Received: by 2002:ac0:a5b6:0:0:0:0:0 with SMTP id m51-v6csp931571imm; Tue, 5 Jun 2018 06:45:21 -0700 (PDT) X-Google-Smtp-Source: ADUXVKLQ8fcACcWRcUkKo5ak59mtz9Jidz6bQIOw1NG78nHx86SWfiKinpMFqhM83VyzlUcSdUnX X-Received: by 2002:a63:86c8:: with SMTP id x191-v6mr20498098pgd.2.1528206320946; Tue, 05 Jun 2018 06:45:20 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1528206320; cv=none; d=google.com; s=arc-20160816; b=ui1zBfcStLsqVFxPPgImPUq/c+6T45UCNbeVmo1nXv6AM4o9aS8Dn6Xu68Xt/+GfCt LcVYez8ceHF5rNLR7xh8o2eCiIhAVjS12lQdGLakY8/9DX86RCs3Tarrx/EbIMZB/wnA Ills3+xFUi7gcoMoiPyxQ8EfWbMCX48UCyHs3uoS+2Fo4f1gkauFCfzHghB9avMm+74o D2FZx1WakN9B0QIIuNoka/G8uSYICpQsMxwqCq2+uVHIaw40utUSd3Qac4hjEinTdTqU DkA4zcXCe2mz8tKP8pifT6+AFI27VC92NR00l1+Ona2w2uByqOg1pZ6qU/F+6OyAmh6/ pwbA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:cc:to:subject:message-id:date:from :references:in-reply-to:mime-version:dkim-signature:dkim-signature :arc-authentication-results; bh=NRI1abTZJ6kicrdP+HfsjaTw1ydLJ5ZT0LGcdUiH+r8=; b=eufX6gnEsZyYt7I/H0zqfrJf0/49XYzMaSL4cqM6hDztWeiIDJA+0rK99cSfO96UMa 7xXCRs659fSYPqmKIE9CxewGwVmcAaWNo9vN1BxZVhrPfAECqSOGTyK6AC6pBSJms0Wk ChRpUKrc/RL/fzBkhB2MkV6SQsxnolins3uFHZZAUOYIkxjyq1t6Cm1hc42getbKZRpC BveLGWQDfZs7atAYSp7ugnGq51ftOrICmHvAe9BYabYl4MgpqgpyEVOIOD/RWoDiU75Y 05NY3RdbTdMyhziDD60AiCKYLL5G4C8yEkzLbhtBmlsuPq01wBYpKyb0QG4Q4B4Bp4Dw jsFg== ARC-Authentication-Results: i=1; mx.google.com; dkim=fail header.i=@google.com header.s=20161025 header.b=YqJgecmD; dkim=fail header.i=@chromium.org header.s=google header.b=VG/fb44O; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=chromium.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id m10-v6si55826pge.245.2018.06.05.06.45.05; Tue, 05 Jun 2018 06:45:20 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=fail header.i=@google.com header.s=20161025 header.b=YqJgecmD; dkim=fail header.i=@chromium.org header.s=google header.b=VG/fb44O; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=chromium.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752039AbeFENng (ORCPT + 99 others); Tue, 5 Jun 2018 09:43:36 -0400 Received: from mail-ua0-f195.google.com ([209.85.217.195]:36955 "EHLO mail-ua0-f195.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751915AbeFENnd (ORCPT ); Tue, 5 Jun 2018 09:43:33 -0400 Received: by mail-ua0-f195.google.com with SMTP id i3-v6so1640435uad.4 for ; Tue, 05 Jun 2018 06:43:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=NRI1abTZJ6kicrdP+HfsjaTw1ydLJ5ZT0LGcdUiH+r8=; b=YqJgecmDEp0fScW6p8zH5j6Jh9TBZppGV986IdjDJQtPtpc2iAiPcarooYWaZ0NXD5 0BITY/7+7pjPvNFXhVW/rRjUsz1vG45dfAUIEDFmb7Yi4H0goERQG/i7du6R4PBAAU3J