)]}'
{"id":"openstack%2Fnova-specs~506720","triplet_id":"openstack%2Fnova-specs~master~Ib88c9b95364ca7e2b9feff3140b77d70faa6ce1c","project":"openstack/nova-specs","branch":"master","topic":"bp/allow-secure-boot-for-qemu-kvm-guests","hashtags":[],"change_id":"Ib88c9b95364ca7e2b9feff3140b77d70faa6ce1c","subject":"Add \"Secure Boot support for KVM \u0026 QEMU guests\" spec","status":"MERGED","created":"2017-09-22 17:03:07.000000000","updated":"2019-07-04 10:14:50.000000000","submitted":"2019-07-04 10:14:50.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":154,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"506720-1562235290268-5870c8eb","meta_rev_id":"6aeea327d2d86779f40ba1599a909d38d1087125","_number":506720,"virtual_id_number":506720,"owner":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":8864,"name":"Artom Lifshitz","email":"notartom@gmail.com","username":"artom"},{"value":0,"_account_id":8768,"name":"Chris Friesen","email":"chris.friesen@windriver.com","username":"cbf123"},{"value":0,"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},{"value":2,"date":"2019-07-04 10:14:50.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},{"value":0,"_account_id":782,"name":"John Garbutt","email":"john@johngarbutt.com","username":"johngarbutt"},{"value":0,"_account_id":6062,"name":"jichenjc","email":"jichenjc@cn.ibm.com","username":"jichenjc"},{"value":0,"_account_id":28433,"name":"Jack Ding","email":"jackding@gmail.com","username":"jackding"},{"value":0,"date":"2019-07-02 14:10:03.000000000","_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},{"value":0,"_account_id":7634,"name":"Takashi Natsume","email":"takanattie@gmail.com","username":"natsumet"},{"value":0,"_account_id":7730,"name":"Sahid Orentino Ferdjaoui","email":"sahid.ferdjaoui@industrialdiscipline.com","username":"sahid"},{"value":0,"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":21813,"name":"Andrey Volkov","email":"m@amadev.ru","username":"avolkov"},{"value":0,"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},{"value":0,"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},{"value":0,"_account_id":6874,"name":"Patrick Uiterwijk","email":"puiterwijk@gmail.com","username":"puiterwijk"},{"value":0,"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"all":[{"value":0,"_account_id":8864,"name":"Artom Lifshitz","email":"notartom@gmail.com","username":"artom"},{"value":0,"_account_id":8768,"name":"Chris Friesen","email":"chris.friesen@windriver.com","username":"cbf123"},{"value":0,"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":2,"date":"2019-07-02 14:16:18.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},{"value":2,"date":"2019-07-04 10:05:29.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":782,"name":"John Garbutt","email":"john@johngarbutt.com","username":"johngarbutt"},{"value":0,"_account_id":6062,"name":"jichenjc","email":"jichenjc@cn.ibm.com","username":"jichenjc"},{"value":0,"_account_id":28433,"name":"Jack Ding","email":"jackding@gmail.com","username":"jackding"},{"value":0,"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},{"value":0,"_account_id":7634,"name":"Takashi Natsume","email":"takanattie@gmail.com","username":"natsumet"},{"value":0,"_account_id":7730,"name":"Sahid Orentino Ferdjaoui","email":"sahid.ferdjaoui@industrialdiscipline.com","username":"sahid"},{"value":0,"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":21813,"name":"Andrey Volkov","email":"m@amadev.ru","username":"avolkov"},{"value":0,"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},{"value":0,"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},{"value":0,"_account_id":6874,"name":"Patrick Uiterwijk","email":"puiterwijk@gmail.com","username":"puiterwijk"},{"value":0,"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":782,"name":"John Garbutt","email":"john@johngarbutt.com","username":"johngarbutt"},"all":[{"value":0,"_account_id":8864,"name":"Artom Lifshitz","email":"notartom@gmail.com","username":"artom"},{"value":0,"_account_id":8768,"name":"Chris Friesen","email":"chris.friesen@windriver.com","username":"cbf123"},{"value":0,"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},{"value":1,"date":"2019-07-04 10:05:29.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":782,"name":"John Garbutt","email":"john@johngarbutt.com","username":"johngarbutt"},{"value":0,"_account_id":6062,"name":"jichenjc","email":"jichenjc@cn.ibm.com","username":"jichenjc"},{"value":0,"_account_id":28433,"name":"Jack Ding","email":"jackding@gmail.com","username":"jackding"},{"value":0,"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},{"value":0,"_account_id":7634,"name":"Takashi Natsume","email":"takanattie@gmail.com","username":"natsumet"},{"value":0,"_account_id":7730,"name":"Sahid Orentino Ferdjaoui","email":"sahid.ferdjaoui@industrialdiscipline.com","username":"sahid"},{"value":0,"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":21813,"name":"Andrey Volkov","email":"m@amadev.ru","username":"avolkov"},{"value":0,"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},{"value":0,"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},{"value":0,"_account_id":6874,"name":"Patrick Uiterwijk","email":"puiterwijk@gmail.com","username":"puiterwijk"},{"value":0,"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true},"Review-Priority":{"all":[{"value":0,"_account_id":8864,"name":"Artom Lifshitz","email":"notartom@gmail.com","username":"artom"},{"value":0,"_account_id":8768,"name":"Chris Friesen","email":"chris.friesen@windriver.com","username":"cbf123"},{"value":0,"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"value":0,"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},{"value":0,"_account_id":782,"name":"John Garbutt","email":"john@johngarbutt.com","username":"johngarbutt"},{"value":0,"_account_id":6062,"name":"jichenjc","email":"jichenjc@cn.ibm.com","username":"jichenjc"},{"value":0,"_account_id":28433,"name":"Jack Ding","email":"jackding@gmail.com","username":"jackding"},{"value":0,"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},{"value":0,"_account_id":7634,"name":"Takashi Natsume","email":"takanattie@gmail.com","username":"natsumet"},{"value":0,"_account_id":7730,"name":"Sahid Orentino Ferdjaoui","email":"sahid.ferdjaoui@industrialdiscipline.com","username":"sahid"},{"value":0,"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"value":0,"_account_id":21813,"name":"Andrey Volkov","email":"m@amadev.ru","username":"avolkov"},{"value":0,"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},{"value":0,"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},{"value":0,"_account_id":6874,"name":"Patrick Uiterwijk","email":"puiterwijk@gmail.com","username":"puiterwijk"},{"value":0,"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"}],"values":{" 0":"Default Priority","+1":"Contributor Review Promise","+2":"Core Review Promise"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":782,"name":"John Garbutt","email":"john@johngarbutt.com","username":"johngarbutt"},{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},{"_account_id":6062,"name":"jichenjc","email":"jichenjc@cn.ibm.com","username":"jichenjc"},{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},{"_account_id":6874,"name":"Patrick Uiterwijk","email":"puiterwijk@gmail.com","username":"puiterwijk"},{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},{"_account_id":7634,"name":"Takashi Natsume","email":"takanattie@gmail.com","username":"natsumet"},{"_account_id":7730,"name":"Sahid Orentino Ferdjaoui","email":"sahid.ferdjaoui@industrialdiscipline.com","username":"sahid"},{"_account_id":8768,"name":"Chris Friesen","email":"chris.friesen@windriver.com","username":"cbf123"},{"_account_id":8864,"name":"Artom Lifshitz","email":"notartom@gmail.com","username":"artom"},{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},{"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},{"_account_id":21813,"name":"Andrey Volkov","email":"m@amadev.ru","username":"avolkov"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},{"_account_id":28433,"name":"Jack Ding","email":"jackding@gmail.com","username":"jackding"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2017-11-28 14:00:03.000000000","updated_by":{"_account_id":7730,"name":"Sahid Orentino Ferdjaoui","email":"sahid.ferdjaoui@industrialdiscipline.com","username":"sahid"},"reviewer":{"_account_id":7730,"name":"Sahid Orentino Ferdjaoui","email":"sahid.ferdjaoui@industrialdiscipline.com","username":"sahid"},"state":"REVIEWER"},{"updated":"2018-10-23 20:50:27.000000000","updated_by":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"reviewer":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"state":"REVIEWER"},{"updated":"2019-02-26 10:42:39.000000000","updated_by":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"reviewer":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"state":"REVIEWER"},{"updated":"2019-04-04 06:47:47.000000000","updated_by":{"_account_id":7634,"name":"Takashi Natsume","email":"takanattie@gmail.com","username":"natsumet"},"reviewer":{"_account_id":7634,"name":"Takashi Natsume","email":"takanattie@gmail.com","username":"natsumet"},"state":"REVIEWER"},{"updated":"2019-04-09 15:10:12.000000000","updated_by":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"reviewer":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"state":"REVIEWER"},{"updated":"2019-04-15 16:09:49.000000000","updated_by":{"_account_id":21813,"name":"Andrey Volkov","email":"m@amadev.ru","username":"avolkov"},"reviewer":{"_account_id":21813,"name":"Andrey Volkov","email":"m@amadev.ru","username":"avolkov"},"state":"REVIEWER"},{"updated":"2019-04-16 08:54:15.000000000","updated_by":{"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},"reviewer":{"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},"state":"REVIEWER"},{"updated":"2019-04-16 09:59:28.000000000","updated_by":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"reviewer":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"state":"REVIEWER"},{"updated":"2019-04-17 07:36:51.000000000","updated_by":{"_account_id":6874,"name":"Patrick Uiterwijk","email":"puiterwijk@gmail.com","username":"puiterwijk"},"reviewer":{"_account_id":6874,"name":"Patrick Uiterwijk","email":"puiterwijk@gmail.com","username":"puiterwijk"},"state":"REVIEWER"},{"updated":"2019-04-18 14:46:07.000000000","updated_by":{"_account_id":28433,"name":"Jack Ding","email":"jackding@gmail.com","username":"jackding"},"reviewer":{"_account_id":28433,"name":"Jack Ding","email":"jackding@gmail.com","username":"jackding"},"state":"REVIEWER"},{"updated":"2019-04-19 00:56:20.000000000","updated_by":{"_account_id":6062,"name":"jichenjc","email":"jichenjc@cn.ibm.com","username":"jichenjc"},"reviewer":{"_account_id":6062,"name":"jichenjc","email":"jichenjc@cn.ibm.com","username":"jichenjc"},"state":"REVIEWER"},{"updated":"2019-04-24 10:28:29.000000000","updated_by":{"_account_id":8864,"name":"Artom Lifshitz","email":"notartom@gmail.com","username":"artom"},"reviewer":{"_account_id":8864,"name":"Artom Lifshitz","email":"notartom@gmail.com","username":"artom"},"state":"REVIEWER"},{"updated":"2019-05-02 20:47:56.000000000","updated_by":{"_account_id":8768,"name":"Chris Friesen","email":"chris.friesen@windriver.com","username":"cbf123"},"reviewer":{"_account_id":8768,"name":"Chris Friesen","email":"chris.friesen@windriver.com","username":"cbf123"},"state":"REVIEWER"},{"updated":"2019-07-02 14:16:18.000000000","updated_by":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"reviewer":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"state":"REVIEWER"},{"updated":"2019-07-04 10:05:29.000000000","updated_by":{"_account_id":782,"name":"John Garbutt","email":"john@johngarbutt.com","username":"johngarbutt"},"reviewer":{"_account_id":782,"name":"John Garbutt","email":"john@johngarbutt.com","username":"johngarbutt"},"state":"REVIEWER"},{"updated":"2019-07-04 10:14:50.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"f7db6742ffdddeeeaaecf9192d1e038e55a36702","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2017-09-22 17:03:07.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"77ef73c59edc979a443a0baf1e955c0eaebd847b","author":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"date":"2017-09-22 18:14:50.000000000","message":"Patch Set 1: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see http://docs.openstack.org/infra/manual/developers.html#automated-testing\n\n- gate-nova-specs-docs-ubuntu-xenial http://docs-draft.openstack.org/20/506720/1/check/gate-nova-specs-docs-ubuntu-xenial/00077e1//doc/build/html/ : SUCCESS in 4m 26s\n- gate-nova-specs-pep8-ubuntu-xenial http://logs.openstack.org/20/506720/1/check/gate-nova-specs-pep8-ubuntu-xenial/ce5dddc/ : SUCCESS in 3m 03s\n- gate-nova-specs-python27-ubuntu-xenial http://logs.openstack.org/20/506720/1/check/gate-nova-specs-python27-ubuntu-xenial/d02650b/ : FAILURE in 3m 27s","accounts_in_message":[],"_revision_number":1},{"id":"e8e13fdc70e1e89fe848ff969df816bdf4727ac3","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2017-09-25 09:18:01.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"89f225fd9f5582d14f5069593b844d5766c9506b","author":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"date":"2017-09-25 09:29:08.000000000","message":"Patch Set 2: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see http://docs.openstack.org/infra/manual/developers.html#automated-testing\n\n- gate-nova-specs-docs-ubuntu-xenial http://docs-draft.openstack.org/20/506720/2/check/gate-nova-specs-docs-ubuntu-xenial/e3e89f3//doc/build/html/ : SUCCESS in 4m 46s\n- gate-nova-specs-pep8-ubuntu-xenial http://logs.openstack.org/20/506720/2/check/gate-nova-specs-pep8-ubuntu-xenial/8b4733c/ : SUCCESS in 3m 01s\n- gate-nova-specs-python27-ubuntu-xenial http://logs.openstack.org/20/506720/2/check/gate-nova-specs-python27-ubuntu-xenial/3520028/ : FAILURE in 3m 01s","accounts_in_message":[],"_revision_number":2},{"id":"e09c5af4d2e13c1ea189ccfc1c5bc18df45c4c77","author":{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},"date":"2017-09-28 18:57:29.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"2360810b80593ee9a26fd1710bc9e2e9de0e33ce","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2017-10-16 10:52:04.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"51901af3b86f2a61b0f339e7d60fc7aaeef68012","author":{"_account_id":6874,"name":"Patrick Uiterwijk","email":"puiterwijk@gmail.com","username":"puiterwijk"},"date":"2017-11-24 10:38:51.000000000","message":"Patch Set 2:\n\n(6 comments)\n\nI think this is a reasonable start, but you seem to be mixing general UEFI improvements over improvements that SecureBoot/System Management Mode add.\nAlso, do note that even if you are using an OVMF build with SMM/SecureBoot enabled, it doesn\u0027t yet enforce any signatures.\nFor that to work, you\u0027ll need an OVMF configuration file (which, unfortunately is binary, so you need to manually drive through the OVMF config/mokutil to enroll keys) to actually enroll keys and enable secure boot.","accounts_in_message":[],"_revision_number":2},{"id":"0972943557e392f3169d351fc70e18724fec6176","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2017-11-28 10:39:10.000000000","message":"Patch Set 2:\n\n(6 comments)\n\nFirst, thanks for the review, Patrick.\n\n \u003e (6 comments)\n \u003e \n \u003e I think this is a reasonable start, but you seem to be mixing\n \u003e general UEFI improvements over improvements that SecureBoot/System\n \u003e Management Mode add.\n\nRight; as noted in-line I\u0027ve mentioned the general OVMF / UEFI improvements as a reminder to those who don\u0027t normally pay attention to it; I\u0027ll fix in the next iteration.\n\n \u003e Also, do note that even if you are using an OVMF build with\n \u003e SMM/SecureBoot enabled, it doesn\u0027t yet enforce any signatures.\n \u003e For that to work, you\u0027ll need an OVMF configuration file (which,\n \u003e unfortunately is binary, so you need to manually drive through the\n \u003e OVMF config/mokutil to enroll keys) to actually enroll keys and\n \u003e enable secure boot.\n\nRight, that\u0027s the key bit (loading the UefiShell.iso, and enrolling the default keys, and verify Secure Boot is enabled) to *actually* make Secure Boot \"secure\".\n\nAlso, the OVMF maintainer Laszlo Ersek explains that the \"MokUtil\"[+] comes later in the picture: \"MokUtil manages the signature database for the \u0027shim\u0027 utility. That\u0027s one step after the UEFI-standard Secure Boot verification is done.\"\n\n[+] https://github.com/lcp/mokutil","accounts_in_message":[],"_revision_number":2},{"id":"395ba4dc4f09c556a3c84483e9503dfbdad24d75","author":{"_account_id":7730,"name":"Sahid Orentino Ferdjaoui","email":"sahid.ferdjaoui@industrialdiscipline.com","username":"sahid"},"date":"2017-11-28 14:00:03.000000000","message":"Patch Set 2: Code-Review-1\n\nAll of this looks good, it\u0027s just not clear how are you going to handle the different paths based on the different distributions","accounts_in_message":[],"_revision_number":2},{"id":"ec15fffc7b26844a960045c96967ca6ec8d459d0","author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"date":"2017-12-18 01:23:09.000000000","message":"Removed reviewer Jenkins with the following votes:\n\n* Verified-1 by Jenkins (3)\n","accounts_in_message":[],"_revision_number":2},{"id":"9ace31124a72e1e4d2a649a892104349345213b8","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2017-12-18 11:06:35.000000000","message":"Patch Set 2:\n\n\u003e All of this looks good, it\u0027s just not clear how are you going to\n \u003e handle the different paths based on the different distributions\n\nYes, that is one of the items we need to get an agreement on.  One of \nthe approaches is to use the getDomainCapabilities() APIs.  Then, we\ncan make an `xpath` query as following:\n\n    $\u003e virsh domcapabilities |\n    \u003e xpath -n -q -e\n     \"/domainCapabilities/os[@supported\u003d\u0027yes\u0027]/loader[@supported\u003d\u0027yes\u0027]/value/text()\"\n     /usr/share/edk2.git/ovmf-x64/OVMF_CODE-pure-efi.fd\n     /usr/share/edk2.git/aarch64/QEMU_EFI-pflash.raw\n     /usr/share/edk2/ovmf/OVMF_CODE.fd\n\nI\u0027ve checked two things:\n\n(1) The  getDomainCapabilities() API was introduced in 1.2.7\n\n(2) The query-ability of UEFI binary path names via `domcapabilities`\nwas introduced by libvirt in version 1.2.9: f05b6a918e (\"domaincaps:\nExpose UEFI binary path, if it exists\")\n\nBoth the above are satisfied by Nova\u0027s current: MIN_LIBVIRT_VERSION \u003d \n(1, 2, 9).","accounts_in_message":[],"_revision_number":2},{"id":"31fc8096ca8d878ce09131fb683c1b61135cf12c","author":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"date":"2017-12-22 17:31:54.000000000","message":"Patch Set 2:\n\nmove this to rocky","accounts_in_message":[],"_revision_number":2},{"id":"d4e034224274265e6ec1a9c86dd8f0229182f36e","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2017-12-22 20:20:50.000000000","message":"Patch Set 2:\n\n\u003e move this to rocky\n\nYep, will do.","accounts_in_message":[],"_revision_number":2},{"id":"79ad13f08498c4311ce105eadf069aacc4abe3d5","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2018-01-02 13:26:00.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"7ae7318e0dc484f495b04cbe943b1bb3d37a435c","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2018-01-02 13:36:47.000000000","message":"Uploaded patch set 4.","accounts_in_message":[],"_revision_number":4},{"id":"7aca3ca0961729ac0f5ffee988565560c1b7e126","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2018-01-02 13:46:10.000000000","message":"Patch Set 4: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttp://docs.openstack.org/infra/manual/developers.html#automated-testing\n\n\n- build-openstack-sphinx-docs http://logs.openstack.org/20/506720/4/check/build-openstack-sphinx-docs/b8a7d4b/html/ : SUCCESS in 4m 39s\n- openstack-tox-pep8 http://logs.openstack.org/20/506720/4/check/openstack-tox-pep8/1f31318/ : FAILURE in 3m 29s","accounts_in_message":[],"_revision_number":4},{"id":"2fd7d12a32d24e7eeed2c184a47b116d0196731d","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2018-01-02 14:32:49.000000000","message":"Uploaded patch set 5.","accounts_in_message":[],"_revision_number":5},{"id":"c4ba58b2ca4c3f25562f1732a984d9eec77b0dba","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2018-01-02 14:42:24.000000000","message":"Patch Set 5: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttp://docs.openstack.org/infra/manual/developers.html#automated-testing\n\n\n- build-openstack-sphinx-docs http://logs.openstack.org/20/506720/5/check/build-openstack-sphinx-docs/dbdc30a/html/ : SUCCESS in 4m 47s\n- openstack-tox-pep8 http://logs.openstack.org/20/506720/5/check/openstack-tox-pep8/b0c57d5/ : FAILURE in 3m 37s","accounts_in_message":[],"_revision_number":5},{"id":"997e59aff7b0580a2ba34ec376cbe78479ec1cd5","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2018-01-02 16:52:40.000000000","message":"Uploaded patch set 6.","accounts_in_message":[],"_revision_number":6},{"id":"86eb4fae807ecc1f236242b253319161c6d101d7","author":{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},"date":"2018-01-02 17:31:42.000000000","message":"Patch Set 6: Code-Review-1\n\n(13 comments)\n\nA couple spelling/typos to address and questions to answer inline. Overall, the idea seems relatively small scoped and well-described, though.\n\n-jay","accounts_in_message":[],"_revision_number":6},{"id":"a5e6928acd4a5b4a3f90934aa2b38305973f457e","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2018-01-02 17:35:37.000000000","message":"Patch Set 6: Verified+1\n\nBuild succeeded (check pipeline).\n\n- build-openstack-sphinx-docs http://logs.openstack.org/20/506720/6/check/build-openstack-sphinx-docs/74037d2/html/ : SUCCESS in 4m 42s\n- openstack-tox-pep8 http://logs.openstack.org/20/506720/6/check/openstack-tox-pep8/e2fc10e/ : SUCCESS in 3m 38s","accounts_in_message":[],"_revision_number":6},{"id":"484b883f199ae0bd423ea366d2127fd8cf7f2fd7","author":{"_account_id":6874,"name":"Patrick Uiterwijk","email":"puiterwijk@gmail.com","username":"puiterwijk"},"date":"2018-01-03 09:27:57.000000000","message":"Patch Set 6:\n\n(3 comments)","accounts_in_message":[],"_revision_number":6},{"id":"4af013671861994eb0e84c968d9c7b59cd68a848","author":{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},"date":"2018-01-03 14:57:40.000000000","message":"Patch Set 6:\n\n(3 comments)","accounts_in_message":[],"_revision_number":6},{"id":"ed70e49c14c6e8572723b8b1a2f353be1f024839","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2018-01-09 14:49:23.000000000","message":"Patch Set 6:\n\n(5 comments)","accounts_in_message":[],"_revision_number":6},{"id":"78f48860a0cb3a677d4c5d62044f88ff85cacb9c","author":{"_account_id":6874,"name":"Patrick Uiterwijk","email":"puiterwijk@gmail.com","username":"puiterwijk"},"date":"2018-01-09 14:53:37.000000000","message":"Patch Set 6:\n\n\u003e     (2) The second dimension, SMM, is not visible to the OS. ...