Branch: refs/heads/master
Home: https://github.com/tianocore/edk2
Commit: 8d7ecf12772131faebf9ed7f06c77d3f30f94c62
https://github.com/tianocore/edk2/commit/8d7ecf12772131faebf9ed7f06c77d3f30f94c62
Author: Dongyan Qian <[email protected]>
Date: 2026-03-20 (Fri, 20 Mar 2026)
Changed paths:
M OvmfPkg/LoongArchVirt/LoongArchVirtQemu.dsc
M OvmfPkg/LoongArchVirt/LoongArchVirtQemu.fdf
Log Message:
-----------
OvmfPkg/LoongArchVirt: Add Secure Boot support
Add Secure Boot framework for LoongArchVirt by enabling:
- AuthVariableLib and SecureBootVariableLib for authenticated variable handling
- DxeImageVerificationLib for image verification
- SecureBootConfigDxe for Secure Boot configuration
Secure Boot can be enabled by setting SECURE_BOOT_ENABLE=TRUE during build:
build -D SECURE_BOOT_ENABLE=TRUE
Signed-off-by: Dongyan Qian <[email protected]>
Cc: Chao Li <[email protected]>
Cc: Bibo Mao <[email protected]>
Cc: Xianglai Li <[email protected]>
Cc: Bo Zhu <[email protected]>
Cc: Gerd Hoffmann <[email protected]>
Cc: Ard Biesheuvel <[email protected]>
Cc: Jiewen Yao <[email protected]>
Cc: Gerd Hoffmann <[email protected]>
Cc: Mike Beaton <[email protected]>
Commit: e98e311062f23527b7be9869f3911b519b3e7025
https://github.com/tianocore/edk2/commit/e98e311062f23527b7be9869f3911b519b3e7025
Author: Dongyan Qian <[email protected]>
Date: 2026-03-20 (Fri, 20 Mar 2026)
Changed paths:
A OvmfPkg/LoongArchVirt/Feature/SecureBoot/SecureBootKeys/README.md
M OvmfPkg/LoongArchVirt/LoongArchVirtQemu.dsc
M OvmfPkg/LoongArchVirt/LoongArchVirtQemu.fdf
Log Message:
-----------
OvmfPkg/LoongArchVirt: Add Secure Boot key layout scaffolding
Add the LoongArchVirt Secure Boot key directory layout and build wiring used
for local validation and future platform-specific key provisioning.
SECURE_BOOT_DEFAULT_KEYS remains disabled by default. Integrators may populate
PK/KEK/db artifacts out of tree and enable the switch locally when validating
embedded default-key enrollment flows.
Default Secure Boot key can be enabled by setting SECURE_BOOT_DEFAULT_KEYS=TRUE
during build.
Test results:
EFI UnSigned:
Image is not signed and SHA1 hash of image is not found in DB/DBX.
EFI Signed:
MeasureVariable (Pcr - 7, EventType - 800000E0, VariableName - db, VendorGuid -
xxx),
MeasureBootPolicyVariable - Success.
Signed-off-by: Dongyan Qian <[email protected]>
Cc: Chao Li <[email protected]>
Cc: Bibo Mao <[email protected]>
Cc: Xianglai Li <[email protected]>
Cc: Bo Zhu <[email protected]>
Cc: Gerd Hoffmann <[email protected]>
Cc: Ard Biesheuvel <[email protected]>
Cc: Jiewen Yao <[email protected]>
Cc: Gerd Hoffmann <[email protected]>
Cc: Mike Beaton <[email protected]>
Commit: 644e5790cdc59f9234a84ede77de9d8f9aa0327b
https://github.com/tianocore/edk2/commit/644e5790cdc59f9234a84ede77de9d8f9aa0327b
Author: Dongyan Qian <[email protected]>
Date: 2026-03-20 (Fri, 20 Mar 2026)
Changed paths:
M OvmfPkg/VirtMmCommunicationDxe/VirtMmCommunication.c
M OvmfPkg/VirtMmCommunicationDxe/VirtMmCommunication.inf
Log Message:
-----------
OvmfPkg/VirtMmCommunicationDxe: enable loongarch64
For QEMU version support references, please see:
https://github.com/qemu/qemu/commit/e1092f765d9c0bf33762a03fe45e3d0de86c86a6
Suggested-by: Gerd Hoffmann <[email protected]>
Signed-off-by: Dongyan Qian <[email protected]>
Cc: Chao Li <[email protected]>
Cc: Bibo Mao <[email protected]>
Cc: Xianglai Li <[email protected]>
Cc: Bo Zhu <[email protected]>
Cc: Ard Biesheuvel <[email protected]>
Cc: Jiewen Yao <[email protected]>
Cc: Gerd Hoffmann <[email protected]>
Cc: Mike Beaton <[email protected]>
Commit: 4018823b6399d5ec86c7bb71c32c542656b41b39
https://github.com/tianocore/edk2/commit/4018823b6399d5ec86c7bb71c32c542656b41b39
Author: Dongyan Qian <[email protected]>
Date: 2026-03-20 (Fri, 20 Mar 2026)
Changed paths:
M OvmfPkg/LoongArchVirt/LoongArchVirtQemu.dsc
M OvmfPkg/LoongArchVirt/LoongArchVirtQemu.fdf
Log Message:
-----------
OvmfPkg/LoongArchVirt: enable qemu uefi variable store support
Add QEMU_PV_VARS build option, when enables the firmware build will
support (and require) the qemu uefi variable store.
This also enables proper (as-in: actually being secure) secure boot
support.
Suggested-by: Gerd Hoffmann <[email protected]>
Signed-off-by: Dongyan Qian <[email protected]>
Cc: Chao Li <[email protected]>
Cc: Bibo Mao <[email protected]>
Cc: Xianglai Li <[email protected]>
Cc: Bo Zhu <[email protected]>
Cc: Ard Biesheuvel <[email protected]>
Cc: Jiewen Yao <[email protected]>
Cc: Gerd Hoffmann <[email protected]>
Cc: Mike Beaton <[email protected]>
Compare: https://github.com/tianocore/edk2/compare/ff2543960090...4018823b6399
To unsubscribe from these emails, change your notification settings at
https://github.com/tianocore/edk2/settings/notifications
_______________________________________________
edk2-commits mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/edk2-commits