hIB/9I54aP3SQ6kgetjTUooeSrD48rzcdD8ConjqLPapRPI6KdV65rcnyF7hEuIX8t6A O5uZTfdRWkbiYgqxJQQaE2JGVka9IcOpyUR+pxJKDmjlU9YEQ4OXq3SVl72T4s+TZHig DQlI40FzSCqGK6Q30uGDRe4xFkROa+sV/J8dQW8O/1kwX/D/zni7at31AbXAL7YdplNj 3cuw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=NRI1abTZJ6kicrdP+HfsjaTw1ydLJ5ZT0LGcdUiH+r8=; b=VG/fb44OaWi0AE+xD63PXWHsMoVeShYNwyWnPnnXMvZbVkGdF7Ffy6ycOVzoHaevQn 2fOhuNqH7jVpEcxHV+b1cfvAA97cIRdENFnLJD1+orvu85CKhF91kA6wZQsXurJq5K50 qlmd1WPCjXbgEwW1EWVFHFqbA/nOt//1Sw4Q0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc; bh=NRI1abTZJ6kicrdP+HfsjaTw1ydLJ5ZT0LGcdUiH+r8=; b=gAWpQfwmU6Pjh2c75svnzMb1UWwZ7vAlavKIVr3hCnC4tq1L2hDgO/CCuLk6jkSxWk A2e9JVxowPwgFnrHafcUOnTD8yi9T3vUFQxpCsGnNFRU0AZiGpGhrZqk7yx6Zul5e3mY NbSubPn3qTZkg8pbk9yMuNhY2ao8rKCd7R2wopOhjDDWU3wuUmuUZvwsdYo1YcqAcLMM lwZuiC3r5TRDcoat+bVg/nyHHo9DsM/htjAykx1hhwuO5SRNeLQAxhrxo+S9WcsBEEgG a+DljXaxR74prG/EznzVjpyRy1YvHw9/zREuw5Ku6dBFFc8WmqzvHMgGAt/qtUwJYRK8 Thmw== X-Gm-Message-State: ALKqPwd6ezdbeFefTUEVao3Mw0etasw1eOOeY/SbW7W81Y6r2WUQTUyn r2GwtJwsiJn/+hJ224T+w0zOuAGxkociUVpxeRFPDg== X-Received: by 2002:a9f:2823:: with SMTP id c32-v6mr17856477uac.193.1528206212509; Tue, 05 Jun 2018 06:43:32 -0700 (PDT) MIME-Version: 1.0 Received: by 2002:a1f:a085:0:0:0:0:0 with HTTP; Tue, 5 Jun 2018 06:43:31 -0700 (PDT) In-Reply-To: <20180605132542.GA26722@mail.hallyn.com> References: <1527616920-5415-1-git-send-email-zohar@linux.vnet.ibm.com> <1528121025.3237.116.camel@linux.vnet.ibm.com> <20180605040920.GA19747@mail.hallyn.com> <20180605132542.GA26722@mail.hallyn.com> From: Kees Cook Date: Tue, 5 Jun 2018 06:43:31 -0700 X-Google-Sender-Auth: wc_1ykMrrsOQoGNFxbVmOCx_PMw Message-ID: Subject: Re: [PATCH v4 0/8] kexec/firmware: support system wide policy requiring signatures To: "Serge E. Hallyn" Cc: Mimi Zohar , Casey Schaufler , Paul Moore , linux-integrity , linux-security-module , LKML , David Howells , "Luis R . Rodriguez" , Eric Biederman , Kexec Mailing List , Andres Rodriguez , Greg Kroah-Hartman , Ard Biesheuvel , Jessica Yu , James Morris Content-Type: text/plain; charset="UTF-8" Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Tue, Jun 5, 2018 at 6:25 AM, Serge E. Hallyn wrote: > Quoting Kees Cook (keescook@chromium.org): >> On Mon, Jun 4, 2018 at 9:09 PM, Serge E. Hallyn wrote: >> > Personally I agree with Eric and prefer a new hook. I don't feel strongly >> > enough about it to keep bikeshedding, but since this set already exists, >> > it seems like the way to go. >> >> And the new hook is "load stuff without a file descriptor"? > > Yes. Load stuff based on my own credentials not those attached > to a file. Okay, I can live with that. :) -- Kees Cook Pixel Security