-
Notifications
You must be signed in to change notification settings - Fork 85
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Kernel Loader Hashes disabled for SEV-SNP #93
Comments
The Qemu patches are an RFC set of patches and enough to boot an SNP guest. Once the hypervisor support is close to being finalized is when the Qemu patches will be more formal. At that point, I would recommend you keep an eye on that mailing list and bring up questions/comments related to this type of support at that time. You could even bring it up now on the mailing list now based on the RFC patches submitted. |
Thank you for the reply! Since we don't have time to wait for an indefinite point in the future, we are going to bring it up now on the corresponding mailing list. If someone had the same issue and solved it for their own project, we are grateful for any hint. |
Hi @hstr0 , edk2 patches: [PATCH 0/2] OvmfPkg: Enable measured direct boot on AMD SEV-SNP QEMU patch: [RFC PATCH] i386/sev: Support measured direct -kernel boot on SNP -- note the it's based on top of the RFC QEMU snp-v3 tree from AMD. Hope this helps. |
Hi @dubek, thanks a lot! We already patched our system and still need to verify the effectiveness of the changes made. |
Hey @Daviiap, |
I've patched OVMF and QEMU also and worked for me, thanks! |
Glad it worked for you too! |
BTW, on 2023-03-02 I submitted new a version (v3) of the ovmf and qemu patches; the qemu patches are now based on top of a newer RFC tree from AMD (which still works even with older SNP host kernels). edk2/ovmf: patch series, git tree qemu: RFC patch series, git tree Hope this helps. Let me know here (or in the relevant mailing lists) if there are any issues. |
Hi @dubek, I've patched QEMU and OVMF, and I'm facing a problem. Here the command I used to boot up the VM:
and the problem I'm facing:
Do you have any idea what could be causing this problem? |
@Anderson-Melo I'm not sure. Here are a few questions to attempt debug this:
Maybe one of these can shed more light on the issue. |
@dubek Thanks, this |
Signed-off-by: Adam Reif <adam@litprotocol.com>
Signed-off-by: Adam Reif <adam@litprotocol.com>
Signed-off-by: Adam Reif <adam@litprotocol.com>
Hi there,
we are currently working with SEV-SNP to include initrd in attestation report. However, the function
sev_add_kernel_loader_hashes()
in /qemu/target/i386/sev.c returns false when SEV-SNP is enabled:What are the next steps to add support for this kind of attestation? Any help is appreciated.
The text was updated successfully, but these errors were encountered: