Branch: refs/heads/master
  Home:   https://github.com/tianocore/edk2
  Commit: 8d7ecf12772131faebf9ed7f06c77d3f30f94c62
      
https://github.com/tianocore/edk2/commit/8d7ecf12772131faebf9ed7f06c77d3f30f94c62
  Author: Dongyan Qian <[email protected]>
  Date:   2026-03-20 (Fri, 20 Mar 2026)

  Changed paths:
    M OvmfPkg/LoongArchVirt/LoongArchVirtQemu.dsc
    M OvmfPkg/LoongArchVirt/LoongArchVirtQemu.fdf

  Log Message:
  -----------
  OvmfPkg/LoongArchVirt: Add Secure Boot support

Add Secure Boot framework for LoongArchVirt by enabling:
- AuthVariableLib and SecureBootVariableLib for authenticated variable handling
- DxeImageVerificationLib for image verification
- SecureBootConfigDxe for Secure Boot configuration

Secure Boot can be enabled by setting SECURE_BOOT_ENABLE=TRUE during build:
  build -D SECURE_BOOT_ENABLE=TRUE

Signed-off-by: Dongyan Qian <[email protected]>
Cc: Chao Li <[email protected]>
Cc: Bibo Mao <[email protected]>
Cc: Xianglai Li <[email protected]>
Cc: Bo Zhu <[email protected]>
Cc: Gerd Hoffmann <[email protected]>
Cc: Ard Biesheuvel <[email protected]>
Cc: Jiewen Yao <[email protected]>
Cc: Gerd Hoffmann <[email protected]>
Cc: Mike Beaton <[email protected]>


  Commit: e98e311062f23527b7be9869f3911b519b3e7025
      
https://github.com/tianocore/edk2/commit/e98e311062f23527b7be9869f3911b519b3e7025
  Author: Dongyan Qian <[email protected]>
  Date:   2026-03-20 (Fri, 20 Mar 2026)

  Changed paths:
    A OvmfPkg/LoongArchVirt/Feature/SecureBoot/SecureBootKeys/README.md
    M OvmfPkg/LoongArchVirt/LoongArchVirtQemu.dsc
    M OvmfPkg/LoongArchVirt/LoongArchVirtQemu.fdf

  Log Message:
  -----------
  OvmfPkg/LoongArchVirt: Add Secure Boot key layout scaffolding

Add the LoongArchVirt Secure Boot key directory layout and build wiring used
for local validation and future platform-specific key provisioning.

SECURE_BOOT_DEFAULT_KEYS remains disabled by default. Integrators may populate
PK/KEK/db artifacts out of tree and enable the switch locally when validating
embedded default-key enrollment flows.

Default Secure Boot key can be enabled by setting SECURE_BOOT_DEFAULT_KEYS=TRUE 
during build.

Test results:
EFI UnSigned:
Image is not signed and SHA1 hash of image is not found in DB/DBX.
EFI Signed:
MeasureVariable (Pcr - 7, EventType - 800000E0, VariableName - db, VendorGuid - 
xxx),
MeasureBootPolicyVariable - Success.

Signed-off-by: Dongyan Qian <[email protected]>
Cc: Chao Li <[email protected]>
Cc: Bibo Mao <[email protected]>
Cc: Xianglai Li <[email protected]>
Cc: Bo Zhu <[email protected]>
Cc: Gerd Hoffmann <[email protected]>
Cc: Ard Biesheuvel <[email protected]>
Cc: Jiewen Yao <[email protected]>
Cc: Gerd Hoffmann <[email protected]>
Cc: Mike Beaton <[email protected]>


  Commit: 644e5790cdc59f9234a84ede77de9d8f9aa0327b
      
https://github.com/tianocore/edk2/commit/644e5790cdc59f9234a84ede77de9d8f9aa0327b
  Author: Dongyan Qian <[email protected]>
  Date:   2026-03-20 (Fri, 20 Mar 2026)

  Changed paths:
    M OvmfPkg/VirtMmCommunicationDxe/VirtMmCommunication.c
    M OvmfPkg/VirtMmCommunicationDxe/VirtMmCommunication.inf

  Log Message:
  -----------
  OvmfPkg/VirtMmCommunicationDxe: enable loongarch64

For QEMU version support references, please see:
https://github.com/qemu/qemu/commit/e1092f765d9c0bf33762a03fe45e3d0de86c86a6

Suggested-by: Gerd Hoffmann <[email protected]>
Signed-off-by: Dongyan Qian <[email protected]>
Cc: Chao Li <[email protected]>
Cc: Bibo Mao <[email protected]>
Cc: Xianglai Li <[email protected]>
Cc: Bo Zhu <[email protected]>
Cc: Ard Biesheuvel <[email protected]>
Cc: Jiewen Yao <[email protected]>
Cc: Gerd Hoffmann <[email protected]>
Cc: Mike Beaton <[email protected]>


  Commit: 4018823b6399d5ec86c7bb71c32c542656b41b39
      
https://github.com/tianocore/edk2/commit/4018823b6399d5ec86c7bb71c32c542656b41b39
  Author: Dongyan Qian <[email protected]>
  Date:   2026-03-20 (Fri, 20 Mar 2026)

  Changed paths:
    M OvmfPkg/LoongArchVirt/LoongArchVirtQemu.dsc
    M OvmfPkg/LoongArchVirt/LoongArchVirtQemu.fdf

  Log Message:
  -----------
  OvmfPkg/LoongArchVirt: enable qemu uefi variable store support

Add QEMU_PV_VARS build option, when enables the firmware build will
support (and require) the qemu uefi variable store.

This also enables proper (as-in: actually being secure) secure boot
support.

Suggested-by: Gerd Hoffmann <[email protected]>
Signed-off-by: Dongyan Qian <[email protected]>
Cc: Chao Li <[email protected]>
Cc: Bibo Mao <[email protected]>
Cc: Xianglai Li <[email protected]>
Cc: Bo Zhu <[email protected]>
Cc: Ard Biesheuvel <[email protected]>
Cc: Jiewen Yao <[email protected]>
Cc: Gerd Hoffmann <[email protected]>
Cc: Mike Beaton <[email protected]>


Compare: https://github.com/tianocore/edk2/compare/ff2543960090...4018823b6399

To unsubscribe from these emails, change your notification settings at 
https://github.com/tianocore/edk2/settings/notifications


_______________________________________________
edk2-commits mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/edk2-commits

Reply via email to