[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH 1/2] tools/firmware: fix setting of fcf-protection=none


  • To: Roger Pau Monne <roger.pau@xxxxxxxxxx>, "xen-devel@xxxxxxxxxxxxxxxxxxxx" <xen-devel@xxxxxxxxxxxxxxxxxxxx>, Jan Beulich <jbeulich@xxxxxxxx>
  • From: Andrew Cooper <Andrew.Cooper3@xxxxxxxxxx>
  • Date: Fri, 1 Apr 2022 15:05:54 +0000
  • Accept-language: en-GB, en-US
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=citrix.com; dmarc=pass action=none header.from=citrix.com; dkim=pass header.d=citrix.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=IcDh3n48SXGCltswn2QBP5U/83++9ulLmrd9BrfHZsE=; b=AB8FOS3aYsTAdRuh++MqRmQpo4Ezlm8J7Xq2yGTOj7xhm48WZS2jWRtTfDEomn4yY/2g8KbpYkAoJRm/bkAU/0qBLaacdfwFo6ukoJ/bDHRSG6YeNadAaiz/M8ZgxbK8KaAvGCUPRDRJ5scTuTZS3ZXHXi+Xwq29nHeZnR3iO7z9o1kIZfbpChr9cwzvWWR0oy8+AQesEo+XmTOKp5vqN322YeYESVIIg6di0NS33xxEO5sRLBAOypd2rceZ1DKvrp7iVC3eNYN4rEHjdOnfPM99nF0uyVSHC+jiRNaPuN/+lCYQTzoLrR6eSwtnkGgdQ5PsCnCp3MdsOBqCutMbvg==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=YzQTyeVIDG5dvI0U3bknoCXW//xuXhQZBmCQG+xbQszC38g4HRrjHv8iL3E5LBOkVZq96FKwfe52UcT7cOvRrhgxuVo7txc90Q3Y/f7U3Txw1oMwPU8/mLAlpXATWD8yI/9dNfyF+Y/A2qHbJyyoZEdOLoTVPcmagVDZfE74vjc1oIe4XsCq1TBcZ9t6sMUBwIudBdCTkFxuOx59Auuibcxz6TzK8PnK8FXd/obEofHcgr2UHr0iLXFzcJkJsPNFHebLh60JLmZXpvPayfddEewCNdmcer9GuW+B4xLRu6hLZiGstc/TyODWE/CoRgbS3LzQg9o15o2Zz5CmUK8agg==
  • Authentication-results: esa5.hc3370-68.iphmx.com; dkim=pass (signature verified) header.i=@citrix.onmicrosoft.com
  • Cc: Wei Liu <wl@xxxxxxx>, Anthony Perard <anthony.perard@xxxxxxxxxx>
  • Delivery-date: Fri, 01 Apr 2022 15:06:03 +0000
  • Ironport-data: A9a23:aO2tcKwBtUgdHvMJrEt6t+clxirEfRIJ4+MujC+fZmUNrF6WrkVWn WEbXWrQPKqJajGgKo0gYYi190xXsMfXx95hTwE5/CAxQypGp/SeCIXCJC8cHc8zwu4v7q5Dx 59DAjUVBJlsFhcwnj/0bv656yMUOZigHtIQMsadUsxKbVIiGX9JZS5LwbZj2NY02YHhWWthh PupyyHhEA79s9JLGjp8B5Kr8HuDa9yr5Vv0FnRnDRx6lAe2e0s9VfrzFonoR5fMeaFGH/bSe gr25OrRElU1XfsaIojNfr7TKiXmS1NJVOSEoiI+t6OK2nCuqsGuu0qS2TV1hUp/0l20c95NJ NplqrOzSiwoN7f126dFYUZcEBsjLLZW5+qSSZS/mZT7I0zudnLtx7NlDV0sPJ1e8eFyaY1M3 aVGcnZXNEnF3r/ohuLgIgVvrp1LwM3DFYUToHx/ixreCu4rW8vrSKTW/95Imjw3g6iiGN6AO JBBOGc1NXwsZTVoP3tOEYIDwNypn2O4WjsCuHXLirootj27IAtZj+G2bYu9lsaxbdpRtlaVo