\n\nWhat Jay I think meant is that the implementation leaks out to the *admin*, in that the qemu/libvirt user needs to remember to set both :).","accounts_in_message":[],"_revision_number":6},{"id":"16f3e259deca854b59460679a8939ff85e780782","author":{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},"date":"2018-01-11 00:41:03.000000000","message":"Patch Set 6:\n\n(1 comment)\n\n\u003e \u003e     (2) The second dimension, SMM, is not visible to the OS. ...\n \u003e \n \u003e What Jay I think meant is that the implementation leaks out to the\n \u003e *admin*, in that the qemu/libvirt user needs to remember to set\n \u003e both :).\n\nYes, that\u0027s precisely what I meant, thank you Peter.\n\nBest,\n\n-jay","accounts_in_message":[],"_revision_number":6},{"id":"24f6362c8f2da6b8344de82bb800e919df683dd0","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2018-06-01 20:39:54.000000000","message":"Patch Set 6:\n\nAn update about where things stand here.  There are three main work items here involving different components:\n\n(1) [QEMU] To define the firmware metadata format and file for firmware\n\n    https://bugzilla.redhat.com/show_bug.cgi?id\u003d1546084 — RFE: Define\n    and provide firmware (OVMF, etc) metadata format and file\n\n(2) [libvirt] To read the metadata files defined from QEMU \u0026 pick the\n    correct firmware binary based on guest configuration\n\n    https://bugzilla.redhat.com/show_bug.cgi?id\u003d1295146 — RFE:\n    provide a bios\u003duefi XML convenience option\n\n(3) [Nova] To wire-up the libvirt OVMF Secure Boot configuration\n\nFor item (1), I  started a design discussion on the QEMU upstream\nmailing list:\n\n    https://lists.nongnu.org/archive/html/qemu-devel/2018-03/msg01978.html\n    -- [RFC] Defining firmware (OVMF, et al) metadata format \u0026 file\n    \nWhich, after a lengthy discussion resulted in a QEMU API definition to\ndescribe the properties of virtual machine firmware.  Contributed by\nLazslo Ersek, et al; which is queued for merge:\n\n    https://lists.nongnu.org/archive/html/qemu-devel/2018-05/msg07194.html\n    -- [qemu RFC] qapi: add \"firmware.json\"","accounts_in_message":[],"_revision_number":6},{"id":"9ebd700941fa2dfe537f2858bdc598a85e432a63","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2018-06-01 20:40:48.000000000","message":"Patch Set 6:\n\n\u003e An update about where things stand here.  There are three main work\n \u003e items here involving different components:\n \u003e \n \u003e (1) [QEMU] To define the firmware metadata format and file for\n \u003e firmware\n \u003e \n \u003e https://bugzilla.redhat.com/show_bug.cgi?id\u003d1546084 — RFE: Define\n \u003e and provide firmware (OVMF, etc) metadata format and file\n \u003e \n \u003e (2) [libvirt] To read the metadata files defined from QEMU \u0026 pick\n \u003e the\n \u003e correct firmware binary based on guest configuration\n \u003e \n \u003e https://bugzilla.redhat.com/show_bug.cgi?id\u003d1295146 — RFE:\n \u003e provide a bios\u003duefi XML convenience option\n \u003e \n \u003e (3) [Nova] To wire-up the libvirt OVMF Secure Boot configuration\n\n\nForgot to note the obvious that items (2) and (3) are still to be done.\n\n[...]","accounts_in_message":[],"_revision_number":6},{"id":"d2ea36fde9785f8e38f4f7c3697ffd61d4fd42e2","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2018-08-28 13:21:03.000000000","message":"Patch Set 6:\n\nAnother update:\n\n(0) OVMF project to provide firmware descriptor meta-files for the OVMF and AAVMF firmware images, for which work is in-progress by the OVMF / EDK2 developer Laszlo Ersek.  (I forgot to note this in my earlier update.)\n\n(1)  The QEMU firmware metadata format, a JSON schema that lets firmware packages, installed on a Linux host, describe the features of the provided firmware binaries—this work is already done, and is available in upstream: https://git.qemu.org/?p\u003dqemu.git;a\u003dblob;f\u003ddocs/interop/firmware.json\n\n(2) libvirt support for the firmware metadata format, this is being tracked here, and a libvirt developer is already looking into this: https://bugzilla.redhat.com/show_bug.cgi?id\u003d1605127 -- \"RFE: QEMU firmware metadata format - libvirt support\"\n\n(3) Nova to wire up all the above in an \"appropriate way\".","accounts_in_message":[],"_revision_number":6},{"id":"d2145a8b7a9b4b09ecaf0578270953e4de8aedfa","author":{"_account_id":6873,"name":"Matt Riedemann","email":"mriedem.os@gmail.com","username":"mriedem"},"date":"2018-10-23 20:50:27.000000000","message":"Patch Set 6:\n\nIs this still being worked on? If so, it needs to be updated for stein.","accounts_in_message":[],"_revision_number":6},{"id":"bc63bb06a43fd90f5dd4724e536f2f42f0fc98e7","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-01-29 15:25:51.000000000","message":"Patch Set 6:\n\n\u003e Is this still being worked on? If so, it needs to be updated for\n \u003e stein.\n\nIt was on the back-burner, as I didn\u0027t have capacity for it.  I am planning to revive this for \"Train\".","accounts_in_message":[],"_revision_number":6},{"id":"12daab33ffc0a22b5afd67804e920498b08eb502","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-02-01 11:02:02.000000000","message":"Patch Set 6:\n\nThere is still a pending item on libvirt.  I wrote up the details in this libvirt RFE:\n\n    https://bugzilla.redhat.com/show_bug.cgi?id\u003d1605127\n    RFE: QEMU firmware metadata format - libvirt support\n\nI\u0027m following up with the libvirt upstream to see when they\u0027ll have capacity to address this.","accounts_in_message":[],"_revision_number":6},{"id":"4905912ef9c01b92c86d41ae05f69c4a7dd5c8bf","author":{"_account_id":2394,"name":"Adam Spiers","email":"aspiers@suse.com","username":"adam.spiers"},"date":"2019-02-26 10:42:39.000000000","message":"Patch Set 6:\n\n(1 comment)","accounts_in_message":[],"_revision_number":6},{"id":"6d241c0ae1509cacbded90d021c5c709dd5a59d1","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-02-26 16:33:55.000000000","message":"Patch Set 6:\n\n(1 comment)","accounts_in_message":[],"_revision_number":6},{"id":"a77da2ad3e50db922aa9788c9e96af9a32be36e6","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-03-15 17:24:08.000000000","message":"Patch Set 6:\n\nAn update: libvirt just merged support for auto-selecting firmware:\n\n  https://libvirt.org/git/?p\u003dlibvirt.git;a\u003dcommitdiff;h\u003d1dd24167b\n  -- news: Document firmware autoselection for QEMU driver\n\nThe above is yet to make it into a release.\n\nI think with this, we should have all the pieces ready (OVMF, QEMU, and libvirt) to integrate this into Nova.\n\nI will work towards re-spinning this spec.","accounts_in_message":[],"_revision_number":6},{"id":"bee5bdfd7c05c42c0e6af78ad2d0cd26ccd9bd0a","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-04-03 10:39:21.000000000","message":"Uploaded patch set 7.","accounts_in_message":[],"_revision_number":7},{"id":"5f511855d19dbad53eccc65f777da0e894112095","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-04-03 10:50:59.000000000","message":"Patch Set 7: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttp://docs.openstack.org/infra/manual/developers.html#automated-testing\n\n\n- openstack-tox-docs http://logs.openstack.org/20/506720/7/check/openstack-tox-docs/4cfa357/ : FAILURE in 4m 50s\n- openstack-tox-pep8 http://logs.openstack.org/20/506720/7/check/openstack-tox-pep8/928b7b2/ : SUCCESS in 6m 08s","accounts_in_message":[],"_revision_number":7},{"id":"51ecf35376c36ad607e333157dd8c038347d22f9","author":{"_account_id":7634,"name":"Takashi Natsume","email":"takanattie@gmail.com","username":"natsumet"},"date":"2019-04-04 06:47:47.000000000","message":"Patch Set 7: Code-Review-1\n\n(1 comment)","accounts_in_message":[],"_revision_number":7},{"id":"1e31e069ce7da299cc70f8b4d9976d81e44ccaa6","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-04-09 10:54:58.000000000","message":"Uploaded patch set 8.","accounts_in_message":[],"_revision_number":8},{"id":"33b738156e35660ec3a05ee661720f542df58e0b","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-04-09 11:05:54.000000000","message":"Patch Set 8: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/20/506720/8/check/openstack-tox-docs/d28a070/html/ : SUCCESS in 9m 03s\n- openstack-tox-pep8 http://logs.openstack.org/20/506720/8/check/openstack-tox-pep8/78e7f90/ : SUCCESS in 6m 32s","accounts_in_message":[],"_revision_number":8},{"id":"b8312a22e0fe221cb8e6713214edf139da5d331f","author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"date":"2019-04-09 15:04:24.000000000","message":"Patch Set 7:\n\n(2 comments)\n\nAgain, this seems mostly sane. However, it seems like there are some cleanups still needed","accounts_in_message":[],"_revision_number":7},{"id":"0e93ac76b814c7acc13d2c1c38f15c53dd8cb390","author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"date":"2019-04-09 15:05:29.000000000","message":"Patch Set 8:\n\n\u003e (2 comments)\n \u003e \n \u003e Again, this seems mostly sane. However, it seems like there are\n \u003e some cleanups still needed\n\nNever mind, I was reading the old version","accounts_in_message":[],"_revision_number":8},{"id":"c250e1efdf1cc85046efbfd96b8b9935f9a583a3","author":{"_account_id":15334,"name":"Stephen Finucane","display_name":"stephenfin","email":"stephenfin@redhat.com","username":"sfinucan"},"date":"2019-04-09 15:10:12.000000000","message":"Patch Set 8:\n\n(3 comments)","accounts_in_message":[],"_revision_number":8},{"id":"6b3a602a502361a70da7e2bd803b0fb4b0b29e60","author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"date":"2019-04-09 15:16:35.000000000","message":"Patch Set 8:\n\n(5 comments)\n\nI have couple of questions inline","accounts_in_message":[],"_revision_number":8},{"id":"9498c35b176aa67109620ffb8d800e2ae747e0ef","author":{"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},"date":"2019-04-09 16:33:19.000000000","message":"Patch Set 8:\n\n(2 comments)","accounts_in_message":[],"_revision_number":8},{"id":"d0e453f26a9e11e14f4175f9c0fa5315bcb11aa8","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-04-12 09:27:04.000000000","message":"Patch Set 8:\n\n(8 comments)","accounts_in_message":[],"_revision_number":8},{"id":"9c7d742d307576d34c5f32d5093725cfe12667a1","author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"date":"2019-04-12 10:26:27.000000000","message":"Patch Set 8: Code-Review+1\n\n(3 comments)\n\n@Kashyap: thanks for the answers. I\u0027m OK with your proposed approach.","accounts_in_message":[],"_revision_number":8},{"id":"4e3df0afdf65338799baf6c6420c48c6633f2ae0","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-04-15 10:40:07.000000000","message":"Uploaded patch set 9.","accounts_in_message":[],"_revision_number":9},{"id":"d47f398ed8ea9c06f89f5cf7ae902f30b832d3cf","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-04-15 10:40:58.000000000","message":"Uploaded patch set 10.","accounts_in_message":[],"_revision_number":10},{"id":"8af0ea4f05a73b35de2febe4e4392f31ca043974","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-04-15 10:50:07.000000000","message":"Patch Set 10: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/20/506720/10/check/openstack-tox-docs/d0c3598/html/ : SUCCESS in 7m 52s\n- openstack-tox-pep8 http://logs.openstack.org/20/506720/10/check/openstack-tox-pep8/140713b/ : SUCCESS in 5m 05s","accounts_in_message":[],"_revision_number":10},{"id":"52b600528526f57f21e9a81278e0837c07ae9f25","author":{"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},"date":"2019-04-15 11:51:27.000000000","message":"Patch Set 8:\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"c187a6888131927c625f5a91de29fe4e46587fe9","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-04-15 14:26:06.000000000","message":"Patch Set 8:\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"3615dc2df10bbd6eec8855c4efac7746524b9434","author":{"_account_id":21813,"name":"Andrey Volkov","email":"m@amadev.ru","username":"avolkov"},"date":"2019-04-15 16:09:49.000000000","message":"Patch Set 10:\n\n(2 comments)\n\nKashyap,\n\nDo you think it\u0027s worth to mention about LinuxBoot here? Would it fit in to the described model or implementation is different if at all.\n\nIt would be great (for me at least) to make a couple of words what operator should do to enable SB, SMM.\n\nThanks.","accounts_in_message":[],"_revision_number":10},{"id":"08c9a937db3889ddfaedbcae961d15b7e9276f45","author":{"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},"date":"2019-04-15 18:57:13.000000000","message":"Patch Set 8:\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"4c1de490b3a27448ac75c1e6193e4cb90ffe6509","author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"date":"2019-04-16 08:37:24.000000000","message":"Patch Set 10: Code-Review+1\n\nLGTM but I feel others needs to look at it, hence the +1","accounts_in_message":[],"_revision_number":10},{"id":"004de645be08cde9fc3561915f645776bc8a127d","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-04-16 08:41:53.000000000","message":"Patch Set 8:\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"93940056416aa5c6a8d1ddf673f69212360eeb5a","author":{"_account_id":10135,"name":"Lee Yarwood","display_name":"Lee Yarwood","email":"lyarwood@redhat.com","username":"lyarwood"},"date":"2019-04-16 08:54:15.000000000","message":"Patch Set 8:\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"2b27be2a291208db18f48ed56f256c0ee5b651f2","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2019-04-16 09:57:53.000000000","message":"Patch Set 8:\n\n(18 comments)","accounts_in_message":[],"_revision_number":8},{"id":"efa06a037fc1cc161ea6699ce15f7d122d82a84d","author":{"_account_id":11604,"name":"sean mooney","email":"smooney@redhat.com","username":"sean-k-mooney"},"date":"2019-04-16 09:59:28.000000000","message":"Patch Set 10: Code-Review-1\n\n-1 while i see if any of the comments i just left on patchset 8 have been adressed","accounts_in_message":[],"_revision_number":10},{"id":"441e1e3d1508e11a7585bd2e05a1b68d4625522a","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-04-16 10:22:11.000000000","message":"Patch Set 10:\n\n(2 comments)","accounts_in_message":[],"_revision_number":10},{"id":"d129c2557cd9ff3d00b560d86b6ad6cb006eb992","author":{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},"date":"2019-04-16 14:00:53.000000000","message":"Patch Set 8:\n\n(3 comments)","accounts_in_message":[],"_revision_number":8},{"id":"dd46918e37af7f58823894ec489da2a53ab44ce0","author":{"_account_id":6874,"name":"Patrick Uiterwijk","email":"puiterwijk@gmail.com","username":"puiterwijk"},"date":"2019-04-17 07:36:51.000000000","message":"Patch Set 8:\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"2e7194d98b37c549ea200f7f014fd1c9171eef34","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-04-17 08:01:13.000000000","message":"Patch Set 8:\n\n(3 comments)","accounts_in_message":[],"_revision_number":8},{"id":"97368c605510c8fc1992e72e75926d2277d512cd","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-04-17 09:40:35.000000000","message":"Patch Set 10:\n\nI\u0027m not going to do an in-line reply to Sean\u0027s comments (some of which\nare already addressed in PS-10).  But summarizing changes that will be\nin PS-11 and my response some points Sean raised.\n\n- On how I organized the content: Describe the change at high-level in\n  the \"Proposed change\" section.  And then describe the \"how\" and\n  related design in the \"Work Items\".  That is okay—as long as the goals\n  of the spec are clearly communicated.\n\n- Fix phrasing in the \"Problem description\" (and in one other place) to\n  remove any implication that Nova\u0027s libvirt driver had Secure Boot\n  support in the past.\n\n- In the \"Proposed change\" section, added a pointer to \"Work Items\"\n  which discusses the Glance image metadata property, `os_secure_boot`\n  and flavor extra specs attribute, `os:secure_boot`.\n\n- On extending Hyper-V to report Secure Boot-related \u0027traits\u0027, it should\n  be done as a separate item.  I want to avoid \"scope creep\".\n\n- On exposing the feature via version constants: Yes, we will just rely\n  on version constants — this will let us keep the code relatively small\n  and simple.  If the QEMU and libvirt versions on a Compute node aren\u0027t\n  sufficient, then we\u0027ll throw a nice error message.  We (Nova) should\n  avoid fragile methods to do the OVMF firmware binary selection, etc.\n  Rather, we should take the more robust route of using the formal API\n  interfaces in libvirt and QEMU.\n\n- On the availability of the libvirt and QEMU features in Linux\n  distributions: Fedora already has the relevant bits from libvirt 5.2\n  in its \u0027virt-preview\u0027 repos for F28, F29 and F30.  And Debian is\n  catching up as well.  For Ubuntu, I am relying on their Cloud Archive\n  repo to pick up libvirt 5.2 and 5.3 (which comes out in May 2019) over\n  the next eight months.  I\u0027ll follow up there.\n\n- On handling the UEFI key enrollment: Firstly, it is not (and should\n  not be) a libvirt or QEMU feature.  Either Linux distributions should\n  ship one (which they already do or are working on it -- refer below),\n  or an external tool, like `ovmf-vars-generator`, should handle it.\n  This tool is already shipped as a sub-package (called: \u0027edk2-qosb\u0027) of\n  the main EDK2/OVMF package in Fedora.  Debian and Ubuntu are working\n  on it, as I write this.\n  \n  Secondly, and more importantly, the common Linux distributions,\n  already _ship_ a \"VARS\" file with default UEFI keys enrolled, so you\n  don\u0027t even need to run the `ovmf-vars-generator` tool:  \n\n  (a) For Ubuntu, here is the work in progress on shipping a template\n      \"VARS\" file that has the UEFI keys enrolled as part of the EDK2\n      pacakge.  See the first point noted here:\n      \u003chttps://launchpad.net/ubuntu/+source/edk2/0~20190309.89910a39-1ubuntu1\u003e.\n  \n  (b) For Debian, I\u0027m working with the Debian QEMU maintainers on IRC\n      (#debian-qemu), and they\u0027re amenable to go the same route as\n      Ubuntu (and Fedora and SUSE) to ship a VARS file template with\n      UEFI keys enrolled.\n\n  (c) Fedora and RHEL already ship the enrolled \"VARS\" file\n     (\u0027OVMF_VARS.secboot.fd\u0027).\n\n  (d) SUSE already ships an enrolled \"VARS\" file (much like RHEL and\n      Fedora).\n\n  The important take away here, as noted earlier, is that most\n  distributions already ship a \"VARS\" file with the default UEFI keys\n  enrolled.  So this eliminates the inconvenience, and extra step, of\n  running the tool altogether in most distributions that matter.","accounts_in_message":[],"_revision_number":10},{"id":"8a282f15df7462d94a2ce89c3fe7a957ecef3692","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-04-17 10:26:24.000000000","message":"Uploaded patch set 11.","accounts_in_message":[],"_revision_number":11},{"id":"4ccf9af55ff5ec90387db2486840c6d9d489981b","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-04-17 10:56:44.000000000","message":"Patch Set 11: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/20/506720/11/check/openstack-tox-docs/78d55d0/html/ : SUCCESS in 7m 30s\n- openstack-tox-pep8 http://logs.openstack.org/20/506720/11/check/openstack-tox-pep8/819c74d/ : SUCCESS in 5m 06s","accounts_in_message":[],"_revision_number":11},{"id":"30ee9b1ed4c273fc18b6eb7ac2ccb6e9df451c0f","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-04-17 11:37:20.000000000","message":"Patch Set 11:\n\n(1 comment)","accounts_in_message":[],"_revision_number":11},{"id":"54db09ff9e8553c2306b0e38cfe9f677d494be6b","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-04-18 13:14:00.000000000","message":"Patch Set 8:\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"b880dc15c182985ad2df084a6b8f4a162ff806cd","author":{"_account_id":8864,"name":"Artom Lifshitz","email":"notartom@gmail.com","username":"artom"},"date":"2019-04-18 15:08:48.000000000","message":"Patch Set 11: Code-Review-1\n\n(6 comments)\n\nSome nits and question, -1 is for the N -\u003e N-1 live migration question.","accounts_in_message":[],"_revision_number":11},{"id":"45b53bf67d3d52224fa127f864d19564588447ad","author":{"_account_id":8768,"name":"Chris Friesen","email":"chris.friesen@windriver.com","username":"cbf123"},"date":"2019-04-18 19:46:13.000000000","message":"Patch Set 11: Code-Review-1\n\n(3 comments)\n\nSome important information is missing.","accounts_in_message":[],"_revision_number":11},{"id":"38ba7f9a905bdf378b08f93523274ccfa1f6906d","author":{"_account_id":7,"name":"Jay Pipes","email":"jaypipes@gmail.com","username":"jaypipes"},"date":"2019-04-19 12:12:12.000000000","message":"Patch Set 8:\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"c3804bab69cb3478841ce0ebf461bcf3d0c1064d","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-04-23 10:32:48.000000000","message":"Patch Set 11:\n\n(7 comments)","accounts_in_message":[],"_revision_number":11},{"id":"103f0831f87e2c581fd05927ca5b7de4ab80520a","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-04-24 10:05:03.000000000","message":"Patch Set 8:\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"70691724fdca008ff12a11a273382a3d837ed8c1","author":{"_account_id":8864,"name":"Artom Lifshitz","email":"notartom@gmail.com","username":"artom"},"date":"2019-04-24 10:28:29.000000000","message":"Patch Set 11: -Code-Review\n\n(1 comment)\n\nMy questions have been addressed (I\u0027ll leave it to your judgment whether you want to include any of your answers in the spec proper). Don\u0027t have the confidence for a +1, but don\u0027t have issues for a -1 either:)","accounts_in_message":[],"_revision_number":11},{"id":"a7d20eebeda00e0b881c2052657430c17693406b","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-04-24 12:01:41.000000000","message":"Patch Set 11:\n\n\u003e (1 comment)\n \u003e \n \u003e My questions have been addressed (I\u0027ll leave it to your judgment\n \u003e whether you want to include any of your answers in the spec\n \u003e proper). Don\u0027t have the confidence for a +1, but don\u0027t have issues\n \u003e for a -1 either:)\n\nI will add some additional notes based on the review.  Thanks!","accounts_in_message":[],"_revision_number":11},{"id":"102474a9542e16c4d3d8420de11a7b509001468c","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-04-26 09:18:52.000000000","message":"Patch Set 8:\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"1be3fa6ff460c570487c774707d61f53fc3cc7ed","author":{"_account_id":8768,"name":"Chris Friesen","email":"chris.friesen@windriver.com","username":"cbf123"},"date":"2019-05-02 20:47:56.000000000","message":"Patch Set 11: -Code-Review\n\n(2 comments)","accounts_in_message":[],"_revision_number":11},{"id":"31496c51b6f90f33d9cf3baa28da4c5d15a87f6c","author":{"_account_id":782,"name":"John Garbutt","email":"john@johngarbutt.com","username":"johngarbutt"},"date":"2019-06-04 09:20:58.000000000","message":"Patch Set 11: Code-Review-1\n\n(15 comments)\n\nSo I like this, and I want this feature, and I think we are close...\n\nbut I think we need to turn this spec upside down...\n\nLets focus on libvirt doing the heavy lifting, Nova doing some scheduling, and add some notes on what we depend on in the dependencies section.","accounts_in_message":[],"_revision_number":11},{"id":"2d565c487ab44ec9a10f8457ac3dbc609c2f6c56","author":{"_account_id":782,"name":"John Garbutt","email":"john@johngarbutt.com","username":"johngarbutt"},"date":"2019-06-04 09:53:41.000000000","message":"Patch Set 11:\n\n(1 comment)","accounts_in_message":[],"_revision_number":11},{"id":"c65a472af2fb0ec5c0a1fd8d64c3749026330f3f","author":{"_account_id":782,"name":"John Garbutt","email":"john@johngarbutt.com","username":"johngarbutt"},"date":"2019-06-04 10:02:43.000000000","message":"Patch Set 11:\n\n(1 comment)","accounts_in_message":[],"_revision_number":11},{"id":"cb0fe74df23482fe87a681aed931da40cd2f10d9","author":{"_account_id":782,"name":"John Garbutt","email":"john@johngarbutt.com","username":"johngarbutt"},"date":"2019-06-04 10:04:54.000000000","message":"Patch Set 11:\n\n(1 comment)","accounts_in_message":[],"_revision_number":11},{"id":"2a7ff7b065cf6667c2d0b97c4160623268479e40","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-06-04 10:19:48.000000000","message":"Patch Set 11:\n\n[Meta Comment]\n\nThanks, John, for the focused review, here and on IRC. Just wanted to ACK that I\u0027m processing the feedback.  I\u0027ll address your remarks, and will write a detailed response.","accounts_in_message":[],"_revision_number":11},{"id":"9bb4e83325c13a1c453a3afde34edf0b6e694d18","author":{"_account_id":782,"name":"John Garbutt","email":"john@johngarbutt.com","username":"johngarbutt"},"date":"2019-06-04 10:21:39.000000000","message":"Patch Set 11:\n\n(1 comment)","accounts_in_message":[],"_revision_number":11},{"id":"cef0a9df3fdec34426e37603fcba2f632f91a4fe","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-06-27 08:32:24.000000000","message":"Patch Set 11:\n\n(3 comments)","accounts_in_message":[],"_revision_number":11},{"id":"b8639c458cb56815d17c9ce1629d2ba59c228044","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-07-02 11:22:02.000000000","message":"Uploaded patch set 12.","accounts_in_message":[],"_revision_number":12},{"id":"5f278773b83767d55906c8ea646649d91bedd9c9","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-07-02 11:26:27.000000000","message":"Patch Set 12:\n\nIn PS-12:\n\nOverall, turned the spec a bit \"upside down\" to reorganize some content:\n\n  - [x] Adjust the \"Use Cases\" section to focus just on the\n        guest-level protection.  Then reference the other white paper\n        for more details.\n  - [x] Remove much of the bits from the OVMF whitepaper from the \"Use \n        Cases\" list, and reference it directly.\n  - [x] Bring the last two Work Items (that talk about the metadata\n        property) to the top.\n  - [x] Mention that Secure Boot in this spec is only concerned with\n        *guest*-level protection, and \"what if you don\u0027t trust the host\"\n        is a completely different problem space, and is out of scope\n        here.\n  - [x] Update the \u0027Proposed Change\u0027 section to reflect changes to Nova:\n        (1) copy Hyper-V interface; (2) libvirt does all the\n        heavy-lifting, i.e. show what the XML is, then describe what it\n        does (in the Work Items section).\n  - [x] Explicitly note that in the first version, we will simply\n        error-out if there\u0027s no support for Secure Boot.  But note in\n        the future, we can add a \"request spec filter\" that is similar\n        to the existing image type filter.\n  - [x] Mention that we\u0027re going to ask libvirt if it can do Secure\n        Boot. Introduce: _has_uefi_secure_boot_support() bit to check if\n        libvirt can support Secure Boot, by querying for the presence of\n        \u0027efi\u0027 firmware, via the getDomainCapabilities() API\n  - [x] Remove background detail on what was considered before.  Reduces\n        some verbosity.\n  - [x] Spell out in the spec that we only support using the default\n        UEFI keys in the first implementation.  I.e. allowing usage of\n        \u0027os_secure_boot_signature\u0027 is a \"nice to have\".\n  - [x] Re-adjust the references.","accounts_in_message":[],"_revision_number":12},{"id":"79aa7a27852764716ad6a1bc3357abe8e24a23b7","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-07-02 11:32:16.000000000","message":"Patch Set 12: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttp://docs.openstack.org/infra/manual/developers.html#automated-testing\n\n\n- openstack-tox-docs http://logs.openstack.org/20/506720/12/check/openstack-tox-docs/42c1488/ : FAILURE in 3m 36s\n- openstack-tox-pep8 http://logs.openstack.org/20/506720/12/check/openstack-tox-pep8/414f715/ : SUCCESS in 3m 28s","accounts_in_message":[],"_revision_number":12},{"id":"07de42d34fe3e0341141dcec3f23b36fb4f74a28","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-07-02 13:13:03.000000000","message":"Uploaded patch set 13.","accounts_in_message":[],"_revision_number":13},{"id":"cc2501a4ac93dd53cc97f7b83e2aff9d1e6131c6","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-07-02 13:25:20.000000000","message":"Patch Set 13: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/20/506720/13/check/openstack-tox-docs/9d46327/html/ : SUCCESS in 6m 20s\n- openstack-tox-pep8 http://logs.openstack.org/20/506720/13/check/openstack-tox-pep8/d0c1639/ : SUCCESS in 5m 07s","accounts_in_message":[],"_revision_number":13},{"id":"ab5c46f18137d18fd12796dd1be81a431d06f7ab","author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"date":"2019-07-02 13:26:56.000000000","message":"Patch Set 12:\n\n(5 comments)","accounts_in_message":[],"_revision_number":12},{"id":"0a13ba05da57523445d7a8cb49e4ede83e1d047a","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-07-02 13:31:25.000000000","message":"Patch Set 13:\n\nPS-14:\n - Fix a couple of rST-related errors: adjust indentation in \n   code block; add the \u0027description\u0027 bullet in the \"History\" section","accounts_in_message":[],"_revision_number":13},{"id":"1e40a3991494c44b6c68cf3940b31a1e0f10b638","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-07-02 13:37:13.000000000","message":"Patch Set 12:\n\n(4 comments)","accounts_in_message":[],"_revision_number":12},{"id":"ebf145685c0ad80cf60b1faf413c0336239f6cbf","author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"date":"2019-07-02 13:40:13.000000000","message":"Patch Set 13: Code-Review+2\n\nLGTM","accounts_in_message":[],"_revision_number":13},{"id":"aa2654ac76820d0ee69de786403f02d8aac6ead5","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-07-02 14:09:44.000000000","message":"Uploaded patch set 14.","accounts_in_message":[],"_revision_number":14},{"id":"e6d5fd852f4a5a3a5c256d022505bafb29defa50","author":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"date":"2019-07-02 14:10:03.000000000","message":"Patch Set 14:\n\nIn PS-14:\n\n - Rework the \"make Nova use libvirt firmware auto-selection\" point in \n   the \u0027Proposed change\u0027 section by incorporating a related point from\n   the \u0027Work Items\u0027.  (And remove the duplicate.)\n    \n - Fix a couple of broken sentences identified by Gibi.\n\n - A couple of sentence rephrasings that I spotted.\n\n - Add a note in the \u0027Dependencies\u0027 section that QEMU\u0027s \"firmware \n   descriptor documents\" does not block the spec in Train.","accounts_in_message":[],"_revision_number":14},{"id":"891ac89f9a435219a3c95a8123f4c79f32f98bae","author":{"_account_id":9708,"name":"Balazs Gibizer","display_name":"gibi","email":"gibizer@gmail.com","username":"gibi"},"date":"2019-07-02 14:16:18.000000000","message":"Patch Set 14: Code-Review+2\n\nLGTM","accounts_in_message":[],"_revision_number":14},{"id":"704420d037628f06aace7d5f2146cfadb8137f52","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-07-02 14:27:58.000000000","message":"Patch Set 14: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/20/506720/14/check/openstack-tox-docs/282c7ce/html/ : SUCCESS in 7m 00s\n- openstack-tox-pep8 http://logs.openstack.org/20/506720/14/check/openstack-tox-pep8/1a88ea0/ : SUCCESS in 3m 53s","accounts_in_message":[],"_revision_number":14},{"id":"7ed92b129634b30c888bd56a5f251d3ccab16241","author":{"_account_id":782,"name":"John Garbutt","email":"john@johngarbutt.com","username":"johngarbutt"},"date":"2019-07-04 10:05:29.000000000","message":"Patch Set 14: Code-Review+2 Workflow+1\n\nNice, thanks for the updates, it reads really well now... and I know a bunch of folks who want to test this out pretty quickly :)","accounts_in_message":[],"_revision_number":14},{"id":"580c34c581252da40fee3522be56157f98cd2019","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-07-04 10:05:44.000000000","message":"Patch Set 14: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":14},{"id":"4a71de03400abcb27a600b881b4ceddf43994073","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-07-04 10:14:50.000000000","message":"Change has been successfully merged by Zuul","accounts_in_message":[],"_revision_number":14},{"id":"64761ad0a336d70eaaf4d602cff27640148b331e","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2019-07-04 10:14:50.000000000","message":"Patch Set 14: Verified+2\n\nBuild succeeded (gate pipeline).\n\n- openstack-tox-docs http://logs.openstack.org/20/506720/14/gate/openstack-tox-docs/31e3869/html/ : SUCCESS in 6m 07s\n- openstack-tox-pep8 http://logs.openstack.org/20/506720/14/gate/openstack-tox-pep8/64ee28c/ : SUCCESS in 3m 19s","accounts_in_message":[],"_revision_number":14}],"current_revision_number":14,"current_revision":"f4c79e4f1a90a328f3373a3540fea331288080f2","revisions":{"325ddceb2afe290f5ee572850f22579de5f332a9":{"kind":"REWORK","_number":1,"created":"2017-09-22 17:03:07.000000000","uploader":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"ref":"refs/changes/20/506720/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/20/506720/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/1"}}},"commit":{"parents":[{"commit":"019285bbd73858d6e4f91e259823929d7e7fbe4c","subject":"Merge \"Add spec to use cinder\u0027s new attachment API\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/019285bbd73858d6e4f91e259823929d7e7fbe4c"}]}],"author":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2017-09-22 16:24:15.000000000","tz":120},"committer":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2017-09-22 17:02:18.000000000","tz":120},"subject":"[WIP] Add ability for OVMF Secure Boot","message":"[WIP] Add ability for OVMF Secure Boot\n\nAdd support to Nova to be able to spin up instances with OVMF\u0027s (Open\nVirtual Machine Firmware) Secure Boot (SB) plus System Management Mode\n(SMM)[0] abilities.\n\nWhat is OVMF?\n\n    A project that enables UEFI [Unified Extensible Firmware Interface]\n    support for QEMU and KVM virtual machines.