grub-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

IS: 2.06-rc1 cut... WAS: Re: [PATCH v2] Add chainloaded image as shim's


From: Daniel Kiper
Subject: IS: 2.06-rc1 cut... WAS: Re: [PATCH v2] Add chainloaded image as shim's verifiable object
Date: Wed, 10 Mar 2021 17:06:31 +0100
User-agent: NeoMutt/20170113 (1.7.2)

On Wed, Mar 10, 2021 at 11:56:47AM +0800, Michael Chang via Grub-devel wrote:
> On Tue, Mar 09, 2021 at 05:18:22PM +0100, Daniel Kiper wrote:
> > On Fri, Mar 05, 2021 at 09:48:53PM +0800, Michael Chang via Grub-devel 
> > wrote:
> > > While attempting to dual boot Microsoft Windows with efi chainloader, it
> > > failed with below error when secure boot was enabled.
> > >
> > > error ../../grub-core/kern/verifiers.c:119:verification requested but
> > > nobody cares: /EFI/Microsoft/Boot/bootmgfw.efi.
> > >
> > > It is a regression, as previously it worked without problem.
> > >
> > > It turns out chainloading image has been locked down introduced by
> > >
> > > 578c95298 kern: Add lockdown support
> > >
> > > However we should consider it as verifiable object to shim to allow
> > > booting in secure boot enabled mode. The chainloaded image could also
> > > have trusted signature signed by vendor with their pubkey cert in db.
> > > For that matters it's usage should not be locked down in secure boot,
> > > and instead use shim to validate it's signature before running it.
> > >
> > > V2:
> > > Keep GRUB_FILE_TYPE_EFI_CHAINLOADED_IMAGE in the lockdown list as it
> > > ensures at least one verifer has validated the image.
> > >
> > > Signed-off-by: Michael Chang <mchang@suse.com>
> >
> > Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
>
> May I ask if the patch is planned or going to be merged to the master
> hence available in the 2.06-rc1 cut ?

I have just pushed it together with other fixes and cleanups from the
grub-devel. If you can see something important missing drop me a line
immediately. Now I am working on 2.06-rc1 cut. If nothing blows up expect
it tomorrow or on Friday...

Daniel



reply via email to

[Prev in Thread] Current Thread [Next in Thread]