* [PATCH v1 0/3] efi/libstub: Build the x86 stub from KBUILD_CFLAGS
@ 2026-10-06 20:42 Kees Cook
2026-10-06 20:42 ` [PATCH v1 1/3] efi/libstub: Declare the x86 stub's assembly entry points Kees Cook
` (2 more replies)
0 siblings, 3 replies; 6+ messages in thread
From: Kees Cook @ 2026-10-06 20:42 UTC (permalink / raw)
To: Ard Biesheuvel
Cc: Kees Cook, Ilias Apalodimas, Nathan Chancellor, Nicolas Schier,
Nick Desaulniers, Bill Wendling, Justin Stitt, linux-efi, llvm,
linux-kernel, linux-hardening
Hi!
The x86 EFI stub builds from its own short list of compiler flags instead
of KBUILD_CFLAGS, so options added kernel-wide reach it only when someone
remembers to add them there too (e.g. for -fms-extensions). Swap it
around to remove unwanted options instead, as we do for all the other
architectures.
This will let Clang's -fexperimental-late-parse-attributes reach the
stub build so that __counted_by() will get parsed without error[1].
Thanks!
-Kees
Link: https://lore.kernel.org/all/202610060642.7C4125F@keescook [1]
Kees Cook (3):
efi/libstub: Declare the x86 stub's assembly entry points
efi/libstub: Build the x86 stub from KBUILD_CFLAGS
efi/libstub: Disable kernel stack erasing in the common flags
drivers/firmware/efi/libstub/Makefile | 41 +++++++++++++------------
drivers/firmware/efi/libstub/x86-stub.h | 9 ++++++
2 files changed, 30 insertions(+), 20 deletions(-)
--
2.55.0
^ permalink raw reply [flat|nested] 6+ messages in thread* [PATCH v1 1/3] efi/libstub: Declare the x86 stub's assembly entry points 2026-10-06 20:42 [PATCH v1 0/3] efi/libstub: Build the x86 stub from KBUILD_CFLAGS Kees Cook @ 2026-10-06 20:42 ` Kees Cook 2026-10-06 20:42 ` [PATCH v1 2/3] efi/libstub: Build the x86 stub from KBUILD_CFLAGS Kees Cook 2026-10-06 20:42 ` [PATCH v1 3/3] efi/libstub: Disable kernel stack erasing in the common flags Kees Cook 2 siblings, 0 replies; 6+ messages in thread From: Kees Cook @ 2026-10-06 20:42 UTC (permalink / raw) To: Ard Biesheuvel Cc: Kees Cook, Ilias Apalodimas, linux-efi, linux-kernel, linux-hardening efi_stub_entry() and efi_handover_entry() are entered from efi-mixed.S and, through the efi32_stub_entry() and efi64_stub_entry() aliases, by boot loaders using the EFI handover protocol, but have no prototypes. Declare them in x86-stub.h, as asmlinkage, so that the stub can be built with the kernel's -Wmissing-prototypes. Assisted-by: LLM Signed-off-by: Kees Cook <kees@kernel.org> --- drivers/firmware/efi/libstub/x86-stub.h | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/drivers/firmware/efi/libstub/x86-stub.h b/drivers/firmware/efi/libstub/x86-stub.h index 1c20e99a6494..cc2474c0f95b 100644 --- a/drivers/firmware/efi/libstub/x86-stub.h +++ b/drivers/firmware/efi/libstub/x86-stub.h @@ -8,6 +8,15 @@ extern const u16 trampoline_ljmp_imm_offset; efi_status_t efi_adjust_memory_range_protection(unsigned long start, unsigned long size); +struct boot_params; + +asmlinkage void __noreturn efi_stub_entry(efi_handle_t handle, + efi_system_table_t *sys_table_arg, + struct boot_params *boot_params); +asmlinkage void efi_handover_entry(efi_handle_t handle, + efi_system_table_t *sys_table_arg, + struct boot_params *boot_params); + #ifdef CONFIG_X86_64 efi_status_t efi_setup_5level_paging(void); void efi_5level_switch(void); -- 2.55.0 ^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH v1 2/3] efi/libstub: Build the x86 stub from KBUILD_CFLAGS 2026-10-06 20:42 [PATCH v1 0/3] efi/libstub: Build the x86 stub from KBUILD_CFLAGS Kees Cook 2026-10-06 20:42 ` [PATCH v1 1/3] efi/libstub: Declare the x86 stub's assembly entry points Kees Cook @ 2026-10-06 20:42 ` Kees Cook 2026-10-07 9:20 ` Nathan Chancellor 2026-10-06 20:42 ` [PATCH v1 3/3] efi/libstub: Disable kernel stack erasing in the common flags Kees Cook 2 siblings, 1 reply; 6+ messages in thread From: Kees Cook @ 2026-10-06 20:42 UTC (permalink / raw) To: Ard Biesheuvel Cc: Kees Cook, Ilias Apalodimas, Nathan Chancellor, Nicolas Schier, Nick Desaulniers, Bill Wendling, Justin Stitt, linux-efi, llvm, linux-kernel, linux-hardening The x86 stub replaces KBUILD_CFLAGS with a short list of its own, so new kernel-wide compiler options go missing, unless explicitly remembered or when lacking them breaks the build, e.g. commit 5ff8ad3909524 ("kbuild: Add '-fms-extensions' to areas with dedicated CFLAGS") did. Today, several still go missing that are provided to non-x86 stub builds, e.g. -ftrivial-auto-var-init, -fzero-call-used-regs, -fstrict-flex-arrays=3, and the various kernel's warnings. Flip the x86 option logic to match the other architectures. Since the x86 stub is linked into the decompressor rather than the kernel proper, remove the kernel code model, the i386 register calling convention, and the kernel's reduced stack alignment, along with the retpoline and return thunks and the call padding, which only the kernel provides, and disable kernel stack erasing as the other architectures do. The existing -mcmodel=small, -march=i386, and -fPIC still get overrides. Build with -fcf-protection=none, since nothing enables IBT while the stub runs: the firmware applies forward-edge CFI only to images that advertise it, which bzImage does not. New flags that change code generation or semantics in a plain x86_64 defconfig hardening.config stub: Hardening: -ftrivial-auto-var-init=zero -fzero-init-padding-bits=all -fstrict-flex-arrays=3 -fno-strict-overflow -fno-delete-null-pointer-checks -fno-allow-store-data-races -fno-jump-tables (from the default IBT config) C semantics: -funsigned-char -fno-common x86 code generation: -mno-sse2 -mno-3dnow -mno-avx -mno-sse4a (stub already added -mno-mmx -mno-sse) -mno-80387 -mno-fp-ret-in-387 -mskip-rax-setup -falign-jumps=1 -falign-loops=1 -fmin-function-alignment=16 -fomit-frame-pointer -fconserve-stack -fno-stack-clash-protection -fno-stack-check -fno-builtin-wcslen Warnings (lots and lots, but notably): -Wall -Wextra -Wundef -Wmissing-prototypes -Wvla-larger-than=1 -Wimplicit-fallthrough=5 Present but with no effect, because the stub's later flags override them: -O2, overridden by -Os -fstack-protector-* flags, overridden by -fno-stack-protector -fno-PIE, overridden by -fPIC -fcf-protection=branch, overridden by -fcf-protection=none the stack-erase plugin, loaded and then disabled Build tested ARCH=x86_64 defconfig hardening.config, plus retpolines, return thunks, call depth tracking, IBT, GCC plugins, and EFI mixed mode, with GCC 16.2.0 and Clang 24.0.0git, and ARCH=i386 defconfig hardening.config with GCC 16.2.0. Each booted through the EFI stub to userspace under QEMU with x64 and IA32 OVMF, the latter in mixed mode for x86_64. Assisted-by: LLM Signed-off-by: Kees Cook <kees@kernel.org> --- drivers/firmware/efi/libstub/Makefile | 24 ++++++++++++++---------- 1 file changed, 14 insertions(+), 10 deletions(-) diff --git a/drivers/firmware/efi/libstub/Makefile b/drivers/firmware/efi/libstub/Makefile index 77a2b2d74f3f..1f588591f458 100644 --- a/drivers/firmware/efi/libstub/Makefile +++ b/drivers/firmware/efi/libstub/Makefile @@ -6,18 +6,22 @@ # enabled, even if doing so doesn't break the build. # -# non-x86 reuses KBUILD_CFLAGS, x86 does not cflags-y := $(KBUILD_CFLAGS) -cflags-$(CONFIG_X86_32) := -march=i386 -cflags-$(CONFIG_X86_64) := -mcmodel=small -cflags-$(CONFIG_X86) += -m$(BITS) -D__KERNEL__ $(CC_FLAGS_DIALECT) \ - -fPIC -fno-strict-aliasing -mno-red-zone \ - -mno-mmx -mno-sse -fshort-wchar \ - -Wno-pointer-sign \ - $(call cc-disable-warning, address-of-packed-member) \ - -fno-asynchronous-unwind-tables \ - $(CLANG_FLAGS) +# x86 links the stub into the decompressor rather than the kernel proper, so +# drop the kernel's code model, calling convention, and stack alignment, and +# the mitigations that rely on thunks and patch sites only the kernel has. +cflags-$(CONFIG_X86) := $(filter-out -mcmodel=kernel \ + -mregparm=3 -freg-struct-return \ + -mpreferred-stack-boundary=% \ + -mstack-alignment=% \ + $(RETPOLINE_CFLAGS) $(RETHUNK_CFLAGS) \ + $(PADDING_CFLAGS), $(cflags-y)) +cflags-$(CONFIG_X86_32) += -march=i386 +cflags-$(CONFIG_X86_64) += -mcmodel=small +cflags-$(CONFIG_X86) += -fPIC $(DISABLE_KSTACK_ERASE) +# Nothing enables IBT while the stub runs, so ENDBR would only take space. +cflags-$(CONFIG_X86) += $(call cc-option,-fcf-protection=none) # arm64 uses the full KBUILD_CFLAGS so it's necessary to explicitly # disable the stackleak plugin -- 2.55.0 ^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH v1 2/3] efi/libstub: Build the x86 stub from KBUILD_CFLAGS 2026-10-06 20:42 ` [PATCH v1 2/3] efi/libstub: Build the x86 stub from KBUILD_CFLAGS Kees Cook @ 2026-10-07 9:20 ` Nathan Chancellor 0 siblings, 0 replies; 6+ messages in thread From: Nathan Chancellor @ 2026-10-07 9:20 UTC (permalink / raw) To: Kees Cook Cc: Ard Biesheuvel, Ilias Apalodimas, Nicolas Schier, Nick Desaulniers, Bill Wendling, Justin Stitt, linux-efi, llvm, linux-kernel, linux-hardening On Tue, Oct 06, 2026 at 01:42:22PM -0700, Kees Cook wrote: > The x86 stub replaces KBUILD_CFLAGS with a short list of its own, so new > kernel-wide compiler options go missing, unless explicitly remembered > or when lacking them breaks the build, e.g. commit 5ff8ad3909524 > ("kbuild: Add '-fms-extensions' to areas with dedicated CFLAGS") > did. Today, several still go missing that are provided to non-x86 > stub builds, e.g. -ftrivial-auto-var-init, -fzero-call-used-regs, > -fstrict-flex-arrays=3, and the various kernel's warnings. > > Flip the x86 option logic to match the other architectures. Since the > x86 stub is linked into the decompressor rather than the kernel proper, > remove the kernel code model, the i386 register calling convention, > and the kernel's reduced stack alignment, along with the retpoline and > return thunks and the call padding, which only the kernel provides, > and disable kernel stack erasing as the other architectures do. The > existing -mcmodel=small, -march=i386, and -fPIC still get overrides. > Build with -fcf-protection=none, since nothing enables IBT while the > stub runs: the firmware applies forward-edge CFI only to images that > advertise it, which bzImage does not. > > New flags that