]> git.proxmox.com Git - mirror_edk2.git/commit - OvmfPkg/OvmfPkg.dec
OvmfPkg/AmdSev: add Grub Firmware Volume Package
authorJames Bottomley <jejb@linux.ibm.com>
Mon, 30 Nov 2020 20:28:16 +0000 (12:28 -0800)
committermergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
Mon, 14 Dec 2020 19:56:18 +0000 (19:56 +0000)
commitb261a30c900a81b76c18bcc71841aab13849d069
tree92a4a12dd7e1e3628d17dbfeb330d6ba8bff8c59
parent30d277ed7a820891b0d85ccc223d05789b1d6148
OvmfPkg/AmdSev: add Grub Firmware Volume Package

This is used to package up the grub bootloader into a firmware volume
where it can be executed as a shell like the UEFI Shell.  Grub itself
is built as a minimal entity into a Fv and then added as a boot
option.  By default the UEFI shell isn't built but for debugging
purposes it can be enabled and will then be presented as a boot option
(This should never be allowed for secure boot in an external data
centre but may be useful for local debugging).  Finally all other boot
options except grub and possibly the shell are stripped and the boot
timeout forced to 0 so the system will not enter a setup menu and will
only boot to grub.  This is done by copying the
Library/PlatformBootManagerLib into Library/PlatformBootManagerLibGrub
and then customizing it.

Boot failure is fatal to try to prevent secret theft.

Ref: https://bugzilla.tianocore.org/show_bug.cgi?id=3077
Signed-off-by: James Bottomley <jejb@linux.ibm.com>
Message-Id: <20201130202819.3910-4-jejb@linux.ibm.com>
Acked-by: Ard Biesheuvel <ard.biesheuvel@arm.com>
[lersek@redhat.com: replace local variable initialization with assignment]
Reviewed-by: Laszlo Ersek <lersek@redhat.com>
[lersek@redhat.com: squash 'OvmfPkg: add "gGrubFileGuid=Grub" to
 GuidCheck.IgnoreDuplicates', reviewed stand-alone by Phil (msgid
 <e6eae551-8563-ccfb-5547-7a97da6d46e5@redhat.com>) and Ard (msgid
 <10aeda37-def6-d9a4-6e02-4c66c1492f57@arm.com>)]
12 files changed:
OvmfPkg/AmdSev/AmdSevX64.dsc
OvmfPkg/AmdSev/AmdSevX64.fdf
OvmfPkg/AmdSev/Grub/.gitignore [new file with mode: 0644]
OvmfPkg/AmdSev/Grub/Grub.inf [new file with mode: 0644]
OvmfPkg/AmdSev/Grub/grub.cfg [new file with mode: 0644]
OvmfPkg/AmdSev/Grub/grub.sh [new file with mode: 0644]
OvmfPkg/Library/PlatformBootManagerLibGrub/BdsPlatform.c [new file with mode: 0644]
OvmfPkg/Library/PlatformBootManagerLibGrub/BdsPlatform.h [new file with mode: 0644]
OvmfPkg/Library/PlatformBootManagerLibGrub/PlatformBootManagerLibGrub.inf [new file with mode: 0644]
OvmfPkg/Library/PlatformBootManagerLibGrub/PlatformData.c [new file with mode: 0644]
OvmfPkg/OvmfPkg.ci.yaml
OvmfPkg/OvmfPkg.dec