From nobody Sat Sep 26 20:51:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789652087; cv=none; d=zohomail.com; s=zohoarc; b=DmZLNuGlJn9rvnoRNniG7Q+RlDA97uQxhid3Wm/DdasQDhS1Qt4KAfa/+aaI5mq8+lfr/o3OcY+tiJvuOw2lwLhtxB58H7opl7bkHvAmxNkZw+gPDE9lhVwkHwHlAB2iEh2NFwnyMiBofWevof6GE8G2XNB3NtDHreHCh7gCntY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789652087; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=CF0kpZJ5GhLztDravSG1LpM76fb5OfpRcRDbaQO4WRM=; b=Dn0BYUJr3RSwcT6miiKwvoQBdeC4MprZaxx13AGs9/ygW5us+oxXdb5D7IZhfJMTeVOhtUyvA+wdGx/iRFy01HXKOYJ1yzqDqaGxncu7SEpQo0A0SEh+T6fk/N2zsClgNhaplF8FsjNMi/I8X9FnG8zIBuIzy+TkR3iaXillTOQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789652087713878.1498668260238; Thu, 17 Sep 2026 06:34:47 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7CFO-0000dV-6U; Thu, 17 Sep 2026 09:33:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7CF6-0000bT-Bd for qemu-devel@nongnu.org; Thu, 17 Sep 2026 09:33:39 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7CEy-0003WG-ID for qemu-devel@nongnu.org; Thu, 17 Sep 2026 09:33:36 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-377-G4UqsCcqMKShI2MLLmT5NA-1; Thu, 17 Sep 2026 09:33:21 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id D45B9195FD22; Thu, 17 Sep 2026 13:33:20 +0000 (UTC) Received: from sirius.home.kraxel.org (unknown [10.44.48.37]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 089D21956095; Thu, 17 Sep 2026 13:33:20 +0000 (UTC) Received: by sirius.home.kraxel.org (Postfix, from userid 1000) id EF81C18003BB; Thu, 17 Sep 2026 15:33:18 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789652006; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=CF0kpZJ5GhLztDravSG1LpM76fb5OfpRcRDbaQO4WRM=; b=hpG/8KJFGgmocwUNGK6XxTEZa3Tc1LSOkbn06EKjENFeUx1JSKd0QCigZ6v9Gq+vqSBUWz NadLMNo1ZrRCdZiobptY0rxhcPpFrPTOgVmWj8xQ7XNH+ZdTPUEQbnd+RapHDa0FUviOQO JysQGg8xpQmK8425fpHZh5hQ+ahkD90= X-MC-Unique: G4UqsCcqMKShI2MLLmT5NA-1 X-Mimecast-MFC-AGG-ID: G4UqsCcqMKShI2MLLmT5NA_1789652001 From: Gerd Hoffmann To: qemu-devel@nongnu.org Cc: Ani Sinha , Gerd Hoffmann , Paolo Bonzini , Stefano Garzarella , Zhao Liu , Luigi Leonardi Subject: [PULL 1/5] hw/uefi: add missing uefi_str_is_valid check to uefi_vars_mm_lock_variable Date: Thu, 17 Sep 2026 15:33:14 +0200 Message-ID: <20260917133318.2004317-2-kraxel@redhat.com> In-Reply-To: <20260917133318.2004317-1-kraxel@redhat.com> References: <20260917133318.2004317-1-kraxel@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=kraxel@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789652091003158500 Content-Type: text/plain; charset="utf-8" Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4213 Reviewed-by: Luigi Leonardi Signed-off-by: Gerd Hoffmann Message-ID: <20260916145050.1329206-1-kraxel@redhat.com> --- hw/uefi/var-service-vars.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/hw/uefi/var-service-vars.c b/hw/uefi/var-service-vars.c index e0ea3d532eb6..ef8849f81511 100644 --- a/hw/uefi/var-service-vars.c +++ b/hw/uefi/var-service-vars.c @@ -690,6 +690,10 @@ uefi_vars_mm_lock_variable(uefi_vars_state *uv, mm_hea= der *mhdr, return uefi_vars_mm_error(mhdr, mvar, EFI_BAD_BUFFER_SIZE); } =20 + if (!uefi_str_is_valid(name, lv->name_size, true)) { + return uefi_vars_mm_error(mhdr, mvar, EFI_INVALID_PARAMETER); + } + uefi_trace_variable(__func__, lv->guid, name, lv->name_size); =20 pe =3D g_malloc0(sizeof(*pe) + lv->name_size); --=20 2.55.0 From nobody Sat Sep 26 