Bug 11030 - RMC: systemd-boot EFI stub: Don't read RMC db in SecureBoot mode
Summary: RMC: systemd-boot EFI stub: Don't read RMC db in SecureBoot mode
Status: RESOLVED OBSOLETE
Alias: None
Product: BSPs
Classification: Build System, Metadata & Runtime
Component: bsps-meta-intel (show other bugs)
Version: unspecified
Hardware: x86 Multiple
: Medium normal
Target Milestone: Future
Assignee: Unassigned
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2017-02-08 09:13 UTC by Mikko Ylinen
Modified: 2020-06-25 08:41 UTC (History)
5 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments
script: change EFI blob sections (4.17 KB, text/plain)
2017-11-22 06:04 UTC, Mikko Ylinen
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Mikko Ylinen 2017-02-08 09:13:16 UTC
The systemd-boot patches that enable RMC for the EFI stub need to be changed so that RMC db is not read when the BIOS has secure boot enabled.

I'll assign this to myself and work on the fix.
Comment 1 Patrick Ohly 2017-02-15 11:30:13 UTC
In addition to preventing reading the DB from the VFAT system partition when Secure Boot is active, please consider supporting a DB that is embedded inside the UEFI combo app. That DB can remain active.
Comment 2 Mikko Ylinen 2017-02-28 15:32:31 UTC
submitted to meta-intel:
https://lists.yoctoproject.org/pipermail/meta-intel/2017-February/004625.html
Comment 3 Patrick Ohly 2017-07-19 07:28:18 UTC
(In reply to comment #1)
> In addition to preventing reading the DB from the VFAT system partition when
> Secure Boot is active, please consider supporting a DB that is embedded
> inside the UEFI combo app. That DB can remain active.

I don't remember whether this was discussed. I thought it had been implemented, but current refkit code still deploys rmc.db separately.

Populating /boot with additional files is problematic for system update, because we only have support in place for updating the combo app, but not for additional files. So the rmc.db isn't going to get updated on devices.

We probably need a new feature request (either for embedding rmc.db or for supporting in in system update), depending on how we want to handle this.
Comment 4 Mikko Ylinen 2017-08-07 08:24:50 UTC
(In reply to comment #3)
> (In reply to comment #1)
> > In addition to preventing reading the DB from the VFAT system partition when
> > Secure Boot is active, please consider supporting a DB that is embedded
> > inside the UEFI combo app. That DB can remain active.
> 
> I don't remember whether this was discussed. I thought it had been
> implemented, but current refkit code still deploys rmc.db separately.
> 

The patch was sent out (see Comment #2) but Saul did not merge it. The reasons are probably obsolete by now so the patch can probably rebased.

Saul, what do you think?
Comment 5 Mikko Ylinen 2017-10-17 04:51:07 UTC
The existing patch is still applicable to meta-intel but it has not been applied. Also, a tool/script is available to update uefi combo app elements.
Comment 6 Mikko Ylinen 2017-11-14 12:27:40 UTC
Re-assign to meta-intel.
Comment 7 Saul Wold 2017-11-21 21:54:43 UTC
https://lists.yoctoproject.org/pipermail/meta-intel/2017-February/004625.html

This patch had been proposed, but had some discussion that Todor can maybe add additional info to here.
Comment 8 Todor Minchev 2017-11-21 22:40:10 UTC
This patch assumes that rmb.db will be always build into the systemd-boot STUB. If we are not going to support standalone rmb.db files on the EFI partition, then this should be safe to merge. Otherwise we need to have a mechanism to differentiate between running in secureboot mode when rmc.db can be read only from the .rmc section of systemd-boot and non-secureboot mode when it can be read from both the .rmc section of systemd-boot and the EFI partition.
Comment 9 Mikko Ylinen 2017-11-22 06:03:37 UTC
(In reply to comment #8)
> This patch assumes that rmb.db will be always build into the systemd-boot

That's not exactly true. The patched stub checks whether ".rmc" section is there
or not and behaves accordingly. With this patch applied, it's still possible to run UEFI combo app without the .rmc section built in.

> STUB. If we are not going to support standalone rmb.db files on the EFI
> partition, then this should be safe to merge. Otherwise we need to have a
> mechanism to differentiate between running in secureboot mode when rmc.db
> can be read only from the .rmc section of systemd-boot and non-secureboot
> mode when it can be read from both the .rmc section of systemd-boot and the
> EFI partition.

IMO, it's much better to always keep .rmc built in the uefi combo app. That's where all other boot artifacts are kept too.

One of the reasons the patch was not put on hold was the concern about rmc.db updateability on the target. I wrote a script to address the use case where UEFI-combo app is used + rmc.db (or some other section, e.g., .cmdline) needs to be changed but never pushed it for a review. Let me attach it here if it helps.

The script could be installed in rmc-tools package.
Comment 10 Mikko Ylinen 2017-11-22 06:04:45 UTC
Created attachment 4128 [details]
script: change EFI blob sections

Attached the script mentioned in comment #9
Comment 11 Tim Orling 2020-06-25 08:41:20 UTC
Work on RMC has been discontinued and it is no longer supported.