On 12/18/23 07:41, Michael Tokarev wrote: <snip />
Yes, we can do that. I don't see much benefit here though. For one, I dislike dangling symlinks in package, and don't want to add yet another directory to firmware search directories.
OpenSBI is security critical as it runs in the highest privilege mode at Linux runtime. There have been potentially security relevant code errors detected in the past like buffer overruns.
I am concerned that security errors fixed in the OpenSBI package might not be fixed in qemu-system-data at the same time. For the security team it would be much more evident what to fix if there were only one package building OpenSBI.
Best regards Heinrich