Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1556558 > unrolled thread
| Started by | Matt Fleming <matt@codeblueprint.co.uk> |
|---|---|
| First post | 2017-01-11 16:00 +0100 |
| Last post | 2017-01-16 16:50 +0100 |
| Articles | 4 — 2 participants |
Back to article view | Back to linux.kernel
This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by
below is the oldest one visible, not the original post.
Re: [PATCH 8/8] efi: Add EFI_SECURE_BOOT bit [ver #6] Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-11 16:00 +0100
Re: [PATCH 8/8] efi: Add EFI_SECURE_BOOT bit [ver #6] David Howells <dhowells@redhat.com> - 2017-01-11 16:40 +0100
Re: [PATCH 8/8] efi: Add EFI_SECURE_BOOT bit [ver #6] Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-16 14:50 +0100
Re: [PATCH 8/8] efi: Add EFI_SECURE_BOOT bit [ver #6] David Howells <dhowells@redhat.com> - 2017-01-16 16:50 +0100
| From | Matt Fleming <matt@codeblueprint.co.uk> |
|---|---|
| Date | 2017-01-11 16:00 +0100 |
| Subject | Re: [PATCH 8/8] efi: Add EFI_SECURE_BOOT bit [ver #6] |
| Message-ID | <sYsxA-89i-17@gated-at.bofh.it> |
On Thu, 08 Dec, at 12:31:08PM, David Howells wrote: > From: Josh Boyer <jwboyer@fedoraproject.org> > > UEFI machines can be booted in Secure Boot mode. Add a EFI_SECURE_BOOT bit > that can be passed to efi_enabled() to find out whether secure boot is > enabled. > > This will be used by the SysRq+x handler, registered by the x86 arch, to find > out whether secure boot mode is enabled so that it can be disabled. > > Signed-off-by: Josh Boyer <jwboyer@fedoraproject.org> > Signed-off-by: David Howells <dhowells@redhat.com> > --- > > arch/x86/kernel/setup.c | 15 +++++++++++++++ > include/linux/efi.h | 1 + > 2 files changed, 16 insertions(+) Before we add more efi.flags bits I'd like this series to include the patch that makes use of EFI_SECURE_BOOT. Alternatively, you move this last patch to a new series.
[toc] | [next] | [standalone]
| From | David Howells <dhowells@redhat.com> |
|---|---|
| Date | 2017-01-11 16:40 +0100 |
| Message-ID | <sYtah-an-13@gated-at.bofh.it> |
| In reply to | #1556558 |
Matt Fleming <matt@codeblueprint.co.uk> wrote: > Before we add more efi.flags bits I'd like this series to include the > patch that makes use of EFI_SECURE_BOOT. Alternatively, you move this > last patch to a new series. Are you willing to take the kernel lock-down patches also? David
[toc] | [prev] | [next] | [standalone]
| From | Matt Fleming <matt@codeblueprint.co.uk> |
|---|---|
| Date | 2017-01-16 14:50 +0100 |
| Message-ID | <t0fPA-14g-21@gated-at.bofh.it> |
| In reply to | #1556630 |
On Wed, 11 Jan, at 03:29:24PM, David Howells wrote: > Matt Fleming <matt@codeblueprint.co.uk> wrote: > > > Before we add more efi.flags bits I'd like this series to include the > > patch that makes use of EFI_SECURE_BOOT. Alternatively, you move this > > last patch to a new series. > > Are you willing to take the kernel lock-down patches also? I'm happy to take them through the EFI tree provided that they've been Reviewed/Ack-ed by the security folks.
[toc] | [prev] | [next] | [standalone]
| From | David Howells <dhowells@redhat.com> |
|---|---|
| Date | 2017-01-16 16:50 +0100 |
| Message-ID | <t0hHI-2nd-23@gated-at.bofh.it> |
| In reply to | #1559750 |
Matt Fleming <matt@codeblueprint.co.uk> wrote: > > > Before we add more efi.flags bits I'd like this series to include the > > > patch that makes use of EFI_SECURE_BOOT. Alternatively, you move this > > > last patch to a new series. > > > > Are you willing to take the kernel lock-down patches also? > > I'm happy to take them through the EFI tree provided that they've been > Reviewed/Ack-ed by the security folks. Thinking further about it, it might be best to push the EFI_SECURE_BOOT flag into a later series and exclude that patch from this one. David
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web