From nobody Sun Sep 14 08:41:15 2025 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=reject dis=none) header.from=cloud.com ARC-Seal: i=1; a=rsa-sha256; t=1757579103; cv=none; d=zohomail.com; s=zohoarc; b=UzFpBhrtHuGb44LwiX/BwzW5fSMFvW/vbx0LIbe2bQjF0DZEit3vZU5X96Hbsf1LXWbPb1NnpX9kDEe3Vn+8NHRhmEZKjgFurptDvNHgjK49nVI/joSOV0J0OFyCWj7ETYO4wme6hoO4qC+onz6L5i9WkyAOQ2SgfWBJqJG8QEs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1757579103; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Hl9F9GdCq3XbjB4Z6CoXc+8IbHjldBrhiMbyobpL14w=; b=Dmp/UaSsIoybyYAORU5snoGsMpAfOD5m26afUHvOSJyak/YmJcwGE4qamxgfT3qP71lf/w7ZbW/q9WMfKCafKxnYR1hugNyHDLkWJmlxdo6ljcMocDI6mfdpM6YqJA2hm3EDXsbtc7e2cXWdiflx7u0CB9WGmAtCP4jox/uQBsA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1757579103488632.2587357819825; Thu, 11 Sep 2025 01:25:03 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1119699.1464994 (Exim 4.92) (envelope-from ) id 1uwcbk-0007wk-6j; Thu, 11 Sep 2025 08:24:44 +0000 Received: by outflank-mailman (output) from mailman id 1119699.1464994; Thu, 11 Sep 2025 08:24:44 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1uwcbk-0007wZ-1n; Thu, 11 Sep 2025 08:24:44 +0000 Received: by outflank-mailman (input) for mailman id 1119699; Thu, 11 Sep 2025 08:24:43 +0000 Received: from se1-gles-flk1-in.inumbo.com ([94.247.172.50] helo=se1-gles-flk1.inumbo.com) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1uwcbi-0007Fi-VF for xen-devel@lists.xenproject.org; Thu, 11 Sep 2025 08:24:42 +0000 Received: from mail-ed1-x533.google.com (mail-ed1-x533.google.com [2a00:1450:4864:20::533]) by se1-gles-flk1.inumbo.com (Halon) with ESMTPS id c38985a8-8ee8-11f0-9809-7dc792cee155; Thu, 11 Sep 2025 10:24:41 +0200 (CEST) Received: by mail-ed1-x533.google.com with SMTP id 4fb4d7f45d1cf-6188b72b7caso453389a12.2 for ; Thu, 11 Sep 2025 01:24:41 -0700 (PDT) Received: from eddie5.eng.citrite.net ([185.25.67.249]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-62ec33b4d63sm699314a12.23.2025.09.11.01.24.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 11 Sep 2025 01:24:40 -0700 (PDT) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" X-Inumbo-ID: c38985a8-8ee8-11f0-9809-7dc792cee155 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloud.com; s=cloud; t=1757579081; x=1758183881; darn=lists.xenproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=Hl9F9GdCq3XbjB4Z6CoXc+8IbHjldBrhiMbyobpL14w=; b=fr0h3FTIxmM+G4o1dmsolkSZje1J3/tPXvZSITkGeUfjrysK9MAyPT3w73nLqejlbx XM2fylkZk++4QwjkJvHMxfUFcUursUBbQZnzWOhKvASB0O4HVQsK2pVx1w4wudg2oKMO mMOF4VY9NW42zlWRo0Ink9O6nl2wPtNZBMUlc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1757579081; x=1758183881; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=Hl9F9GdCq3XbjB4Z6CoXc+8IbHjldBrhiMbyobpL14w=; b=dabbcyCveCATqLHkCr9t+Hi49Pa/NoSWXnciMFjHMK4gYeBo4E5t/n1wWKPWdscWxo