Received: by 2002:a05:6a10:413:0:0:0:0 with SMTP id 19csp2265531pxp; Mon, 21 Mar 2022 15:20:54 -0700 (PDT) X-Google-Smtp-Source: ABdhPJzMwd1AYTmPy8w0iWOqhsVrzpVt57r5+7x3SXmxnVn4ms+SiOW2y64cd9XMMmb16DYb5zyJ X-Received: by 2002:a05:6a00:421a:b0:4fa:9396:638f with SMTP id cd26-20020a056a00421a00b004fa9396638fmr9386430pfb.63.1647901254168; Mon, 21 Mar 2022 15:20:54 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1647901254; cv=none; d=google.com; s=arc-20160816; b=h469vxIO5vU+61RGcWAuGsf/x1fEMsrLWpliFQnheCk97CRQNiHkNhm/hjJbyrR7sd jw2bq/5qiJTSfjJ318Y3Dy/OLvpIxCiMuywQqD3ufn9IjLBxZSGFSAGI6z4o5KcQ8Ppm aC8NNsOGD4nsNe0TIsha9GQ3Jl5ghZhDpLgJtGnuk5Mwkm/Afi8cA70OvyrdXn1h5bAG qtVFAWPZGb523Tv13wWropbkTHQeliMkqWm9SMMSKm4ymLULsGZm8dzA2fNAxO3RTRfR aDfSCTVvMrHCOBry23C86gGxvv0wVO1x1HP01GXUCmcw4bgx2xChBAmsjStcrwp0wkhF fskA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-transfer-encoding :content-disposition:mime-version:references:message-id:subject:cc :to:from:date:dkim-signature; bh=mCa2JuGs2d0YCs4Pa0r1nyCQX1MKfvWzvi9fVwxh1Wg=; b=RM3WpRAr5RaSyNyNwDbG3+LENgH06ow/cjNBM1qMXhUiij9dEGPV36gxmE+UIo4aYe rFxCE5G6NDKmI5rHMpz4ni2bVCBiGut6Joar7IgA16NQUD5ES+uWeSIq5HUnsdET73t3 HNV4IHuURowt5I/LHPzl3EJWFDnGQZVH8iiBS2uTkC+XfntzTb5yPHEG96SxcEQWHcea Ufo+t7e7c7LhUtPtYJE/Y7ipOdVJCKllLg6RhQND6266/cMHaLzuX2cMhI1Va8Xry08W ejh0rTFI3AywxnhMcbN5Q2njlhMP323tQNa/lJaB5iRaM31uVFS236N870fDZptCDGf3 ULrw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=p3XF6opL; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from lindbergh.monkeyblade.net (lindbergh.monkeyblade.net. [2620:137:e000::1:18]) by mx.google.com with ESMTPS id y4-20020a170902ed4400b00153b2d16434si11525825plb.60.2022.03.21.15.20.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 21 Mar 2022 15:20:54 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:18 as permitted sender) client-ip=2620:137:e000::1:18; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=p3XF6opL; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by lindbergh.monkeyblade.net (Postfix) with ESMTP id E5C0D3878CC; Mon, 21 Mar 2022 14:37:33 -0700 (PDT) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1343745AbiCTVbq (ORCPT + 99 others); Sun, 20 Mar 2022 17:31:46 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:57194 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S236574AbiCTVbp (ORCPT ); Sun, 20 Mar 2022 17:31:45 -0400 Received: from ams.source.kernel.org (ams.source.kernel.org [145.40.68.75]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 30B233819D; Sun, 20 Mar 2022 14:30:21 -0700 (PDT) Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ams.source.kernel.org (Postfix) with ESMTPS id CEF69B80EFA; Sun, 20 Mar 2022 21:30:19 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 996A3C340E9; Sun, 20 Mar 2022 21:30:17 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1647811818; bh=tTXsRvXcOgBE9bkryBEz2qKjZqFOG8apagVn9U/uti0=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=p3XF6opLAITbuzC6qPWYfipEKm/uQr/7rBFwWLFBwnrqPVlc4t1suLbbQU3nDKoQz Vt/UhFCvJs8KCgIq+j9X68rMLv48PO5LS8XUDHxEPCRFoK/q3pqFpKnCmRdzv1TwSY rgFf3mCujGbriNThhNRY/4yE8Obdxg4MBzEEQHbzFJ366yxzohQnnQqbhFzxziYfFN 5jle4eIxmZtag+2HXRCLHQ7D/4b9u1p8Jck87YEYb+cunlYAn1R2HCKkCUN/ftVyLL k/gAnAma91++7ccEszyF0PvfCuinT1joWPi7wpyoJf+7xQHOUWeBucleeQyAfhlW7F W178jPJ4zAWRg== Date: Sun, 20 Mar 2022 23:31:19 +0200 From: Jarkko Sakkinen To: Nayna Cc: Nageswara Sastry , Nayna Jain , linux-integrity@vger.kernel.org, keyrings@vger.kernel.org, dhowells@redhat.com, zohar@linux.ibm.com, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, dimitri.ledkov@canonical.com, seth@forshee.me, Masahiro Yamada Subject: Re: [PATCH v11 0/4] integrity: support including firmware ".platform" keys at build time Message-ID: References: <20220310214450.676505-1-nayna@linux.ibm.com> <4afae87c-2986-6b0e-07be-954dd4937afd@linux.ibm.com> <57d7034a-fb5c-444e-a709-4f993459688e@linux.vnet.ibm.com> MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <57d7034a-fb5c-444e-a709-4f993459688e@linux.vnet.ibm.com> X-Spam-Status: No, score=-3.5 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,MAILING_LIST_MULTI, RDNS_NONE,SPF_HELO_NONE,T_SCC_BODY_TEXT_LINE autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Fri, Mar 18, 2022 at 05:25:07PM -0400, Nayna wrote: > > On 3/17/22 03:38, Jarkko Sakkinen wrote: > > On Fri, Mar 11, 2022 at 04:03:12PM -0500, Nayna wrote: > > > On 3/11/22 11:42, Jarkko Sakkinen wrote: > > > > ".platform" keyring. > > > > > > Changelog: > > > > > > v11: > > > > > > * Added a new patch to conditionally build extract-cert if > > > > > > PLATFORM_KEYRING is enabled. > > > > > > > > > > > Tested the following four patches with and with out setting > > > > > CONFIG_INTEGRITY_PLATFORM_KEYS > > > > > > > > > > Tested-by: Nageswara R Sastry > > > > OK, I added it: > > > > > > > > git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd.git > > > Thanks Jarkko. Masahiro Yamada would prefer to revert the original commit > > > 340a02535ee785c64c62a9c45706597a0139e972 i.e. move extract-cert back to the > > > scripts/ directory. > > > > > > I am just posting v12 which includes Masahiro feedback. Nageswara has > > > already tested v12 version as well. > > > > > > I am fine either way 1.) Adding v11 and then separately handling of > > > reverting of the commit or 2.) Adding v12 version which includes the revert. > > > I leave the decision on you as to which one to upstream. > > > > > > Thanks & Regards, > > > > > > ??? - Nayna > > > > > I already sent PR for v5.18. Too many late changes to include this, which > > means that v12 is the way to go. > > Assuming v12 looks good, could you please queue it now ? > > Thanks & Regards, > > ??? - Nayna > Unfortunately, I've already sent my v5.18 PR over a week ago. I can put it to my queue but I think it is lacking some of the tested by tags, doesn't it? BR, Jarkko