Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1493715 > unrolled thread

ima measurement carrying on -mm

Started byThiago Jung Bauermann <bauerman@linux.vnet.ibm.com>
First post2016-09-29 22:50 +0200
Last post2016-09-29 23:50 +0200
Articles 6 — 3 participants

Back to article view | Back to linux.kernel


Contents

  ima measurement carrying on -mm Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com> - 2016-09-29 22:50 +0200
    Re: ima measurement carrying on -mm Andrew Morton <akpm@linux-foundation.org> - 2016-09-29 23:10 +0200
      Re: ima measurement carrying on -mm Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com> - 2016-09-29 23:30 +0200
        Re: ima measurement carrying on -mm ebiederm@xmission.com (Eric W. Biederman) - 2016-09-30 00:00 +0200
          Re: ima measurement carrying on -mm Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com> - 2016-09-30 00:20 +0200
      Re: ima measurement carrying on -mm ebiederm@xmission.com (Eric W. Biederman) - 2016-09-29 23:50 +0200

#1493715 — ima measurement carrying on -mm

FromThiago Jung Bauermann <bauerman@linux.vnet.ibm.com>
Date2016-09-29 22:50 +0200
Subjectima measurement carrying on -mm
Message-ID<smQrg-xo-11@gated-at.bofh.it>
Hello Andrew,

You have in the -mm tree a version of the "kexec handover buffer" and "ima 
carry measurement list" patches that were NAKed by Eric Biederman. I would 
just like to double-check that there's no risk of that version reaching 
v4.9.

Mimi posted v5 of a merged patch set that addresses Eric's concern:

https://lists.ozlabs.org/pipermail/linuxppc-dev/2016-September/149183.html

There are no separate kexec handover patches anymore. They were folded into 
the series above. The kexec code is simplified now, it doesn't support 
updating the buffer and recalculating the hash on reboot, and is now IMA-
specific instead of a generic kexec feature.

-- 
[]'s
Thiago Jung Bauermann
IBM Linux Technology Center

[toc] | [next] | [standalone]


#1493722

FromAndrew Morton <akpm@linux-foundation.org>
Date2016-09-29 23:10 +0200
Message-ID<smQKB-TX-27@gated-at.bofh.it>
In reply to#1493715
On Thu, 29 Sep 2016 17:44:10 -0300 Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com> wrote:

> Hello Andrew,
> 
> You have in the -mm tree a version of the "kexec handover buffer" and "ima 
> carry measurement list" patches that were NAKed by Eric Biederman. I would 
> just like to double-check that there's no risk of that version reaching 
> v4.9.
> 
> Mimi posted v5 of a merged patch set that addresses Eric's concern:
> 
> https://lists.ozlabs.org/pipermail/linuxppc-dev/2016-September/149183.html
> 
> There are no separate kexec handover patches anymore. They were folded into 
> the series above. The kexec code is simplified now, it doesn't support 
> updating the buffer and recalculating the hash on reboot, and is now IMA-
> specific instead of a generic kexec feature.

Yup, thanks.

I wasn't thinking any of this material is suitable for 4.9.  Seems that
a bit more consideration will be needed.  Am I wrong about that?

Are all of these -mm patches up to date?

kexec_file-allow-arch-specific-memory-walking-for-kexec_add_buffer.patch
kexec_file-change-kexec_add_buffer-to-take-kexec_buf-as-argument.patch
kexec_file-factor-out-kexec_locate_mem_hole-from-kexec_add_buffer.patch
powerpc-change-places-using-config_kexec-to-use-config_kexec_core-instead.patch
powerpc-factor-out-relocation-code-from-module_64c-to-elf_util_64c.patch
powerpc-generalize-elf64_apply_relocate_add.patch
powerpc-adapt-elf64_apply_relocate_add-for-kexec_file_load.patch
powerpc-add-functions-to-read-elf-files-of-any-endianness.patch
powerpc-implement-kexec_file_load.patch
powerpc-add-code-to-work-with-device-trees-in-kexec_file_load.patch
powerpc-add-support-for-loading-elf-kernels-with-kexec_file_load.patch
powerpc-add-support-for-loading-elf-kernels-with-kexec_file_load-fix.patch
powerpc-add-purgatory-for-kexec_file_load-implementation.patch
powerpc-add-purgatory-for-kexec_file_load-implementation-fix.patch
powerpc-enable-config_kexec_file-in-powerpc-server-defconfigs.patch
#
kexec_file-include-the-purgatory-segment-in-the-kexec-image-checksum.patch
kexec_file-add-buffer-hand-over-support-for-the-next-kernel.patch
powerpc-kexec_file-add-buffer-hand-over-support-for-the-next-kernel.patch
kexec_file-add-mechanism-to-update-kexec-segments.patch

