git: 58741fa51dc2 - main - boot-test.sh: Add virtio-rng-pci to the EFI RAM-disk netboot qemu invocation

From: Warner Losh <imp_at_FreeBSD.org>
Date: Sat, 26 Sep 2026 06:44:51 UTC
The branch main has been updated by imp:

URL: https://cgit.FreeBSD.org/src/commit/?id=58741fa51dc207123c18b3a4125af99cab798898

commit 58741fa51dc207123c18b3a4125af99cab798898
Author:     Warner Losh <imp@FreeBSD.org>
AuthorDate: 2026-09-24 14:35:45 +0000
Commit:     Warner Losh <imp@FreeBSD.org>
CommitDate: 2026-09-26 06:43:53 +0000

    boot-test.sh: Add virtio-rng-pci to the EFI RAM-disk netboot qemu invocation
    
    Since the PixieFail security fixes (CVE-2023-45237), EDK II's DxeNetLib --
    underneath essentially all of NetworkPkg (Mnp/Arp/Ip4/Dhcp4/Tcp/Http) --
    carries a DEPEX on EFI_RNG_PROTOCOL. With no RNG protocol producer
    available, that DEPEX is never satisfied and the entire NetworkPkg driver
    stack silently fails to load: no error, no assert, it just isn't there.
    
    netboot-efi and netboot-ramdisk never noticed because they only ever touch
    the raw EFI_SIMPLE_NETWORK_PROTOCOL via our own net.c, which has no such
    dependency. A test that needs EDK II's own NetworkPkg (e.g. one exercising
    EFI_HTTP_PROTOCOL) is the first to be affected.
    
    RngDxe can satisfy the DEPEX from the RDRAND instruction alone on a
    sufficiently recent edk2 build, but not every installed OVMF is that
    recent. -device virtio-rng-pci provides an RNG unconditionally via
    VirtioRngDxe, regardless of edk2 vintage or host CPU features.
    
    Unfortunately, the edk2 shipped with qemu lacks the network this needs.
    
    Sponsored by:           Netflix
---
 tools/boot/boot-test.sh | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/tools/boot/boot-test.sh b/tools/boot/boot-test.sh
index 5ead7260d781..023d2589824c 100755
--- a/tools/boot/boot-test.sh
+++ b/tools/boot/boot-test.sh
@@ -277,6 +277,9 @@ qemu_netboot() {
 # we don't use the ipxe USB path we use here. We use that because Tianocore
 # expects http/https booting when the obvious '-boot n' sort of things
 # are used.
+#
+# -device virtio-rng-pci: EDK II's network stack has required an RNG
+# device since CVE-2023-45237.
 qemu_netboot_ramdisk() {
     netif=$1
     echo "$(param qemu_bin) -M q35 -cpu max -m 2g \
@@ -285,6 +288,7 @@ qemu_netboot_ramdisk() {
 	-hda ${OUTDIR}/netboot-ipxe.img \
 	-device virtio-net,netdev=net0 \
 	-netdev tap,id=net0,ifname=${netif},script=no,downscript=no \
+	-device virtio-rng-pci \
 	-fw_cfg name=opt/org.tianocore/IPv4PXESupport,string=no \
 	-fw_cfg name=opt/org.tianocore/IPv6PXESupport,string=no \
 	-nographic -monitor none -serial stdio"