Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #81076 > unrolled thread

No longer sign i386 kernels

Started byBastian Blank <waldi@debian.org>
First post2023-12-06 18:20 +0100
Last post2023-12-10 00:00 +0100
Articles 5 — 3 participants

Back to article view | Back to linux.debian.kernel


Contents

  No longer sign i386 kernels Bastian Blank <waldi@debian.org> - 2023-12-06 18:20 +0100
    Re: No longer sign i386 kernels Steve McIntyre <steve@einval.com> - 2023-12-06 22:10 +0100
      Re: No longer sign i386 kernels Pascal Hambourg <pascal@plouf.fr.eu.org> - 2023-12-06 23:50 +0100
        Re: No longer sign i386 kernels Steve McIntyre <steve@einval.com> - 2023-12-07 00:10 +0100
      Re: No longer sign i386 kernels Bastian Blank <waldi@debian.org> - 2023-12-10 00:00 +0100

#81076 — No longer sign i386 kernels

FromBastian Blank <waldi@debian.org>
Date2023-12-06 18:20 +0100
SubjectNo longer sign i386 kernels
Message-ID<HI3IZ-bKNF-5@gated-at.bofh.it>
Hi

I would like do stop signing i386 kernels.

- IA32 UEFI is basically non existent outside of the Apple world and
  maybe some embedded stuff.
- i386 lacks many of the microarchitectural fixes that creeped in during
  the last years.  So those kernels are unsuitable for real world usage
  of processors released in the last ten years.

Install base of a IA32 EFI capable boot chain, as possible to see by
popcon (via grub-efi-ia32-signed): 178

Install base of a X64 EFI capable boot chain (via
grub-efi-amd64-signed): 71743

Bastian

-- 
Military secrets are the most fleeting of all.
		-- Spock, "The Enterprise Incident", stardate 5027.4

[toc] | [next] | [standalone]


#81081

FromSteve McIntyre <steve@einval.com>
Date2023-12-06 22:10 +0100
Message-ID<HI7jz-bNXM-5@gated-at.bofh.it>
In reply to#81076
Hey Bastian!

On Wed, Dec 06, 2023 at 06:01:17PM +0100, Bastian Blank wrote:
>
>I would like do stop signing i386 kernels.
>
>- IA32 UEFI is basically non existent outside of the Apple world and
>  maybe some embedded stuff.
>- i386 lacks many of the microarchitectural fixes that creeped in during
>  the last years.  So those kernels are unsuitable for real world usage
>  of processors released in the last ten years.
>
>Install base of a IA32 EFI capable boot chain, as possible to see by
>popcon (via grub-efi-ia32-signed): 178
>
>Install base of a X64 EFI capable boot chain (via
>grub-efi-amd64-signed): 71743

ACK. We're heading towards deprecating i386 as a full architecture
anyway and just keeping it as a secondary arch for backwards
compatibility for old programs, Wine, games etc. So I think this makes
sense.

We should publicise this for users and be consistent for all the EFI
signed binaries - there's no point in signing i386 grub and fwupd or
having a signed shim if we don't have a signed kernel.

Agreed?

-- 
Steve McIntyre, Cambridge, UK.                                steve@einval.com
< Aardvark> I dislike C++ to start with. C++11 just seems to be
            handing rope-creating factories for users to hang multiple
            instances of themselves.

[toc] | [prev] | [next] | [standalone]


#81083

FromPascal Hambourg <pascal@plouf.fr.eu.org>
Date2023-12-06 23:50 +0100
Message-ID<HI8Sl-bOMe-5@gated-at.bofh.it>
In reply to#81081
Hello,

On 06/12/2023 at 22:09, Steve McIntyre wrote:
> 
> On Wed, Dec 06, 2023 at 06:01:17PM +0100, Bastian Blank wrote:
>>
>> I would like do stop signing i386 kernels.
>>
>> - IA32 UEFI is basically non existent outside of the Apple world and
>>   maybe some embedded stuff.
(...)
> there's no point in signing i386 grub and fwupd or
> having a signed shim if we don't have a signed kernel.

Over the years I have seen a number of netbook or tablet-style PCs with 
32-bit UEFI firmware and a 64-bit capable CPU, so they could boot with 
grub-efi-ia32 and an amd64 kernel. I do not remember if they supported 
secure boot though.

[toc] | [prev] | [next] | [standalone]


#81084

FromSteve McIntyre <steve@einval.com>
Date2023-12-07 00:10 +0100
Message-ID<HI9bH-bP8f-3@gated-at.bofh.it>
In reply to#81083
On Wed, Dec 06, 2023 at 11:44:52PM +0100, Pascal Hambourg wrote:
>Hello,
>
>On 06/12/2023 at 22:09, Steve McIntyre wrote:
>> 
>> On Wed, Dec 06, 2023 at 06:01:17PM +0100, Bastian Blank wrote:
>> > 
>> > I would like do stop signing i386 kernels.
>> > 
>> > - IA32 UEFI is basically non existent outside of the Apple world and
>> >   maybe some embedded stuff.
>(...)
>> there's no point in signing i386 grub and fwupd or
>> having a signed shim if we don't have a signed kernel.
>
>Over the years I have seen a number of netbook or tablet-style PCs with
>32-bit UEFI firmware and a 64-bit capable CPU, so they could boot with
>grub-efi-ia32 and an amd64 kernel. I do not remember if they supported secure
>boot though.

Some of them did, but at this point the most recent of those Bay Trail
netbooks is heading for a decade old. They were designed to be very
cheap, which means very few will have survived this long. We're not
proposing to kill support *altogether*, but SB isn't a priority here
for such old machines IMHO.

-- 
Steve McIntyre, Cambridge, UK.                                steve@einval.com
“Why do people find DNS so difficult? It’s just cache invalidation and
 naming things.”
   -– Jeff Waugh (https://twitter.com/jdub)

[toc] | [prev] | [next] | [standalone]


#81134

FromBastian Blank <waldi@debian.org>
Date2023-12-10 00:00 +0100
Message-ID<HJesF-ctA1-1@gated-at.bofh.it>
In reply to#81081
On Wed, Dec 06, 2023 at 09:09:01PM +0000, Steve McIntyre wrote:
> We should publicise this for users and be consistent for all the EFI
> signed binaries - there's no point in signing i386 grub and fwupd or
> having a signed shim if we don't have a signed kernel.
> Agreed?

Signing of i386 kernels is gone.
https://salsa.debian.org/kernel-team/linux/-/merge_requests/944

Bastian

-- 
Suffocating together ... would create heroic camaraderie.
		-- Khan Noonian Singh, "Space Seed", stardate 3142.8

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web