20:51:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789652061; cv=none; d=zohomail.com; s=zohoarc; b=iPFVtFEWQZ5ms9LjRvJwMInEa7HaSGFmINaR+E+RaXE3H8kI2e/11il/VPe6oFgLx5NKSDhtdb3t83yvKicQGDAXgSFNd123bCW9dI07bQPB3sYSFbdUUNCTt7QHeRy5LBjK9wc+Nds1+PC8F3BeVmMxpBXKBpSwU0QcuceA58c= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789652061; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=rC0MvOwoBF73sE6fWWaPxdO0f1psZR9mBvPUchKomSM=; b=BJZTmfGV1e01DaD8tk4k7RTPy2HppHxOQLj+D2ignO/J3Mj6XFfHeMFfcpLp+DmvZFdTID3yZ3nQIL9cqlde7XmvJWRup5UMr7nwTD7xS4UlN7WxAKe/XwApZqZf2sxM/VoLa8owUvLs8S14Qr+PaOoklYD/TVcRHT4/hGXYAjI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789652061591990.8588569985214; Thu, 17 Sep 2026 06:34:21 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7CFE-0000bj-QO; Thu, 17 Sep 2026 09:33:47 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7CF2-0000bI-9U for qemu-devel@nongnu.org; Thu, 17 Sep 2026 09:33:33 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7CEx-0003Vv-JR for qemu-devel@nongnu.org; Thu, 17 Sep 2026 09:33:30 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-688-vV1dLViVM1W1n7BLKwkXgQ-1; Thu, 17 Sep 2026 09:33:23 -0400 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 9C2011955BED; Thu, 17 Sep 2026 13:33:22 +0000 (UTC) Received: from sirius.home.kraxel.org (unknown [10.44.48.37]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id EDA54180035F; Thu, 17 Sep 2026 13:33:21 +0000 (UTC) Received: by sirius.home.kraxel.org (Postfix, from userid 1000) id 167E9180063D; Thu, 17 Sep 2026 15:33:19 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789652005; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=rC0MvOwoBF73sE6fWWaPxdO0f1psZR9mBvPUchKomSM=; b=e0IipeQNdIdDN3G3s1B+ak7hPjnxlhBx3z7DO9uxYSqygj15wSW08RvGEEZdYwuDGjaDRB XVr5rLCDqN//B+G6+byIY49IkPb1Jgb+qfqbqkSYVw1w0NTj7wuJljJmEIoDVeVJlCe9d5 VgBrAtiy3o2uU0VO4TEaMiltXJkFv3w= X-MC-Unique: vV1dLViVM1W1n7BLKwkXgQ-1 X-Mimecast-MFC-AGG-ID: vV1dLViVM1W1n7BLKwkXgQ_1789652002 From: Gerd Hoffmann To: qemu-devel@nongnu.org Cc: Ani Sinha , Gerd Hoffmann , Paolo Bonzini , Stefano Garzarella , Zhao Liu , Luigi Leonardi Subject: [PULL 2/5] igvm: validate and honor byte_offset in parameter directives Date: Thu, 17 Sep 2026 15:33:15 +0200 Message-ID: <20260917133318.2004317-3-kraxel@redhat.com> In-Reply-To: <20260917133318.2004317-1-kraxel@redhat.com> References: <20260917133318.2004317-1-kraxel@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=kraxel@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789652064596158500 Content-Type: text/plain; charset="utf-8" From: Luigi Leonardi Parameter directive handlers either ignore param->byte_offset, overwriting each other when several parameters share one area, or use it without validating it, letting a malformed IGVM file corrupt QEMU's memory. Add qigvm_get_param_data(), which validates byte_offset against the parameter area size and returns the offset-adjusted pointer together with the space left after it. Convert all parameter directive handlers to use it and to check their writes against that remaining space, so that no parameter can be written past the end of its area. Fixes: c1d466d267 ("backends/igvm: Add IGVM loader and configuration") Fixes: dea1f68a5c ("igvm: Fill MADT IGVM parameter field on x86_64") Fixes: 1c4bd8f13c ("igvm: add device tree parameter support") Signed-off-by: Luigi Leonardi Reviewed-by: Stefano Garzarella Message-ID: <20260916-fix_offset-v5-1-11cf8ef37854@redhat.com> Signed-off-by: Gerd Hoffmann --- include/system/igvm-internal.h | 5 ++ backends/igvm.c | 