git: 58741fa51dc2 - main - boot-test.sh: Add virtio-rng-pci to the EFI RAM-disk netboot qemu invocation
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Sat, 26 Sep 2026 06:44:51 UTC
The branch main has been updated by imp:
URL: https://cgit.FreeBSD.org/src/commit/?id=58741fa51dc207123c18b3a4125af99cab798898
commit 58741fa51dc207123c18b3a4125af99cab798898
Author: Warner Losh <imp@FreeBSD.org>
AuthorDate: 2026-09-24 14:35:45 +0000
Commit: Warner Losh <imp@FreeBSD.org>
CommitDate: 2026-09-26 06:43:53 +0000
boot-test.sh: Add virtio-rng-pci to the EFI RAM-disk netboot qemu invocation
Since the PixieFail security fixes (CVE-2023-45237), EDK II's DxeNetLib --
underneath essentially all of NetworkPkg (Mnp/Arp/Ip4/Dhcp4/Tcp/Http) --
carries a DEPEX on EFI_RNG_PROTOCOL. With no RNG protocol producer
available, that DEPEX is never satisfied and the entire NetworkPkg driver
stack silently fails to load: no error, no assert, it just isn't there.
netboot-efi and netboot-ramdisk never noticed because they only ever touch
the raw EFI_SIMPLE_NETWORK_PROTOCOL via our own net.c, which has no such
dependency. A test that needs EDK II's own NetworkPkg (e.g. one exercising
EFI_HTTP_PROTOCOL) is the first to be affected.
RngDxe can satisfy the DEPEX from the RDRAND instruction alone on a
sufficiently recent edk2 build, but not every installed OVMF is that
recent. -device virtio-rng-pci provides an RNG unconditionally via
VirtioRngDxe, regardless of edk2 vintage or host CPU features.
Unfortunately, the edk2 shipped with qemu lacks the network this needs.
Sponsored by: Netflix
---
tools/boot/boot-test.sh | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/tools/boot/boot-test.sh b/tools/boot/boot-test.sh
index 5ead7260d781..023d2589824c 100755
--- a/tools/boot/boot-test.sh
+++ b/tools/boot/boot-test.sh
@@ -277,6 +277,9 @@ qemu_netboot() {
# we don't use the ipxe USB path we use here. We use that because Tianocore
# expects http/https booting when the obvious '-boot n' sort of things
# are used.
+#
+# -device virtio-rng-pci: EDK II's network stack has required an RNG
+# device since CVE-2023-45237.
qemu_netboot_ramdisk() {
netif=$1
echo "$(param qemu_bin) -M q35 -cpu max -m 2g \
@@ -285,6 +288,7 @@ qemu_netboot_ramdisk() {
-hda ${OUTDIR}/netboot-ipxe.img \
-device virtio-net,netdev=net0 \
-netdev tap,id=net0,ifname=${netif},script=no,downscript=no \
+ -device virtio-rng-pci \
-fw_cfg name=opt/org.tianocore/IPv4PXESupport,string=no \
-fw_cfg name=opt/org.tianocore/IPv6PXESupport,string=no \
-nographic -monitor none -serial stdio"