[toc] | [prev] | [next] | [standalone]


#1493730

FromThiago Jung Bauermann <bauerman@linux.vnet.ibm.com>
Date2016-09-29 23:30 +0200
Message-ID<smR3X-12A-15@gated-at.bofh.it>
In reply to#1493722
Am Donnerstag, 29 September 2016, 14:02:06 schrieb Andrew Morton:
> On Thu, 29 Sep 2016 17:44:10 -0300 Thiago Jung Bauermann 
<bauerman@linux.vnet.ibm.com> wrote:
> > Hello Andrew,
> > 
> > You have in the -mm tree a version of the "kexec handover buffer" and
> > "ima carry measurement list" patches that were NAKed by Eric Biederman.
> > I would just like to double-check that there's no risk of that version
> > reaching v4.9.
> > 
> > Mimi posted v5 of a merged patch set that addresses Eric's concern:
> > 
> > https://lists.ozlabs.org/pipermail/linuxppc-dev/2016-September/149183.ht
> > ml
> > 
> > There are no separate kexec handover patches anymore. They were folded
> > into the series above. The kexec code is simplified now, it doesn't
> > support updating the buffer and recalculating the hash on reboot, and
> > is now IMA- specific instead of a generic kexec feature.
> 
> Yup, thanks.
> 
> I wasn't thinking any of this material is suitable for 4.9.  Seems that
> a bit more consideration will be needed.  Am I wrong about that?

Yes regarding the "ima carry measurement list" patches, but I was hoping 
that at least the kexec_file_load patches would be upstreamed.

> Are all of these -mm patches up to date?
> 
> kexec_file-allow-arch-specific-memory-walking-for-kexec_add_buffer.patch
> kexec_file-change-kexec_add_buffer-to-take-kexec_buf-as-argument.patch
> kexec_file-factor-out-kexec_locate_mem_hole-from-kexec_add_buffer.patch
> powerpc-change-places-using-config_kexec-to-use-config_kexec_core-instead.
> patch
> powerpc-factor-out-relocation-code-from-module_64c-to-elf_util_64c.patch
> powerpc-generalize-elf64_apply_relocate_add.patch
> powerpc-adapt-elf64_apply_relocate_add-for-kexec_file_load.patch
> powerpc-add-functions-to-read-elf-files-of-any-endianness.patch
> powerpc-implement-kexec_file_load.patch
> powerpc-add-code-to-work-with-device-trees-in-kexec_file_load.patch
> powerpc-add-support-for-loading-elf-kernels-with-kexec_file_load.patch
> powerpc-add-support-for-loading-elf-kernels-with-kexec_file_load-fix.patch
> powerpc-add-purgatory-for-kexec_file_load-implementation.patch
> powerpc-add-purgatory-for-kexec_file_load-implementation-fix.patch
> powerpc-enable-config_kexec_file-in-powerpc-server-defconfigs.patch

Yes, the above are the latest version (v8).

> kexec_file-include-the-purgatory-segment-in-the-kexec-image-checksum.patch
> kexec_file-add-buffer-hand-over-support-for-the-next-kernel.patch
> powerpc-kexec_file-add-buffer-hand-over-support-for-the-next-kernel.patch
> kexec_file-add-mechanism-to-update-kexec-segments.patch

The above were superseded by the version Mimi posted this week I referred 
to.

Thanks for the quick response.

-- 
[]'s
Thiago Jung Bauermann
IBM Linux Technology Center

[toc] | [prev] | [next] | [standalone]


#1493744

Fromebiederm@xmission.com (Eric W. Biederman)
Date2016-09-30 00:00 +0200
Message-ID<smRwZ-1dR-3@gated-at.bofh.it>
In reply to#1493730
Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com> writes:

