Received: by 2002:ac0:a5b6:0:0:0:0:0 with SMTP id m51-v6csp957881imm; Tue, 5 Jun 2018 07:07:16 -0700 (PDT) X-Google-Smtp-Source: ADUXVKItq/J1n93i0UHqPhgSqkhXApyI3c/CjxN+2fKZpJU1j5AFNQBwlFeedQmK+kaE2TqNE2/R X-Received: by 2002:a62:2414:: with SMTP id r20-v6mr17599986pfj.108.1528207636902; Tue, 05 Jun 2018 07:07:16 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1528207636; cv=none; d=google.com; s=arc-20160816; b=odeEc/W+Fy99eBqOX+x9qFnhfobV7dH4q6z5S3vim5kfRLWFer0gO/e2SiSPxOMTKV A9AvYL5ruXKDz5giqX9HXI+4R250vqzlixaqfKhosih8993jtCpkFKYlb8eleJ+gQvUK oEzULWOy7cCK+AwQQJWFjUUXi89QoAfE5lAy67E/3zCW9hXrfCs+/Ea03TI4hRj4msAf mbLytr98t74IgHOel2DcV3PZYtlKAPm0gyShJeZO7e9IWTn3f7sBSK4tZic7gCbwcb/p HtFrqrk5FJllJVGdc4uOHXwzOiyYyChMpFYhUQEoioYdiQ3qdscF9+/LqRzNbl/3cHg9 szuQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:message-id:content-transfer-encoding :mime-version:references:in-reply-to:date:cc:to:from:subject :arc-authentication-results; bh=6j3wEEnkZ6i0hKvz1KZdlXVn7nA5KiKeu57+mUlF2bI=; b=P3W49vjbMqIkPRZU6wJhW2wtUAM3VPNfkPBvvx8UD+HhV0quD7VPBtDPnIcKEDJfH2 VW8zGWVYP+Ubz/CzZNdR5FEmQPAxgSWJtlvSpyri6mqmsEI/P5Q68j3GZ6wLzXUGFgSz Gbm9+pV13FycM947gqsRuK4PBliIHCxm2zBVB5uaaSWNcMB3KEbIRZNspjmGdlWM7OEx WxaecBo5n3BiFqeTyvVGP+Q4zaPojTsLdfQzjZbcpZbY+Lv0sHPxwmVIDeqX7htVeJHx i04byi5uLwFzbLs0AC5zgulzZRboeAp3Tikao0PPioE/jXRiIvwFNyVNAPdM4FgsazmU sVTg== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=ibm.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id p12-v6si31300479pll.142.2018.06.05.07.07.02; Tue, 05 Jun 2018 07:07:16 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=ibm.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752162AbeFEOGN (ORCPT + 99 others); Tue, 5 Jun 2018 10:06:13 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]:36384 "EHLO mx0a-001b2d01.pphosted.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751912AbeFEOGM (ORCPT ); Tue, 5 Jun 2018 10:06:12 -0400 Received: from pps.filterd (m0098393.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.16.0.22/8.16.0.22) with SMTP id w55E00Rd117495 for ; Tue, 5 Jun 2018 10:06:12 -0400 Received: from e06smtp05.uk.ibm.com (e06smtp05.uk.ibm.com [195.75.94.101]) by mx0a-001b2d01.pphosted.com with ESMTP id 2jdsxepe81-1 (version=TLSv1.2 cipher=AES256-GCM-SHA384 bits=256 verify=NOT) for ; Tue, 05 Jun 2018 10:06:11 -0400 Received: from localhost by e06smtp05.uk.ibm.com with IBM ESMTP SMTP Gateway: Authorized Use Only! Violators will be prosecuted for from ; Tue, 5 Jun 2018 15:06:08 +0100 Received: from b06cxnps4075.portsmouth.uk.ibm.com (9.149.109.197) by e06smtp05.uk.ibm.com (192.168.101.135) with IBM ESMTP SMTP Gateway: Authorized Use Only! Violators will be prosecuted; (version=TLSv1/SSLv3 cipher=AES256-GCM-SHA384 bits=256/256) Tue, 5 Jun 2018 15:06:03 +0100 Received: from d06av26.portsmouth.uk.ibm.com (d06av26.portsmouth.uk.ibm.com [9.149.105.62]) by b06cxnps4075.portsmouth.uk.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id w55E62Yc27328598 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=FAIL); Tue, 5 Jun 2018 14:06:02 GMT Received: from d06av26.portsmouth.uk.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 1E033AE053; Tue, 5 Jun 2018 14:55:02 +0100 (BST) Received: from d06av26.portsmouth.uk.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 274A2AE045; Tue, 5 Jun 2018 14:55:00 +0100 (BST) Received: from localhost.localdomain (unknown [9.80.107.39]) by d06av26.portsmouth.uk.ibm.com (Postfix) with ESMTP; Tue, 5 Jun 2018 14:55:00 +0100 (BST) Subject: Re: [PATCH v4 0/8] kexec/firmware: support system wide policy requiring signatures From: Mimi Zohar To: Kees Cook , "Serge E. Hallyn" Cc: Casey Schaufler , Paul Moore , linux-integrity , linux-security-module , LKML , David Howells , "Luis R . Rodriguez" , Eric Biederman , Kexec Mailing List , Andres Rodriguez , Greg Kroah-Hartman , Ard Biesheuvel , Jessica Yu , James Morris Date: Tue, 05 Jun 2018 10:05:49 -0400 In-Reply-To: References: <1527616920-5415-1-git-send-email-zohar@linux.vnet.ibm.com> <1528121025.3237.116.camel@linux.vnet.ibm.com> <20180605040920.GA19747@mail.hallyn.com> <20180605132542.GA26722@mail.hallyn.com> Content-Type: text/plain; charset="UTF-8" X-Mailer: Evolution 3.20.5 (3.20.5-1.fc24) Mime-Version: 1.0 Content-Transfer-Encoding: 7bit X-TM-AS-GCONF: 00 x-cbid: 18060514-0020-0000-0000-0000029762C6 X-IBM-AV-DETECTION: SAVI=unused REMOTE=unused XFE=unused x-cbparentid: 18060514-0021-0000-0000-000020E36A06 Message-Id: <1528207549.3237.149.camel@linux.vnet.ibm.com> X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:,, definitions=2018-06-05_05:,, signatures=0 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 suspectscore=0 malwarescore=0 phishscore=0 bulkscore=0 spamscore=0 mlxscore=0 lowpriorityscore=0 mlxlogscore=990 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1805220000 definitions=main-1806050162 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Tue, 2018-06-05 at 06:43 -0700, Kees Cook wrote: > On Tue, Jun 5, 2018 at 6:25 AM, Serge E. Hallyn wrote: > > Quoting Kees Cook (keescook@chromium.org): > >> On Mon, Jun 4, 2018 at 9:09 PM, Serge E. Hallyn wrote: > >> > Personally I agree with Eric and prefer a new hook. I don't feel strongly > >> > enough about it to keep bikeshedding, but since this set already exists, > >> > it seems like the way to go. > >> > >> And the new hook is "load stuff without a file descriptor"? > > > > Yes. Load stuff based on my own credentials not those attached > > to a file. > > Okay, I can live with that. :) Can I get your Ack on the loadpin changes in v4a patch 8/8? Mimi