From nobody Tue Feb 10 04:03:01 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) client-ip=66.175.222.108; envelope-from=bounce+27952+90945+1787277+3901457@groups.io; helo=mail02.groups.io; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) smtp.mailfrom=bounce+27952+90945+1787277+3901457@groups.io; dmarc=fail(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1656631792; cv=none; d=zohomail.com; s=zohoarc; b=EPnqD+NpSgzKRX3aeX0ag5v+4FkRsuEJ6Yx/ig8QVLjuCvM6QNW3k8WkAqIOc+X64X79I9+e6/0BhafLyy6uzwFieVd1ZVqTKgM4faf36FOrNpoT4Bkln2LvLnncLgSttxceVmeJ+7kAdOvlHruZLCot+DHHfwmCdLsouzW6/tA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1656631792; h=Content-Transfer-Encoding:Cc:Date:From:In-Reply-To:List-Subscribe:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:References:Sender:Subject:To; bh=ZgPJWd7onQXjjKSTREjPFf/VczpTOcNNs+gSnZ2h47o=; b=CBOYo62Atn7ThziC4jYVTupJCmxJoQPFrPZ625eJZTsABW8qdFkQ1RFn7LcQgoOdJNKSHOMlN0ZpvO+Nx9ZDx0FSmEpqU+eGm4wswSSoZeVptLqm+HGVBaOIxJRTJMRvu5vv49zGRg9IukZ9GSTexyHyYTZtcPc8pVCMD5pvpY4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) smtp.mailfrom=bounce+27952+90945+1787277+3901457@groups.io; dmarc=fail header.from= (p=none dis=none) Received: from mail02.groups.io (mail02.groups.io [66.175.222.108]) by mx.zohomail.com with SMTPS id 1656631792054923.90979023064; Thu, 30 Jun 2022 16:29:52 -0700 (PDT) Return-Path: X-Received: by 127.0.0.2 with SMTP id dqBBYY1788612xMf2nJvwkMV; Thu, 30 Jun 2022 16:29:51 -0700 X-Received: from mga18.intel.com (mga18.intel.com [134.134.136.126]) by mx.groups.io with SMTP id smtpd.web12.32335.1656631779038420889 for ; Thu, 30 Jun 2022 16:29:51 -0700 X-IronPort-AV: E=McAfee;i="6400,9594,10394"; a="265528354" X-IronPort-AV: E=Sophos;i="5.92,235,1650956400"; d="scan'208";a="265528354" X-Received: from fmsmga008.fm.intel.com ([10.253.24.58]) by orsmga106.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 30 Jun 2022 16:29:50 -0700 X-IronPort-AV: E=Sophos;i="5.92,235,1650956400"; d="scan'208";a="648098703" X-Received: from mxu9-mobl1.ccr.corp.intel.com ([10.255.29.210]) by fmsmga008-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 30 Jun 2022 16:29:47 -0700 From: "Min Xu" To: devel@edk2.groups.io Cc: Min M Xu , Erdem Aktas , James Bottomley , Jiewen Yao , Tom Lendacky , Gerd Hoffmann Subject: [edk2-devel] [PATCH V4 6/8] OvmfPkg/NvVarsFileLib: Shortcut ConnectNvVarsToFileSystem in secure-boot Date: Fri, 1 Jul 2022 07:29:15 +0800 Message-Id: <970dca46a90a9b6a00f084e8663f22ee712a7057.1656630360.git.min.m.xu@intel.com> In-Reply-To: References: MIME-Version: 1.0 Precedence: Bulk List-Unsubscribe: List-Subscribe: List-Help: Sender: devel@edk2.groups.io List-Id: Mailing-List: list devel@edk2.groups.io; contact devel+owner@edk2.groups.io Reply-To: devel@edk2.groups.io,min.m.xu@intel.com X-Gm-Message-State: SlKL6SdQsWPXVtq1BCnLN6wDx1787277AA= Content-Transfer-Encoding: quoted-printable DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=groups.io; q=dns/txt; s=20140610; t=1656631791; bh=VXNi9EJ7AjUIR2HeCVv7RqnLtQ9qV0r1TTEeR5wN8gQ=; h=Cc:Date:From:Reply-To:Subject:To; b=OSpd48MEy/wo0QHhgWG3rePLBoYWjoFx0g3adXF65KTXDEC58qogoTq5PGm4rNcWDFV 9+Wlxrt6Q5a1lZN9Xnan+jPV171ZaUQ41nFQT9yfwQTBqHCB71kus4zAwsjUp5zpzj5q6 gmE+dGWw6tb9L7l5BY4ZlVJFfdyEgKLa1E8= X-ZohoMail-DKIM: pass (identity @groups.io) X-ZM-MESSAGEID: 1656631792439100006 Content-Type: text/plain; charset="utf-8" From: Min M Xu OvmfPkg/Library/NvVarsFileLib allows loading variables into emulated varstore from a on-disk NvVars file. We can't allow that when secure boot is active. So check secure-boot feature and shortcut the ConnectNvVarsToFileSystem() function when sb is enabled. Cc: Erdem Aktas Cc: James Bottomley Cc: Jiewen Yao Cc: Tom Lendacky Cc: Gerd Hoffmann Suggested-by: Gerd Hoffmann Signed-off-by: Min Xu --- OvmfPkg/Library/NvVarsFileLib/NvVarsFileLib.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/OvmfPkg/Library/NvVarsFileLib/NvVarsFileLib.c b/OvmfPkg/Librar= y/NvVarsFileLib/NvVarsFileLib.c index 21b71524ea48..72289da35819 100644 --- a/OvmfPkg/Library/NvVarsFileLib/NvVarsFileLib.c +++ b/OvmfPkg/Library/NvVarsFileLib/NvVarsFileLib.c @@ -28,6 +28,12 @@ ConnectNvVarsToFileSystem ( IN EFI_HANDLE FsHandle ) { + #ifdef SECURE_BOOT_FEATURE_ENABLED + + return EFI_UNSUPPORTED; + + #else + EFI_STATUS Status; =20 // @@ -46,6 +52,7 @@ ConnectNvVarsToFileSystem ( } =20 return Status; + #endif } =20 /** --=20 2.29.2.windows.2 -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#90945): https://edk2.groups.io/g/devel/message/90945 Mute This Topic: https://groups.io/mt/92098441/1787277 Group Owner: devel+owner@edk2.groups.io Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org] -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-