LWN.net Logo

Re: [PATCH 07/11] kexec: Disable in a secure boot environment

From:  Matthew Garrett <mjg59-AT-srcf.ucam.org>
To:  "Eric W. Biederman" <ebiederm-AT-xmission.com>
Subject:  Re: [PATCH 07/11] kexec: Disable in a secure boot environment
Date:  Wed, 5 Sep 2012 08:03:22 +0100
Message-ID:  <20120905070322.GA8014@srcf.ucam.org>
Cc:  linux-kernel-AT-vger.kernel.org, linux-security-module-AT-vger.kernel.org, linux-efi-AT-vger.kernel.org
Archive-link:  Article, Thread

On Wed, Sep 05, 2012 at 12:00:31AM -0700, Eric W. Biederman wrote:
> Matthew Garrett <mjg59@srcf.ucam.org> writes:
> > Fine. We'll just carry this one out of tree for now.
> 
> It is your tree.
> 
> I am disappointed to learn that you aren't enthusiastic about
> implementing verification of signatures for all code that goes into
> ring 0.

I am enthusiastic, but October 26th is a date outside my control and 
kexec isn't at the top of the priority list. We ship with the code we 
have, not the code we want.

-- 
Matthew Garrett | mjg59@srcf.ucam.org
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html



(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds