Received: by 2002:a25:f815:0:0:0:0:0 with SMTP id u21csp2484580ybd; Mon, 24 Jun 2019 07:14:21 -0700 (PDT) X-Google-Smtp-Source: APXvYqx0r2KB+OpPul2xIZ1CWE5hpKDs4yYAPJsx7FCvcGm1ZssuNUrEHjD4vIYS+5SUZDOxG7Zn X-Received: by 2002:a17:902:31c3:: with SMTP id x61mr32513434plb.331.1561385661664; Mon, 24 Jun 2019 07:14:21 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1561385661; cv=none; d=google.com; s=arc-20160816; b=fBsy5OuPtcM/Q8ulx9BoS0qkNx6Pd64SCeOEhSoHHcegYhUQw0pnKU27vq8HCG7TS7 u5qcIpk8uQI+L55XUc4VScsiZMdwPuSQXBwRgBKTNxZJMZ817vGyRJynx3N4HByPoknZ mMg8Ys2tKM9uJADyV/eFCBsgtL9Uz6pss92RoeikGPNb9tZVHkOhs47urOO5+2MEzn4f V1cmBgcYQnlTGU1jhE4o3vhMFPaZDfSCrphQgWP8SFBKf0bsHRy6A8z9u9GWTJokScqE Q8xfQGZLoPuZYJdN6b5Xh+SQs+Ll1X2m9JSQvgKgB8lLlRzhcNocoASsD0+ZyB11/3Cn RM7Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:user-agent:references :message-id:in-reply-to:subject:cc:to:from:date:dkim-signature; bh=asHwNepGZCX0jdLSyxbrvpfpvY09RdiQes8ZpK4ah0E=; b=Lm4WD3/szIg/ua6GB42SvNjRKVjrcc1lgAHeoJIvslEVEE5HE5okmTVE5S7OQoUuQ+ wGOxMdBVxFASu7x6qUrjf9uH1WDAAs7Ucr1Nf4mcfUDXyxAeglVbb8w44qlffUxXmkRN 9SI1Kmbf1Vua5zRlsJuSMaCrxgJbTsUWp+TCn06wCdLqXUPGIYWAxldLvVYHkB2/k5pn yaJaLoFVq8lE/YdvZujRHO0FOjfSQWbilZTeJcXiMjoDCQT1nI5aEOqxg0H6BohcDDyj 1cO7HwN9tTD+5hrJ4jJYKefXX/U8do0YDpGsYs7taNW+lb3LB9+tgh86fefnRX6XFgg7 eDXw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=g8JlED+0; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id d18si11156591pfn.202.2019.06.24.07.14.04; Mon, 24 Jun 2019 07:14:21 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=g8JlED+0; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727912AbfFXNV3 (ORCPT + 99 others); Mon, 24 Jun 2019 09:21:29 -0400 Received: from mail.kernel.org ([198.145.29.99]:55214 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726773AbfFXNV3 (ORCPT ); Mon, 24 Jun 2019 09:21:29 -0400 Received: from pobox.suse.cz (prg-ext-pat.suse.com [213.151.95.130]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id 4916120820; Mon, 24 Jun 2019 13:21:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1561382488; bh=WAE1HR6hUH9xAcKn4xMqspK9ebAd/XkgtM/HqIgBdiw=; h=Date:From:To:cc:Subject:In-Reply-To:References:From; b=g8JlED+0oqILB6Ch8fwGlZ6lFtDGij9D2xNScUPrTW24XcjIZqN3PWDME2nCrPQHj jTfTQ37BG6gJhCI9mC4lB2ztn87SlhnIA3MIoPJGVfHXgFuhP36lfNf9D97jvgEAk9 ha9OKapyPhY/qyD9EJbEttZLSeYCwIXergjN8nUQ= Date: Mon, 24 Jun 2019 15:21:23 +0200 (CEST) From: Jiri Kosina To: Pavel Machek cc: Matthew Garrett , jmorris@namei.org, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, linux-api@vger.kernel.org, Josh Boyer , David Howells , Matthew Garrett , rjw@rjwysocki.net, Joey Lee , linux-pm@vger.kernel.org Subject: Re: [PATCH V34 10/29] hibernate: Disable when the kernel is locked down In-Reply-To: <20190622175208.GB30317@amd> Message-ID: References: <20190622000358.19895-1-matthewgarrett@google.com> <20190622000358.19895-11-matthewgarrett@google.com> <20190622175208.GB30317@amd> User-Agent: Alpine 2.21 (LSU 202 2017-01-01) MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Sat, 22 Jun 2019, Pavel Machek wrote: > > There is currently no way to verify the resume image when returning > > from hibernate. This might compromise the signed modules trust model, > > so until we can work with signed hibernate images we disable it when the > > kernel is locked down. > > I keep getting these... > > IIRC suse has patches to verify the images. Yeah, Joey Lee is taking care of those. CCing. -- Jiri Kosina SUSE Labs