RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Bug 2135715 - Sym links missing edk2-ovmf
Summary: Sym links missing edk2-ovmf
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Red Hat Enterprise Linux 9
Classification: Red Hat
Component: edk2
Version: 9.0
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: rc
: ---
Assignee: Miroslav Rezanina
QA Contact: Xueqiang Wei
URL:
Whiteboard:
Depends On: 2132951
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-10-18 09:00 UTC by Marko Myllynen
Modified: 2022-10-25 15:05 UTC (History)
10 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-10-25 12:47:03 UTC
Type: Bug
Target Upstream Version:
Embargoed:
pm-rhel: mirror+


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RHELPLAN-136837 0 None None None 2022-10-18 09:20:22 UTC

Description Marko Myllynen 2022-10-18 09:00:17 UTC
Description of problem:
The edk2-ovmf package provides sym link only for OVMF_VARS.fd but not for OVMF_CODE.fd.

Some tools expect to find both CODE and VARS in /usr/share/OVMF so it would be helpful to add sym links from /usr/share/OVMF to /usr/share/edk2/ovmf for at least all the .fd files, perhaps for others as well. Thanks.

Comment 1 Xueqiang Wei 2022-10-18 15:13:34 UTC
Tested with edk2-ovmf-20220826gitba0e0e4c6a-1.el9.noarch, it contains the following 4 symbol links.

# ls /usr/share/OVMF/ -l
total 0
lrwxrwxrwx. 1 root root 33 Oct 11 11:04 OVMF_CODE.secboot.fd -> ../edk2/ovmf/OVMF_CODE.secboot.fd
lrwxrwxrwx. 1 root root 25 Oct 11 11:04 OVMF_VARS.fd -> ../edk2/ovmf/OVMF_VARS.fd
lrwxrwxrwx. 1 root root 33 Oct 11 11:04 OVMF_VARS.secboot.fd -> ../edk2/ovmf/OVMF_VARS.secboot.fd
lrwxrwxrwx. 1 root root 26 Oct 11 11:04 UefiShell.iso -> ../edk2/ovmf/UefiShell.iso


Hi Marko,

You mean, add symbol links for the following files, right?

# ls /usr/share/edk2/ovmf -l
total 15772
-rw-r--r--. 1 root root   18816 Oct 11 11:04 EnrollDefaultKeys.efi
-rw-r--r--. 1 root root 4194304 Oct 11 11:04 OVMF.amdsev.fd
-rw-r--r--. 1 root root 3653632 Oct 11 11:04 OVMF_CODE.cc.fd
-rw-r--r--. 1 root root 3653632 Oct 11 11:04 OVMF_CODE.secboot.fd
-rw-r--r--. 1 root root  540672 Oct 16 10:36 OVMF_VARS.fd
-rw-r--r--. 1 root root  540672 Oct 11 11:04 OVMF_VARS.secboot.fd
-rw-r--r--. 1 root root  948096 Oct 11 11:04 Shell.efi
-rw-r--r--. 1 root root 2594816 Oct 11 11:04 UefiShell.iso

Comment 2 Marko Myllynen 2022-10-19 07:35:38 UTC
Thanks for looking into this.

Yes, in particular I was affected by missing the sym link for OVMF_CODE.fd but perhaps other would be helpful as well.

Thanks.

Comment 3 Miroslav Rezanina 2022-10-21 11:32:12 UTC
Just a note - there's no OVMF_CODE.fd shipped for RHEL.

Comment 5 Laszlo Ersek 2022-10-25 07:27:33 UTC
Please refer to the discussion in bug 2132951.

OVMF_CODE.fd has traditionally not been provided in RHEL (unlike in Fedora) because it does not include the (Secure Boot + SMM) feature set. The original idea was to avoid providing a firmware binary in RHEL that lacked the ability to implement (securely) the Secure Boot operational mode.

With the advent of Confidential Computing, a new use case has appeared for a firmware binary that lacks the (Secure Boot + SMM) feature set. However, this binary is not meant as the reinstatement of "OVMF_CODE.fd" in RHEL. Hence the new filename "OVMF_CODE.cc.fd", and the deliberate lack of a compatibility symlink. Please refer to the commit message in <https://gitlab.com/redhat/rhel/src/edk2/-/commit/14f5d2513745> (which is on the "rhel-8.5.0-20200602" branch).

Thus, I'd argue against additional symlinks in RHEL. Either way, I believe bug 2132951 should be solved first.

Comment 6 Miroslav Rezanina 2022-10-25 12:47:03 UTC
As we do not provide required package so we can't create link and there isn't good enough reason for linking other files, closing the BZ.


Note You need to log in before you can comment on or make changes to this bug.