Glass wrote: Hi, On Thu, 19 Sept 2024 at 16:32, Ilias Apalodimas wrote: Hi all, On Thu, 19 Sept 2024 at

Re: [PATCH 1/1] efi_leader: delete rng-seed if having EFI RNG protocol

2024-09-19 Thread Simon Glass
Hi, On Thu, 19 Sept 2024 at 17:13, Ilias Apalodimas wrote: > > > > On Thu, Sep 19, 2024, 18:05 Heinrich Schuchardt > wrote: >> >> On 19.09.24 17:00, Simon Glass wrote: >> > Hi, >> > >> > On Thu, 19 Sept 2024 at 16:32, Ilias Apalodimas >> > wrote: >> >> >> >> Hi all, >> >> >> >> On Thu, 19 Sept

Re: [PATCH 1/1] efi_leader: delete rng-seed if having EFI RNG protocol

2024-09-19 Thread Ilias Apalodimas
On Thu, Sep 19, 2024, 18:05 Heinrich Schuchardt < heinrich.schucha...@canonical.com> wrote: > On 19.09.24 17:00, Simon Glass wrote: > > Hi, > > > > On Thu, 19 Sept 2024 at 16:32, Ilias Apalodimas > > wrote: > >> > >> Hi all, > >> > >> On Thu, 19 Sept 2024 at 17:20, Heinrich Schuchardt > >> wrote

Re: [PATCH 1/1] efi_leader: delete rng-seed if having EFI RNG protocol

2024-09-19 Thread Heinrich Schuchardt
On 19.09.24 17:00, Simon Glass wrote: Hi, On Thu, 19 Sept 2024 at 16:32, Ilias Apalodimas wrote: Hi all, On Thu, 19 Sept 2024 at 17:20, Heinrich Schuchardt wrote: On 19.09.24 16:10, Simon Glass wrote: Hi Heinrich, On Sat, 14 Sept 2024 at 18:06, Heinrich Schuchardt wrote: For measured

Re: [PATCH 1/1] efi_leader: delete rng-seed if having EFI RNG protocol

2024-09-19 Thread Simon Glass
Hi, On Thu, 19 Sept 2024 at 16:32, Ilias Apalodimas wrote: > > Hi all, > > On Thu, 19 Sept 2024 at 17:20, Heinrich Schuchardt > wrote: > > > > On 19.09.24 16:10, Simon Glass wrote: > > > Hi Heinrich, > > > > > > On Sat, 14 Sept 2024 at 18:06, Heinrich Schuchardt > > > wrote: > > >> > > >> For m

Re: [PATCH 1/1] efi_leader: delete rng-seed if having EFI RNG protocol

2024-09-19 Thread Ilias Apalodimas
Hi all, On Thu, 19 Sept 2024 at 17:20, Heinrich Schuchardt wrote: > > On 19.09.24 16:10, Simon Glass wrote: > > Hi Heinrich, > > > > On Sat, 14 Sept 2024 at 18:06, Heinrich Schuchardt > > wrote: > >> > >> For measured be boot we must avoid any volatile values in the device-tree. > >> We already

Re: [PATCH 1/1] efi_leader: delete rng-seed if having EFI RNG protocol

2024-09-19 Thread Simon Glass
Hi Heinrich, On Sat, 14 Sept 2024 at 18:06, Heinrich Schuchardt wrote: > > For measured be boot we must avoid any volatile values in the device-tree. > We already delete /chosen/kaslr-seed if we provide and EFI RNG protocol. Could you explain a bit why this is, and where this is checked? > > Add

Re: [PATCH 1/1] efi_leader: delete rng-seed if having EFI RNG protocol

2024-09-19 Thread Heinrich Schuchardt
On 19.09.24 16:10, Simon Glass wrote: Hi Heinrich, On Sat, 14 Sept 2024 at 18:06, Heinrich Schuchardt wrote: For measured be boot we must avoid any volatile values in the device-tree. We already delete /chosen/kaslr-seed if we provide and EFI RNG protocol. Could you explain a bit why this i

[PATCH 1/1] efi_leader: delete rng-seed if having EFI RNG protocol

2024-09-14 Thread Heinrich Schuchardt
For measured be boot we must avoid any volatile values in the device-tree. We already delete /chosen/kaslr-seed if we provide and EFI RNG protocol. Additionally remove /chosen/rng-seed provided by QEMU or U-Boot. Signed-off-by: Heinrich Schuchardt --- include/efi_loader.h | 2 +- lib/