[PATCH] disable VBE by default

Tom Rini trini at konsulko.com
Wed Jun 18 01:10:46 CEST 2025


On Tue, Jun 17, 2025 at 09:39:25AM +0300, Ilias Apalodimas wrote:

> On Sun Jun 15, 2025 at 12:33 PM EEST, Peter Robinson wrote:
> > The VBE protocol needs explicit device support and as
> > such isn't particularly useful by itself without that,
> > it also adds size and the potential of an attack vector
> > so devices that wish to use this protocol should
> > explicitly opt in to it like all other large features
> > in U-Boot.
> >
> > Signed-off-by: Peter Robinson <pbrobinson at gmail.com>
> 
> Acked-by: Ilias Apalodimas <ilias.apalodimas at linaro.org>

This is I think a tad premature. I believe Fedora has been carrying this
patch for some time, and that's the prerogative of that project and so
fine. There is a chicken-and-egg type problem with this feature and if
we aren't going to enable it by default, we then ought not bother
including it and that's not a collection of issues I wish to open at
this time.

-- 
Tom
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 659 bytes
Desc: not available
URL: <https://lists.denx.de/pipermail/u-boot/attachments/20250617/83c62ace/attachment.sig>


More information about the U-Boot mailing list