Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1569756
| Path | csiph.com!eternal-september.org!feeder.eternal-september.org!aioe.org!bofh.it!news.nic.it!robomod |
|---|---|
| From | Matt Fleming <matt@codeblueprint.co.uk> |
| Newsgroups | linux.kernel |
| Subject | Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization? |
| Date | Mon, 30 Jan 2017 15:00:02 +0100 |
| Message-ID | <t5kEW-4Ed-43@gated-at.bofh.it> (permalink) |
| References | <t4fnY-58H-3@gated-at.bofh.it> <t2Ulz-3fA-3@gated-at.bofh.it> <t0gVk-1Kl-15@gated-at.bofh.it> <sYsee-82P-29@gated-at.bofh.it> <sM69r-68W-3@gated-at.bofh.it> <sM69t-68W-67@gated-at.bofh.it> <sYtai-an-29@gated-at.bofh.it> <t0hy2-2jl-17@gated-at.bofh.it> <t2V7X-3R1-15@gated-at.bofh.it> <t5j6b-3SD-25@gated-at.bofh.it> |
| Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=codeblueprint-co-uk.20150623.gappssmtp.com; s=20150623; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=ZnD0KNjc8gqSUaKWUtLrfI40yovc7OJ/NR/sd7NhKT0=; b=fpv0YSCCgpkgYGPJ6f08VMpOm7QT1ihPE8PbG83BP8fi8VDxTwjpymVm2Te/Vhvdvh UD6T2FVepNpWukrPeA2cnhYgJ/uXLfjn4vcIy3HfE1nqGbIMZ6yuV9AMbSP1nQIgy6W1 22Y4RTFkFiOfPeGwa8a5nkMzTlEqUyLxOYXIaQtp93c2UAjGKkX9tkKNmNgUipNZPrry KOPXtYyWPX2H7rl/LPFo7wUG1ZW7O6JCbhTgvDYHUfGNqILvDGzxVeSwkM6i0GKGvAx3 oufbtUkXPte8wFb98xnWdRkGeFyH0HYC1M7IsaotELUlgz/4VoSgiGYgD+y/0OAq8hbj BPYA== |
| X-Google-Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=ZnD0KNjc8gqSUaKWUtLrfI40yovc7OJ/NR/sd7NhKT0=; b=tVXGI7qAg8mijb7ObcP8LhNUpM+YQKDk0Msv0vXkv/dSYcKGKMJCX0cgdz4cBao4SA 86ty1sEp6Vl9ddgz9Ry5Z+qCMJAdirE7TYuP0JD3A9bxgbS+dZ5KNfkk08CwIbc9Pc23 YJ6mgGGsJyzZs0BSZDOvvAOm0W1FItohYb68+Pe5fbpUvxMgS/7gjKCuf8aQYDMLuB6R uc4Vvb5zeY1Ja/LQQ+ssucjForsgM8utDNmmV9kOFtsVUYBafsh9djoBNSWqCXGOPbYw 5upTFJUyx7A0KfIjiJV04MhnYYfPM0iw125kpzh3wKWt0b/KGC9AqM4hibbHizlNr6za Lqzw== |
| X-Gm-Message-State | AIkVDXKjoVuiBiZiVlB2d677OVbkIY+WbhLJ2U1ROGL7u3gtt3rzHBWRTrYeiJXjBvS7nw== |
| X-Received | by 10.223.160.84 with SMTP id l20mr18603227wrl.106.1485784203929; Mon, 30 Jan 2017 05:50:03 -0800 (PST) |
| MIME-Version | 1.0 |
| Content-Type | text/plain; charset=us-ascii |
| Content-Disposition | inline |
| User-Agent | Mutt/1.5.24+41 (02bc14ed1569) (2015-08-30) |
| Sender | robomod@news.nic.it |
| List-ID | <linux-kernel.vger.kernel.org> |
| X-Mailing-List | linux-kernel@vger.kernel.org |
| Approved | robomod@news.nic.it |
| Lines | 12 |
| Organization | linux.* mail to news gateway |
| X-Original-Cc | Peter Jones <pjones@redhat.com>, mjg59@srcf.ucam.org, ard.biesheuvel@linaro.org, linux-efi@vger.kernel.org, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, keyrings@vger.kernel.org, linux-arm-kernel@lists.infradead.org, "H. Peter Anvin" <hpa@zytor.com>, Michael Chang <mchang@suse.com> |
| X-Original-Date | Mon, 30 Jan 2017 13:50:02 +0000 |
| X-Original-Message-ID | <20170130135002.GL31613@codeblueprint.co.uk> |
| X-Original-References | <20170127140101.GD31613@codeblueprint.co.uk> <20170123212642.GA2766@codeblueprint.co.uk> <20170116144954.GB27351@codeblueprint.co.uk> <20170111143304.GA29649@codeblueprint.co.uk> <148120020832.5854.5448601415491330495.stgit@warthog.procyon.org.uk> <148120024570.5854.10638278395097394138.stgit@warthog.procyon.org.uk> <7948.1484148443@warthog.procyon.org.uk> <794.1484581158@warthog.procyon.org.uk> <6306.1485209503@warthog.procyon.org.uk> <25118.1485778229@warthog.procyon.org.uk> |
| X-Original-Sender | linux-kernel-owner@vger.kernel.org |
| Xref | csiph.com linux.kernel:1569756 |
Show key headers only | View raw
On Mon, 30 Jan, at 12:10:29PM, David Howells wrote: > > Matt argues, however, that boot_params->secure_boot should be propagated from > the bootloader and if the bootloader wants to set it, then we should skip the > check in efi_main() and go with the bootloader's opinion. This is something > we probably want to do with kexec() so that the lockdown state is propagated > there. Actually what I was arguing for was that if the boot loader wants to set it and bypass the EFI boot stub, e.g. by going via the legacy 64-bit entry point, startup_64, then we should allow that as well as setting the flag in the EFI boot stub.
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-23 22:30 +0100
Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] David Howells <dhowells@redhat.com> - 2017-01-23 23:20 +0100
Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-27 15:10 +0100
Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] David Howells <dhowells@redhat.com> - 2017-01-31 15:20 +0100
What should the default lockdown mode be if the bootloader sentinel triggers sanitization? David Howells <dhowells@redhat.com> - 2017-01-30 13:20 +0100
Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization? Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-30 15:00 +0100
Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization? David Howells <dhowells@redhat.com> - 2017-01-30 15:10 +0100
Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization? Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-31 13:00 +0100
csiph-web