]> git.ipfire.org Git - thirdparty/systemd.git/commit
efi: don't pull kernel cmdline from SMBIOS in a confidential VM 28301/head
authorDaniel P. Berrangé <berrange@redhat.com>
Fri, 7 Jul 2023 15:30:20 +0000 (16:30 +0100)
committerDaniel P. Berrangé <berrange@redhat.com>
Fri, 14 Jul 2023 13:18:09 +0000 (14:18 +0100)
commit4b1153cfcc397df5a095f2ec7e587787e8ba47ee
treee51816ed258a05fddbcb74d9c18a96551136e619
parentb354a2cafc8ea38b4551aa3e4f078f1d7aa40c7c
efi: don't pull kernel cmdline from SMBIOS in a confidential VM

In a confidential VM, the SMBIOS data is not trusted, as it is under the
control of the host OS/admin and not covered by attestation of the machine.

Fixes: https://github.com/systemd/systemd/issues/27604
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
src/boot/efi/stub.c