change code generation or semantics in a plain x86_64 > defconfig hardening.config stub: > > Hardening: > -ftrivial-auto-var-init=zero > -fzero-init-padding-bits=all > -fstrict-flex-arrays=3 > -fno-strict-overflow > -fno-delete-null-pointer-checks > -fno-allow-store-data-races > -fno-jump-tables (from the default IBT config) > > C semantics: > -funsigned-char > -fno-common > > x86 code generation: > -mno-sse2 -mno-3dnow -mno-avx -mno-sse4a > (stub already added -mno-mmx -mno-sse) > -mno-80387 -mno-fp-ret-in-387 -mskip-rax-setup > -falign-jumps=1 -falign-loops=1 -fmin-function-alignment=16 > -fomit-frame-pointer -fconserve-stack > -fno-stack-clash-protection -fno-stack-check -fno-builtin-wcslen > > Warnings (lots and lots, but notably): > -Wall -Wextra -Wundef -Wmissing-prototypes > -Wvla-larger-than=1 -Wimplicit-fallthrough=5 > > Present but with no effect, because the stub's later flags override them: > -O2, overridden by -Os > -fstack-protector-* flags, overridden by -fno-stack-protector > -fno-PIE, overridden by -fPIC > -fcf-protection=branch, overridden by -fcf-protection=none > the stack-erase plugin, loaded and then disabled > > Build tested ARCH=x86_64 defconfig hardening.config, plus retpolines, > return thunks, call depth tracking, IBT, GCC plugins, and EFI mixed > mode, with GCC 16.2.0 and Clang 24.0.0git, and ARCH=i386 defconfig > hardening.config with GCC 16.2.0. Each booted through the EFI stub to > userspace under QEMU with x64 and IA32 OVMF, the latter in mixed mode > for x86_64. > > Assisted-by: LLM > Signed-off-by: Kees Cook <kees@kernel.org> Yeah, this has long been needed. Looking over the list of flags in the .cmd files, I don't think there should be anything problematic. I'd love to test this on one of my machines at home to make sure but the coaxial line from my condo unit to the junction box is broken :) so I'll just settle for: Reviewed-by: Nathan Chancellor <nathan@kernel.org> > --- > drivers/firmware/efi/libstub/Makefile | 24 ++++++++++++++---------- > 1 file changed, 14 insertions(+), 10 deletions(-) > > diff --git a/drivers/firmware/efi/libstub/Makefile b/drivers/firmware/efi/libstub/Makefile > index 77a2b2d74f3f..1f588591f458 100644 > --- a/drivers/firmware/efi/libstub/Makefile > +++ b/drivers/firmware/efi/libstub/Makefile > @@ -6,18 +6,22 @@ > # enabled, even if doing so doesn't break the build. > # > > -# non-x86 reuses KBUILD_CFLAGS, x86 does not > cflags-y := $(KBUILD_CFLAGS) > > -cflags-$(CONFIG_X86_32) := -march=i386 > -cflags-$(CONFIG_X86_64) := -mcmodel=small > -cflags-$(CONFIG_X86) += -m$(BITS) -D__KERNEL__ $(CC_FLAGS_DIALECT) \ > - -fPIC -fno-strict-aliasing -mno-red-zone \ > - -mno-mmx -mno-sse -fshort-wchar \ > - -Wno-pointer-sign \ > - $(call cc-disable-warning, address-of-packed-member) \ > - -fno-asynchronous-unwind-tables \ > - $(CLANG_FLAGS) > +# x86 links the stub into the decompressor rather than the kernel proper, so > +# drop the kernel's code model, calling convention, and stack alignment, and > +# the mitigations that rely on thunks and patch sites only the kernel has. > +cflags-$(CONFIG_X86) := $(filter-out -mcmodel=kernel \ > + -mregparm=3 -freg-struct-return \ > + -mpreferred-stack-boundary=% \ > + -mstack-alignment=% \ > + $(RETPOLINE_CFLAGS) $(RETHUNK_CFLAGS) \ > + $(PADDING_CFLAGS), $(cflags-y)) > +cflags-$(CONFIG_X86_32) += -march=i386 > +cflags-$(CONFIG_X86_64) += -mcmodel=small > +cflags-$(CONFIG_X86) += -fPIC $(DISABLE_KSTACK_ERASE) > +# Nothing enables IBT while the stub runs, so ENDBR would only take space. > +cflags-$(CONFIG_X86) += $(call cc-option,-fcf-protection=none) Note that post commit 454e00cf8ee5 ("kbuild: avoid re-running compiler and linker probes") in the kbuild tree, this can become cflags-$(CONFIG_X86) += $(CONFIG_CC_OPT_CF_PROTECTION_NONE) > # arm64 uses the full KBUILD_CFLAGS so it's necessary to explicitly > # disable the stackleak plugin > -- > 2.55.0 > -- Cheers, Nathan ^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH v1 3/3] efi/libstub: Disable kernel stack erasing in the common flags 2026-10-06 20:42 [PATCH v1 0/3] efi/libstub: Build the x86 stub from KBUILD_CFLAGS Kees Cook 2026-10-06 20:42 ` [PATCH v1 1/3] efi/libstub: Declare the x86 stub's assembly entry points Kees Cook 2026-10-06 20:42 ` [PATCH v1 2/3] efi/libstub: Build the x86 stub from KBUILD_CFLAGS Kees Cook @ 2026-10-06 20:42 ` Kees Cook 2026-10-07 9:21 ` Nathan Chancellor 2 siblings, 1 reply; 6+ messages in thread From: Kees Cook @ 2026-10-06 20:42 UTC (permalink / raw) To: Ard Biesheuvel Cc: Kees Cook, Ilias Apalodimas, Nathan Chancellor, Nicolas Schier, linux-efi, linux-kernel, linux-hardening Every architecture that builds the stub now adds $(DISABLE_KSTACK_ERASE) to its own flags, so add it once to the flags they share instead. Assisted-by: LLM Signed-off-by: Kees Cook <kees@kernel.org> --- drivers/firmware/efi/libstub/Makefile | 17 +++++++---------- 1 file changed, 7 insertions(+), 10 deletions(-) diff --git a/drivers/firmware/efi/libstub/Makefile b/drivers/firmware/efi/libstub/Makefile index 1f588591f458..d6fe69c3af87 100644 --- a/drivers/firmware/efi/libstub/Makefile +++ b/drivers/firmware/efi/libstub/Makefile @@ -19,22 +19,18 @@ cflags-$(CONFIG_X86) := $(filter-out -mcmodel=kernel \ $(PADDING_CFLAGS), $(cflags-y)) cflags-$(CONFIG_X86_32) += -march=i386 cflags-$(CONFIG_X86_64) += -mcmodel=small -cflags-$(CONFIG_X86) += -fPIC $(DISABLE_KSTACK_ERASE) +cflags-$(CONFIG_X86) += -fPIC # Nothing enables IBT while the stub runs, so ENDBR would only take space. cflags-$(CONFIG_X86) += $(call cc-option,-fcf-protection=none) -# arm64 uses the full KBUILD_CFLAGS so it's necessary to explicitly -# disable the stackleak plugin -cflags-$(CONFIG_ARM64) += -fpie $(DISABLE_KSTACK_ERASE) \ - -fno-unwind-tables -fno-asynchronous-unwind-tables +cflags-$(CONFIG_ARM64) += -fpie -fno-unwind-tables \ + -fno-asynchronous-unwind-tables cflags-$(CONFIG_ARM) += -DEFI_HAVE_STRLEN -DEFI_HAVE_STRNLEN \ -DEFI_HAVE_MEMCHR -DEFI_HAVE_STRRCHR \ -DEFI_HAVE_STRCMP -fno-builtin -fpic \ - $(call cc-option,-mno-single-pic-base) \ - $(DISABLE_KSTACK_ERASE) -cflags-$(CONFIG_RISCV) += -fpic -DNO_ALTERNATIVE -mno-relax \ - $(DISABLE_KSTACK_ERASE) -cflags-$(CONFIG_LOONGARCH) += -fpie $(DISABLE_KSTACK_ERASE) + $(call cc-option,-mno-single-pic-base) +cflags-$(CONFIG_RISCV) += -fpic -DNO_ALTERNATIVE -mno-relax +cflags-$(CONFIG_LOONGARCH) += -fpie cflags-$(CONFIG_EFI_PARAMS_FROM_FDT) += -I$(srctree)/scripts/dtc/libfdt @@ -44,6 +40,7 @@ KBUILD_CFLAGS := $(subst $(CC_FLAGS_FTRACE),,$(cflags-y)) \ -D__NO_FORTIFY \ -ffreestanding \ -fno-stack-protector \ + $(DISABLE_KSTACK_ERASE) \ $(call cc-option,-fno-addrsig) \ -D__DISABLE_EXPORTS -- 2.55.0 ^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH v1 3/3] efi/libstub: Disable kernel