On Wed, 2026-07-01 at 16:49 -0400, Zhuoying Cai wrote:
> Enable secure IPL in audit mode, which performs signature verification,
> but any error does not terminate the boot process. Only warnings will be
> logged to the console instead.
> 
> Secure IPL in audit mode requires at least one certificate provided in
> the key store along with necessary facilities (Secure IPL Facility,
> Certificate Store Facility and secure IPL extension support).
> 
> Note: Secure IPL in audit mode is implemented for the SCSI scheme of
> virtio-blk/virtio-scsi devices.
> 
> Signed-off-by: Zhuoying Cai <[email protected]>
> ---
>  docs/system/s390x/secure-ipl.rst |  15 ++
>  pc-bios/s390-ccw/Makefile        |   2 +-
>  pc-bios/s390-ccw/bootmap.c       |  27 +++
>  pc-bios/s390-ccw/bootmap.h       |   9 +
>  pc-bios/s390-ccw/jump2ipl.c      |   7 +
>  pc-bios/s390-ccw/main.c          |  18 +-
>  pc-bios/s390-ccw/s390-ccw.h      |  20 ++
>  pc-bios/s390-ccw/sclp.c          |  27 +++
>  pc-bios/s390-ccw/sclp.h          |   6 +
>  pc-bios/s390-ccw/secure-ipl.c    | 362 +++++++++++++++++++++++++++++++
>  pc-bios/s390-ccw/secure-ipl.h    | 116 ++++++++++
>  11 files changed, 607 insertions(+), 2 deletions(-)
>  create mode 100644 pc-bios/s390-ccw/secure-ipl.c
>  create mode 100644 pc-bios/s390-ccw/secure-ipl.h

...snip...

> 
> diff --git a/pc-bios/s390-ccw/secure-ipl.c b/pc-bios/s390-ccw/secure-ipl.c
> new file mode 100644
> index 0000000000..2d9a4cbc02
> --- /dev/null
> +++ b/pc-bios/s390-ccw/secure-ipl.c

...snip...

> +void update_cert_list(IplSignatureCertificateList *cert_list)
> +{
> +    IplSignatureCertificateEntry *cert_entry;
> +    uint8_t *cert_buf;
> +
> +    cert_buf = (uint8_t *)qipl.ipl_data;
> +
> +    for_each_rb_entry(cert_entry, cert_list) {
> +        memcpy(cert_buf, (uint8_t *)cert_entry->addr, cert_entry->len);
> +        cert_entry->addr = (uint64_t)cert_buf;
> +        cert_buf += cert_entry->len;
> +    }
> +}

Apologies if this is elsewhere in the patch (I'll revisit this tomorrow with 
coffee), but is there
any limit to the number of entries in this loop, or could we walk off the end 
of qipl.ipl_data with
a sufficiently large list?

Reply via email to