summary refs log tree commit diff stats
diff options
context:
space:
mode:
authorGerd Hoffmann <kraxel@redhat.com>2024-09-05 16:12:07 +0200
committerGerd Hoffmann <kraxel@redhat.com>2024-12-16 07:31:28 +0100
commit57e2cc9abf5da38f600354fe920ff20e719607b4 (patch)
treee941a0b159cc4dca2c6c6d43dbe7e07f807a0abb
parentca80a5d026a280762e0772615f1988db542b3ade (diff)
downloadfocaccia-qemu-57e2cc9abf5da38f600354fe920ff20e719607b4.tar.gz
focaccia-qemu-57e2cc9abf5da38f600354fe920ff20e719607b4.zip
x86/loader: only patch linux kernels
If the binary loaded via -kernel is *not* a linux kernel (in which
case protocol == 0), do not patch the linux kernel header fields.

It's (a) pointless and (b) might break binaries by random patching
and (c) changes the binary hash which in turn breaks secure boot
verification.

Background: OVMF happily loads and runs not only linux kernels but
any efi binary via direct kernel boot.

Note: Breaking the secure boot verification is a problem for linux
kernels too, but fixed that is left for another day ...

Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
Message-ID: <20240905141211.1253307-3-kraxel@redhat.com>
-rw-r--r--hw/i386/x86-common.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/hw/i386/x86-common.c b/hw/i386/x86-common.c
index dc031af662..dadc9d99e7 100644
--- a/hw/i386/x86-common.c
+++ b/hw/i386/x86-common.c
@@ -945,7 +945,7 @@ void x86_load_linux(X86MachineState *x86ms,
      * kernel on the other side of the fw_cfg interface matches the hash of the
      * file the user passed in.
      */
-    if (!sev_enabled()) {
+    if (!sev_enabled() && protocol > 0) {
         memcpy(setup, header, MIN(sizeof(header), setup_size));
     }