Pull request efi-2026-01-rc2

CI: https://git.u-boot-project.org/u-boot/custodians/u-boot-efi/-/pipelines/753

Documentation:

* sandbox: fix enum host_platform_flags description
* switch from setenv to env set and from printenv to env print
* document Renesas R-Car Gen5 RSIP Cortex-R52 start
* thead: lpi4a: detail how to enable fastboot

UEFI:

* unify and correct GUID selection for security database variables
* test: check default GUID selection of security database variables
* set correct frame buffer address
* check efi_deserialize_load_option() in get_dp_device()
This commit is contained in:
Tom Rini
2026-07-28 07:52:13 -06:00
76 changed files with 511 additions and 239 deletions
@@ -96,6 +96,14 @@ def efi_boot_env(request, ubman):
check_call('cd %s; %ssign-efi-sig-list -t "2020-04-05" -c KEK.crt -k KEK.key dbx db.esl dbx_db.auth'
% (mnt_point, EFITOOLS_PATH),
shell=True)
# dbt (with TEST_db certificate)
check_call('cd %s; %ssign-efi-sig-list -t "2020-04-05" -c KEK.crt -k KEK.key dbt db.esl dbt.auth'
% (mnt_point, EFITOOLS_PATH),
shell=True)
# dbr (with TEST_db certificate)
check_call('cd %s; %ssign-efi-sig-list -t "2020-04-05" -c KEK.crt -k KEK.key dbr db.esl dbr.auth'
% (mnt_point, EFITOOLS_PATH),
shell=True)
# Copy image
check_call('cp %s/lib/efi_loader/helloworld.efi %s' %
@@ -279,3 +279,50 @@ class TestEfiAuthVar(object):
output = ubman.run_command(
'printenv -e SetupMode')
assert '00000000: 01' in output
def test_efi_var_auth6(self, ubman, efi_boot_env):
"""
Test Case 6 - Default GUID of signature database variables
"""
ubman.restart_uboot()
disk_img = efi_boot_env
with ubman.log.section('Test Case 6a'):
# Test Case 6a, install signature database variables in setup
# mode without -guid
output = ubman.run_command_list([
'host bind 0 %s' % disk_img,
'printenv -e SetupMode'])
assert '00000000: 01' in ''.join(output)
for var in ('db', 'dbx', 'dbt', 'dbr'):
output = ubman.run_command_list([
'fatload host 0:1 4000000 %s.auth' % var,
'setenv -e -nv -bs -rt -at -i 4000000:$filesize %s' % var,
'printenv -e -n -guid d719b2cb-3d3a-4596-a3bc-dad00e67656f %s' % var])
assert 'Failed to set EFI variable' not in ''.join(output)
assert '%s:' % var in ''.join(output)
with ubman.log.section('Test Case 6b'):
# Test Case 6b, variables must not exist under the global
# variable GUID
for var in ('db', 'dbx', 'dbt', 'dbr'):
output = ubman.run_command(
'printenv -e -n -guid 8be4df61-93ca-11d2-aa0d-00e098032b8c %s' % var)
assert '\"%s\" not defined' % var in output
with ubman.log.section('Test Case 6c'):
# Test Case 6c, PK and KEK get the global variable GUID by
# default. Enrolling PK leaves setup mode, so this must come
# after the signature database enrollment above.
for var in ('PK', 'KEK'):
output = ubman.run_command_list([
'fatload host 0:1 4000000 %s.auth' % var,
'setenv -e -nv -bs -rt -at -i 4000000:$filesize %s' % var,
'printenv -e -n -guid 8be4df61-93ca-11d2-aa0d-00e098032b8c %s' % var])
assert 'Failed to set EFI variable' not in ''.join(output)
assert '%s:' % var in ''.join(output)
for var in ('PK', 'KEK'):
output = ubman.run_command(
'printenv -e -n -guid d719b2cb-3d3a-4596-a3bc-dad00e67656f %s' % var)
assert '\"%s\" not defined' % var in output