<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>11030</bug_id>
          
          <creation_ts>2017-02-08 09:13:16 +0000</creation_ts>
          <short_desc>RMC: systemd-boot EFI stub: Don&apos;t read RMC db in SecureBoot mode</short_desc>
          <delta_ts>2020-06-25 08:41:20 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>BSPs</product>
          <component>bsps-meta-intel</component>
          <version>unspecified</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>OBSOLETE</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>Future</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Mikko Ylinen">mikko.ylinen</reporter>
          <assigned_to name="Unassigned">unassigned</assigned_to>
          <cc>california.l.sullivan</cc>
    
    <cc>patrick.ohly</cc>
    
    <cc>richard.purdie</cc>
    
    <cc>sgw</cc>
    
    <cc>tim.orling</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>70531</commentid>
    <comment_count>0</comment_count>
    <who name="Mikko Ylinen">mikko.ylinen</who>
    <bug_when>2017-02-08 09:13:16 +0000</bug_when>
    <thetext>The systemd-boot patches that enable RMC for the EFI stub need to be changed so that RMC db is not read when the BIOS has secure boot enabled.

I&apos;ll assign this to myself and work on the fix.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>70712</commentid>
    <comment_count>1</comment_count>
    <who name="Patrick Ohly">patrick.ohly</who>
    <bug_when>2017-02-15 11:30:13 +0000</bug_when>
    <thetext>In addition to preventing reading the DB from the VFAT system partition when Secure Boot is active, please consider supporting a DB that is embedded inside the UEFI combo app. That DB can remain active.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>70986</commentid>
    <comment_count>2</comment_count>
    <who name="Mikko Ylinen">mikko.ylinen</who>
    <bug_when>2017-02-28 15:32:31 +0000</bug_when>
    <thetext>submitted to meta-intel:
https://lists.yoctoproject.org/pipermail/meta-intel/2017-February/004625.html</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>75128</commentid>
    <comment_count>3</comment_count>
    <who name="Patrick Ohly">patrick.ohly</who>
    <bug_when>2017-07-19 07:28:18 +0000</bug_when>
    <thetext>(In reply to comment #1)
&gt; In addition to preventing reading the DB from the VFAT system partition when
&gt; Secure Boot is active, please consider supporting a DB that is embedded
&gt; inside the UEFI combo app. That DB can remain active.

I don&apos;t remember whether this was discussed. I thought it had been implemented, but current refkit code still deploys rmc.db separately.

Populating /boot with additional files is problematic for system update, because we only have support in place for updating the combo app, but not for additional files. So the rmc.db isn&apos;t going to get updated on devices.

We probably need a new feature request (either for embedding rmc.db or for supporting in in system update), depending on how we want to handle this.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>75678</commentid>
    <comment_count>4</comment_count>
    <who name="Mikko Ylinen">mikko.ylinen</who>
    <bug_when>2017-08-07 08:24:50 +0000</bug_when>
    <thetext>(In reply to comment #3)
&gt; (In reply to comment #1)
&gt; &gt; In addition to preventing reading the DB from the VFAT system partition when
&gt; &gt; Secure Boot is active, please consider supporting a DB that is embedded
&gt; &gt; inside the UEFI combo app. That DB can remain active.
&gt; 
&gt; I don&apos;t remember whether this was discussed. I thought it had been
&gt; implemented, but current refkit code still deploys rmc.db separately.
&gt; 

The patch was sent out (see Comment #2) but Saul did not merge it. The reasons are probably obsolete by now so the patch can probably rebased.

Saul, what do you think?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>77629</commentid>
    <comment_count>5</comment_count>
    <who name="Mikko Ylinen">mikko.ylinen</who>
    <bug_when>2017-10-17 04:51:07 +0000</bug_when>
    <thetext>The existing patch is still applicable to meta-intel but it has not been applied. Also, a tool/script is available to update uefi combo app elements.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>78198</commentid>
    <comment_count>6</comment_count>
    <who name="Mikko Ylinen">mikko.ylinen</who>
    <bug_when>2017-11-14 12:27:40 +0000</bug_when>
    <thetext>Re-assign to meta-intel.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>78302</commentid>
    <comment_count>7</comment_count>
    <who name="Saul Wold">sgw</who>
    <bug_when>2017-11-21 21:54:43 +0000</bug_when>
    <thetext>https://lists.yoctoproject.org/pipermail/meta-intel/2017-February/004625.html