93 +++++++++++++++++++++++++--------- target/i386/igvm.c | 12 ++--- 3 files changed, 79 insertions(+), 31 deletions(-) diff --git a/include/system/igvm-internal.h b/include/system/igvm-internal.h index 9e9fa1d9afdb..0467eff0ceab 100644 --- a/include/system/igvm-internal.h +++ b/include/system/igvm-internal.h @@ -81,4 +81,9 @@ QIgvmParameterData* qigvm_find_param_entry(QIgvm *igvm, uint32_t parameter_area_index, Error **errp); =20 +uint8_t * +qigvm_get_param_data(QIgvm *igvm, const IGVM_VHS_PARAMETER *param, + uint32_t *param_size, + Error **errp); + #endif diff --git a/backends/igvm.c b/backends/igvm.c index 7b7bdc72b75b..9a2bafc0cad0 100644 --- a/backends/igvm.c +++ b/backends/igvm.c @@ -101,6 +101,38 @@ qigvm_find_param_entry(QIgvm *igvm, uint32_t parameter= _area_index, return NULL; } =20 +/* + * Get parameter area data at byte_offset with bounds validation. + * On success, returns offset-adjusted data pointer and sets param_size + * to remaining space. + * Returns NULL on failure. + */ +uint8_t * +qigvm_get_param_data(QIgvm *igvm, const IGVM_VHS_PARAMETER *param, + uint32_t *param_size, + Error **errp) +{ + QIgvmParameterData *param_entry; + + assert(param_size); + + param_entry =3D qigvm_find_param_entry(igvm, param->parameter_area_ind= ex, + errp); + if (!param_entry) { + return NULL; + } + + if (param->byte_offset > param_entry->size) { + error_setg(errp, + "IGVM: byte_offset 0x%x exceeds parameter area size 0x%= x", + param->byte_offset, param_entry->size); + return NULL; + } + + *param_size =3D param_entry->size - param->byte_offset; + return param_entry->data + param->byte_offset; +} + static int qigvm_directive_page_data(QIgvm *ctx, const uint8_t *header_dat= a, Error **errp); static int qigvm_directive_vp_context(QIgvm *ctx, const uint8_t *header_da= ta, @@ -605,7 +637,7 @@ static int qigvm_directive_memory_map(QIgvm *ctx, const= uint8_t *header_data, const IGVM_VHS_PARAMETER *param =3D (const IGVM_VHS_PARAMETER *)header= _data; int (*get_mem_map_entry)(int index, ConfidentialGuestMemoryMapEntry *e= ntry, Error **errp) =3D NULL; - QIgvmParameterData *param_entry; + uint32_t param_size; int max_entry_count; int entry =3D 0; IGVM_VHS_MEMORY_MAP_ENTRY *mm_entry; @@ -626,14 +658,14 @@ static int qigvm_directive_memory_map(QIgvm *ctx, con= st uint8_t *header_data, } =20 /* Find the parameter area that should hold the memory map */ - param_entry =3D qigvm_find_param_entry(ctx, - param->parameter_area_index, errp= ); - if (param_entry =3D=3D NULL) { + mm_entry =3D + (IGVM_VHS_MEMORY_MAP_ENTRY *)qigvm_get_param_data(ctx, param, + ¶m_size, err= p); + if (!mm_entry) { return -1; } =20 - max_entry_count =3D param_entry->size / sizeof(IGVM_VHS_MEMORY_MAP_ENT= RY); - mm_entry =3D (IGVM_VHS_MEMORY_MAP_ENTRY *)param_entry->data; + max_entry_count =3D param_size / sizeof(IGVM_VHS_MEMORY_MAP_ENTRY); =20 retval =3D get_mem_map_entry(entry, &cgmm_entry, errp); while (retval =3D=3D 0) { @@ -682,17 +714,22 @@ static int qigvm_directive_vp_count(QIgvm *ctx, const= uint8_t *header_data, Error **errp) { const IGVM_VHS_PARAMETER *param =3D (const IGVM_VHS_PARAMETER *)header= _data; - QIgvmParameterData *param_entry; + uint32_t param_size; uint32_t *vp_count; CPUState *cpu; =20 - param_entry =3D qigvm_find_param_entry(ctx, - param->parameter_area_index, errp= ); - if (param_entry =3D=3D NULL) { + vp_count =3D (uint32_t *)qigvm_get_param_data(ctx, param, ¶m_size,= errp); + if (!vp_count) { + return -1; + } + + if (sizeof(*vp_count) > param_size) { + error_setg(errp, + "IGVM: vp-count parameter exceeds parameter area " + "defined in IGVM file"); return -1; } =20 - vp_count =3D (uint32_t *)(param_entry->data + param->byte_offset); *vp_count =3D 0; CPU_FOREACH(cpu) { @@ -707,17 +744,23 @@ static int qigvm_directive_environment_info(QIgvm *ct= x, Error **errp) { const IGVM_VHS_PARAMETER *param =3D (const IGVM_VHS_PARAMETER *)header= _data; - QIgvmParameterData *param_entry; + uint32_t param_size; IgvmEnvironmentInfo *environmental_state; =20 - param_entry =3D qigvm_find_param_entry(ctx, - param->parameter_area_index, errp= ); - if (param_entry =3D=3D NULL) { - return -1; - } - environmental_state =3D - (IgvmEnvironmentInfo *)(param_entry->data + param->byte_offset); + (IgvmEnvironmentInfo *)qigvm_get_param_data(ctx, param, ¶m_siz= e, + errp); + if (!environmental_state) { + return -1; + } + + if (sizeof(*environmental_state) > param_size) { + error_setg(errp, + "IGVM: environment-info parameter exceeds parameter are= a " + "defined in IGVM file"); + return -1; + } + environmental_state->memory_is_shared =3D 1; =20 return 0; @@ -814,12 +857,12 @@ static int qigvm_directive_device_tree(QIgvm *ctx, co= nst uint8_t *header_data, { const IGVM_VHS_PARAMETER *param =3D (const IGVM_VHS_PARAMETER *)header= _data; g_autofree void *fdt_packed =3D NULL; - QIgvmParameterData *param_entry; + uint8_t *param_data; + uint32_t param_size; uint32_t fdt_size; =20 - param_entry =3D qigvm_find_param_entry(ctx, - param->parameter_area_index, errp= ); - if (param_entry =3D=3D NULL) { + param_data =3D qigvm_get_param_data(ctx, param, ¶m_size, errp); + if (!param_data) { return -1; } =20 @@ -837,14 +880,14 @@ static int qigvm_directive_device_tree(QIgvm *ctx, co= nst uint8_t *header_data, } =20 fdt_size =3D fdt_totalsize(fdt_packed); - if (fdt_size > param_entry->size) { + if (fdt_size > param_size) { error_setg(errp, "IGVM: device tree size exceeds parameter area" " defined in IGVM file"); return -1; } =20 - memcpy(param_entry->data, fdt_packed, fdt_size); + memcpy(param_data, fdt_packed, fdt_size); =20 return 0; } diff --git a/target/i386/igvm.c b/target/i386/igvm.c index ad9bf87761fb..9c2f8d516492 100644 --- a/target/i386/igvm.c +++ b/target/i386/igvm.c @@ -187,20 +187,20 @@ void qigvm_x86_bsp_reset(CPUX86State *env) int qigvm_directive_madt(QIgvm *ctx, const uint8_t *header_data, Error **e= rrp) { const IGVM_VHS_PARAMETER *param =3D (const IGVM_VHS_PARAMETER *)header= _data; - QIgvmParameterData *param_entry; + uint8_t *param_data; + uint32_t param_size; int result =3D 0; =20 /* Find the parameter area that should hold the MADT data */ - param_entry =3D qigvm_find_param_entry(ctx, - param->parameter_area_index, errp= ); - if (param_entry =3D=3D NULL) { + param_data =3D qigvm_get_param_data(ctx, param, ¶m_size, errp); + if (!param_data) { return -1; } =20 GArray *madt =3D acpi_build_madt_standalone(ctx->machine_state); =20 - if (madt->len <=3D param_entry->size) { - memcpy(param_entry->data, madt->data, madt->len); + if (madt->len <=3D param_size) { + memcpy(param_data, madt->data, madt->len); } else { error_setg( errp, --=20 2.55.0 From nobody Sat Sep 26 20:51:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789652078; cv=none; d=zohomail.com; s=zohoarc; b=kZ0wEjxtIRyoamAxoOP5Vl7C2Ivj9pSS00/henr6qR9sUo0k0vvoIAnYfcAepCEn8ymxRpex9qdb9PLji5M/HAOj4y8wW4kxlqURPHo82BPqNRnzerwdQjrW90yL0GAd++BhmkL7g6Mqp8gVzTbV5+oROfKhChqKBxJH3xTEo5I= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789652078; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Gwt7byog0znHqLQSJptfme+CjdJYRGTbgDMgA+bi2VU=; b=hz9UhSM2F/em6DSo+HwGHqehWVkaVQ7MofiJqfxoF9Mjt+t/L8DycLfPod3vQ7nt7Yvdd4WSMT8qQX2555SHW1JPKmbjUV3AvNFUQHMVBZ5+HSk5yVnwl7jBT19LtdKy9NIkjQi6GevCMMAFb+hbVGjp6XUmwLhcpSbAqrtvAN8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789652078044626.3153711823763; Thu, 