Received: by 2002:a05:6359:c8b:b0:c7:702f:21d4 with SMTP id go11csp538142rwb; Tue, 4 Oct 2022 07:25:38 -0700 (PDT) X-Google-Smtp-Source: AMsMyM6huMc4SjydCz4xdohjX7wncJAiQR5YN+9cRERV+xiLh8x4F80VoSo1rpusATa9+STqIWh2 X-Received: by 2002:a17:907:a0e:b0:780:72bb:5ce4 with SMTP id bb14-20020a1709070a0e00b0078072bb5ce4mr19945989ejc.234.1664893538118; Tue, 04 Oct 2022 07:25:38 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1664893538; cv=none; d=google.com; s=arc-20160816; b=iVRwPBlNeyarxuH6cd9/TP4m/p4ltZm4JU1Jqd1RNCQ0pbR6+rRDMdwSXqAUP1FcUi n/zLtgudY0MrR1rNZ+SxvPHGgE3yfm3vkOjRoj7w29DB9Oig71/ltHq/dAHpA2+aPQks X+SieQVb62rFjVn0HzuePSwVpvJR9vDpRxafxM4feGkfdwEuY4PqA8maQ/+cw1Mh3FSV DdNCidpC/RrpT7++qW0o++ecpLTYYPfdNPEZcW+4WOkorz3giiwUQuYDjIof6aj3AWk3 2Cqt1fFqXsq1nZgA5dTWOdCxrbF/JTIIDYlASB6830Hrz6XGdfWv+Qk6Yw7FHSA7MJeA Uh/A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version:date :message-id:subject:references:in-reply-to:cc:to:from; bh=QTdEQbxWjJYoM2oj/aOEdYdJcl6QiFAjbMEKFMpBC20=; b=BBgjZ+Tymv3jat7ranwXuYl9Ktobjia+EVnw/YE36Iz88foawsMmOL/drFTH0JgTI5 kAmRoYcdeVKGzP4kzHEQ8QplZH05gWYK1oo2iMJ+XTxb3KuG0ZHiMw8KOOlMb1Cvj+aU 8RfxZzQrUGHuw4lCwU1dqonT5i597jAqV5LFBtd0x8BdoysTaga3+zqqdnAgdZRbGEaN LwzGssAXkQk+0cm4zJ+EvTi60UZIq8ubSGvWCQUKc+vW5c1mgHYklH7dcR3icxLgeXfV q9mjJhWVAu46IyunMQ0PwgIxrxQP89CHvNvA2GbGnBFomxtLhxYtU7U2donfNuxvg7dV rwWw== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id gn41-20020a1709070d2900b0077cb9bc7918si10966918ejc.30.2022.10.04.07.25.12; Tue, 04 Oct 2022 07:25:38 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S230160AbiJDNjm (ORCPT + 99 others); Tue, 4 Oct 2022 09:39:42 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:55960 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229621AbiJDNjQ (ORCPT ); Tue, 4 Oct 2022 09:39:16 -0400 Received: from gandalf.ozlabs.org (gandalf.ozlabs.org [150.107.74.76]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 9640A564F0; Tue, 4 Oct 2022 06:39:07 -0700 (PDT) Received: from authenticated.ozlabs.org (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail.ozlabs.org (Postfix) with ESMTPSA id 4Mhf1h2yB1z4xHW; Wed, 5 Oct 2022 00:39:04 +1100 (AEDT) From: Michael Ellerman To: Nathan Lynch , linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, linuxppc-dev@lists.ozlabs.org Cc: nayna@linux.ibm.com, jmorris@namei.org, paul@paul-moore.com, ajd@linux.ibm.com, serge@hallyn.com, gcwilson@linux.ibm.com, mpe@ellerman.id.au In-Reply-To: <20220926131643.146502-1-nathanl@linux.ibm.com> References: <20220926131643.146502-1-nathanl@linux.ibm.com> Subject: Re: [PATCH v2 0/2] powerpc/pseries: restrict error injection and DT changes when locked down Message-Id: <166488995179.779920.16022330580724234832.b4-ty@ellerman.id.au> Date: Wed, 05 Oct 2022 00:25:51 +1100 MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 8bit X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,SPF_HELO_PASS, SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, 26 Sep 2022 08:16:41 -0500, Nathan Lynch wrote: > Add two new lockdown reasons for use in powerpc's pseries platform > code. > > The pseries platform allows hardware-level error injection via certain > calls to the RTAS (Run Time Abstraction Services) firmware. ACPI-based > error injection is already restricted in lockdown; this facility > should be restricted for the same reasons. > > [...] Applied to powerpc/next. [1/2] powerpc/pseries: block untrusted device tree changes when locked down https://git.kernel.org/powerpc/c/99df7a2810b6d24651d4887ab61a142e042fb235 [2/2] powerpc/rtas: block error injection when locked down https://git.kernel.org/powerpc/c/b8f3e48834fe8c86b4f21739c6effd160e2c2c19 cheers