Branch: refs/heads/master
  Home:   https://github.com/tianocore/edk2
  Commit: 61733cb16c5d6c1b50fbff291b87fedb0fe74755
      
https://github.com/tianocore/edk2/commit/61733cb16c5d6c1b50fbff291b87fedb0fe74755
  Author: Gerd Hoffmann <[email protected]>
  Date:   2026-08-27 (Thu, 27 Aug 2026)

  Changed paths:
    M OvmfPkg/QemuFlashFvbServicesRuntimeDxe/FvbServicesRuntimeDxe.inf
    M OvmfPkg/QemuFlashFvbServicesRuntimeDxe/FvbServicesSmm.inf
    M OvmfPkg/QemuFlashFvbServicesRuntimeDxe/FvbServicesStandaloneMm.inf
    M OvmfPkg/QemuFlashFvbServicesRuntimeDxe/QemuFlash.c

  Log Message:
  -----------
  OvmfPkg/QemuFlashFvbServicesRuntimeDxe: reject insecure pflash config

In case the variable store is backed by qemu pflash make sure the edk2
build and the virtual machine setup are properly configured for secure
boot.

With this patch applied the pflash driver will only load if:
  (a) The edk2 build uses SMM to properly protect pflash storage, or
  (b) The edk2 build has secure boot support turned off.

Should that not be the case the firmware will CpuDeadLoop().

Signed-off-by: Gerd Hoffmann <[email protected]>



To unsubscribe from these emails, change your notification settings at 
https://github.com/tianocore/edk2/settings/notifications


_______________________________________________
edk2-commits mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/edk2-commits

Reply via email to