\n\nAbout[1] Secure Boot:\n\n    \"Secure Boot is not magic. It’s not complicated. OK, that’s a lie,\n    it’s incredibly complicated [...]\n\n    \"Secure Boot is defined in chapter 28 of the UEFI spec (2.4a,\n    anyway).  It’s actually a pretty clever mechanism. But what it does\n    can be described very, very simply. It says that the firmware can\n    contain a set of signatures, and refuse to run any EFI executable\n    which is not signed with one of those signatures.\n\n    \"That’s it. Well, no, it really isn’t, but that’s a reasonably\n    acceptable simplification. [...]\"\n\nOn OVMF with SB + SMM, from the README[1] of Open Virtual Machine\nFirmware (OVMF) project:\n\n    OVMF is capable of utilizing SMM if the underlying QEMU or KVM\n    hypervisor emulates SMM. SMM is put to use in the S3 suspend and\n    resume infrastructure, and in the UEFI variable driver stack. The\n    purpose is (virtual) hardware separation between the runtime guest\n    OS and the firmware (OVMF), with the intent to make Secure Boot\n    actually secure, by preventing the runtime guest OS from tampering\n    with the variable store and S3 areas.\n\n[0] https://en.wikipedia.org/wiki/System_Management_Mode\n[1] https://www.happyassassin.net/2014/01/25/uefi-boot-how-does-that-actually-work-then/\n[2] https://github.com/tianocore/edk2/blob/master/OvmfPkg/README\n\nChange-Id: Ib88c9b95364ca7e2b9feff3140b77d70faa6ce1c\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/325ddceb2afe290f5ee572850f22579de5f332a9"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/325ddceb2afe290f5ee572850f22579de5f332a9"}]},"branch":"refs/heads/master"},"3bbde99c3e39236bf66f4ba2c56503b046d2e743":{"kind":"REWORK","_number":2,"created":"2017-09-25 09:18:01.000000000","uploader":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"ref":"refs/changes/20/506720/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/20/506720/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/2"}}},"commit":{"parents":[{"commit":"019285bbd73858d6e4f91e259823929d7e7fbe4c","subject":"Merge \"Add spec to use cinder\u0027s new attachment API\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/019285bbd73858d6e4f91e259823929d7e7fbe4c"}]}],"author":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2017-09-22 16:24:15.000000000","tz":120},"committer":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2017-09-25 09:16:36.000000000","tz":120},"subject":"[WIP] Add ability for OVMF Secure Boot","message":"[WIP] Add ability for OVMF Secure Boot\n\nAdd support to Nova to be able to spin up instances with OVMF\u0027s (Open\nVirtual Machine Firmware) Secure Boot (SB) plus System Management Mode\n(SMM)[0] abilities.\n\nWhat is OVMF?\n\n    A project that enables UEFI [Unified Extensible Firmware Interface]\n    support for QEMU and KVM virtual machines.\n\nAbout[1] Secure Boot:\n\n    \"Secure Boot is not magic. It’s not complicated. OK, that’s a lie,\n    it’s incredibly complicated [...]\n\n    \"Secure Boot is defined in chapter 28 of the UEFI spec (2.4a,\n    anyway).  It’s actually a pretty clever mechanism. But what it does\n    can be described very, very simply. It says that the firmware can\n    contain a set of signatures, and refuse to run any EFI executable\n    which is not signed with one of those signatures.\n\n    \"That’s it. Well, no, it really isn’t, but that’s a reasonably\n    acceptable simplification. [...]\"\n\nOn OVMF with SB + SMM, from the README[1] of Open Virtual Machine\nFirmware (OVMF) project:\n\n    OVMF is capable of utilizing SMM if the underlying QEMU or KVM\n    hypervisor emulates SMM. SMM is put to use in the S3 suspend and\n    resume infrastructure, and in the UEFI variable driver stack. The\n    purpose is (virtual) hardware separation between the runtime guest\n    OS and the firmware (OVMF), with the intent to make Secure Boot\n    actually secure, by preventing the runtime guest OS from tampering\n    with the variable store and S3 areas.\n\n[0] https://en.wikipedia.org/wiki/System_Management_Mode\n[1] https://www.happyassassin.net/2014/01/25/uefi-boot-how-does-that-actually-work-then/\n[2] https://github.com/tianocore/edk2/blob/master/OvmfPkg/README\n\nChange-Id: Ib88c9b95364ca7e2b9feff3140b77d70faa6ce1c\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/3bbde99c3e39236bf66f4ba2c56503b046d2e743"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/3bbde99c3e39236bf66f4ba2c56503b046d2e743"}]},"branch":"refs/heads/master"},"5b819831b3063f5fa12aa0cd7bcc3ebbd90d45be":{"kind":"REWORK","_number":3,"created":"2018-01-02 13:26:00.000000000","uploader":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"ref":"refs/changes/20/506720/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/20/506720/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/3"}}},"commit":{"parents":[{"commit":"81d9207d616c4981738f406cca65877af2f9885e","subject":"Merge \"Amend flavor description spec for GET /flavors API\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/81d9207d616c4981738f406cca65877af2f9885e"}]}],"author":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2017-09-22 16:24:15.000000000","tz":120},"committer":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2018-01-02 13:25:47.000000000","tz":60},"subject":"Add UEFI Secure Boot support for QEMU/KVM guests, using OVMF","message":"Add UEFI Secure Boot support for QEMU/KVM guests, using OVMF\n\nAdd support for Nova to be able to boot instances with UEFI Secure Boot\n(SB) plus System Management Mode (SMM)[0] abilities, using OVMF.\n\nWhat is OVMF?\n\n    A project that enables UEFI (Unified Extensible Firmware Interface)\n    support for QEMU and KVM virtual machines.\n\nAbout[1] Secure Boot:\n\n    \"Secure Boot is not magic. It’s not complicated. OK, that’s a lie,\n    it’s incredibly complicated [...]\n\n    \"Secure Boot is defined in chapter 28 of the UEFI spec (2.4a,\n    anyway).  It’s actually a pretty clever mechanism. But what it does\n    can be described very, very simply. It says that the firmware can\n    contain a set of signatures, and refuse to run any EFI executable\n    which is not signed with one of those signatures.\n\n    \"That’s it. Well, no, it really isn’t, but that’s a reasonably\n    acceptable simplification. [...]\"\n\nOn OVMF with SB + SMM (from the README[2] of Open Virtual Machine\nFirmware (OVMF) project):\n\n    OVMF is capable of utilizing SMM if the underlying QEMU or KVM\n    hypervisor emulates SMM. SMM is put to use in the S3 suspend [to\n    RAM) and resume infrastructure, and in the UEFI variable driver\n    stack. The purpose is (virtual) hardware separation between the\n    runtime guest OS and the firmware (OVMF), with the intent to make\n    Secure Boot actually secure, by preventing the runtime guest OS from\n    tampering with the variable store and S3 areas.\n\nNB: Support for Hyper-V in Nova was added in:\n    http://git.openstack.org/cgit/openstack/nova/commit/?h\u003dmaster\u0026id\u003d29dab99\n    -- Hyper-V: Adds Hyper-V UEFI Secure Boot\n\n[0] https://en.wikipedia.org/wiki/System_Management_Mode\n[1] https://www.happyassassin.net/2014/01/25/uefi-boot-how-does-that-actually-work-then/\n[2] https://github.com/tianocore/edk2/blob/master/OvmfPkg/README\n\nChange-Id: Ib88c9b95364ca7e2b9feff3140b77d70faa6ce1c\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/5b819831b3063f5fa12aa0cd7bcc3ebbd90d45be"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/5b819831b3063f5fa12aa0cd7bcc3ebbd90d45be"}]},"branch":"refs/heads/master"},"7d8849e0bb9bd5135f8b5c39c31fdfacc206cab4":{"kind":"REWORK","_number":4,"created":"2018-01-02 13:36:47.000000000","uploader":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"ref":"refs/changes/20/506720/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/20/506720/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/4"}}},"commit":{"parents":[{"commit":"81d9207d616c4981738f406cca65877af2f9885e","subject":"Merge \"Amend flavor description spec for GET /flavors API\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/81d9207d616c4981738f406cca65877af2f9885e"}]}],"author":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2017-09-22 16:24:15.000000000","tz":120},"committer":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2018-01-02 13:36:37.000000000","tz":60},"subject":"Add UEFI Secure Boot support for QEMU/KVM guests, using OVMF","message":"Add UEFI Secure Boot support for QEMU/KVM guests, using OVMF\n\nAdd support for Nova to be able to boot instances with UEFI Secure Boot\n(SB) plus System Management Mode (SMM)[0] abilities, using OVMF.\n\nWhat is OVMF?\n\n    A project that enables UEFI (Unified Extensible Firmware Interface)\n    support for QEMU and KVM virtual machines.\n\nAbout[1] Secure Boot:\n\n    \"Secure Boot is not magic. It’s not complicated. OK, that’s a lie,\n    it’s incredibly complicated [...]\n\n    \"Secure Boot is defined in chapter 28 of the UEFI spec (2.4a,\n    anyway).  It’s actually a pretty clever mechanism. But what it does\n    can be described very, very simply. It says that the firmware can\n    contain a set of signatures, and refuse to run any EFI executable\n    which is not signed with one of those signatures.\n\n    \"That’s it. Well, no, it really isn’t, but that’s a reasonably\n    acceptable simplification. [...]\"\n\nOn OVMF with SB + SMM (from the README[2] of Open Virtual Machine\nFirmware (OVMF) project):\n\n    OVMF is capable of utilizing SMM if the underlying QEMU or KVM\n    hypervisor emulates SMM. SMM is put to use in the S3 suspend [to\n    RAM) and resume infrastructure, and in the UEFI variable driver\n    stack. The purpose is (virtual) hardware separation between the\n    runtime guest OS and the firmware (OVMF), with the intent to make\n    Secure Boot actually secure, by preventing the runtime guest OS from\n    tampering with the variable store and S3 areas.\n\nNB: Support for Hyper-V in Nova was added in:\n    http://git.openstack.org/cgit/openstack/nova/commit/?h\u003dmaster\u0026id\u003d29dab99\n    -- Hyper-V: Adds Hyper-V UEFI Secure Boot\n\n[0] https://en.wikipedia.org/wiki/System_Management_Mode\n[1] https://www.happyassassin.net/2014/01/25/uefi-boot-how-does-that-actually-work-then/\n[2] https://github.com/tianocore/edk2/blob/master/OvmfPkg/README\n\nChange-Id: Ib88c9b95364ca7e2b9feff3140b77d70faa6ce1c\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/7d8849e0bb9bd5135f8b5c39c31fdfacc206cab4"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/7d8849e0bb9bd5135f8b5c39c31fdfacc206cab4"}]},"branch":"refs/heads/master"},"13459f91feda9f85ade7637b92130d317e10f6fd":{"kind":"REWORK","_number":5,"created":"2018-01-02 14:32:49.000000000","uploader":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"ref":"refs/changes/20/506720/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/20/506720/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/5"}}},"commit":{"parents":[{"commit":"81d9207d616c4981738f406cca65877af2f9885e","subject":"Merge \"Amend flavor description spec for GET /flavors API\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/81d9207d616c4981738f406cca65877af2f9885e"}]}],"author":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2017-09-22 16:24:15.000000000","tz":120},"committer":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2018-01-02 14:32:03.000000000","tz":60},"subject":"Add UEFI Secure Boot support for QEMU/KVM guests, using OVMF","message":"Add UEFI Secure Boot support for QEMU/KVM guests, using OVMF\n\nAdd support for Nova to be able to boot instances with UEFI Secure Boot\n(SB) plus System Management Mode (SMM)[0] abilities, using OVMF.\n\nWhat is OVMF?\n\n    A project that enables UEFI (Unified Extensible Firmware Interface)\n    support for QEMU and KVM virtual machines.\n\nAbout[1] Secure Boot:\n\n    \"Secure Boot is not magic. It’s not complicated. OK, that’s a lie,\n    it’s incredibly complicated [...]\n\n    \"Secure Boot is defined in chapter 28 of the UEFI spec (2.4a,\n    anyway).  It’s actually a pretty clever mechanism. But what it does\n    can be described very, very simply. It says that the firmware can\n    contain a set of signatures, and refuse to run any EFI executable\n    which is not signed with one of those signatures.\n\n    \"That’s it. Well, no, it really isn’t, but that’s a reasonably\n    acceptable simplification. [...]\"\n\nOn OVMF with SB + SMM (from the README[2] of Open Virtual Machine\nFirmware (OVMF) project):\n\n    OVMF is capable of utilizing SMM if the underlying QEMU or KVM\n    hypervisor emulates SMM. SMM is put to use in the S3 suspend [to\n    RAM) and resume infrastructure, and in the UEFI variable driver\n    stack. The purpose is (virtual) hardware separation between the\n    runtime guest OS and the firmware (OVMF), with the intent to make\n    Secure Boot actually secure, by preventing the runtime guest OS from\n    tampering with the variable store and S3 areas.\n\nNB: Support for Hyper-V in Nova was added in:\n    http://git.openstack.org/cgit/openstack/nova/commit/?h\u003dmaster\u0026id\u003d29dab99\n    -- Hyper-V: Adds Hyper-V UEFI Secure Boot\n\n[0] https://en.wikipedia.org/wiki/System_Management_Mode\n[1] https://www.happyassassin.net/2014/01/25/uefi-boot-how-does-that-actually-work-then/\n[2] https://github.com/tianocore/edk2/blob/master/OvmfPkg/README\n\nChange-Id: Ib88c9b95364ca7e2b9feff3140b77d70faa6ce1c\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/13459f91feda9f85ade7637b92130d317e10f6fd"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/13459f91feda9f85ade7637b92130d317e10f6fd"}]},"branch":"refs/heads/master"},"918cfb78a27871265612b3fee98676523a007323":{"kind":"REWORK","_number":6,"created":"2018-01-02 16:52:40.000000000","uploader":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"ref":"refs/changes/20/506720/6","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/20/506720/6","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/6"}}},"commit":{"parents":[{"commit":"81d9207d616c4981738f406cca65877af2f9885e","subject":"Merge \"Amend flavor description spec for GET /flavors API\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/81d9207d616c4981738f406cca65877af2f9885e"}]}],"author":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2017-09-22 16:24:15.000000000","tz":120},"committer":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2018-01-02 15:56:04.000000000","tz":60},"subject":"Add UEFI Secure Boot support for QEMU/KVM guests, using OVMF","message":"Add UEFI Secure Boot support for QEMU/KVM guests, using OVMF\n\nAdd support for Nova to be able to boot instances with UEFI Secure Boot\n(SB) plus System Management Mode (SMM)[0] abilities, using OVMF.\n\nWhat is OVMF?\n\n    A project that enables UEFI (Unified Extensible Firmware Interface)\n    support for QEMU and KVM virtual machines.\n\nAbout[1] Secure Boot:\n\n    \"Secure Boot is not magic. It’s not complicated. OK, that’s a lie,\n    it’s incredibly complicated [...]\n\n    \"Secure Boot is defined in chapter 28 of the UEFI spec (2.4a,\n    anyway).  It’s actually a pretty clever mechanism. But what it does\n    can be described very, very simply. It says that the firmware can\n    contain a set of signatures, and refuse to run any EFI executable\n    which is not signed with one of those signatures.\n\n    \"That’s it. Well, no, it really isn’t, but that’s a reasonably\n    acceptable simplification. [...]\"\n\nOn OVMF with SB + SMM (from the README[2] of Open Virtual Machine\nFirmware (OVMF) project):\n\n    OVMF is capable of utilizing SMM if the underlying QEMU or KVM\n    hypervisor emulates SMM. SMM is put to use in the S3 suspend [to\n    RAM) and resume infrastructure, and in the UEFI variable driver\n    stack. The purpose is (virtual) hardware separation between the\n    runtime guest OS and the firmware (OVMF), with the intent to make\n    Secure Boot actually secure, by preventing the runtime guest OS from\n    tampering with the variable store and S3 areas.\n\nNB: Support for Hyper-V in Nova was added in:\n    http://git.openstack.org/cgit/openstack/nova/commit/?h\u003dmaster\u0026id\u003d29dab99\n    -- Hyper-V: Adds Hyper-V UEFI Secure Boot\n\n[0] https://en.wikipedia.org/wiki/System_Management_Mode\n[1] https://www.happyassassin.net/2014/01/25/uefi-boot-how-does-that-actually-work-then/\n[2] https://github.com/tianocore/edk2/blob/master/OvmfPkg/README\n\nChange-Id: Ib88c9b95364ca7e2b9feff3140b77d70faa6ce1c\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/918cfb78a27871265612b3fee98676523a007323"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/918cfb78a27871265612b3fee98676523a007323"}]},"branch":"refs/heads/master"},"a1380a054b0c374686a8d9364b51614f1f1ee698":{"kind":"REWORK","_number":7,"created":"2019-04-03 10:39:21.000000000","uploader":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"ref":"refs/changes/20/506720/7","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/20/506720/7","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/7"}}},"commit":{"parents":[{"commit":"a2a3d7203489b85cf519259d9a4eca5ed439aa71","subject":"Re-propose emulated virtual TPM spec to train","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/a2a3d7203489b85cf519259d9a4eca5ed439aa71"}]}],"author":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2017-09-22 16:24:15.000000000","tz":120},"committer":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2019-04-03 10:39:11.000000000","tz":120},"subject":"Add Secure Boot support for KVM- and QEMU-based guests","message":"Add Secure Boot support for KVM- and QEMU-based guests\n\nAllow Secure Boot (SB) support for (KVM- and QEMU-based) instances,\nusing OVMF (Open Virtual Machine Firmware), and other SB-related\nfeatures in libvirt and QEMU.\n\nWhat exactly is OVMF?\n\n    An open source project that enables UEFI (Unified Extensible\n    Firmware Interface) support for KVM- and QEMU-based virtual\n    machines.\n\nKey benefits of Secure Boot:\n\n  - It provides protection from boot-time malware\n  - Provides a trusted boot path\n\nFor a more in-depth treatment on Secure Boot, refer to this[1].\n\nNB: Support for Hyper-V in Nova was added in:\n    http://git.openstack.org/cgit/openstack/nova/commit/?h\u003dmaster\u0026id\u003d29dab99\n    -- Hyper-V: Adds Hyper-V UEFI Secure Boot\n\nBlueprint: allow-secure-boot-for-qemu-kvm-guests\n\n[1] http://www.rodsbooks.com/efi-bootloaders/secureboot.html\n\nChange-Id: Ib88c9b95364ca7e2b9feff3140b77d70faa6ce1c\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/a1380a054b0c374686a8d9364b51614f1f1ee698"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/a1380a054b0c374686a8d9364b51614f1f1ee698"}]},"branch":"refs/heads/master"},"bef59b9d2c28ddd5932676735deb4fde2d11d701":{"kind":"REWORK","_number":8,"created":"2019-04-09 10:54:58.000000000","uploader":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"ref":"refs/changes/20/506720/8","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/20/506720/8","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/8 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/8 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/8 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/8"}}},"commit":{"parents":[{"commit":"78afc9d49cc1fad705092eb9b54a80af900be875","subject":"Merge \"Re-propose volume backed server rebuild\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/78afc9d49cc1fad705092eb9b54a80af900be875"}]}],"author":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2017-09-22 16:24:15.000000000","tz":120},"committer":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2019-04-09 10:54:38.000000000","tz":120},"subject":"Add \"Secure Boot support for KVM \u0026 QEMU guests\" spec","message":"Add \"Secure Boot support for KVM \u0026 QEMU guests\" spec\n\nAllow Secure Boot (SB) support for KVM- and QEMU-based instances,\nusing OVMF (Open Virtual Machine Firmware), and other SB-related\nfeatures in libvirt and QEMU.\n\nWhat exactly is OVMF?\n\n    An open source project that enables UEFI (Unified Extensible\n    Firmware Interface) support for KVM- and QEMU-based virtual\n    machines.\n\nKey benefits of Secure Boot:\n\n  - It provides protection from boot-time malware\n  - Provides a trusted boot path\n\nFor a more in-depth treatment on Secure Boot, refer to this[1].\n\nNB: Support for Hyper-V in Nova was added in:\n    http://git.openstack.org/cgit/openstack/nova/commit/?h\u003dmaster\u0026id\u003d29dab99\n    -- Hyper-V: Adds Hyper-V UEFI Secure Boot\n\nBlueprint: allow-secure-boot-for-qemu-kvm-guests\n\n[1] http://www.rodsbooks.com/efi-bootloaders/secureboot.html\n\nChange-Id: Ib88c9b95364ca7e2b9feff3140b77d70faa6ce1c\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/bef59b9d2c28ddd5932676735deb4fde2d11d701"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/bef59b9d2c28ddd5932676735deb4fde2d11d701"}]},"branch":"refs/heads/master"},"cc05209e17cde001f83489e9e4e66759a3c9360d":{"kind":"REWORK","_number":9,"created":"2019-04-15 10:40:07.000000000","uploader":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"ref":"refs/changes/20/506720/9","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/20/506720/9","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/9 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/9 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/9 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/9"}}},"commit":{"parents":[{"commit":"78afc9d49cc1fad705092eb9b54a80af900be875","subject":"Merge \"Re-propose volume backed server rebuild\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/78afc9d49cc1fad705092eb9b54a80af900be875"}]}],"author":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2017-09-22 16:24:15.000000000","tz":120},"committer":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2019-04-15 10:38:34.000000000","tz":120},"subject":"Add \"Secure Boot support for KVM \u0026 QEMU guests\" spec","message":"Add \"Secure Boot support for KVM \u0026 QEMU guests\" spec\n\nAllow Secure Boot (SB) support for KVM- and QEMU-based instances,\nusing OVMF (Open Virtual Machine Firmware), and other SB-related\nfeatures in libvirt and QEMU.\n\nWhat exactly is OVMF?\n\n    An open source project that enables UEFI (Unified Extensible\n    Firmware Interface) support for KVM- and QEMU-based virtual\n    machines.\n\nKey benefits of Secure Boot:\n\n  - It provides protection from boot-time malware\n  - Provides a trusted boot path\n\nFor a more in-depth treatment on Secure Boot, refer to this[1].\n\nNB: Support for Hyper-V in Nova was added in:\n    http://git.openstack.org/cgit/openstack/nova/commit/?h\u003dmaster\u0026id\u003d29dab99\n    -- Hyper-V: Adds Hyper-V UEFI Secure Boot\n\nBlueprint: allow-secure-boot-for-qemu-kvm-guests\n\n[1] http://www.rodsbooks.com/efi-bootloaders/secureboot.html\n\nChange-Id: Ib88c9b95364ca7e2b9feff3140b77d70faa6ce1c\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/cc05209e17cde001f83489e9e4e66759a3c9360d"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/cc05209e17cde001f83489e9e4e66759a3c9360d"}]},"branch":"refs/heads/master"},"4f44b1e5bf2c5280d68a1e9d1b60857ae6e9eacc":{"kind":"REWORK","_number":10,"created":"2019-04-15 10:40:58.000000000","uploader":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"ref":"refs/changes/20/506720/10","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/20/506720/10","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/10 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/10 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/10 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/10"}}},"commit":{"parents":[{"commit":"78afc9d49cc1fad705092eb9b54a80af900be875","subject":"Merge \"Re-propose volume backed server rebuild\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/78afc9d49cc1fad705092eb9b54a80af900be875"}]}],"author":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2017-09-22 16:24:15.000000000","tz":120},"committer":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2019-04-15 10:40:47.000000000","tz":120},"subject":"Add \"Secure Boot support for KVM \u0026 QEMU guests\" spec","message":"Add \"Secure Boot support for KVM \u0026 QEMU guests\" spec\n\nAllow Secure Boot (SB) support for KVM- and QEMU-based instances,\nusing OVMF (Open Virtual Machine Firmware), and other SB-related\nfeatures in libvirt and QEMU.\n\nWhat exactly is OVMF?\n\n    An open source project that enables UEFI (Unified Extensible\n    Firmware Interface) support for KVM- and QEMU-based virtual\n    machines.\n\nKey benefits of Secure Boot:\n\n  - It provides protection from boot-time malware\n  - Provides a trusted boot path\n\nFor a more in-depth treatment on Secure Boot, refer to this[1].\n\nNB: Support for Hyper-V in Nova was added in:\n    http://git.openstack.org/cgit/openstack/nova/commit/?h\u003dmaster\u0026id\u003d29dab99\n    -- Hyper-V: Adds Hyper-V UEFI Secure Boot\n\nBlueprint: allow-secure-boot-for-qemu-kvm-guests\n\n[1] http://www.rodsbooks.com/efi-bootloaders/secureboot.html\n\nChange-Id: Ib88c9b95364ca7e2b9feff3140b77d70faa6ce1c\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/4f44b1e5bf2c5280d68a1e9d1b60857ae6e9eacc"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/4f44b1e5bf2c5280d68a1e9d1b60857ae6e9eacc"}]},"branch":"refs/heads/master"},"333be63c64df7dd12b0c5098500336da4427c854":{"kind":"REWORK","_number":11,"created":"2019-04-17 10:26:24.000000000","uploader":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"ref":"refs/changes/20/506720/11","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/20/506720/11","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/11 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/11 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/11 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/11"}}},"commit":{"parents":[{"commit":"78afc9d49cc1fad705092eb9b54a80af900be875","subject":"Merge \"Re-propose volume backed server rebuild\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/78afc9d49cc1fad705092eb9b54a80af900be875"}]}],"author":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2017-09-22 16:24:15.000000000","tz":120},"committer":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2019-04-17 10:20:46.000000000","tz":120},"subject":"Add \"Secure Boot support for KVM \u0026 QEMU guests\" spec","message":"Add \"Secure Boot support for KVM \u0026 QEMU guests\" spec\n\nAllow Secure Boot (SB) support for KVM- and QEMU-based instances,\nusing OVMF (Open Virtual Machine Firmware), and other SB-related\nfeatures in libvirt and QEMU.\n\nWhat exactly is OVMF?\n\n    An open source project that enables UEFI (Unified Extensible\n    Firmware Interface) support for KVM- and QEMU-based virtual\n    machines.\n\nKey benefits of Secure Boot:\n\n  - It provides protection from boot-time malware\n  - Provides a trusted boot path\n\nFor a more in-depth treatment on Secure Boot, refer to this[1].\n\nNB: Support for Hyper-V in Nova was added in:\n    http://git.openstack.org/cgit/openstack/nova/commit/?h\u003dmaster\u0026id\u003d29dab99\n    -- Hyper-V: Adds Hyper-V UEFI Secure Boot\n\nBlueprint: allow-secure-boot-for-qemu-kvm-guests\n\n[1] http://www.rodsbooks.com/efi-bootloaders/secureboot.html\n\nChange-Id: Ib88c9b95364ca7e2b9feff3140b77d70faa6ce1c\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/333be63c64df7dd12b0c5098500336da4427c854"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/333be63c64df7dd12b0c5098500336da4427c854"}]},"branch":"refs/heads/master"},"184930122e5c723b2b8a655c7961bc6a102a0fcd":{"kind":"REWORK","_number":12,"created":"2019-07-02 11:22:02.000000000","uploader":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"ref":"refs/changes/20/506720/12","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/20/506720/12","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/12 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/12 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/12 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/12"}}},"commit":{"parents":[{"commit":"78afc9d49cc1fad705092eb9b54a80af900be875","subject":"Merge \"Re-propose volume backed server rebuild\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/78afc9d49cc1fad705092eb9b54a80af900be875"}]}],"author":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2017-09-22 16:24:15.000000000","tz":120},"committer":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2019-07-02 10:06:45.000000000","tz":120},"subject":"Add \"Secure Boot support for KVM \u0026 QEMU guests\" spec","message":"Add \"Secure Boot support for KVM \u0026 QEMU guests\" spec\n\nAllow Secure Boot (SB) support for KVM- and QEMU-based instances,\nusing OVMF (Open Virtual Machine Firmware), and other SB-related\nfeatures in libvirt and QEMU.\n\nWhat exactly is OVMF?\n\n    An open source project that enables UEFI (Unified Extensible\n    Firmware Interface) support for KVM- and QEMU-based virtual\n    machines.\n\nKey benefits of Secure Boot:\n\n  - It provides protection from boot-time malware\n  - Provides a trusted boot path\n\nFor a more in-depth treatment on Secure Boot, refer to this[1].\n\nNB: Support for Hyper-V in Nova was added in:\n    http://git.openstack.org/cgit/openstack/nova/commit/?h\u003dmaster\u0026id\u003d29dab99\n    -- Hyper-V: Adds Hyper-V UEFI Secure Boot\n\nBlueprint: allow-secure-boot-for-qemu-kvm-guests\n\n[1] http://www.rodsbooks.com/efi-bootloaders/secureboot.html\n\nChange-Id: Ib88c9b95364ca7e2b9feff3140b77d70faa6ce1c\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/184930122e5c723b2b8a655c7961bc6a102a0fcd"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/184930122e5c723b2b8a655c7961bc6a102a0fcd"}]},"branch":"refs/heads/master"},"7d6849ed8a5b79b1043f03d90696c6b57f65ca23":{"kind":"REWORK","_number":13,"created":"2019-07-02 13:13:03.000000000","uploader":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"ref":"refs/changes/20/506720/13","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/20/506720/13","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/13 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/13 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/13 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/13"}}},"commit":{"parents":[{"commit":"78afc9d49cc1fad705092eb9b54a80af900be875","subject":"Merge \"Re-propose volume backed server rebuild\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/78afc9d49cc1fad705092eb9b54a80af900be875"}]}],"author":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2017-09-22 16:24:15.000000000","tz":120},"committer":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2019-07-02 13:12:55.000000000","tz":120},"subject":"Add \"Secure Boot support for KVM \u0026 QEMU guests\" spec","message":"Add \"Secure Boot support for KVM \u0026 QEMU guests\" spec\n\nAllow Secure Boot (SB) support for KVM- and QEMU-based instances,\nusing OVMF (Open Virtual Machine Firmware), and other SB-related\nfeatures in libvirt and QEMU.\n\nWhat exactly is OVMF?\n\n    An open source project that enables UEFI (Unified Extensible\n    Firmware Interface) support for KVM- and QEMU-based virtual\n    machines.\n\nKey benefits of Secure Boot:\n\n  - It provides protection from boot-time malware\n  - Provides a trusted boot path\n\nFor a more in-depth treatment on Secure Boot, refer to this[1].\n\nNB: Support for Hyper-V in Nova was added in:\n    http://git.openstack.org/cgit/openstack/nova/commit/?h\u003dmaster\u0026id\u003d29dab99\n    -- Hyper-V: Adds Hyper-V UEFI Secure Boot\n\nBlueprint: allow-secure-boot-for-qemu-kvm-guests\n\n[1] http://www.rodsbooks.com/efi-bootloaders/secureboot.html\n\nChange-Id: Ib88c9b95364ca7e2b9feff3140b77d70faa6ce1c\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/7d6849ed8a5b79b1043f03d90696c6b57f65ca23"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/7d6849ed8a5b79b1043f03d90696c6b57f65ca23"}]},"branch":"refs/heads/master"},"f4c79e4f1a90a328f3373a3540fea331288080f2":{"kind":"REWORK","_number":14,"created":"2019-07-02 14:09:44.000000000","uploader":{"_account_id":6962,"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","username":"kashyapc"},"ref":"refs/changes/20/506720/14","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/nova-specs","ref":"refs/changes/20/506720/14","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/14 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/14 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/14 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/nova-specs refs/changes/20/506720/14"}}},"commit":{"parents":[{"commit":"78afc9d49cc1fad705092eb9b54a80af900be875","subject":"Merge \"Re-propose volume backed server rebuild\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/78afc9d49cc1fad705092eb9b54a80af900be875"}]}],"author":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2017-09-22 16:24:15.000000000","tz":120},"committer":{"name":"Kashyap Chamarthy","email":"kchamart@redhat.com","date":"2019-07-02 14:04:58.000000000","tz":120},"subject":"Add \"Secure Boot support for KVM \u0026 QEMU guests\" spec","message":"Add \"Secure Boot support for KVM \u0026 QEMU guests\" spec\n\nAllow Secure Boot (SB) support for KVM- and QEMU-based instances,\nusing OVMF (Open Virtual Machine Firmware), and other SB-related\nfeatures in libvirt and QEMU.\n\nWhat exactly is OVMF?\n\n    An open source project that enables UEFI (Unified Extensible\n    Firmware Interface) support for KVM- and QEMU-based virtual\n    machines.\n\nKey benefits of Secure Boot:\n\n  - It provides protection from boot-time malware\n  - Provides a trusted boot path\n\nFor a more in-depth treatment on Secure Boot, refer to this[1].\n\nNB: Support for Hyper-V in Nova was added in:\n    http://git.openstack.org/cgit/openstack/nova/commit/?h\u003dmaster\u0026id\u003d29dab99\n    -- Hyper-V: Adds Hyper-V UEFI Secure Boot\n\nBlueprint: allow-secure-boot-for-qemu-kvm-guests\n\n[1] http://www.rodsbooks.com/efi-bootloaders/secureboot.html\n\nChange-Id: Ib88c9b95364ca7e2b9feff3140b77d70faa6ce1c\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/f4c79e4f1a90a328f3373a3540fea331288080f2"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/nova-specs/commit/f4c79e4f1a90a328f3373a3540fea331288080f2"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