XAbqoE3/0S5ArCw9VdwuakMifElu+aBmftDo8La6SsAu3nstfVXWwCHFHhMrdpJBYQMT QdTb9z1XOiFQCOwFFeuTXV2vYjaRJkcKkgwqufhhNj3x2ihbYk6ahZYyxE9eOLSsQIa/ hLF83vuhUVX8WnaZ1h1uglJE/CiZmfvBv44IEM8duDreOWYsOoZardwdR9oyUvYYXkhv CFa7UZZfthNrxzgLXvwhjdF1IafW+EvZurHvprfW4cmC7Dv1+EsQhcSBTXkhjY8JBxlJ 01QQ== X-Gm-Message-State: AOJu0YxY28lulxA3ZuIqd4W9vo/LrZkvc9/yTuNQ2YrqGDMERmqDELIm TX+29L4rLBfS4MICVz5T6iHi3/2+ehfudjeE+QwHjnzgJhAPLqeL3ZJQdRo85HG13V4PAJ6Q7kR ewPQm X-Gm-Gg: ASbGncsFVJMNShJnssiaMfJLnC1S9CV9h1BbRL4kdhj2ZKqYM6avuqr5+FKSt5kO3vB skSqKfiazWtEiJU97rDYQuoHhKIPJrW803CA/o8Hdo3r242D7wrQ5WUmzRyifK5ovb2XQGE7i3q w+cCdc1QwFmP/QOfT/UF8Z2IQPl5Y6EeyzyFBbQ9r2PVmYm5S6MKCrpqF1y/Ea7LK0IPX8014Rv +WSeqsICs1QvRalQ6z6M4vSuDfLRh4rC8MyfuBUU462Az4ZjUGK9vvKetSHxtV/YeUW7pahfequ pJ215mUwO1FjpmGn+hHwq1+VSrmbAoPECCf9VhECOzC8Hn1Z19yBKeRvbtLa+Dv+8Vl5zd238JY UxtrmO43xyXGdqFuAsnmEcR090GL47B1cPeXxPKWxsgTszw== X-Google-Smtp-Source: AGHT+IEKYdGW49F1QRWZFaaOhXYtDEMXUm2DU7DUuF8lWq0D1h9ghowYA5zkYThRoQSb4KytgD1/BQ== X-Received: by 2002:a05:6402:5049:b0:61c:e99d:fdef with SMTP id 4fb4d7f45d1cf-62372bbf6cdmr15573109a12.2.1757579080505; Thu, 11 Sep 2025 01:24:40 -0700 (PDT) From: Gerald Elder-Vass To: Xen-devel Cc: Gerald Elder-Vass , =?UTF-8?q?Marek=20Marczykowski-G=C3=B3recki?= , "Daniel P. Smith" , Jan Beulich , Andrew Cooper , Anthony PERARD , Michal Orzel , Julien Grall , =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= , Stefano Stabellini Subject: [PATCH 3/3] efi: Limit Shim's Verify success to EFI_SUCCESS Date: Thu, 11 Sep 2025 08:24:29 +0000 Message-ID: <20fa42c198ab257085a49e157a2d0e58a0010393.1757519202.git.gerald.elder-vass@cloud.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-ZohoMail-DKIM: pass (identity @cloud.com) X-ZM-MESSAGEID: 1757579107153116600 Commit 59a1d6d3ea1e replaced the Verify status check with !EFI_ERROR(...), this changed the behaviour to consider any warnings (EFI_WARN_) to be considered a successful verification. This commit reverts that behaviour change. Signed-off-by: Gerald Elder-Vass Reported-by: Jan Beulich Reviewed-by: Jan Beulich --- CC: Marek Marczykowski-G=C3=B3recki CC: "Daniel P. Smith" CC: Jan Beulich CC: Andrew Cooper CC: Anthony PERARD CC: Michal Orzel CC: Julien Grall CC: "Roger Pau Monn=C3=A9" CC: Stefano Stabellini --- xen/common/efi/boot.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/xen/common/efi/boot.c b/xen/common/efi/boot.c index ca162db0d8d3..36e1e2cf9d4a 100644 --- a/xen/common/efi/boot.c +++ b/xen/common/efi/boot.c @@ -1090,7 +1090,7 @@ static void __init efi_verify_kernel(EFI_HANDLE Image= Handle) if ( !verified && !EFI_ERROR(efi_bs->LocateProtocol(&shim_lock_guid, NULL, (void **)&shim_lock)) && - !EFI_ERROR(shim_lock->Verify(kernel.ptr, kernel.size)) ) + shim_lock->Verify(kernel.ptr, kernel.size) =3D=3D EFI_SUCCESS ) verified =3D true; =20 if ( !verified ) --=20 2.47.3