F45 Change Proposal: Grub EFI For Confidential Computing (self-contained)

I find the points against systemd-boot to not be very convincing.

This feels contradictory to the idea of limiting GRUB features. Are there some features that you want to keep for this minimal GRUB that aren’t present in sd-boot?

Citation needed. Also, it’s not like systemd-boot is something entirely new and unused. Trying to guess which is more secure by popularity seems like reading tea leaves.

This is a more convincing point, but unless the regular GRUB configuration is limited to only using features that are available to the minimal configuration, there is still a risk of feature disparity.

Could you elaborate on this? Is there some architecture candidate for support that is or surely will be supported by GRUB but not sd-boot?

3 Likes