diff --git a/src/runtime/Makefile b/src/runtime/Makefile index 4c14fbc788..23d28085f6 100644 --- a/src/runtime/Makefile +++ b/src/runtime/Makefile @@ -149,7 +149,7 @@ FIRMWARETDVFPATH := PLACEHOLDER_FOR_DISTRO_OVMF_WITH_TDX_SUPPORT FIRMWARETDVFVOLUMEPATH := FIRMWARESEVPATH := $(PREFIXDEPS)/share/ovmf/OVMF.fd -FIRMWARESNPPATH := $(PREFIXDEPS)/share/ovmf/OVMF.fd +FIRMWARESNPPATH := $(PREFIXDEPS)/share/ovmf/AMDSEV.fd ROOTMEASURECONFIG ?= "" KERNELPARAMS += $(ROOTMEASURECONFIG) diff --git a/src/runtime/pkg/govmm/qemu/qemu.go b/src/runtime/pkg/govmm/qemu/qemu.go index 092c0b8ca2..d9c1e21a2c 100644 --- a/src/runtime/pkg/govmm/qemu/qemu.go +++ b/src/runtime/pkg/govmm/qemu/qemu.go @@ -375,12 +375,19 @@ func (object Object) QemuParams(config *Config) []string { objectParams = append(objectParams, prepareObjectWithTdxQgs(object)) config.Bios = object.File case SEVGuest: - fallthrough + objectParams = append(objectParams, string(object.Type)) + objectParams = append(objectParams, fmt.Sprintf("id=%s", object.ID)) + objectParams = append(objectParams, fmt.Sprintf("cbitpos=%d", object.CBitPos)) + objectParams = append(objectParams, fmt.Sprintf("reduced-phys-bits=%d", object.ReducedPhysBits)) + + driveParams = append(driveParams, "if=pflash,format=raw,readonly=on") + driveParams = append(driveParams, fmt.Sprintf("file=%s", object.File)) case SNPGuest: objectParams = append(objectParams, string(object.Type)) objectParams = append(objectParams, fmt.Sprintf("id=%s", object.ID)) objectParams = append(objectParams, fmt.Sprintf("cbitpos=%d", object.CBitPos)) objectParams = append(objectParams, fmt.Sprintf("reduced-phys-bits=%d", object.ReducedPhysBits)) + objectParams = append(objectParams, "kernel-hashes=on") driveParams = append(driveParams, "if=pflash,format=raw,readonly=on") driveParams = append(driveParams, fmt.Sprintf("file=%s", object.File)) diff --git a/versions.yaml b/versions.yaml index a59c86c109..4cf2a4d85a 100644 --- a/versions.yaml +++ b/versions.yaml @@ -324,12 +324,12 @@ externals: url: "https://github.com/tianocore/edk2" x86_64: description: "Vanilla firmware build" - version: "edk2-stable202202" + version: "edk2-stable202402" package: "OvmfPkg/OvmfPkgX64.dsc" package_output_dir: "OvmfX64" sev: description: "AmdSev build needed for SEV measured direct boot." - version: "edk2-stable202302" + version: "edk2-stable202402" package: "OvmfPkg/AmdSev/AmdSevX64.dsc" package_output_dir: "AmdSev"