CTB5WuRKhMQOcGbyDGF2mmxneKJliT+MKoCGbv9+vN0jVm7wm0IFAZQRVa9ueO+iEO1R5RYM UN8x8Y1hfFsrgrxFIC7BkDm5i7f1vIBZzZOO/IV6wKmy6PO2kXaXlpbSj17Nc09pNBjEFTGy WS1t9/uADVutpicRnSc6qqYoFuOBMQFEYMRTXRaFFVYurEPtKl210uSFYg7TMZZm/WvQVnNL ya2QD/Sbln5peoCzO2F8F/OmFpATbCZH1dutm07so9Ihz6VhbJJhaT1sTA3Dt4ade51q2VtW lBexKByC8hUUfmweNSlGrllIV1Qz6/t3MfgqVBuBYI90D+m5mSue4tdiBknehs5bZteI2e4M RKO0e+02HO1FCH1BUOQS9jsY/nGMIC6TYi1PhwqRoQmjmdNmP+vo3g1OB/4M5HFm0kwi6AvU ap3gu73ZUv2/Z9PlWLsL89EiOdD7nlnmQv7GMCqpzz6gOH2TCPEFt843K6mM7lRAFWs+16Or b6y9qKiln1ibQEJSnKJqdRKdwBbcCBT6FKfg5U/S9Nv6zFOQQkJI/TQ3akga8pimaFUnf3P5 XazRglTz1+XuJENAVnihqxLAF83YatCkA==
  • Ironport-hdrordr: A9a23:6r9PCqiIhfG073qDkmQGB50VIHBQX3p13DAbv31ZSRFFG/FwyP rBoB1L73DJYWgqNE3IwerwRJVpQRvnhPpICRF4B8btYOCUghrWEGgE1/qi/9SAIVywygc578 ZdmsdFeaXN5DRB/KTHCUyDYqsdKbq8geCVbIXlvgxQpGhRAskKhWoYe2Wm+w9NNXN77PICZc ChD6F81l2dkAEsH72G7w4+Lo7+TrPw5ffbSC9DIyRixBiFjDuu5rK/OQOfxA0iXzRGxqpn2X TZkiTij5/T8M2T+1v57Sv+/p5WkNzuxp9oH8qXkPUYLT3ql0KBeJlhYbufpzo4ydvfqmrC0e O85ivIDf4DrE85TVvF5ycFHDOQiQrG3kWSjWNwR0GT+fARCghKUPapzrgpDCcxo3BQze2Ulp g7gl5x/qAnfi8p1k7Glqj1fgAvmUyurXU4l+kPy3RZTIsFcbdU6ZcS5UVPDf47bWjHAa0cYa FT5fvnlb1rmJKhHgfkl3gqxMbpUmU4Hx+ATERHssuJ0yJOlHQ8y0cD3sQQknoJ6Zp4EvB/lq j5G7UtkKsLQt4dbKp7CutEScyrCnbVSRaJNG6JO1zoGKwOJnqIoZ/q57c+4v2sZfUzvdYPsY WEVEkduX85ekroB8HL1JpX8grVSGH4RjjpwtE23ekxhlQ9fsucDcSuciFaryL7mYRsPiTyYY fGBK5r
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>
  • Thread-index: AQHYRdaC1Ty1lDbR3E6vxjqdlx39GKzbI4SAgAAExYA=
  • Thread-topic: [PATCH 1/2] tools/firmware: fix setting of fcf-protection=none

On 01/04/2022 15:48, Andrew Cooper wrote:
> On 01/04/2022 15:37, Roger Pau Monne wrote:
>> Setting the fcf-protection=none option in EMBEDDED_EXTRA_CFLAGS in the
>> Makefile doesn't get it propagated to the subdirectories, so instead
>> set the flag in firmware/Rules.mk, like it's done for other compiler
>> flags.
>>
>> Fixes: 3667f7f8f7 ('x86: Introduce support for CET-IBT')
>> Signed-off-by: Roger Pau Monné <roger.pau@xxxxxxxxxx>
> Acked-by: Andrew Cooper <andrew.cooper3@xxxxxxxxxx>

This also needs backporting with the XSA-398 CET-IBT fixes.

~Andrew

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.