From mboxrd@z Thu Jan 1 00:00:00 1970 From: Eric DeVolder Subject: [RFC v1 0/8] Prototype for kexec signature verification within Xen Date: Mon, 14 Jan 2019 13:47:57 -0600 Message-ID: <1547495285-28907-1-git-send-email-eric.devolder__3844.99873403019$1547495279$gmane$org@oracle.com> Mime-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 Return-path: List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Sender: "Xen-devel" To: xen-devel@lists.xen.org Cc: daniel.kiper@oracle.com, eric.devolder@oracle.com, kexec@lists.infradead.org, boris.ostrovsky@oracle.com List-Id: xen-devel@lists.xenproject.org T24gQXByaWwgMjAsIDIwMTgsIEkgcG9zdGVkIHRvIHhlbi1kZXZlbCBhbiBSRkMgaW5xdWlyaW5n IGFib3V0CnN1cHBvcnQgZm9yIHNpZ25hdHVyZSB2ZXJpZmljYXRpb24gb2Yga2V4ZWMgd2l0aGlu IFhlbjoKCmh0dHBzOi8vbGlzdHMueGVucHJvamVjdC5vcmcvYXJjaGl2ZXMvaHRtbC94ZW4tZGV2 ZWwvMjAxOC0wNC9tc2cwMTY1NS5odG1sCgpTaW5jZSB0aGVuLCBJJ3ZlIHdvcmtlZCB0b3dhcmRz IGEgc29sdXRpb24uIEZvciB0aGUgcHVycG9zZXMgb2YKdW5kZXJzdGFuZGluZyBzaWduYXR1cmUg dmVyaWZpY2F0aW9uLCBJIGJ1aWx0IGEgc3RhbmRhbG9uZSB1dGlsaXR5IHRvCnBhcnNlIHRoZSB4 ZW4ubWIuZWZpIFBFQ09GRiBmaWxlLCBoYXNoIGl0IGNvbnRlbnRzLCBhbmQgZXh0cmFjdCBpdHMK ZGlnaXRpYWwgY2VydGlmaWNhdGUgYW5kIHBlcmZvcm0gdGhlIEF1dGhlbnRpY29kZSBzaWduYXR1 cmUKdmVyaWZpY2F0aW9uLiBPbmNlIHRoaXMgd2FzIGFsbCB3b3JraW5nLCBJIGludGVncmF0ZWQg dGhlIGZpbGVzIGludG8KWGVuLgoKSSBoYXZlIGEgd29ya2luZyBwcm90b3R5cGUsIHdoaWNoIGlu dGVncmF0ZXMgW2Vub3VnaF0gT3BlblNTTCBpbnRvClhlbiB0byBlbmFibGUga2V4ZWMgc2lnbmF0 dXJlIHZlcmlmaWNhdGlvbi4gQWxhcyBJIG5vdyBoYXZlIGRpZmZlcmVudApwcmlvcml0aWVzLCBi dXQgbXkgZW1wbG95ZXIgZGlkIGFzayB0aGF0IEkgcG9zdCB0aGlzIHNldCBvZiBjaGFuZ2VzLgpZ b3UgbWF5IGRvIHdpdGggdGhlbSBhcyB5b3Ugd2lzaC4gSSB3b3VsZCBiZSBhdmFpbGFibGUgZm9y IGNvbnN1bHRhdGlvbgpzaG91bGQgc29tZWJvZHkgd2lzaCB0byBwdXJzdWUgdGhpcyBmdXJ0aGVy LgoKQmVpbmcgYSBwcm90b3R5cGUsIGl0IGhhcyB0aGUgZm9sbG93aW5nIGtub3duLXRvLW1lIHNo b3J0Y29taW5nczoKCjE6IERvZXMgbm90IGZvbGxvd2luZyBYZW4gY29kaW5nIHN0YW5kYXJkLiBU aGVyZSBtYXkgYmUgYXJlYXMgd2hlcmUgSQpkbyBub3QgdXNlIHRoZSBtb3N0IGFwcHJvcHJpYXRl