On 16/05/16 09:54, Big Strong wrote:
Problem solved by booting xen with grub instead of efi. The deep reason is unknown.
Ah - that is very useful to know, and now obvious. EFI has no concept of modules, which probably means the XSM policy doesn't get loaded.
FWIW, there is a plan to change how XSM policies are done in the future, by embedding the policy at build time.
~Andrew