Received: by 10.213.65.68 with SMTP id h4csp138235imn; Tue, 3 Apr 2018 17:18:31 -0700 (PDT) X-Google-Smtp-Source: AIpwx48XxNiuna3yX2+7j7Cm60A2WchpA7OVlDekmsKyJIOGECfRGHzoE7+nqHRinXTxr73hbVMa X-Received: by 2002:a17:902:207:: with SMTP id 7-v6mr16469611plc.261.1522801111612; Tue, 03 Apr 2018 17:18:31 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1522801111; cv=none; d=google.com; s=arc-20160816; b=IWKcudDGYXrL2CBBBLGVdXPII4gAFU4Vg5B4EqVLFyliI7ZpQ5+j8LylNGrT6LeoGF TqlNQBZj5ZMVK/XjNGLXWQbQ8jWIeZ3vnGAJ7Ii6dJKseGxuUnn+WBQ1ZJIhoQ1ntQDR bE5v/7VOEb0p0OsSzs1PcKtJt0+KF0A+6jGihFvIOXjn5TnE4BkkYmt3nCM/RA0cwLEj wWNnsL6Tx9jgiCOTYVrr9NsZLyf4+0y6yFwHs+8WaCdteYPS62a+Baydq2sWD1cJDQwC 2eD0RxWro1AukdJiwdkdEDUGoTRQR0Sj9lj766Do/3ej+o4PMu+FuE5IWT0JvY96YC03 vqow== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:dkim-signature :arc-authentication-results; bh=OIanxuFZtpTJZsF5bebtGvgfQjT+1i+rwvUrzvrsKI8=; b=WlKqedaUnqb3YF+ww6qnA3GGGG6fRWHnoIlIWQ909NnYmADU6Xvd2vmkIR76ZE/2R9 lhlgereLfUwkL67orZeRCufoLmG6GXPZG/8qyC2Wbt18+QAAtPapAW+m5P0t7ctLIHap H6mMC+DqrQ4V61XdMITZxhpNdwwpqELNNIRRE3jNrU3Qq8iwVg0BtCkZr6NCsbThdZo+ n5MWTQaL3Bek2OqjXc1HgobEPcWW7tY7WG3Znnxq9HhD4096Co+n1rIsItfKUVEYMYQk Iu9bKXZ3L2c9gdP103tOvvfjXgYp9iEt3pPZyQRg3/IB9rzsLMxK1/GB88h+0GdCAuh2 UHGQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=tH/tc2Fc; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id x3-v6si1730055plo.479.2018.04.03.17.18.17; Tue, 03 Apr 2018 17:18:31 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=tH/tc2Fc; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1756405AbeDDARB (ORCPT + 99 others); Tue, 3 Apr 2018 20:17:01 -0400 Received: from mail-it0-f65.google.com ([209.85.214.65]:53064 "EHLO mail-it0-f65.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1755976AbeDDAQ6 (ORCPT ); Tue, 3 Apr 2018 20:16:58 -0400 Received: by mail-it0-f65.google.com with SMTP id f6-v6so14515736ita.2 for ; Tue, 03 Apr 2018 17:16:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=OIanxuFZtpTJZsF5bebtGvgfQjT+1i+rwvUrzvrsKI8=; b=tH/tc2FchtHmTm8VxQaqgg/vjWiOPnyXIBLAplI3++ScHTruOuUbfsb9fZkHpf6vEp acJtKGNmoLK2BqNkKrHH7siGjALGEyjAJ2xFXzkwN49+DnVU5Sxv4AS3qhOXO6TmRsyq 20/lL1+i45Zs8ArcreGOJy6kKzRlB5rxOKGj2Z+TutHqG2oa8dSePzqP/kjPDZrzWAIS HFOMculEunYlW/O6usiebd9eRx0L3ThT/t1M7bfX6Q9PRx8fTQepUncf32tAlYcQw7ok hf0OyiLCf+5B/gZD4R0tVBmpBFww9DhisNX8UIbOsy5IqZLMQndDz+sUkgeJpXzJV1DL rYBQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=OIanxuFZtpTJZsF5bebtGvgfQjT+1i+rwvUrzvrsKI8=; b=BwW6oHNFTFCOWOG5svLJwBEDo6IcydDZ+vbsvfQTaFsI5dgLvkNGo6Wyt/HN1qoN9l eQrl4aXsHadD7t2ACRXEz9V9ViE7VdgRPX5lOhfdBINxXz7e8mh2eiIk2XfJsW39yXZR bwRCqXEUDio//571Ceh9Mwx+sQwPI3JGHO1AK457guPyL27sQhMDEMVZVPQgbxmlYfcs 3CgCN6i7H8ShKfsCKqeiQBsPFk4CFnkNls7b8p5eqVgrlbvC/kxoR+5OBakvtf2CUUej Ae+N5OIiYspGlIA73YIGvQzE/aqn/VAXux9XJLXM+NlYESna3HvZtwxMpZOfX0xuI106 lPKg== X-Gm-Message-State: ALQs6tBNdmjTyaYr7MKIKS0x8Z8B5dosCh2tw6swUvb1gHH5u6Pd1Dcb Ci02QPyu+wzEri+HxZLT2vBhpt262HqxZA9fPS4CTQ== X-Received: by 2002:a24:46cd:: with SMTP id j196-v6mr6943015itb.8.1522801017422; Tue, 03 Apr 2018 17:16:57 -0700 (PDT) MIME-Version: 1.0 References: <4136.1522452584@warthog.procyon.org.uk> <186aeb7e-1225-4bb8-3ff5-863a1cde86de@kernel.org> <30459.1522739219@warthog.procyon.org.uk> <9758.1522775763@warthog.procyon.org.uk> <13189.1522784944@warthog.procyon.org.uk> <9349.1522794769@warthog.procyon.org.uk> In-Reply-To: From: Matthew Garrett Date: Wed, 04 Apr 2018 00:16:46 +0000 Message-ID: Subject: Re: [GIT PULL] Kernel lockdown for secure boot To: Linus Torvalds Cc: luto@kernel.org, David Howells , Ard Biesheuvel , jmorris@namei.org, Alan Cox , Greg Kroah-Hartman , Linux Kernel Mailing List , jforbes@redhat.com, linux-man@vger.kernel.org, jlee@suse.com, LSM List , linux-api@vger.kernel.org, Kees Cook , linux-efi Content-Type: text/plain; charset="UTF-8" Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Tue, Apr 3, 2018 at 5:15 PM Linus Torvalds wrote: > On Tue, Apr 3, 2018 at 5:10 PM, Matthew Garrett wrote: > > > >> Exactly like EVERY OTHER KERNEL CONFIG OPTION. > > > > So your argument is that we should make the user experience worse? Without > > some sort of verified boot mechanism, lockdown is just security theater. > > There's no good reason to enable it unless you have some mechanism for > > verifying that you booted something you trust. > Wow. Way to snip the rest of the email where I told you what the > solution was. Let me repeat it here, since you so conveniently missed > it and deleted it: I ignored it because it's not a viable option. Part of the patchset disables various kernel command line options. If there's a kernel command line option that disables the patchset then it's pointless.