From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752583AbdBOSrR (ORCPT ); Wed, 15 Feb 2017 13:47:17 -0500 Received: from david.siemens.de ([192.35.17.14]:47772 "EHLO david.siemens.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752051AbdBOSrP (ORCPT ); Wed, 15 Feb 2017 13:47:15 -0500 Subject: Re: [PATCH 0/2] efi: Enhance capsule loader to support signed Quark images To: Ard Biesheuvel References: Cc: Matt Fleming , "linux-efi@vger.kernel.org" , Linux Kernel Mailing List , Andy Shevchenko From: Jan Kiszka Message-ID: <63c7f925-869e-1053-2f80-0fbb680dcc2f@siemens.com> Date: Wed, 15 Feb 2017 19:47:11 +0100 User-Agent: Mozilla/5.0 (X11; U; Linux i686 (x86_64); de; rv:1.8.1.12) Gecko/20080226 SUSE/2.0.0.12-1.1 Thunderbird/2.0.0.12 Mnenhy/0.7.5.666 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 2017-02-15 19:17, Ard Biesheuvel wrote: > On 15 February 2017 at 18:14, Jan Kiszka wrote: >> See patch 2 for the background. >> >> Series has been tested on the Galileo Gen2, to exclude regressions, with >> a firmware.cap without security header and the SIMATIC IOT2040 which >> requires the header because of its mandatory secure boot. >> > > Hello Jan, > > What is a Quark? Is it in the UEFI spec? http://ark.intel.com/products/79084/Intel-Quark-SoC-X1000-16K-Cache-400-MHz I didn't find any obvious reference to this format in the UEFI spec. This might be specific to the Quark UEFI EDK2 that Intel ships (it's not in upstream edk2) and that was used as foundation for the IOT2000 series. The capsule driver that Intel includes in their Galileo BSP does something similar (I don't have a browsable reference to that at hand, sorry, must be in this nice package https://downloadcenter.intel.com/download/24702/Intel-Galileo-Board-GPL-Compliance-files-1-0-4?product=83137). Jan > >> Jan Kiszka (2): >> efi/capsule: Prepare for loading images with security header >> efi/capsule: Add support for Quark security header >> >> drivers/firmware/efi/capsule-loader.c | 73 ++++++++++++++++++++++++++++++----- >> drivers/firmware/efi/capsule.c | 19 +++++++-- >> include/linux/efi.h | 2 +- >> 3 files changed, 79 insertions(+), 15 deletions(-) >> >> -- >> 2.1.4 >> -- Siemens AG, Corporate Technology, CT RDA ITP SES-DE Corporate Competence Center Embedded Linux