> Am Donnerstag, 29 September 2016, 14:02:06 schrieb Andrew Morton:
>> On Thu, 29 Sep 2016 17:44:10 -0300 Thiago Jung Bauermann 
> <bauerman@linux.vnet.ibm.com> wrote:
>> > Hello Andrew,
>> > 
>> > You have in the -mm tree a version of the "kexec handover buffer" and
>> > "ima carry measurement list" patches that were NAKed by Eric Biederman.
>> > I would just like to double-check that there's no risk of that version
>> > reaching v4.9.
>> > 
>> > Mimi posted v5 of a merged patch set that addresses Eric's concern:
>> > 
>> > https://lists.ozlabs.org/pipermail/linuxppc-dev/2016-September/149183.ht
>> > ml
>> > 
>> > There are no separate kexec handover patches anymore. They were folded
>> > into the series above. The kexec code is simplified now, it doesn't
>> > support updating the buffer and recalculating the hash on reboot, and
>> > is now IMA- specific instead of a generic kexec feature.
>> 
>> Yup, thanks.
>> 
>> I wasn't thinking any of this material is suitable for 4.9.  Seems that
>> a bit more consideration will be needed.  Am I wrong about that?
>
> Yes regarding the "ima carry measurement list" patches, but I was hoping 
> that at least the kexec_file_load patches would be upstreamed.

Oh bah. I was confused about that straight forward adding of kexec_file
support to powerpc.  I thought that was already in existence.

In that case let me say I am concerned about modifying the flattened
device tree, especially in the kexec_file.  I would think that the
flattened device tree would be something that it would be desirable to
keep intact.

I know in the x86 boot protocol we have some variables that are purely
passed by the bootloader (like the command line) and some that just
representations of firmware provided information.  Does powerpc not have
that separation.

I would think being able to pass the flattened device tree through
unchanged would be very desirable in the kexec case as it removes the
possibility of error.

>> Are all of these -mm patches up to date?
>> 
>> kexec_file-allow-arch-specific-memory-walking-for-kexec_add_buffer.patch
>> kexec_file-change-kexec_add_buffer-to-take-kexec_buf-as-argument.patch
>> kexec_file-factor-out-kexec_locate_mem_hole-from-kexec_add_buffer.patch
>> powerpc-change-places-using-config_kexec-to-use-config_kexec_core-instead.
>> patch
>> powerpc-factor-out-relocation-code-from-module_64c-to-elf_util_64c.patch
>> powerpc-generalize-elf64_apply_relocate_add.patch
>> powerpc-adapt-elf64_apply_relocate_add-for-kexec_file_load.patch
>> powerpc-add-functions-to-read-elf-files-of-any-endianness.patch
>> powerpc-implement-kexec_file_load.patch
>> powerpc-add-code-to-work-with-device-trees-in-kexec_file_load.patch
>> powerpc-add-support-for-loading-elf-kernels-with-kexec_file_load.patch
>> powerpc-add-support-for-loading-elf-kernels-with-kexec_file_load-fix.patch
>> powerpc-add-purgatory-for-kexec_file_load-implementation.patch
>> powerpc-add-purgatory-for-kexec_file_load-implementation-fix.patch
>> powerpc-enable-config_kexec_file-in-powerpc-server-defconfigs.patch
>
> Yes, the above are the latest version (v8).

Eric

[toc] | [prev] | [next] | [standalone]


#1493752

FromThiago Jung Bauermann <bauerman@linux.vnet.ibm.com>
Date2016-09-30 00:20 +0200
Message-ID<smRQm-1IF-19@gated-at.bofh.it>
In reply to#1493744
Am Donnerstag, 29 September 2016, 16:53:50 schrieb Eric W. Biederman:
> Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com> writes:
> > Am Donnerstag, 29 September 2016, 14:02:06 schrieb Andrew Morton:
> >> On Thu, 29 Sep 2016 17:44:10 -0300 Thiago Jung Bauermann
> > 
> > <bauerman@linux.vnet.ibm.com> wrote:
> >> > Hello Andrew,
> >> > 
> >> > You have in the -mm tree a version of the "kexec handover buffer" and
> >> > "ima carry measurement list" patches that were NAKed by Eric
> >> > Biederman.
> >> > I would just like to double-check that there's no risk of that
> >> > version
> >> > reaching v4.9.
> >> > 
> >> > Mimi posted v5 of a merged patch set that addresses Eric's concern:
> >> > 
> >> > https://lists.ozlabs.org/pipermail/linuxppc-dev/2016-September/149183
> >> > .ht
> >> > ml
> >> > 
> >> > There are no separate kexec handover patches anymore. They were
> >> > folded
> >> > into the series above. The kexec code is simplified now, it doesn't
> >> > support updating the buffer and recalculating the hash on reboot, and
> >> > is now IMA- specific instead of a generic kexec feature.
> >> 
> >> Yup, thanks.
> >> 
> >> I wasn't thinking any of this material is suitable for 4.9.  Seems that
> >> a bit more consideration will be needed.  Am I wrong about that?
> > 
> > Yes regarding the "ima carry measurement list" patches, but I was hoping
> > that at least the kexec_file_load patches would be upstreamed.
> 
> Oh bah. I was confused about that straight forward adding of kexec_file
> support to powerpc.  I thought that was already in existence.
> 
> In that case let me say I am concerned about modifying the flattened
> device tree, especially in the kexec_file.  I would think that the
> flattened device tree would be something that it would be desirable to
> keep intact.
> 
> I know in the x86 boot protocol we have some variables that are purely
> passed by the bootloader (like the command line) and some that just
> representations of firmware provided information.  Does powerpc not have
> that separation.
> 
> I would think being able to pass the flattened device tree through
> unchanged would be very desirable in the kexec case as it removes the
> possibility of error.

