Received: by 2002:ac0:aed5:0:0:0:0:0 with SMTP id t21csp6231982imb; Fri, 8 Mar 2019 12:24:00 -0800 (PST) X-Google-Smtp-Source: APXvYqyNkvUC2ORkrF9nw5vuB8AP15r/kmSh/TjSmlN8ySGMMZh1/7WhXyAvK2QUwO0hQgh4tPlf X-Received: by 2002:a63:94:: with SMTP id 142mr18409934pga.277.1552076640016; Fri, 08 Mar 2019 12:24:00 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1552076640; cv=none; d=google.com; s=arc-20160816; b=DTU2JttU3p/MKMO/Qk7gMsvuIauxnUKQaTlFVshBCevBFtWOHBSAp023/4cyH3isym 2mxOf8u5yufG0L22/FQG+eUiTZx10atvMubQdWHqkegl8HuSvHq3brqOTsp7go1zqisp dymsuuHJDhV6ITEOwmyOuyz5sHxTLnlmK7jTrgAa7p2B4JZC3vcuRZ5s9/hwRuckMrRU EW0Iy8E3AFFn9NIu6rjbmsaEAewTPz6U5gI99dfc3bAaYoXvggBqhFQfnIFIBXxaTMLn pSLWxkRmHi88MAvTIrQ7x7itBaxASbDtmDblHOESBGpSw1uwZqmJV1XRzC+PjKoV6lDa S9oA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:cc:to:subject :message-id:date:from:in-reply-to:references:mime-version :dkim-signature; bh=7kPqabAbJ+GgmrQih894fm1IROGUPdO8kPS7MzSjgwQ=; b=BsKLsPkTNjmWa28WmFd6BwCLM98d6l3pdAgNajUCdk8q1jIrI2laOH7dIWWnYs4ln2 axJrJEDIknASZ/RrjtZ9nT6OlesTNJaLnOd4n14ffVdaibznX4jt9oB9rWiuJE1NioI0 8ir4E1LfgQc5wMwWC9F2S8JnZabiGp7XsJNW5/E9RVvEeRFZVZuAd+zqz6XMOdYyAn5h L8sRb4AWM+FrPZVlKG4iuSC83zuD+O1NneqJHzWD6GHwjU0FHK9aWJrfk7xJyuHysrlm ZUpqt7dFn0W4CSVXeBJHpprGQswEVYaRpzWgImHbjmP2x+efVxDAjBj/0yf6jlz32NBS N27w== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=qcu93xVt; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id o32si8108548pld.163.2019.03.08.12.23.44; Fri, 08 Mar 2019 12:24:00 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20161025 header.b=qcu93xVt; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727097AbfCHUW7 (ORCPT + 99 others); Fri, 8 Mar 2019 15:22:59 -0500 Received: from mail-io1-f51.google.com ([209.85.166.51]:32787 "EHLO mail-io1-f51.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726981AbfCHUW7 (ORCPT ); Fri, 8 Mar 2019 15:22:59 -0500 Received: by mail-io1-f51.google.com with SMTP id b6so4278535iog.0 for ; Fri, 08 Mar 2019 12:22:58 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc:content-transfer-encoding; bh=7kPqabAbJ+GgmrQih894fm1IROGUPdO8kPS7MzSjgwQ=; b=qcu93xVtH4Qvq7lNP0Sul72S/hamhxAyYWyZiv4TjgYHxSFOQ7frztz2L7VzrcWzk3 1q5aKqt23oRc/ALmksMJHMifcGUxltqXwLAzA2DK2zYE8YLfNCDEiH5mHi+c2wWjfSCu CaGVOdMAR6Ja0c8p7beJk40+4LcoFc06VDiuhVuoCPcoyxars4ZeP6A5okHN21d92HIM DrM4SaEKZ2dgx0lXECteYSBfW4RsWPQO50thMCvBEsYpv7HCYgohKnVpIO9VWh11iA0F SX7vgPD17UTq/b0tpgYsqcNzQc+r79korDztQshdaiuYB8nTs+s/8pIov1/YcAsbqWiW tR7A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc:content-transfer-encoding; bh=7kPqabAbJ+GgmrQih894fm1IROGUPdO8kPS7MzSjgwQ=; b=TcF/XtJGXwcvYuTxtIQAUbFR+FN5NmcTQi6SrvUS5kcI7uOuCNDF1i6601dCnQXtr2 Vtm4kk8CxnOi/oQ57pweJmOCIfpVveeTy4vUXjcuO/ZgUmSOI0IDzYSvaKJgSSbQd8q/ RpB2aFLA7avQGEZn4uJuKHAz0KU8Jzh0A0Q0jJFJtHyrx/D9hHH7O4LW83k2jXZHIe3H cuqhvY1lBRQ1GjkZnYWswjic5tuY6dzwwjagauE/VKrwfo1wbRRDqjRbSRJT0RcWo4pW 2ooK4sbB764TvPNoJEWoKt34rJh75nKWZXn2y+IFIglx4IOjuZpwGGtqI5rYPLR40/Jh IR/g== X-Gm-Message-State: APjAAAU8pspEpS13VbfTOPqEjH2Fuq/fY6hh+d3ReKDd+WS9CEIqX6kW y8ldTJmOuCMqPWbj1iinZO/5/Hqpy6KQvF+o+97mjQ== X-Received: by 2002:a6b:ec19:: with SMTP id c25mr10621944ioh.169.1552076578180; Fri, 08 Mar 2019 12:22:58 -0800 (PST) MIME-Version: 1.0 References: <1542657371-7019-1-git-send-email-zohar@linux.ibm.com> <1542657371-7019-4-git-send-email-zohar@linux.ibm.com> <1551998897.31706.461.camel@linux.ibm.com> <1552052377.4134.23.camel@linux.ibm.com> <1552070598.4134.51.camel@linux.ibm.com> In-Reply-To: <1552070598.4134.51.camel@linux.ibm.com> From: Matthew Garrett Date: Fri, 8 Mar 2019 12:22:46 -0800 Message-ID: Subject: Re: [PATCH 3/3] x86/ima: retry detecting secure boot mode To: Mimi Zohar Cc: Justin Forbes , linux-integrity , LSM List , linux-efi , Linux Kernel Mailing List , David Howells , Seth Forshee , kexec@lists.infradead.org, Nayna Jain Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Fri, Mar 8, 2019 at 10:43 AM Mimi Zohar wrote: > FYI, efi_printk() works before exit_boot(), but not afterwards. The > system hangs. efi_printk() uses boot services to print, so that's not unexpected :) It would probably be sensible to return an error rather than crash, though=E2=80=A6