17 Sep 2026 06:34:38 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7CFL-0000d1-DT; Thu, 17 Sep 2026 09:33:51 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7CF5-0000bR-KB for qemu-devel@nongnu.org; Thu, 17 Sep 2026 09:33:39 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7CEz-0003Wb-5M for qemu-devel@nongnu.org; Thu, 17 Sep 2026 09:33:34 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-251-znEgBguvPDyC6sAm0dBRwA-1; Thu, 17 Sep 2026 09:33:23 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id A40B0182E699; Thu, 17 Sep 2026 13:33:22 +0000 (UTC) Received: from sirius.home.kraxel.org (unknown [10.44.48.37]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 04DF930001BE; Thu, 17 Sep 2026 13:33:21 +0000 (UTC) Received: by sirius.home.kraxel.org (Postfix, from userid 1000) id 280061800780; Thu, 17 Sep 2026 15:33:19 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789652008; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Gwt7byog0znHqLQSJptfme+CjdJYRGTbgDMgA+bi2VU=; b=VYcukAGweyCHfdzd5idxC2OZBO5yiAqice5WjZole9lOPLtBaofrcP+2O/YBOcbk+2N49l wLRgQY64hDkIxURnNoar73KM3m3Vsf1LVB/b6Rjl+g2nxLuKe2+UD40aqZvVmIrKm1ONIX HqkG5sdW2k7l3pT6zDmJHVY5oRFn91w= X-MC-Unique: znEgBguvPDyC6sAm0dBRwA-1 X-Mimecast-MFC-AGG-ID: znEgBguvPDyC6sAm0dBRwA_1789652002 From: Gerd Hoffmann To: qemu-devel@nongnu.org Cc: Ani Sinha , Gerd Hoffmann , Paolo Bonzini , Stefano Garzarella , Zhao Liu , Luigi Leonardi Subject: [PULL 3/5] igvm: mark qigvm_find_param_entry as static Date: Thu, 17 Sep 2026 15:33:16 +0200 Message-ID: <20260917133318.2004317-4-kraxel@redhat.com> In-Reply-To: <20260917133318.2004317-1-kraxel@redhat.com> References: <20260917133318.2004317-1-kraxel@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=kraxel@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789652080564158500 Content-Type: text/plain; charset="utf-8" From: Luigi Leonardi Previous commit removed all external usage of `qigvm_find_param_entry`, therefore we can mark it as a static function. Suggested-by: Stefano Garzarella Signed-off-by: Luigi Leonardi Reviewed-by: Stefano Garzarella Message-ID: <20260916-fix_offset-v5-2-11cf8ef37854@redhat.com> Signed-off-by: Gerd Hoffmann --- include/system/igvm-internal.h | 4 ---- backends/igvm.c | 2 +- 2 files changed, 1 insertion(+), 5 deletions(-) diff --git a/include/system/igvm-internal.h b/include/system/igvm-internal.h index 0467eff0ceab..b3b64cb58444 100644 --- a/include/system/igvm-internal.h +++ b/include/system/igvm-internal.h @@ -77,10 +77,6 @@ struct QIgvm { =20 IgvmHandle qigvm_file_init(char *filename, Error **errp); =20 -QIgvmParameterData* -qigvm_find_param_entry(QIgvm *igvm, uint32_t parameter_area_index, - Error **errp); - uint8_t * qigvm_get_param_data(QIgvm *igvm, const IGVM_VHS_PARAMETER *param, uint32_t *param_size, diff --git a/backends/igvm.c b/backends/igvm.c index 9a2bafc0cad0..ec7bee428bcc 100644 --- a/backends/igvm.c +++ b/backends/igvm.c @@ -85,7 +85,7 @@ struct QEMU_PACKED sev_id_authentication { =20 #define IGVM_SEV_ID_BLOCK_VERSION 1 =20 -QIgvmParameterData* +static QIgvmParameterData* qigvm_find_param_entry(QIgvm *igvm, uint32_t parameter_area_index, Error **errp) { --=20 2.55.0 From nobody Sat Sep 26 