As far as I know, that is not possible. The device tree always needs to be 
modified to add or update the properties that indicate where the initrd is 
loaded and, as you mentioned, the kernel command line. The IMA buffer 
patches just adds another property.

-- 
[]'s
Thiago Jung Bauermann
IBM Linux Technology Center

[toc] | [prev] | [next] | [standalone]


#1493739

Fromebiederm@xmission.com (Eric W. Biederman)
Date2016-09-29 23:50 +0200
Message-ID<smRnk-19a-19@gated-at.bofh.it>
In reply to#1493722
Andrew Morton <akpm@linux-foundation.org> writes:

> On Thu, 29 Sep 2016 17:44:10 -0300 Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com> wrote:
>
>> Hello Andrew,
>> 
>> You have in the -mm tree a version of the "kexec handover buffer" and "ima 
>> carry measurement list" patches that were NAKed by Eric Biederman. I would 
>> just like to double-check that there's no risk of that version reaching 
>> v4.9.
>> 
>> Mimi posted v5 of a merged patch set that addresses Eric's concern:
>> 
>> https://lists.ozlabs.org/pipermail/linuxppc-dev/2016-September/149183.html
>> 
>> There are no separate kexec handover patches anymore. They were folded into 
>> the series above. The kexec code is simplified now, it doesn't support 
>> updating the buffer and recalculating the hash on reboot, and is now IMA-
>> specific instead of a generic kexec feature.
>
> Yup, thanks.
>
> I wasn't thinking any of this material is suitable for 4.9.  Seems that
> a bit more consideration will be needed.  Am I wrong about that?

With Mimi's v5 version of these patches the kexec portions look reasonable
and the rest is pretty much just ima code and a little bit of powerpc
specific glue (as this is only currently supported for the powerpc
way of passing boot parameters).

> Are all of these -mm patches up to date?

No.  There was a v5 that mimi posted.  I think the patches listed below are
obsolete at this point.

> kexec_file-allow-arch-specific-memory-walking-for-kexec_add_buffer.patch
> kexec_file-change-kexec_add_buffer-to-take-kexec_buf-as-argument.patch
> kexec_file-factor-out-kexec_locate_mem_hole-from-kexec_add_buffer.patch
> powerpc-change-places-using-config_kexec-to-use-config_kexec_core-instead.patch
> powerpc-factor-out-relocation-code-from-module_64c-to-elf_util_64c.patch
> powerpc-generalize-elf64_apply_relocate_add.patch
> powerpc-adapt-elf64_apply_relocate_add-for-kexec_file_load.patch
> powerpc-add-functions-to-read-elf-files-of-any-endianness.patch
> powerpc-implement-kexec_file_load.patch
> powerpc-add-code-to-work-with-device-trees-in-kexec_file_load.patch
> powerpc-add-support-for-loading-elf-kernels-with-kexec_file_load.patch
> powerpc-add-support-for-loading-elf-kernels-with-kexec_file_load-fix.patch
> powerpc-add-purgatory-for-kexec_file_load-implementation.patch
> powerpc-add-purgatory-for-kexec_file_load-implementation-fix.patch
> powerpc-enable-config_kexec_file-in-powerpc-server-defconfigs.patch
> #
> kexec_file-include-the-purgatory-segment-in-the-kexec-image-checksum.patch
> kexec_file-add-buffer-hand-over-support-for-the-next-kernel.patch
> powerpc-kexec_file-add-buffer-hand-over-support-for-the-next-kernel.patch
> kexec_file-add-mechanism-to-update-kexec-segments.patch

Eric

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web