summaryrefslogtreecommitdiffstats
path: root/src/image
diff options
context:
space:
mode:
authorMichael Brown2026-01-14 14:25:34 +0100
committerMichael Brown2026-01-14 14:25:34 +0100
commit6cccb3bdc00359068c07125258d71ce24db5118a (patch)
tree11120ed933b1846fadc4eaf543d35d1098e95803 /src/image
parent[build] Check for standalone FILE_LICENCE() and FILE_SECBOOT() declarations (diff)
downloadipxe-6cccb3bdc00359068c07125258d71ce24db5118a.tar.gz
ipxe-6cccb3bdc00359068c07125258d71ce24db5118a.tar.xz
ipxe-6cccb3bdc00359068c07125258d71ce24db5118a.zip
[build] Mark core files as permitted for UEFI Secure Boot
Mark all files used in a standard build of bin-x86_64-efi/snponly.efi as permitted for UEFI Secure Boot. These files represent the core functionality of iPXE that is guaranteed to have been included in every binary that was previously subject to a security review and signed by Microsoft. It is therefore legitimate to assume that at least these files have already been reviewed to the required standard multiple times. Signed-off-by: Michael Brown <mcb30@ipxe.org>
Diffstat (limited to 'src/image')
-rw-r--r--src/image/efi_image.c1
-rw-r--r--src/image/embedded.c1
-rw-r--r--src/image/script.c1
3 files changed, 3 insertions, 0 deletions
diff --git a/src/image/efi_image.c b/src/image/efi_image.c
index e7b19c4ce..2631530e7 100644
--- a/src/image/efi_image.c
+++ b/src/image/efi_image.c
@@ -18,6 +18,7 @@
*/
FILE_LICENCE ( GPL2_OR_LATER );
+FILE_SECBOOT ( PERMITTED );
#include <errno.h>
#include <stdlib.h>
diff --git a/src/image/embedded.c b/src/image/embedded.c
index 652cfc85f..22d3738cc 100644
--- a/src/image/embedded.c
+++ b/src/image/embedded.c
@@ -7,6 +7,7 @@
*/
FILE_LICENCE ( GPL2_OR_LATER_OR_UBDL );
+FILE_SECBOOT ( PERMITTED );
#include <string.h>
#include <ipxe/image.h>
diff --git a/src/image/script.c b/src/image/script.c
index 257e59a09..57662b788 100644
--- a/src/image/script.c
+++ b/src/image/script.c
@@ -22,6 +22,7 @@
*/
FILE_LICENCE ( GPL2_OR_LATER_OR_UBDL );
+FILE_SECBOOT ( PERMITTED );
/**
* @file