stack erasing in the common flags 2026-10-06 20:42 ` [PATCH v1 3/3] efi/libstub: Disable kernel stack erasing in the common flags Kees Cook @ 2026-10-07 9:21 ` Nathan Chancellor 0 siblings, 0 replies; 6+ messages in thread From: Nathan Chancellor @ 2026-10-07 9:21 UTC (permalink / raw) To: Kees Cook Cc: Ard Biesheuvel, Ilias Apalodimas, Nicolas Schier, linux-efi, linux-kernel, linux-hardening On Tue, Oct 06, 2026 at 01:42:23PM -0700, Kees Cook wrote: > Every architecture that builds the stub now adds $(DISABLE_KSTACK_ERASE) > to its own flags, so add it once to the flags they share instead. > > Assisted-by: LLM > Signed-off-by: Kees Cook <kees@kernel.org> Reviewed-by: Nathan Chancellor <nathan@kernel.org> > --- > drivers/firmware/efi/libstub/Makefile | 17 +++++++---------- > 1 file changed, 7 insertions(+), 10 deletions(-) > > diff --git a/drivers/firmware/efi/libstub/Makefile b/drivers/firmware/efi/libstub/Makefile > index 1f588591f458..d6fe69c3af87 100644 > --- a/drivers/firmware/efi/libstub/Makefile > +++ b/drivers/firmware/efi/libstub/Makefile > @@ -19,22 +19,18 @@ cflags-$(CONFIG_X86) := $(filter-out -mcmodel=kernel \ > $(PADDING_CFLAGS), $(cflags-y)) > cflags-$(CONFIG_X86_32) += -march=i386 > cflags-$(CONFIG_X86_64) += -mcmodel=small > -cflags-$(CONFIG_X86) += -fPIC $(DISABLE_KSTACK_ERASE) > +cflags-$(CONFIG_X86) += -fPIC > # Nothing enables IBT while the stub runs, so ENDBR would only take space. > cflags-$(CONFIG_X86) += $(call cc-option,-fcf-protection=none) > > -# arm64 uses the full KBUILD_CFLAGS so it's necessary to explicitly > -# disable the stackleak plugin > -cflags-$(CONFIG_ARM64) += -fpie $(DISABLE_KSTACK_ERASE) \ > - -fno-unwind-tables -fno-asynchronous-unwind-tables > +cflags-$(CONFIG_ARM64) += -fpie -fno-unwind-tables \ > + -fno-asynchronous-unwind-tables > cflags-$(CONFIG_ARM) += -DEFI_HAVE_STRLEN -DEFI_HAVE_STRNLEN \ > -DEFI_HAVE_MEMCHR -DEFI_HAVE_STRRCHR \ > -DEFI_HAVE_STRCMP -fno-builtin -fpic \ > - $(call cc-option,-mno-single-pic-base) \ > - $(DISABLE_KSTACK_ERASE) > -cflags-$(CONFIG_RISCV) += -fpic -DNO_ALTERNATIVE -mno-relax \ > - $(DISABLE_KSTACK_ERASE) > -cflags-$(CONFIG_LOONGARCH) += -fpie $(DISABLE_KSTACK_ERASE) > + $(call cc-option,-mno-single-pic-base) > +cflags-$(CONFIG_RISCV) += -fpic -DNO_ALTERNATIVE -mno-relax > +cflags-$(CONFIG_LOONGARCH) += -fpie > > cflags-$(CONFIG_EFI_PARAMS_FROM_FDT) += -I$(srctree)/scripts/dtc/libfdt > > @@ -44,6 +40,7 @@ KBUILD_CFLAGS := $(subst $(CC_FLAGS_FTRACE),,$(cflags-y)) \ > -D__NO_FORTIFY \ > -ffreestanding \ > -fno-stack-protector \ > + $(DISABLE_KSTACK_ERASE) \ > $(call cc-option,-fno-addrsig) \ > -D__DISABLE_EXPORTS > > -- > 2.55.0 > -- Cheers, Nathan ^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-10-07 9:21 UTC | newest] Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed) -- links below jump to the message on this page -- 2026-10-06 20:42 [PATCH v1 0/3] efi/libstub: Build the x86 stub from KBUILD_CFLAGS Kees Cook 2026-10-06 20:42 ` [PATCH v1 1/3] efi/libstub: Declare the x86 stub's assembly entry points Kees Cook 2026-10-06 20:42 ` [PATCH v1 2/3] efi/libstub: Build the x86 stub from KBUILD_CFLAGS Kees Cook 2026-10-07 9:20 ` Nathan Chancellor 2026-10-06 20:42 ` [PATCH v1 3/3] efi/libstub: Disable kernel stack erasing in the common flags Kees Cook 2026-10-07 9:21 ` Nathan Chancellor
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®