Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1569760

Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization?

Path csiph.com!news.redatomik.org!aioe.org!bofh.it!news.nic.it!robomod
From David Howells <dhowells@redhat.com>
Newsgroups linux.kernel
Subject Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization?
Date Mon, 30 Jan 2017 15:10:01 +0100
Message-ID <t5kOB-4Wr-13@gated-at.bofh.it> (permalink)
References <t5kEW-4Ed-43@gated-at.bofh.it> <t4fnY-58H-3@gated-at.bofh.it> <t2Ulz-3fA-3@gated-at.bofh.it> <t0gVk-1Kl-15@gated-at.bofh.it> <sYsee-82P-29@gated-at.bofh.it> <sM69r-68W-3@gated-at.bofh.it> <sM69t-68W-67@gated-at.bofh.it> <sYtai-an-29@gated-at.bofh.it> <t0hy2-2jl-17@gated-at.bofh.it> <t2V7X-3R1-15@gated-at.bofh.it> <t5j6b-3SD-25@gated-at.bofh.it> <t5kEW-4Ed-43@gated-at.bofh.it>
X-Original-To Matt Fleming <matt@codeblueprint.co.uk>
Organization Red Hat UK Ltd. Registered Address: Red Hat UK Ltd, Amberley Place, 107-111 Peascod Street, Windsor, Berkshire, SI4 1TE, United Kingdom. Registered in England and Wales under Company Registration No. 3798903
MIME-Version 1.0
Content-Type text/plain; charset="us-ascii"
Content-ID <12080.1485784892.1@warthog.procyon.org.uk>
Content-Transfer-Encoding 8BIT
X-Scanned-By MIMEDefang 2.68 on 10.5.11.24
X-Greylist Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.26]); Mon, 30 Jan 2017 14:01:36 +0000 (UTC)
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 17
X-Original-Cc dhowells@redhat.com, Peter Jones <pjones@redhat.com>, mjg59@srcf.ucam.org, ard.biesheuvel@linaro.org, linux-efi@vger.kernel.org, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, keyrings@vger.kernel.org, linux-arm-kernel@lists.infradead.org, "H. Peter Anvin" <hpa@zytor.com>, Michael Chang <mchang@suse.com>
X-Original-Date Mon, 30 Jan 2017 14:01:32 +0000
X-Original-Message-ID <12081.1485784892@warthog.procyon.org.uk>
X-Original-References <20170130135002.GL31613@codeblueprint.co.uk> <20170127140101.GD31613@codeblueprint.co.uk> <20170123212642.GA2766@codeblueprint.co.uk> <20170116144954.GB27351@codeblueprint.co.uk> <20170111143304.GA29649@codeblueprint.co.uk> <148120020832.5854.5448601415491330495.stgit@warthog.procyon.org.uk> <148120024570.5854.10638278395097394138.stgit@warthog.procyon.org.uk> <7948.1484148443@warthog.procyon.org.uk> <794.1484581158@warthog.procyon.org.uk> <6306.1485209503@warthog.procyon.org.uk> <25118.1485778229@warthog.procyon.org.uk> <20170130135002.GL31613@codeblueprint.co.uk>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1569760

Show key headers only | View raw


Matt Fleming <matt@codeblueprint.co.uk> wrote:

> > Matt argues, however, that boot_params->secure_boot should be propagated from
> > the bootloader and if the bootloader wants to set it, then we should skip the
> > check in efi_main() and go with the bootloader's opinion.  This is something
> > we probably want to do with kexec() so that the lockdown state is propagated
> > there.
>  
> Actually what I was arguing for was that if the boot loader wants to
> set it and bypass the EFI boot stub, e.g. by going via the legacy
> 64-bit entry point, startup_64, then we should allow that as well as
> setting the flag in the EFI boot stub.

That brings up another question:  Should the non-EFI entry points clear the
secure_boot mode flag and set a default?

David

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-23 22:30 +0100
  Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] David Howells <dhowells@redhat.com> - 2017-01-23 23:20 +0100
    Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-27 15:10 +0100
      Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] David Howells <dhowells@redhat.com> - 2017-01-31 15:20 +0100
    What should the default lockdown mode be if the bootloader sentinel triggers sanitization? David Howells <dhowells@redhat.com> - 2017-01-30 13:20 +0100
      Re: What should the default lockdown mode be if the bootloader  sentinel triggers sanitization? Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-30 15:00 +0100
        Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization? David Howells <dhowells@redhat.com> - 2017-01-30 15:10 +0100
          Re: What should the default lockdown mode be if the bootloader  sentinel triggers sanitization? Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-31 13:00 +0100

csiph-web