Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 006DCC64ED6 for ; Sun, 26 Feb 2023 04:29:24 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229587AbjBZE3X (ORCPT ); Sat, 25 Feb 2023 23:29:23 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:54020 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229445AbjBZE3T (ORCPT ); Sat, 25 Feb 2023 23:29:19 -0500 Received: from todd.t-8ch.de (todd.t-8ch.de [IPv6:2a01:4f8:c010:41de::1]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 6AD1B2739; Sat, 25 Feb 2023 20:29:17 -0800 (PST) Date: Sat, 25 Feb 2023 22:28:56 -0600 (CST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=t-8ch.de; s=mail; t=1677385754; bh=yl/hlBinxDM5IGBWq7H2QzpdT6RFq3YQQHzeNxTBwhs=; h=Date:From:To:Cc:In-Reply-To:References:Subject:From; b=RvzQgNqjnaN+g4plpsbTMU5pBDfx0cdS1dMN0hYUB2DMwOuyZmr8wteJx6amX6jdZ VVrr1q5qCEvTYWzAH4lZWKGkFSdY2xqggR9AxzpE/WrtegXagd6D2VC6PRS9M5ym6j 2rdVnEQWxOp7bjjmHjL9Zt4+/9L7+gTUwuDTY0q0= From: =?UTF-8?Q?Thomas_Wei=C3=9Fschuh_?= To: Jeremy Kerr Cc: Mark Pearson , =?UTF-8?Q?Micka=C3=ABl_Sala=C3=BCn?= , Jarkko Sakkinen , David Howells , David Woodhouse , keyrings@vger.kernel.org, linux-kernel@vger.kernel.org, linux-security-module , linux-integrity@vger.kernel.org Message-ID: <860048ca-d827-4319-9755-9b44ba3c4157@t-8ch.de> In-Reply-To: References: <632d2180-02f8-4a5f-803a-57a6443a60f4@t-8ch.de> <12ceffb8-4e90-4eb5-2110-a0e69b412cea@lenovo.com> Subject: Re: [External] Re: [BUG] blacklist: Problem blacklisting hash (-13) during boot MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Correlation-ID: <860048ca-d827-4319-9755-9b44ba3c4157@t-8ch.de> Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hi, Feb 25, 2023 21:42:54 Jeremy Kerr : > Hi Mark, > >> I have flagged this to the FW team (LO-2105) to get their feedback >> and see if we can get it addressed on our platforms. > > Any progress from the FW team about this? I have a fresh-out-of-the-box > T14s with this issue, there's 33 duplicated hashes in dbx: > > $ mokutil --dbx | grep -E '[[:xdigit:]]{64}' | sort | uniq -cd > [...] > > - and so generating 33 KERN_ERR messages on boot. > > Given there's (at least) a few months' worth of GA machines with this > issue, can we suppress the warning? In 6.3 this message will be downgraded to a warning. https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c95e8f6fd157b45ef0685c221931561e943e82da A fixed firmware is still desirable, though. Thomas