Received: by 2002:ac0:a5b6:0:0:0:0:0 with SMTP id m51-v6csp834893imm; Tue, 5 Jun 2018 05:20:50 -0700 (PDT) X-Google-Smtp-Source: ADUXVKJJn0upyMg7hNBJPDfL4ugRD35p0tW/sdqUl/BWugKKob0aaYwE8lwVTNgRUgNETUXUKDEf X-Received: by 2002:a63:aa07:: with SMTP id e7-v6mr20613746pgf.331.1528201250388; Tue, 05 Jun 2018 05:20:50 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1528201250; cv=none; d=google.com; s=arc-20160816; b=JZ4/xRnqi7Kc1Ac8hnpkCclZvj0Fal+12Jg3VDFzEDq7JiHukDfQ+o71m1jXfvTgVl 6/xGEzkxByQQmN5bBkL1GfIk2WOqrTG46kjSHjnkQOSPWdLEaD0q6wUjaUDQInSW2aoU GwiWYgUmE1RyZcj8dnOrYyytziQtJV7wn1UBbmu38pEbkCTm6AFEdH0GF81zREXFlXed JzX6kwqh/omIYXFNi01O89jlffijCKu4+BKL8C0I8+kGnySyrau4/oL2Sb31VKs354vf ymrRrKpO0Kdbv3lh42Fum+Q7Vrr7i9+x2I7yW3jn9Dbgz2axyuwDaeD5SblEKbmZpTdC DGaQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:cc:to:subject:message-id:date:from :references:in-reply-to:mime-version:dkim-signature:dkim-signature :arc-authentication-results; bh=xttNXUhYVTjFbtgmKD5rbPTkaeVLLmgbiBgOq2kBuM8=; b=aybcy1w7WXpTqVVrqfft1sUZRTT9azkEioPQUCSskdPPANo/2GjBdCe51FT+VX/2YI iYffeClSyzRuKQB+2tGSYLKBP5kCdkWt8RjVEszdRFdxRXSQbZnEJb8BgTpUYzCuNAeu lpXWmNv+RiydlrJ2hLx0hBqSb8poKhwrX12BpFLsBTtLKY5qGooUNI/ePmqP/J+/bk+b qR2ZafHIYq+h6T05VhNsCzswoDDBINcOAWBVS/3fo40nTqwS4xX/pIgwNavR1JSro33a UGLIpCUjMeCvBUDQSTar5SSE6PvLsPI3jh2UKiziCRy5WXXeC4o8uaokBr1K6j07XUxe ODjg== ARC-Authentication-Results: i=1; mx.google.com; dkim=fail header.i=@google.com header.s=20161025 header.b=qR3Guw/b; dkim=fail header.i=@chromium.org header.s=google header.b=Wy+9zhZQ; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=chromium.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id m22-v6si14892857pls.147.2018.06.05.05.20.35; Tue, 05 Jun 2018 05:20:50 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=fail header.i=@google.com header.s=20161025 header.b=qR3Guw/b; dkim=fail header.i=@chromium.org header.s=google header.b=Wy+9zhZQ; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=chromium.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751897AbeFEMTz (ORCPT + 99 others); Tue, 5 Jun 2018 08:19:55 -0400 Received: from mail-ua0-f196.google.com ([209.85.217.196]:35728 "EHLO mail-ua0-f196.