This patch had been proposed, but had some discussion that Todor can maybe add additional info to here.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>78305</commentid>
    <comment_count>8</comment_count>
    <who name="Todor Minchev">todor.minchev</who>
    <bug_when>2017-11-21 22:40:10 +0000</bug_when>
    <thetext>This patch assumes that rmb.db will be always build into the systemd-boot STUB. If we are not going to support standalone rmb.db files on the EFI partition, then this should be safe to merge. Otherwise we need to have a mechanism to differentiate between running in secureboot mode when rmc.db can be read only from the .rmc section of systemd-boot and non-secureboot mode when it can be read from both the .rmc section of systemd-boot and the EFI partition.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>78312</commentid>
    <comment_count>9</comment_count>
    <who name="Mikko Ylinen">mikko.ylinen</who>
    <bug_when>2017-11-22 06:03:37 +0000</bug_when>
    <thetext>(In reply to comment #8)
&gt; This patch assumes that rmb.db will be always build into the systemd-boot

That&apos;s not exactly true. The patched stub checks whether &quot;.rmc&quot; section is there
or not and behaves accordingly. With this patch applied, it&apos;s still possible to run UEFI combo app without the .rmc section built in.

&gt; STUB. If we are not going to support standalone rmb.db files on the EFI
&gt; partition, then this should be safe to merge. Otherwise we need to have a
&gt; mechanism to differentiate between running in secureboot mode when rmc.db
&gt; can be read only from the .rmc section of systemd-boot and non-secureboot
&gt; mode when it can be read from both the .rmc section of systemd-boot and the
&gt; EFI partition.

IMO, it&apos;s much better to always keep .rmc built in the uefi combo app. That&apos;s where all other boot artifacts are kept too.

One of the reasons the patch was not put on hold was the concern about rmc.db updateability on the target. I wrote a script to address the use case where UEFI-combo app is used + rmc.db (or some other section, e.g., .cmdline) needs to be changed but never pushed it for a review. Let me attach it here if it helps.

The script could be installed in rmc-tools package.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>78313</commentid>
    <comment_count>10</comment_count>
      <attachid>4128</attachid>
    <who name="Mikko Ylinen">mikko.ylinen</who>
    <bug_when>2017-11-22 06:04:45 +0000</bug_when>
    <thetext>Created attachment 4128
script: change EFI blob sections

Attached the script mentioned in comment #9</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>87607</commentid>
    <comment_count>11</comment_count>
    <who name="Tim Orling">tim.orling</who>
    <bug_when>2020-06-25 08:41:20 +0000</bug_when>
    <thetext>Work on RMC has been discontinued and it is no longer supported.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>4128</attachid>
            <date>2017-11-22 06:04:45 +0000</date>
            <delta_ts>2017-11-22 06:07:13 +0000</delta_ts>
            <desc>script: change EFI blob sections</desc>
            <filename>change-efi-blob-sections</filename>
            <type>text/plain</type>
            <size>4270</size>
            <attacher name="Mikko Ylinen">mikko.ylinen</attacher>
            
