Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1569760
| Path | csiph.com!news.redatomik.org!aioe.org!bofh.it!news.nic.it!robomod |
|---|---|
| From | David Howells <dhowells@redhat.com> |
| Newsgroups | linux.kernel |
| Subject | Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization? |
| Date | Mon, 30 Jan 2017 15:10:01 +0100 |
| Message-ID | <t5kOB-4Wr-13@gated-at.bofh.it> (permalink) |
| References | <t5kEW-4Ed-43@gated-at.bofh.it> <t4fnY-58H-3@gated-at.bofh.it> <t2Ulz-3fA-3@gated-at.bofh.it> <t0gVk-1Kl-15@gated-at.bofh.it> <sYsee-82P-29@gated-at.bofh.it> <sM69r-68W-3@gated-at.bofh.it> <sM69t-68W-67@gated-at.bofh.it> <sYtai-an-29@gated-at.bofh.it> <t0hy2-2jl-17@gated-at.bofh.it> <t2V7X-3R1-15@gated-at.bofh.it> <t5j6b-3SD-25@gated-at.bofh.it> <t5kEW-4Ed-43@gated-at.bofh.it> |
| X-Original-To | Matt Fleming <matt@codeblueprint.co.uk> |
| Organization | Red Hat UK Ltd. Registered Address: Red Hat UK Ltd, Amberley Place, 107-111 Peascod Street, Windsor, Berkshire, SI4 1TE, United Kingdom. Registered in England and Wales under Company Registration No. 3798903 |
| MIME-Version | 1.0 |
| Content-Type | text/plain; charset="us-ascii" |
| Content-ID | <12080.1485784892.1@warthog.procyon.org.uk> |
| Content-Transfer-Encoding | 8BIT |
| X-Scanned-By | MIMEDefang 2.68 on 10.5.11.24 |
| X-Greylist | Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.26]); Mon, 30 Jan 2017 14:01:36 +0000 (UTC) |
| Sender | robomod@news.nic.it |
| List-ID | <linux-kernel.vger.kernel.org> |
| X-Mailing-List | linux-kernel@vger.kernel.org |
| Approved | robomod@news.nic.it |
| Lines | 17 |
| X-Original-Cc | dhowells@redhat.com, Peter Jones <pjones@redhat.com>, mjg59@srcf.ucam.org, ard.biesheuvel@linaro.org, linux-efi@vger.kernel.org, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, keyrings@vger.kernel.org, linux-arm-kernel@lists.infradead.org, "H. Peter Anvin" <hpa@zytor.com>, Michael Chang <mchang@suse.com> |
| X-Original-Date | Mon, 30 Jan 2017 14:01:32 +0000 |
| X-Original-Message-ID | <12081.1485784892@warthog.procyon.org.uk> |
| X-Original-References | <20170130135002.GL31613@codeblueprint.co.uk> <20170127140101.GD31613@codeblueprint.co.uk> <20170123212642.GA2766@codeblueprint.co.uk> <20170116144954.GB27351@codeblueprint.co.uk> <20170111143304.GA29649@codeblueprint.co.uk> <148120020832.5854.5448601415491330495.stgit@warthog.procyon.org.uk> <148120024570.5854.10638278395097394138.stgit@warthog.procyon.org.uk> <7948.1484148443@warthog.procyon.org.uk> <794.1484581158@warthog.procyon.org.uk> <6306.1485209503@warthog.procyon.org.uk> <25118.1485778229@warthog.procyon.org.uk> <20170130135002.GL31613@codeblueprint.co.uk> |
| X-Original-Sender | linux-kernel-owner@vger.kernel.org |
| Xref | csiph.com linux.kernel:1569760 |
Show key headers only | View raw
Matt Fleming <matt@codeblueprint.co.uk> wrote: > > Matt argues, however, that boot_params->secure_boot should be propagated from > > the bootloader and if the bootloader wants to set it, then we should skip the > > check in efi_main() and go with the bootloader's opinion. This is something > > we probably want to do with kexec() so that the lockdown state is propagated > > there. > > Actually what I was arguing for was that if the boot loader wants to > set it and bypass the EFI boot stub, e.g. by going via the legacy > 64-bit entry point, startup_64, then we should allow that as well as > setting the flag in the EFI boot stub. That brings up another question: Should the non-EFI entry points clear the secure_boot mode flag and set a default? David
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-23 22:30 +0100
Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] David Howells <dhowells@redhat.com> - 2017-01-23 23:20 +0100
Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-27 15:10 +0100
Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] David Howells <dhowells@redhat.com> - 2017-01-31 15:20 +0100
What should the default lockdown mode be if the bootloader sentinel triggers sanitization? David Howells <dhowells@redhat.com> - 2017-01-30 13:20 +0100
Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization? Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-30 15:00 +0100
Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization? David Howells <dhowells@redhat.com> - 2017-01-30 15:10 +0100
Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization? Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-31 13:00 +0100
csiph-web