audk/OvmfPkg/CloudHv
Jan Bobek f6e4824533 OvmfPkg: require self-signed PK when secure boot is enabled
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=2506

In all DSC files that define SECURE_BOOT_ENABLE, opt-in into requiring
self-signed PK when SECURE_BOOT_ENABLE is TRUE.

Cc: Ard Biesheuvel <ardb+tianocore@kernel.org>
Cc: Jiewen Yao <jiewen.yao@intel.com>
Cc: Jordan Justen <jordan.l.justen@intel.com>
Cc: Gerd Hoffmann <kraxel@redhat.com>
Cc: Rebecca Cran <rebecca@bsdio.com>
Cc: Peter Grehan <grehan@freebsd.org>
Cc: Sebastien Boeuf <sebastien.boeuf@intel.com>
Signed-off-by: Jan Bobek <jbobek@nvidia.com>
Reviewed-by: Sean Brogan <sean.brogan@microsoft.com>
Acked-by: Jiewen Yao <jiewen.yao@intel.com>
2023-02-04 11:53:59 +00:00
..
CloudHvDefines.fdf.inc OvmfPkg: CloudHv: Fix FW_BASE_ADDRESS 2022-06-03 10:51:26 +00:00
CloudHvElfHeader.fdf.inc
CloudHvX64.dsc OvmfPkg: require self-signed PK when secure boot is enabled 2023-02-04 11:53:59 +00:00
CloudHvX64.fdf mv OvmfPkg: move fdf include snippets to Include/Fdf 2022-12-09 14:07:21 +00:00
README OvmfPkg: CloudHv: Add README 2022-03-04 02:41:57 +00:00

README

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.


CloudHv is a port of OVMF for the Cloud Hypervisor project.

The Cloud Hypervisor project
----------------------------

Cloud Hypervisor is a Virtual Machine Monitor that runs on top of KVM. The
project focuses on exclusively running modern, cloud workloads, on top of a
limited set of hardware architectures and platforms. Cloud workloads refers to
those that are usually run by customers inside a cloud provider. This means
modern operating systems with most I/O handled by paravirtualised devices
(i.e. virtio), no requirement for legacy devices, and 64-bit CPUs.

https://github.com/cloud-hypervisor/cloud-hypervisor

Design
------

Based on Cloud Hypervisor's motto to reduce the emulation as much as possible,
the project logically decided to support the PVH boot specification as the only
way of booting virtual machines. That includes both direct kernel boot and OVMF
firmware which must be generated as PVH ELF binaries.
PVH allows information like location of ACPI tables and location of guest RAM
ranges to be shared without the need of an extra emulated device like a CMOS.

Features
--------

* Serial console
* EFI shell
* virtio-pci

Build
-----

The way to build the CloudHv target is as follows:

OvmfPkg/build.sh -p OvmfPkg/CloudHv/CloudHvX64.dsc -a X64 -b DEBUG

Usage
-----

Assuming Cloud Hypervisor is already built, one can start a virtual machine as
follows:

./cloud-hypervisor \
    --cpus boot=1 \
    --memory size=1G \
    --kernel Build/CloudHvX64/DEBUG_GCC5/FV/CLOUDHV.fd \
    --disk path=/path/to/disk.raw

Releases
--------

In edk2-stable202202, CloudHv is generated as data-only binary.
Starting with edk2-stable202205, CloudHv is generated as a PVH ELF binary to
reduce the amount of emulation needed from Cloud Hypervisor.
For TDX, things are handled differently and PVH is not used, which is why the
firmware is always generated as a data-only binary.

+-------------------+----------------+
|                   |    CloudHv     |
+-------------------+----------------+
| edk2-stable202202 | Data binary    |
+-------------------+----------------+
| edk2-stable202205 | PVH ELF binary |
+-------------------+----------------+