              <data encoding="base64">IyEvYmluL3NoCiMKIyBDb3B5cmlnaHQgKEMpIDIwMTcgSW50ZWwgQ29ycG9yYXRpb24KIwojIEEg
aGVscGVyIHNjcmlwdCB0byB1cGRhdGUvbW9kaWZ5IHVlZmktY29tYmluZWQgYXBwIHNlY3Rpb25z
LgojCiMgQXV0aG9yZWQtYnk6ICBNaWtrbyBZbGluZW4gPG1pa2tvLnlsaW5lbkBsaW51eC5pbnRl
bC5jb20+CiMKCnVzYWdlICgpIHsKICBjYXQgPDwgRU9GCk1vZGlmeSBFRkkgQ29tYm8gQXBwbGlj
YXRpb24gU2VjdGlvbnMKJDAgPE9QVElPTlM+CgpPcHRpb25zOgogIC1jLCAtLWNvbW1hbmQKICAg
ICAgICBDb21tYW5kIHdoYXQgdG8gZG8uIFZhbGlkIGNvbW1hbmRzIGFyZTogYWRkLCByZW1vdmUs
CiAgICAgICAgYW5kIHVwZGF0ZS4KICAtcywgLS1zZWN0aW9uCiAgICAgICAgUEUvQ09GRiBzZWN0
aW9uIHRvIGNoYW5nZS4gVmFsaWQgc2VjdGlvbnMgYXJlOiAubGludXgsIC5jbWRsaW5lLAogICAg
ICAgIC5pbml0cmQsIGFuZCAucm1jLgogIC1mLCAtLWZpbGUKICAgICAgICBFRkkgY29tYm8gZmls
ZSB0byBvcGVyYXRlIHdpdGguCiAgLWEsIC0tYWRkcmVzcwogICAgICAgIFBFL0NPRkYgc2VjdGlv
biBhZGRyZXNzIHdoZXJlIHRvIGNvcHkgdGhlIHNlY3Rpb24gZGF0YS4KICAtZCwgLS1kYXRhCiAg
ICAgICAgRUZJIGNvbWJvIHNlY3Rpb24gZGF0YSB0byBhZGQvdXBkYXRlLgogIC1oLCAtLWhlbHAK
ICAgICAgICBEaXNwbGF5IHRoaXMgaGVscCBhbmQgZXhpdC4KCkVPRgp9Cgpjb21tYW5kPQpzZWN0
aW9uPQphZGRyZXNzPQpmaWxlPQpkYXRhPQoKaXNfdmFsaWQoKQp7Cglsb2NhbCB2YWx1ZT0kMQoJ
c2hpZnQKCglmb3IgaSBpbiAiJEAiCglkbwoJCWlmIFsgIiRpIiA9ICIkdmFsdWUiIF07IHRoZW4K
CQkJcmV0dXJuIDAKCQlmaQoJZG9uZQoKCXJldHVybiAxCn0KCmVycm9yX291dCgpCnsKCWVjaG8g
IiQwOiBFUlJPUjogJDEiCglleGl0IDEKfQoKb2JqPWB3aGljaCBvYmpjb3B5YApbIC1uICIkb2Jq
IiBdIHx8IGVycm9yX291dCAib2JqY29weSBub3QgaW4gUEFUSCIKCm9iaj1gd2hpY2ggb2JqZHVt
cGAKWyAtbiAiJG9iaiIgXSB8fCBlcnJvcl9vdXQgIm9iamR1bXAgbm90IGluIFBBVEgiCgp3aGls
ZSBbIC1uICIkMSIgXTsgZG8KICBjYXNlICQxIGluCiAgICAtLWNvbW1hbmR8LWMpCiAgICAgIHNo
aWZ0CiAgICAgIGlzX3ZhbGlkICQxICJhZGQiICJyZW1vdmUiICJ1cGRhdGUiCiAgICAgIFsgJD8g
LWVxIDAgXSB8fCBlcnJvcl9vdXQgIickMScgaXMgbm90IGEgdmFsaWQgY29tbWFuZCIKICAgICAg
Y29tbWFuZD0kMQogICAgICBzaGlmdAogICAgICAgIDs7CiAgICAtLXNlY3Rpb258LXMpCiAgICAg
IHNoaWZ0CiAgICAgIGlzX3ZhbGlkICQxICIubGludXgiICIuY21kbGluZSIgIi5pbml0cmQiICIu
cm1jIgogICAgICBbICQ/IC1lcSAwIF0gfHwgZXJyb3Jfb3V0ICJzZWN0aW9uICckMScgY2Fubm90