IFhlbiBzdHlsZSwgY2FsbCBvciBtYWNybywgb3IgZXJyb3IKY2hlY2tpbmcuCgoyOiBUaGUgYWRh cHRhdGlvbiBvZiBPcGVuU1NMIGludG8gWGVuIGlzIGluY29tcGxldGUuIFRoZXJlIGFyZSBhIG51 bWJlcgpvZiBzdHViIHJvdXRpbmVzIHRoYXQgaGF2ZSBub3QgYmVlbiBpbXBsZW1lbnRlZCAoYnV0 IGN1cnJlbnRseSBkbyBub3QKc2VlbSB0byBpbnRlcmZlcmUgd2l0aCB0aGUgc2lnbmF0dXJlIHZl cmlmaWNhdGlvbiBvcGVyYXRpb24pLiBTb21lCnBvc3NpYmxlIHdheXMgdG8gYWRkcmVzcyB0aGlz IGFyZToKIC0gUHJvcGVybHkgaW1wbGVtZW50IHRoZXNlIHJvdXRpbmVzCiAtIEludmVzdGlnYXRl IGZ1cnRoZXIgdGhlIE9wZW5TU0wgY29uZmlndXJ5IHRvIHNlZSBpZiB0aGVzZSBjYW4gYmUKICAg Y29uZmlndXJlZCBhd2F5IChOb3RlIHRoYXQgSSBjaG9zZSBPcGVuU1NMLTEuMS4waSBzcGVjaWZp Y2FsbHkKICAgYmVjYXVzZSB0aGF0IGlzIHdoYXQgRURLMiB1c2VzLCBhbmQgRURLMiBpcyBhcyBj bG9zZSB0byBYZW4KICAgZW1iZWRkZWQva2VybmVsIGVudmlyb25tZW50IChPdGhlcndpc2UgT3Bl blNTTCBpcyBwcmltYXJpbHkgYQogICB1c2VybGFuZCBwYWNrYWdlKSkuCiAtIEFsbCAxNTArIE9w ZW5TU0wgZmlsZXMgYXJlIGNvbXBpbGVkLWluLCBjb3VsZCBsb29rIGF0IGVsaW1pbmF0aW5nCiAg IGZpbGVzIG1hbnVhbGx5LgogLSBNYXliZSBsb29rIGF0IG5ld2VyIE9wZW5TU0wgdmVyc2lvbnMs IHdoaWNoIG1pZ2h0IGhhdmUgYWRkaXRpb25hbAogICBjb25maWd1cmFiaWxpdHk/CiAtIFBlcmhh cHMgaW5zdGVhZCB1dGlsaXplIGxpYmdjcnlwdCArIGxpYmtzYmEgaW5zdGVhZCBvZiBPcGVuU1NM LgoKMzogQSBjb25maWd1cmUgb3B0aW9uIGlzIG5lZWRlZCBmb3IgdGhlIHNpZ25hdHVyZSB2ZXJp ZmljYXRpb24uIFRoaXMKb3B0aW9uIHNob3VsZCBzaW11bHRhbmVvdXNseSBkaXNhYmxlIGtleGVj X2xvYWQgd2hpbGUgZW5hYmxpbmcKa2V4ZWNfZmlsZV9sb2FkLgoKNDogTGludXggaGFzIGluZnJh c3RydWN0dXJlIHRvIHN1cHBvcnQgbXVsdGlwbGUgZmlsZSB0eXBlcyBhcyB3ZWxsIGFzCm11bHRp cGxlIHNpZ25hdHVyZSB2ZXJpZmljYXRpb24gdGVjaG5pcXVlcy4gQnkgY29udHJhc3QsIHRoaXMg cHJvdG90eXBlCmlzIGhhcmR3aXJlZCBmb3IgUEVDT0ZGK0F1dGhlbnRpY29kZSAoRUZJKSBmb3Jt YXQuCgo1OiBMaW51eCBoYXMga2V5cmluZyBpbmZyYXN0cnVjdHVyZSB0byBzdXBwb3J0IG11bHRp cGxlIGNlcnRpZmljYXRlcy4KQ3VycmVudGx5IHRoZSBhcHByb3ByaWF0ZSByb290IGNlcnRpZmlj YXRlIHRvIHNhdGlzZnkgT3JhY2xlLXNpZ25lZApYZW4ga2VybmVsIGlzIGNvbXBpbGVkLWluLiBU aGlzIGFyZWEgYWxvbmUgd291bGQgbmVlZCBzaWduaWZpY2FudAphdHRlbnRpb24gaWYgYW55IGhv cGUgaW4gdXBzdHJlYW1pbmcgaXMgdG8gb2NjdXIuCgo1OiBUaGVyZSBpcyBwcm9iYWJseSBhIGJl