Hi Ian

Apologies for the late reply.

I am on PTO, I'll have a look next week

Cheers
/Ilias

On Fri, 10 Jul 2026 at 16:24, Ian Mullins <[email protected]> wrote:

> This series implements the EFI_SECURITY_ARCH_PROTOCOL and
> EFI_SECURITY2_ARCH_PROTOCOL. The primary motivation is to support EFI
> applications like systemd-stub in Unified Kernel Images (UKI) so they
> can temporarily override authentication for embedded payloads.
>
> Note: This work was originally authored by Enric Balletbo i Serra.
> I am submitting it upstream on his behalf with additional testing.
>
> ---
> Testing Performed
>
> I have validated these patches across various secure boot scenarios on
> both physical hardware and emulators to ensure the new overrides work
> without regressing standard secure boot enforcement.
>
> Hardware: Renesas R-Car S4 (EBBR UKI boot)
> - [PASS] Unsigned image, Secure Boot disabled, without patch
>   (Boots)
> - [PASS] Unsigned image, Secure Boot compiled (not enforcing),
>   without patch (Boots)
> - [PASS] Signed image, Secure Boot enforcing, without patch
>   (Fails to boot as expected)
> - [PASS] Signed image, Secure Boot enforcing, with patch
>   (Boots successfully)
> - [PASS] Signed image (wrong keys), Secure Boot enforcing, with patch
>   (Fails to boot as expected)
>
> Emulator: QEMU (qemu UKI boot)
> - [PASS] Unsigned image, Secure Boot disabled, without patch
>   (Boots)
> - [PASS] Unsigned image, Secure Boot enabled, without patch
>   (Boots)
> - [PASS] Signed image, Secure Boot enabled, without patch
>   (Fails to boot as expected)
> - [PASS] Signed image, Secure Boot enabled, with patch
>   (Boots successfully)
>
> Signed-off-by: Ian Mullins <[email protected]>
>
> ---
> Enric Balletbo i Serra (2):
>       efi_loader: implement EFI Security Architecture protocols
>       efi_selftest: add tests for security architecture protocols
>
>  include/efi_api.h                                  |  30 +++
>  include/efi_loader.h                               |  15 +-
>  lib/efi_loader/Kconfig                             |  11 ++
>  lib/efi_loader/Makefile                            |   1 +
>  lib/efi_loader/efi_boottime.c                      |   3 +-
>  lib/efi_loader/efi_image_loader.c                  |  31 ++-
>  lib/efi_loader/efi_security.c                      |  99 ++++++++++
>  lib/efi_loader/efi_setup.c                         |   7 +
>  lib/efi_selftest/Makefile                          |   1 +
>  lib/efi_selftest/efi_selftest_security_arch.c      | 110 +++++++++++
>  .../py/tests/test_efi_secboot/README.security_arch | 208
> +++++++++++++++++++++
>  .../tests/test_efi_secboot/test_security_arch.py   |  73 ++++++++
>  12 files changed, 580 insertions(+), 9 deletions(-)
> ---
> base-commit: 913fedc816570c07bfc7f9c4046dc2a3a55e4099
> change-id: 20260710-efi_security_protocol-6b9fb0e8da41
>
> Best regards,
> --
> Ian Mullins <[email protected]>
>
>

Reply via email to