[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[PATCH v1 0/2] Secure Boot Advanced Targeting (SBAT) support on powerpc
From: |
Sudhakar Kuppusamy |
Subject: |
[PATCH v1 0/2] Secure Boot Advanced Targeting (SBAT) support on powerpc |
Date: |
Thu, 6 Jun 2024 21:44:08 +0530 |
In powerpc, PE format Binary are not supported and can't use shim
(https://github.com/rhboot/shim/blob/main/SBAT.md).
However, ELF binary are supported. So, we created new ELF note for SBAT in ELF
binary which store the SBAT data and
SBAT verifier will be there in firmware to read SBAT data from ELF note and
validate it.
this patch series consists of 2 parts:
1) Patch 1: create new ELF Note for SBAT
we add a new ELF note for SBAT which store the SBAT data.
The name field of shall be the string "Secure-Boot-Advanced-Targeting",
zero-padded
to 4 byte alignment. The type field shall be 0x41536967 (the ASCII values
for the string "sbat").
2) Patch 2: adding sbat data into sbat ELF Note
it reads the SBAT data from sbat.csv and create the ELF Note for it then
store the SBAT data on it while generate image with -s option
Sudhakar Kuppusamy (2):
mkimage: create new ELF Note for SBAT
mkimage: adding sbat data into sbat ELF Note on powerpc
include/grub/util/mkimage.h | 4 +--
util/grub-mkimagexx.c | 59 ++++++++++++++++++++++++++++++++-----
util/mkimage.c | 19 +++++++++---
3 files changed, 68 insertions(+), 14 deletions(-)
--
2.39.3
- [PATCH v1 0/2] Secure Boot Advanced Targeting (SBAT) support on powerpc,
Sudhakar Kuppusamy <=