IGJlIGNoYW5nZWQiCiAgICAgIHNlY3Rpb249JDEKICAgICAgc2hpZnQKICAgICAgICA7OwogICAg
LS1hZGRyZXNzfC1hKQogICAgICBzaGlmdAogICAgICBhZGRyZXNzPSQxCiAgICAgIHNoaWZ0CiAg
ICAgICAgOzsKICAgIC0tZmlsZXwtZikKICAgICAgc2hpZnQKICAgICAgWyAtciAiJDEiIF0gfHwg
ZXJyb3Jfb3V0ICInJDEnIG5vdCByZWFkYWJsZSIgCiAgICAgIFsgYGVjaG8gJDF8c2VkIC1lICdz
Ly4qXC5cKC4qXCkkL1wxLydgID0gImVmaSIgXSB8fCBlcnJvcl9vdXQgIickMScgbWlzc2luZyAu
ZWZpIHN1ZmZpeCIgCiAgICAgIGZpbGU9JDEKICAgICAgc2hpZnQKICAgICAgICA7OwogICAgLS1k
YXRhfC1kKQogICAgICBzaGlmdAogICAgICBbIC1yICIkMSIgXSB8fCBlcnJvcl9vdXQgIickMScg
bm90IHJlYWRhYmxlIgogICAgICBkYXRhPSQxCiAgICAgIHNoaWZ0CiAgICAgICAgOzsKICAgIC0t
aGVscHwtaCkKICAgICAgdXNhZ2UKICAgICAgZXhpdCAwCiAgICAgICAgOzsKICAgICopCiAgICAg
IGVjaG8gIkludmFsaWQgYXJndW1lbnRzICQqIgogICAgICBlY2hvICJVc2UgJyQwIC1oJyBmb3Ig
bW9yZSBpbmZvcm1hdGlvbi4iCiAgICAgIGV4aXQgMAogICAgICAgIDs7CiAgZXNhYwpkb25lCgpj
aGVja19jb3B5KCkKewoJbG9jYWwgc3JjPWBvYmpkdW1wIC1mICIkMSJ8Z3JlcCBeIiQxInxhd2sg
J3twcmludCAkNH0nYAoJbG9jYWwgZHN0PWBvYmpkdW1wIC1mICIkMiJ8Z3JlcCBeIiQyInxhd2sg
J3twcmludCAkNH0nYAoKCSMgQ2hlY2sgdGhlIGNvcHkgd2FzIE9LIGJ5IGNoZWNraW5nIHRoZSBm
aWxlIGZvcm1hdHMKCSMgYXJlIChzdGlsbCkgdGhlIHNhbWUuCglpZiBbICIkc3JjIiA9ICIkZHN0
IiBdOyB0aGVuCgkJcmV0dXJuIDAKCWVsc2UKCQlyZXR1cm4gMQoJZmkKfQoKY2hlY2tfc2VjdGlv
bl9leGlzdHMoKQp7Cglsb2NhbCBzZWM9JDEKCWxvY2FsIGY9JDIKCgllbnRyeT1gb2JqZHVtcCAt
aCAiJGYifGdyZXAgIiRzZWMiYAoJaWYgWyAteiAiJGVudHJ5IiBdOyB0aGVuCgkJcmV0dXJuIDEK
CWZpCgoJcmV0dXJuIDAKCn0KCnJlbW92ZV9zZWN0aW9uKCkKewoJbG9jYWwgc2VjPSQxCglsb2Nh
bCBmPSQyCgoJY2hlY2tfc2VjdGlvbl9leGlzdHMgJHNlYyAkZgoJaWYgWyAkPyAtZXEgMSBdOyB0
aGVuCgkJcmV0dXJuIDEKCWZpCgoJbG9jYWwgdG1wPWBta3RlbXBgCgoJb2JqY29weSAtLXJlbW92
ZS1zZWN0aW9uICRzZWMgJGYgJHRtcAoKCWNoZWNrX2NvcHkgJGYgJHRtcAoJaWYgWyAkPyAtZXEg
MSBdOyB0aGVuCgkJcm0gJHRtcAoJCXJldHVybiAxCglmaQoJCgltdiAkdG1wICR7ZiUlLmVmaX0t
cmVtb3ZlLmVmaQoKCXJldHVybiAwCn0KCmFkZF9zZWN0aW9uKCkKewoJbG9jYWwgc2VjPSQxCgls
b2NhbCBhPSQyCglsb2NhbCBkPSQzCglsb2NhbCBmPSQ0CgoJY2hlY2tfc2VjdGlvbl9leGlzdHMg