20:51:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789652090; cv=none; d=zohomail.com; s=zohoarc; b=Y8b9IGWleue99qJPw1UgHmRF6aouZidnsgwGfwN5vzihTYy1FjVf7KaQsL8nRcaYasMHCkybyhVYFu6FxX2qKXlzbME4+h2S2HN+hpmgYGgRL7hDmaduX56Z22/z4MrlhKYoFDHBOx5E8S7XQBX0MXC3iUhYQ5YysLyJSCEZsdk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789652090; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=zMqYfTijQ33nsHRqkS6ubKuRUZRkxvpFtxxgFqHHGLg=; b=Fbk+J068njMDwGo1yiCvFXHATUij54nQPY6oLnWXxSJBFf0d8EUEJqxJdZ7WnnpYeVlNSHN4ZocDyu6/iirHcxF+B2nMaEDxS3h+MfTqxzI7O9SfYUVzPBXWu3JNPRHS6+rp0U2JeNT7WJbaV+nfwFXzYPS6xHTKVmwLYGjHf9w= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789652090418697.072270021316; Thu, 17 Sep 2026 06:34:50 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7CFO-0000dO-5R; Thu, 17 Sep 2026 09:33:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7CF6-0000bU-E1 for qemu-devel@nongnu.org; Thu, 17 Sep 2026 09:33:39 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7CEy-0003W4-Ho for qemu-devel@nongnu.org; Thu, 17 Sep 2026 09:33:36 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-388-JUwrULbWPbGo_T_f18qRCg-1; Thu, 17 Sep 2026 09:33:24 -0400 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 8F6BF18000A3; Thu, 17 Sep 2026 13:33:23 +0000 (UTC) Received: from sirius.home.kraxel.org (unknown [10.44.48.37]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 3284B180034C; Thu, 17 Sep 2026 13:33:23 +0000 (UTC) Received: by sirius.home.kraxel.org (Postfix, from userid 1000) id 3C3761800782; Thu, 17 Sep 2026 15:33:19 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789652006; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=zMqYfTijQ33nsHRqkS6ubKuRUZRkxvpFtxxgFqHHGLg=; b=hm1nSxok1B5rle0IU6pIq5TYb3oPK39jWKxFwO1hf8PQwJt6YYMTH2skdmkS0Q2+pmG14x onZUpsX8O0D5y3LD42ezw3iR8Wi57A5wm7gUkDJGpB+K/nEIsSPNHr4WTzMHB2IEH34yNg o4Wwbp9j1Vlps1K2vMj+W8RhYxu4E10= X-MC-Unique: JUwrULbWPbGo_T_f18qRCg-1 X-Mimecast-MFC-AGG-ID: JUwrULbWPbGo_T_f18qRCg_1789652003 From: Gerd Hoffmann To: qemu-devel@nongnu.org Cc: Ani Sinha , Gerd Hoffmann , Paolo Bonzini , Stefano Garzarella , Zhao Liu Subject: [PULL 4/5] hw/uefi: add require-self-signed-pk config option Date: Thu, 17 Sep 2026 15:33:17 +0200 Message-ID: <20260917133318.2004317-5-kraxel@redhat.com> In-Reply-To: <20260917133318.2004317-1-kraxel@redhat.com> References: <20260917133318.2004317-1-kraxel@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=kraxel@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789652092837158500 Content-Type: text/plain; charset="utf-8" Traditional edk2 behavior is to require a self-signed platform key when enrolling secure boot certificates in setup mode. In 2023 a config option has been added (PcdRequireSelfSignedPk) which allows to relax that requirement, see edk2 commit 566cdfc675fa ("SecurityPkg: limit verification of enrolled PK in setup mode"). This patch adds a similar config option to the qemu uefi variable driver. No functional change, the default value for the new config option maintains existing behavior. Signed-off-by: Gerd Hoffmann Message-ID: <20260904085509.2267560-2-kraxel@redhat.com> --- include/hw/uefi/var-service.h | 1 + hw/uefi/var-service-auth.c | 25 +++++++++++++++---------- hw/uefi/var-service-sysbus.c | 2 ++ 3 files changed, 18 insertions(+), 10 deletions(-) diff --git a/include/hw/uefi/var-service.h b/include/hw/uefi/var-service.h index 7d84025cd58d..7f74b4423381 100644 --- a/include/hw/uefi/var-service.h +++ b/include/hw/uefi/var-service.h @@ -76,6 +76,7 @@ struct uefi_vars_state { int jsonfd; bool force_secure_boot; bool disable_custom_mode; + bool require_self_signed_pk; bool use_pio; =20 /* request + reply capture */ diff --git a/hw/uefi/var-service-auth.c b/hw/uefi/var-service-auth.c index 899444af12df..21fc50f904d5 100644 --- a/hw/uefi/var-service-auth.c +++ b/hw/uefi/var-service-auth.c @@ -201,16 +201,21 @@ static efi_status uefi_vars_check_auth_2_sb(uefi_vars= _state *uv, =20 siglist =3D uefi_vars_find_siglist(uv, var); if (!siglist && setup_mode_is_active(uv) && uefi_vars_is_sb_pk(var)) { - /* check PK is self-signed */ - uefi_variable tmp =3D { - .guid =3D EfiGlobalVariable, - .name =3D (uint16_t *)name_pk, - .name_size =3D sizeof(name_pk), - .attributes =3D sigdb_attrs, - .data =3D data + data_offset, - .data_size =3D va->data_size - data_offset, - }; - return uefi_vars_check_pkcs7_2(&tmp, NULL, NULL, va, data); + /* edk2 config option is PcdRequireSelfSignedPk */ + if (uv->require_self_signed_pk) { + /* check PK is self-signed */ + uefi_variable tmp =3D { + .guid =3D EfiGlobalVariable, + .name =3D (uint16_t *)name_pk, + .name_size =3D sizeof(name_pk), + .attributes =3D sigdb_attrs, + .data =3D data + data_offset, + .data_size =3D va->data_size - data_offset, + }; + return uefi_vars_check_pkcs7_2(&tmp, NULL, NULL, va, data); + } else { + return true; + } } =20 return uefi_vars_check_pkcs7_2(siglist, NULL, NULL, va, data); diff --git a/hw/uefi/var-service-sysbus.c b/hw/uefi/var-service-sysbus.c index 97a96cae6a2b..c4acdea275ad 100644 --- a/hw/uefi/var-service-sysbus.c +++ b/hw/uefi/var-service-sysbus.c @@ -38,6 +38,8 @@ static const Property uefi_vars_sysbus_properties[] =3D { state.force_secure_boot, false), DEFINE_PROP_BOOL("disable-custom-mode", uefi_vars_sysbus_state, state.disable_custom_mode, false), + DEFINE_PROP_BOOL("require-self-signed-pk", uefi_vars_sysbus_state, + state.require_self_signed_pk, true), DEFINE_PROP_BOOL("use-pio", uefi_vars_sysbus_state, state.use_pio, false), }; --=20 2.55.0 From nobody Sat Sep 26 20:51:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789652077; cv=none; d=zohomail.com; s=zohoarc; b=huvBJZpy3cscTdmR0MBbghYSKJcCZ7frdp2azFb7pIycz9KNRCXIgO4MQKDp8ViAuFBVawdJMVwB96XwMkXwvY2uO3Df71uEYaT/viVWdJOU5o9VR2bEbHuPkRhkzweVjJClZWs34uctmGJCGXzNdDHerI8zPhDcnnzO7e2HPSU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789652077; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=QUgn2pLNsDWfsI6yE3tCPpGdwJeOajVyjdQeyTCT2nc=; b=Ba+iM4g3jQX62STT2inh0cM1+m0ZEWZZnqyX3xS511j5WIzRKGqVvGANxk1jsnx7Tb/rjtFMOemzsDePJjkBbai24ZBYNTim4GC+uJzbWuyDKH0EVO3aCAcBbneOTp16FPhG6U9b6jpN2ZS0jnFYFUKuVf1aTPZTs8hL6ae7oxE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789652077944541.3657058634292; Thu, 17 Sep 2026 06:34:37 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x7CFL-0000d5-Ef; Thu, 17 Sep 2026 09:33:51 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7CF5-0000bP-9H for qemu-devel@nongnu.org; Thu, 17 Sep 2026 09:33:38 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x7CEy-0003WR-HY for qemu-devel@nongnu.org; Thu, 17 Sep 2026 09:33:33 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-374-Nc-w_BsHMGGsZdXqzUmUEA-1; Thu, 17 Sep 2026 09:33:24 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 731511953964; Thu, 17 Sep 2026 13:33:23 +0000 (UTC) Received: from sirius.home.kraxel.org (unknown [10.44.48.37]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 32B4430001BE; Thu, 17 Sep 2026 13:33:23 +0000 (UTC) Received: by sirius.home.kraxel.org (Postfix, from userid 1000) id 53A7C1800788; Thu, 17 Sep 2026 15:33:19 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789652007; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=QUgn2pLNsDWfsI6yE3tCPpGdwJeOajVyjdQeyTCT2nc=; b=ATAlKa4D9FOdfKywUF8GnPCHeXDjxWNzWURbYWNc6tp+Ykxi21helOW/J4A79NaRoD0SMc iS8Oqg88Uha8wdwYIXdfCg5E6AStOpesaBLz4lg12y442CGJ3j2DLUeAOovKodAyHi7Q8x z2iAEJ/u3yAVIxKLC5/2lfRcqOsoAmg= X-MC-Unique: Nc-w_BsHMGGsZdXqzUmUEA-1 X-Mimecast-MFC-AGG-ID: Nc-w_BsHMGGsZdXqzUmUEA_1789652003 From: Gerd Hoffmann To: qemu-devel@nongnu.org Cc: Ani Sinha , Gerd Hoffmann , Paolo Bonzini , Stefano Garzarella , Zhao Liu Subject: [PULL 5/5] hw/uefi: improve default config security Date: Thu, 17 Sep 2026 15:33:18 +0200 Message-ID: <20260917133318.2004317-6-kraxel@redhat.com> In-Reply-To: <20260917133318.2004317-1-kraxel@redhat.com> References: <20260917133318.2004317-1-kraxel@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=kraxel@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789652080568158501 Content-Type: text/plain; charset="utf-8" Recent UEFI spec versions do not require a self-signed PK any more. There is no good reason to stick to this requirement, but there is one reason to remove it: It is not needed to enable CustomMode then to enroll secure boot keys which are not self-signed. This commit changes the uefi-vars default configuration to remove the self signed platform key requirement and to disable CustomMode. Little background on CustomMode: This is a special edk2 mode which allows to freely update secure boot variables. This is used by the firmware setup utility to allow the user change the secure boot certificates. The EnrollDefaultKeys.efi utility used to depend on CustomMode too. Typically enabling CustomMode requires the user being physically present. Implementing such a check in a sensible way for a virtual machine is not really possible though. So OVMF doesn't do that and CustomMode can be enabled without that physical presence check. Therefore disabling CustomMode (by the qemu variable service blocking updates of the EFI variable with EFI_WRITE_PROTECTED) is a nice security improvement for secure boot support in virtual machines. User-visible change: Updating secure boot configuration via firmware setup utility does not work by default. Setting the "disable-custom-mode=3Doff" property will re-enable this if needed. Alternatively the variable store can be prepared on the host machine instead of doing it inside the guest. Related edk2 commits: - 3c01a11daae2 ("OvmfPkg: set PcdRequireSelfSignedPk to FALSE"). - 0a7ed7ed3457 ("OvmfPkg/EnrollDefaultKeys: do not require CustomMode") Signed-off-by: Gerd Hoffmann Message-ID: <20260904085509.2267560-3-kraxel@redhat.com> --- hw/uefi/var-service-sysbus.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/hw/uefi/var-service-sysbus.c b/hw/uefi/var-service-sysbus.c index c4acdea275ad..e5e0441e16f7 100644 --- a/hw/uefi/var-service-sysbus.c +++ b/hw/uefi/var-service-sysbus.c @@ -37,9 +37,9 @@ static const Property uefi_vars_sysbus_properties[] =3D { DEFINE_PROP_BOOL("force-secure-boot", uefi_vars_sysbus_state, state.force_secure_boot, false), DEFINE_PROP_BOOL("disable-custom-mode", uefi_vars_sysbus_state, - state.disable_custom_mode, false), + state.disable_custom_mode, true), DEFINE_PROP_BOOL("require-self-signed-pk", uefi_vars_sysbus_state, - state.require_self_signed_pk, true), + state.require_self_signed_pk, false), DEFINE_PROP_BOOL("use-pio", uefi_vars_sysbus_state, state.use_pio, false), }; --=20 2.55.0