From 5768d55a08e163f718bd87498b9e763687ae7137 Mon Sep 17 00:00:00 2001 From: Peter Oberparleiter Date: Fri, 16 Sep 2022 15:13:01 +0200 Subject: [PATCH] zipl/boot: add secure boot trailer MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This patch enhances the zipl stage3 loader image adding a trailer as required for secure boot by future firmware versions. Note: with the change in this patch the padding via objcopy command line options is replaced by padding via linker script directives with the same effect. Signed-off-by: Peter Oberparleiter Signed-off-by: Jan Höppner --- zipl/boot/Makefile | 2 +- zipl/boot/stage3.lds.S | 10 ++++++++++ 2 files changed, 11 insertions(+), 1 deletion(-) diff --git a/zipl/boot/Makefile b/zipl/boot/Makefile index c2ec76ae..f195df0e 100644 --- a/zipl/boot/Makefile +++ b/zipl/boot/Makefile @@ -106,7 +106,7 @@ stage3.bin: stage3.exec --only-section=.stage2dump.tail \ --only-section=.eckd2dump_mv.tail \ --only-section=.fixup \ - --pad-to=0xe000 \ + --only-section=.sb.trailer \ $< $@ data.o: $(FILES) diff --git a/zipl/boot/stage3.lds.S b/zipl/boot/stage3.lds.S index fa4c81f7..d8305f11 100644 --- a/zipl/boot/stage3.lds.S +++ b/zipl/boot/stage3.lds.S @@ -14,6 +14,7 @@ */ #include "boot/loaders_layout.h" +#include "boot/s390.h" SECTIONS { @@ -46,6 +47,15 @@ SECTIONS .rodata : {*(.rodata) } .data : { *(.data) } + /* Trailer needed for Secure Boot */ + . = COMMAND_LINE_EXTRA - 32; + .sb.trailer : { + QUAD(0x0000c00000000000) + QUAD(STAGE3_ENTRY + PSW_LOAD) + QUAD(STAGE3_ENTRY) + QUAD(0x000000207a49504c) + } + . = COMMAND_LINE_EXTRA; .cmdline_extra : { . += COMMAND_LINE_EXTRA_SIZE;