JHNlYyAkZgoJaWYgWyAkPyAtZXEgMCBdOyB0aGVuCgkJcmV0dXJuIDEKCWZpCgoJbG9jYWwgdG1w
PWBta3RlbXBgCgoJb2JqY29weSAtLWFkZC1zZWN0aW9uICRzZWM9JGQgLS1jaGFuZ2Utc2VjdGlv
bi12bWEgJHNlYz0kYSAkZiAkdG1wCgoJY2hlY2tfY29weSAkZiAkdG1wCglpZiBbICQ/IC1lcSAx
IF07IHRoZW4KCQlybSAkdG1wCgkJcmV0dXJuIDEKCWZpCgkKCW12ICR0bXAgJHtmJSUuZWZpfS1h
ZGQuZWZpCgoJcmV0dXJuIDAKfQoKdXBkYXRlX3NlY3Rpb24oKQp7Cglsb2NhbCBzZWM9JDEKCWxv
Y2FsIGQ9JDIKCWxvY2FsIGY9JDMKCglsb2NhbCB0bXA9YG1rdGVtcGAKCWxvY2FsIGJhc2VuYW1l
PSR7ZiUlLmVmaX0KCgkjIEFsd2F5cyB1c2UgdGhlIG9yaWdpbmFsIHNlY3Rpb24gYWRkcmVzcwoJ
bG9jYWwgYWRkcj1gb2JqZHVtcCAtaCAiJGYifGdyZXAgIiRzZWMifGF3ayAne3ByaW50ICQ0fSdg
CgoJcmVtb3ZlX3NlY3Rpb24gJHNlYyAkZgoJaWYgWyAkPyAtZXEgMSBdOyB0aGVuCgkJcmV0dXJu
IDEKCWZpCgkJCglhZGRfc2VjdGlvbiAkc2VjICRhZGRyICRkICRiYXNlbmFtZS1yZW1vdmUuZWZp
CglpZiBbICQ/IC1lcSAxIF07IHRoZW4KCQlyZXR1cm4gMQoJZmkKCglybSAkYmFzZW5hbWUtcmVt
b3ZlLmVmaQoJbXYgJGJhc2VuYW1lLXJlbW92ZS1hZGQuZWZpICRiYXNlbmFtZS11cGRhdGUuZWZp
CgoJcmV0dXJuIDAKCn0KClsgLW4gIiRjb21tYW5kIiBdIHx8IGVycm9yX291dCAibWlzc2luZyBj
b21tYW5kIHBhcmFtZXRlciIKWyAtbiAiJHNlY3Rpb24iIF0gfHwgZXJyb3Jfb3V0ICJtaXNzaW5n
IHNlY3Rpb24gcGFyYW1ldGVyIgpbIC1uICIkZmlsZSIgXSB8fCBlcnJvcl9vdXQgIm1pc3Npbmcg
aW5wdXQgZmlsZSIKCmNhc2UgJGNvbW1hbmQgaW4KCWFkZCkKCSAgWyAtbiAiJGFkZHJlc3MiIC1h
IC1uICIkZGF0YSIgXSB8fCBlcnJvcl9vdXQgImFkZDogbWlzc2luZyBwYXJhbWV0ZXJzIiAKCSAg
YWRkX3NlY3Rpb24gJHNlY3Rpb24gJGFkZHJlc3MgJGRhdGEgJGZpbGUgJG91dHB1dCB8fCBlcnJv
cl9vdXQgImFkZCBzZWN0aW9uOiBjb3B5IGZhaWxlZCIKCSAgOzsKCXJlbW92ZSkKCSAgcmVtb3Zl
X3NlY3Rpb24gJHNlY3Rpb24gJGZpbGUgJG91dHB1dCB8fCBlcnJvcl9vdXQgInJlbW92ZSBzZWN0
aW9uOiBjb3B5IGZhaWxlZCIKCSAgOzsKCXVwZGF0ZSkKCSAgWyAtbiAiJGRhdGEiIF0gfHwgZXJy
b3Jfb3V0ICJ1cGRhdGU6IG1pc3NpbmcgcGFyYW1ldGVycyIKCSAgdXBkYXRlX3NlY3Rpb24gJHNl
Y3Rpb24gJGRhdGEgJGZpbGUgJG91dHB1dCB8fCBlcnJvcl9vdXQgInVwZGF0ZSBzZWN0aW9uOiBj
b3B5IGZhaWxlZCIKCSAgOzsKCSopCgkgIGV4aXQgMAoJICA7Owplc2FjCgplY2hvICIkMDogSU5G
Tzogb3V0cHV0IHdyaXR0ZW4gdG86ICR7ZmlsZSUlLmVmaX0tJHtjb21tYW5kfS5lZmkiCg==
</data>

          </attachment>
      

    </bug>

</bugzilla>