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751784AbeFEMTx (ORCPT ); Tue, 5 Jun 2018 08:19:53 -0400 Received: by mail-ua0-f196.google.com with SMTP id a2-v6so1460750uak.2 for ; Tue, 05 Jun 2018 05:19:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=xttNXUhYVTjFbtgmKD5rbPTkaeVLLmgbiBgOq2kBuM8=; b=qR3Guw/bKHl/Z5YVKWnJ3mlCvGBwEf/5uGR7O8HFqE6+qQ1qw7wOZfODBjYLWGZjck SPnA+zWKa3JXKWSeyGjyMp8JScbR0y6D1zDE/fktUjjg2Zhc9oWn38CNlf6TXvYhMc7p w1Qt8kSTc0DW6KKxPnKJvkkl+PCBdY9DHbIKPYzPJOZuYJJAWXSH8Hu2naqfV4j0c5/0 LXUdbfMaaGjIyVESJDx7cTsrDpqryHfaTzLslV3jJUwzdf0kko4KQO4o7L32igOSNXdg KyRRJYz4ve1VZ185/Z67UCXo6AU6xLhAQVuENCAbui7fW9+BdDgOeDGaKM6qUhNeu/Wl 0zSw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=xttNXUhYVTjFbtgmKD5rbPTkaeVLLmgbiBgOq2kBuM8=; b=Wy+9zhZQ1bQ5+4o4jF/SBExE7A3pNMKkQjNdYMZeIDEZk1d54et3nIsdhzz9FN56xo L/G97dH/wtoyAYTljUFQe6LZ0P0A410anyIyywq/ulEoFAj7GDnozg4p8pUxPla8z1pz d01yST4WuFA2rmBdzvxCopw+7ux6/8MRj9qF8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc; bh=xttNXUhYVTjFbtgmKD5rbPTkaeVLLmgbiBgOq2kBuM8=; b=olndy+xbid+hXPW1iM5nCkRURwDLn62tYjXQ2mNoc0ea5TA86TtlKyUlUOso/s0B5p sc4T0vfoS7oPE/d4zZe/CCXsjjijuR3kaTQFJK3wCnXtCFH/Ngm+b51aAmh1Z0eDpnQ+ rfEoY8+289szjOFE1m6rGSlJxxiu0h8Anvs/nswze3TuNk5jJ73WajDFlBI/r8xFvCW6 aDl5jOFaLpyRdJ6NyhLnX22hZrPF8MXPJCRRmlvGLICun73/K60WVDctNG1lsgUzjacM 6KfYoraF4RyiHPlxHwSpk6UOzBPkjlsRh+pXmAzCVwUykNmIslbodFlTWeLJ1NJ0ionV n8RQ== X-Gm-Message-State: ALKqPwfWHaRDpNAZ9h8yKlIbk8NsyXw2XlS9upigyNisNasn2GFwIfSJ pqh4bg8Oe4lp8yA2mFLno6Jt54e8KqXQcGadmcLKwA== X-Received: by 2002:a9f:2823:: with SMTP id c32-v6mr17629683uac.193.1528201191774; Tue, 05 Jun 2018 05:19:51 -0700 (PDT) MIME-Version: 1.0 Received: by 2002:a1f:a085:0:0:0:0:0 with HTTP; Tue, 5 Jun 2018 05:19:50 -0700 (PDT) In-Reply-To: <20180605040920.GA19747@mail.hallyn.com> References: <1527616920-5415-1-git-send-email-zohar@linux.vnet.ibm.com> <1528121025.3237.116.camel@linux.vnet.ibm.com> <20180605040920.GA19747@mail.hallyn.com> From: Kees Cook Date: Tue, 5 Jun 2018 05:19:50 -0700 X-Google-Sender-Auth: Fjmatf4jpBswGjytWVV6kU8PkGY Message-ID: Subject: Re: [PATCH v4 0/8] kexec/firmware: support system wide policy requiring signatures To: "Serge E. Hallyn" Cc: Mimi Zohar , Casey Schaufler , James Morris , Paul Moore , linux-integrity , linux-security-module , LKML , David Howells , "Luis R . Rodriguez" , Eric Biederman , Kexec Mailing List , Andres Rodriguez , Greg Kroah-Hartman , Ard Biesheuvel , Jessica Yu Content-Type: text/plain; charset="UTF-8" Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, Jun 4, 2018 at 9:09 PM, Serge E. Hallyn wrote: > Personally I agree with Eric and prefer a new hook. I don't feel strongly > enough about it to keep bikeshedding, but since this set already exists, > it seems like the way to go. And the new hook is "load stuff without a file descriptor"? -Kees -- Kees Cook Pixel Security