Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753758AbdDGGb2 (ORCPT ); Fri, 7 Apr 2017 02:31:28 -0400 Received: from mx1.redhat.com ([209.132.183.28]:54818 "EHLO mx1.redhat.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752245AbdDGGbU (ORCPT ); Fri, 7 Apr 2017 02:31:20 -0400 DMARC-Filter: OpenDMARC Filter v1.3.2 mx1.redhat.com 0462980F7C Authentication-Results: ext-mx03.extmail.prod.ext.phx2.redhat.com; dmarc=none (p=none dis=none) header.from=redhat.com Authentication-Results: ext-mx03.extmail.prod.ext.phx2.redhat.com; spf=pass smtp.mailfrom=dyoung@redhat.com DKIM-Filter: OpenDKIM Filter v2.11.0 mx1.redhat.com 0462980F7C Date: Fri, 7 Apr 2017 14:31:07 +0800 From: Dave Young To: "Rafael J. Wysocki" Cc: David Howells , Linux Kernel Mailing List , gnomes@lxorguk.ukuu.org.uk, linux-efi@vger.kernel.org, Josh Boyer , Greg Kroah-Hartman , ACPI Devel Maling List , linux-security-module@vger.kernel.org, keyrings@vger.kernel.org, matthew.garrett@nebula.com Subject: Re: [PATCH 17/24] acpi: Ignore acpi_rsdp kernel param when the kernel has been locked down Message-ID: <20170407063107.GA10451@dhcp-128-65.nay.redhat.com> References: <149142326734.5101.4596394505987813763.stgit@warthog.procyon.org.uk> <149142341772.5101.12366553346604485034.stgit@warthog.procyon.org.uk> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.7.1 (2016-10-04) X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.27]); Fri, 07 Apr 2017 06:31:20 +0000 (UTC) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1059 Lines: 27 On 04/06/17 at 09:43pm, Rafael J. Wysocki wrote: > On Wed, Apr 5, 2017 at 10:16 PM, David Howells wrote: > > From: Josh Boyer > > > > This option allows userspace to pass the RSDP address to the kernel, which > > makes it possible for a user to circumvent any restrictions imposed on > > loading modules. Ignore the option when the kernel is locked down. > > I'm not really sure here. > > What exactly is the mechanism? Actually this acpi_rsdp param is created for EFI kexec reboot in old days when we had not supported persistent efi vm space across kexec reboot. At that time kexec reboot runs as noefi mode, it can not find the acpi root table thus kernel will hang early. Now kexec can support EFI boot so this param is not necessary for most user unless they still use efi=old_map. > > Thanks, > Rafael > -- > To unsubscribe from this list: send the line "unsubscribe linux-efi" in > the body of a message to majordomo@vger.kernel.org > More majordomo info at http://vger.kernel.org/majordomo-info.html