New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Xen "no-real-mode" boot option integration into QubesOS #3388

Open
tlaurion opened this Issue Dec 10, 2017 · 0 comments

Comments

Projects
None yet
2 participants
@tlaurion
Contributor

tlaurion commented Dec 10, 2017

Qubes OS version:

3.2, 4.0

Affected TemplateVMs:

dom0


General notes:

I'm wondering if there is any reason, or discussions I haven't found justifying QubesOS not including the effective no-real-mode patches upstream from (1) (2) into QubesOS for it too boot from linux's coreboot payload.

Steps to reproduce the behavior:

Every time QubesOS releases a security fix related to Xen and provides new Xen packages, Heads needs to patch Xen code to provide effective no-real-mode boot option and include hypervisor binaries in provided firmware, resulting in unnecessary firmware upgrades and flashes from end users and system administrators.

Related discussion between Trammel Hudson and Andrew Cooper

Expected behavior:

Inclusion of Heads's patchwork to support optional and effective no-real-mode Xen boot option, from QubesOS or upstream from Xen.

Actual behavior:

Heads needs to patch QubesOS's Xen hypervisor to provide no-real-mode boot option.


Related issues:

osresearch/heads#227

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment