Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1536183

Re: [PATCH 01/39] Annotate module params that specify hardware parameters (eg. ioport)

From Greg KH <gregkh@linuxfoundation.org>
Newsgroups linux.kernel
Subject Re: [PATCH 01/39] Annotate module params that specify hardware parameters (eg. ioport)
Date 2016-12-05 16:50 +0100
Message-ID <sL3GG-6lh-9@gated-at.bofh.it> (permalink)
References (1 earlier) <sJyEV-3Or-7@gated-at.bofh.it> <sJyEV-3Or-25@gated-at.bofh.it> <sJB9L-5sv-5@gated-at.bofh.it> <sJN1f-6yi-1@gated-at.bofh.it> <sJXtE-5bN-39@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Fri, Dec 02, 2016 at 02:59:22PM +0000, David Howells wrote:
> Greg KH <gregkh@linuxfoundation.org> wrote:
> 
> > > If root is able to modify the behaviour of verified code after it was 
> > > verified, then the value of that verification is reduced. Ensuring that 
> > > the code remains trustworthy is vital in a number of security use cases.
> > 
> > Ok, but why are you now deciding to somehow try to "classify" the types
> > of module parameters?
> 
> Because Alan says that locking down the module parameters needs to be done
> first.  Since I had to go through and modify each module parameter to mark the
> hardware config ones, it seemed like a good opportunity to label their type
> (ioport, iomem, irq, etc.) whilst I was at it.
> 
> > Then just mark them all as "bad", why pick and choose?
> 
> Because some drivers, IPMI for example, can also be autoconfigured via PCI,
> PNP, ACPI or whatever and still be useful, if not important, to the system's
> operation.
> 
> Simply marking all drivers that can be so configured as "bad" and rejecting
> them outright in lockdown mode is a non-starter.

Sorry, I meant to mark all of these types of attributes as "bad", not
trying to classify all of the different types of attributes, given that
you will probably want to just ban all of them or none, right?

> > > Right now, the secure boot patchset
> >
> > "this stuff" is brand new things, that no one is shipping.
> 
> True, but my other two patchsets are primarily made up of things people *are*
> shipping.  If you're happy to for those to go in and can persuade Alan to okay
> deferral of module parameter lockdown for an extra cycle, that's fine by me.

I'll defer to Alan as to what he feels is needed here, given that this
patchset isn't being shipped by anyone I think it's odd to somehow make
this a pre-requisite for anything to be merged as no real user of the
patchset seemed to feel this type of thing was needed :)

> > Come on, you know better than this, each patch/series/feature has to be
> > justifable on it's own, and this patchset, as-is, doesn't pass that test
> > to me, if for no other reason than it is just "marking" things that is
> > never then being used.
> 
> You're being unreasonable.  The complete set is on the order of 90 patches, I
> think.  I could submit them all in one go in a single series, but then people
> would be complaining that it's too big and that I have to split it up.
> 
> I have broken it up into a number of logical series, of which I've published
> some:
> 
>  (1) Determining the EFI secure boot state.  This only depends on tip
>      efi/core.  This mostly takes what the ARM arch already does upstream and
>      extends it to x86 too.
> 
>  (2) Marking hardware config module params.  Patches 2+ all depend on patch 1,
>      but there are no dependencies outside of that series.  If I could get
>      patch 1 upstream, I could distribute patches 2+ individually to the
>      maintainers.
> 
>  (3) Kernel lockdown.  This takes the determination made by (1) and applies
>      it, enabling various lockdowns, including locking down anything annotated
>      in (2).
> 
>  (4) System blacklist.  List hashes to be blacklisted.  This is independent of
>      all other series.

These are hashes of what?

>  (5) UEFI/SHIM whitelist/blacklist loading.  This has a dependency on some
>      constants added in (1).
> 
> I have to do them in some order.  Doing it this way means that some of these
> are self-contained, making it technically easier to upstream those pieces.

I think patch 3 is going to be the "hardest", along with 2, given the
large area it touches.  Why not work on the other bits first?

thanks,

greg k-h

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 00/39] Annotate hw config module params for future lockdown David Howells <dhowells@redhat.com> - 2016-12-01 13:30 +0100
  [PATCH 01/39] Annotate module params that specify hardware  parameters (eg. ioport) David Howells <dhowells@redhat.com> - 2016-12-01 13:30 +0100
    Re: [PATCH 01/39] Annotate module params that specify hardware  parameters (eg. ioport) Greg KH <gregkh@linuxfoundation.org> - 2016-12-01 16:10 +0100
      Re: [PATCH 01/39] Annotate module params that specify hardware parameters (eg. ioport) David Howells <dhowells@redhat.com> - 2016-12-01 17:10 +0100
        Re: [PATCH 01/39] Annotate module params that specify hardware  parameters (eg. ioport) One Thousand Gnomes <gnomes@lxorguk.ukuu.org.uk> - 2016-12-05 22:20 +0100
          Re: [PATCH 01/39] Annotate module params that specify hardware  parameters (eg. ioport) Greg KH <gregkh@linuxfoundation.org> - 2016-12-06 08:20 +0100
            Re: [PATCH 01/39] Annotate module params that specify hardware parameters (eg. ioport) David Howells <dhowells@redhat.com> - 2016-12-06 11:50 +0100
              Re: [PATCH 01/39] Annotate module params that specify hardware  parameters (eg. ioport) Greg KH <gregkh@linuxfoundation.org> - 2016-12-06 12:00 +0100
      Re: [PATCH 01/39] Annotate module params that specify hardware  parameters (eg. ioport) Matthew Garrett <mjg59@srcf.ucam.org> - 2016-12-02 04:50 +0100
        Re: [PATCH 01/39] Annotate module params that specify hardware  parameters (eg. ioport) Greg KH <gregkh@linuxfoundation.org> - 2016-12-02 08:00 +0100
          Re: [PATCH 01/39] Annotate module params that specify hardware  parameters (eg. ioport) Matthew Garrett <mjg59@srcf.ucam.org> - 2016-12-02 08:20 +0100
            Re: [PATCH 01/39] Annotate module params that specify hardware  parameters (eg. ioport) One Thousand Gnomes <gnomes@lxorguk.ukuu.org.uk> - 2016-12-05 22:30 +0100
          Re: [PATCH 01/39] Annotate module params that specify hardware parameters (eg. ioport) David Howells <dhowells@redhat.com> - 2016-12-02 16:00 +0100
            Re: [PATCH 01/39] Annotate module params that specify hardware  parameters (eg. ioport) Greg KH <gregkh@linuxfoundation.org> - 2016-12-05 16:50 +0100
              Re: [PATCH 01/39] Annotate module params that specify hardware parameters (eg. ioport) David Howells <dhowells@redhat.com> - 2016-12-06 12:00 +0100
  [PATCH 20/39] Annotate hardware config module parameters in  drivers/net/hamradio/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 34/39] Annotate hardware config module parameters in  drivers/watchdog/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
    Re: [PATCH 34/39] Annotate hardware config module parameters in  drivers/watchdog/ Guenter Roeck <linux@roeck-us.net> - 2016-12-01 14:00 +0100
  [PATCH 03/39] Annotate hardware config module parameters in  drivers/char/ipmi/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
    Re: [PATCH 03/39] Annotate hardware config module parameters in  drivers/char/ipmi/ Corey Minyard <minyard@acm.org> - 2016-12-01 14:20 +0100
  [PATCH 05/39] Annotate hardware config module parameters in  drivers/char/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 28/39] Annotate hardware config module parameters in  drivers/staging/i4l/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 07/39] Annotate hardware config module parameters in  drivers/cpufreq/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
    Re: [PATCH 07/39] Annotate hardware config module parameters in drivers/cpufreq/ "Rafael J. Wysocki" <rafael@kernel.org> - 2016-12-01 15:10 +0100
      Re: [PATCH 07/39] Annotate hardware config module parameters in drivers/cpufreq/ David Howells <dhowells@redhat.com> - 2016-12-01 15:20 +0100
        Re: [PATCH 07/39] Annotate hardware config module parameters in drivers/cpufreq/ "Rafael J. Wysocki" <rjw@rjwysocki.net> - 2016-12-01 15:30 +0100
  [PATCH 39/39] Annotate hardware config module parameters in  sound/pci/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 35/39] Annotate hardware config module parameters in  fs/pstore/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 11/39] Annotate hardware config module parameters in  drivers/input/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
    Re: [PATCH 11/39] Annotate hardware config module parameters in  drivers/input/ Dmitry Torokhov <dmitry.torokhov@gmail.com> - 2016-12-03 20:00 +0100
  [PATCH 21/39] Annotate hardware config module parameters in  drivers/net/irda/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 31/39] Annotate hardware config module parameters in  drivers/staging/vme/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 33/39] Annotate hardware config module parameters in  drivers/video/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 04/39] Annotate hardware config module parameters in  drivers/char/mwave/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 38/39] Annotate hardware config module parameters in  sound/oss/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 06/39] Annotate hardware config module parameters in  drivers/clocksource/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 12/39] Annotate hardware config module parameters in  drivers/isdn/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 23/39] Annotate hardware config module parameters in  drivers/net/wireless/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
    Re: [PATCH 23/39] Annotate hardware config module parameters in drivers/net/wireless/ Kalle Valo <kvalo@codeaurora.org> - 2016-12-02 06:10 +0100
      Re: [PATCH 23/39] Annotate hardware config module parameters in drivers/net/wireless/ David Howells <dhowells@redhat.com> - 2016-12-07 14:50 +0100
  [PATCH 29/39] Annotate hardware config module parameters in  drivers/staging/media/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
    Re: [PATCH 29/39] Annotate hardware config module parameters in  drivers/staging/media/ Mauro Carvalho Chehab <mchehab@s-opensource.com> - 2016-12-01 16:00 +0100
      Re: [PATCH 29/39] Annotate hardware config module parameters in drivers/staging/media/ David Howells <dhowells@redhat.com> - 2016-12-01 16:10 +0100
        Re: [PATCH 29/39] Annotate hardware config module parameters in  drivers/staging/media/ Mauro Carvalho Chehab <mchehab@s-opensource.com> - 2016-12-01 16:20 +0100
  [PATCH 09/39] Annotate hardware config module parameters in  drivers/i2c/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
    Re: [PATCH 09/39] Annotate hardware config module parameters in  drivers/i2c/ Jean Delvare <jdelvare@suse.de> - 2016-12-01 14:50 +0100
      Re: [PATCH 09/39] Annotate hardware config module parameters in drivers/i2c/ David Howells <dhowells@redhat.com> - 2016-12-01 15:20 +0100
        Re: [PATCH 09/39] Annotate hardware config module parameters in  drivers/i2c/ Jean Delvare <jdelvare@suse.de> - 2016-12-01 17:10 +0100
        Re: [PATCH 09/39] Annotate hardware config module parameters in  drivers/i2c/ One Thousand Gnomes <gnomes@lxorguk.ukuu.org.uk> - 2016-12-05 22:20 +0100
  [PATCH 19/39] Annotate hardware config module parameters in  drivers/net/ethernet/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 18/39] Annotate hardware config module parameters in  drivers/net/can/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
    Re: [PATCH 18/39] Annotate hardware config module parameters in  drivers/net/can/ Marc Kleine-Budde <mkl@pengutronix.de> - 2016-12-01 14:10 +0100
  [PATCH 25/39] Annotate hardware config module parameters in  drivers/pci/hotplug/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
    Re: [PATCH 25/39] Annotate hardware config module parameters in  drivers/pci/hotplug/ Bjorn Helgaas <helgaas@kernel.org> - 2016-12-07 19:40 +0100
  [PATCH 27/39] Annotate hardware config module parameters in  drivers/scsi/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
    Re: [PATCH 27/39] Annotate hardware config module parameters in  drivers/scsi/ Finn Thain <fthain@telegraphics.com.au> - 2016-12-01 23:10 +0100
  [PATCH 26/39] Annotate hardware config module parameters in  drivers/pcmcia/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 08/39] Annotate hardware config module parameters in  drivers/gpio/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
    Re: [PATCH 08/39] Annotate hardware config module parameters in  drivers/gpio/ William Breathitt Gray <vilhelm.gray@gmail.com> - 2016-12-01 14:50 +0100
    Re: [PATCH 08/39] Annotate hardware config module parameters in drivers/gpio/ Linus Walleij <linus.walleij@linaro.org> - 2016-12-02 14:00 +0100
  [PATCH 32/39] Annotate hardware config module parameters in  drivers/tty/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
    Re: [PATCH 32/39] Annotate hardware config module parameters in  drivers/tty/ Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-12-01 16:10 +0100
  [PATCH 13/39] Annotate hardware config module parameters in  drivers/media/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 36/39] Annotate hardware config module parameters in  sound/drivers/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 17/39] Annotate hardware config module parameters in  drivers/net/arcnet/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 24/39] Annotate hardware config module parameters in  drivers/parport/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 15/39] Annotate hardware config module parameters in  drivers/mmc/host/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 02/39] Annotate hardware config module parameters in  arch/x86/mm/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 16/39] Annotate hardware config module parameters in  drivers/net/appletalk/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 37/39] Annotate hardware config module parameters in  sound/isa/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 30/39] Annotate hardware config module parameters in  drivers/staging/speakup/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 22/39] Annotate hardware config module parameters in  drivers/net/wan/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
  [PATCH 10/39] Annotate hardware config module parameters in  drivers/iio/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100
    Re: [PATCH 10/39] Annotate hardware config module parameters in  drivers/iio/ William Breathitt Gray <vilhelm.gray@gmail.com> - 2016-12-01 15:00 +0100
      Re: [PATCH 10/39] Annotate hardware config module parameters in  drivers/iio/ Jonathan Cameron <jic23@kernel.org> - 2016-12-03 15:40 +0100
        Re: [PATCH 10/39] Annotate hardware config module parameters in drivers/iio/ David Howells <dhowells@redhat.com> - 2016-12-07 14:50 +0100
  [PATCH 14/39] Annotate hardware config module parameters in  drivers/misc/ David Howells <dhowells@redhat.com> - 2016-12-01 13:40 +0100

csiph-web