dHRlciBQRUNPRkYgZGVjb2RlciB0aGFuIHRoZSBvbmUgY3VycmVudGx5IGluCnVzZS4KCjY6IENv bnZlcnQgdGhlIHVzYWdlIG9mIERMQ0wgbWFjcm9zIHRvIFhlbiBzdGFuZGFyZCBsaXN0IG9wZXJh dGlvbnMuCgo3OiBGb3IgdGhlIGluY2x1ZGUyLyB4ZW5vc3NsLmggaGVhZGVyIGZpbGUgaGFjayB0 byBmYWNpbGl0YXRlCmNvbXBpbGluZyBPcGVuU1NMIHdpdGhpbiBYZW47IHRoYXQgbmVlZHMgdG8g YmUgcmV2aXNpdGVkLiBJIGRpZAp0aGlzIHRvIGRlYWwgd2l0aCB0aGUgc3RhbmRhcmQgaGVhZGVy IGZpbGVzIHRoZSAodXNlcmxhbmQpIE9wZW5TU0wKZXhwZWN0cyBwcmVzZW50OyByYXRoZXIgdGhh biBjaGFuZ2luZyBuZWFybHkgZXZlcnkgT3BlblNTTCBzb3VyY2UKZmlsZS4KCjg6IEFuYWx5c2lz IHRvIHVuZGVyc3RhbmQgdGhlIGNvbXBpbGVkLXNpemUgaW5jcmVhc2UsIGFzIHdlbGwKYXMgdGhl IHJ1bi10aW1lIHNpemUgaW5jcmVhc2U/Cgo5OiBBIHRydWUgc2VjdXJpdHkgYXVkaXQgb24gdGhl c2UgY2hhbmdlcz8gRm9yIGV4YW1wbGUsIHRoaXMgcHJvdG90eXBlCnN0aWxsIHJlbGllcyB1cG9u IHRoZSBrZXhlYyB1c2VybGFuZCB0b29sIHRvIHByb3ZpZGUgdGhlIHB1cmdhdG9yeQpleGVjdXRh YmxlLiBGb3Igb2J2aW91cyBzZWN1cml0eSByZWFzb25zLCB0aGlzIG5lZWRzIHRvIGJlIG1pZ3Jh dGVkCndpdGhpbiBYZW4sIGFzIExpbnV4IGRvZXMgKG5vdGUgdGhhdCBpbnZvbHZlcyBzb21lIGxl dmVsIG9mIEVMRgpwYXJzaW5nIGFuZCByZWxvY2F0aW9uIHN1cHBvcnQpLgoKMTA6IExpY2Vuc2lu ZyBvZiB0aGUgdmFyaW91cyBwaWVjZXMgbWF5IGJlIHByb2JsZW1hdGljLgoKTm90ZSB0aGF0IHRo ZXJlIGlzIGEgY29ycmVzcG9uZGluZyBjaGFuZ2UgdG8ga2V4ZWMtdG9vbHMgdG8KYWxsb3cvZW5h YmxlIHRoZSBYZW4ga2V4ZWNfZmlsZV9sb2FkKCkgaHlwZXJjYWxsLiBUaG9zZSBjaGFuZ2VzCmFy ZSBub3QgcGFydCBvZiB0aGlzIGNoYW5nZSBzZXQsIGJ1dCB3aWxsIGJlIHBvc3RlZCBzZXBhcmF0 ZWx5LgoKQW55d2F5LCB0aGlzIGRvZXMgd29yaywgZm9yIG1lLgplcmljCgoKCkVyaWMgRGVWb2xk ZXIgKDgpOgogIGtleGVjOiBhZGQga2V4ZWNfZmlsZV9sb2FkIHRvIGxpYnhlbmN0cmwKICBrZXhl YzogaW1wbGVtZW50IGtleGVjX2ZpbGVfbG9hZCgpIGZvciBQRUNPRkYrQXV0aGVudGljb2RlIGZp bGVzCiAga2V4ZWM6IG5ldyBmaWxlIG9wZW5zc2wtMS4xLjBpLnBhdGNoCiAga2V4ZWM6IHhlbi9j b21tb24vTWFrZWZpbGU6IGluY2x1ZGUgYnVpbGRpbmcgb2YgT3BlblNTTAogIGtleGVjOiBjaGFu Z2VzIHRvIGZhY2lsaXRhdGUgY29tcGlsaW5nIE9wZW5TU0wgd2l0aGluIFhlbgogIGtleGVjOiBz dXBwb3J0IGZpbGVzIGZvciBQRUNPRkYgQXV0aGVudGljb2RlIHNpZ25hdHVyZSB2ZXJpZmljYXRp b24KICBrZXhlYzogWGVuIGNvbXBhdGlibGUgbWFrZWZpbGUgZm9yIE9wZW5TU0wKICBrZXhlYzog aW5jbHVkZSBPcGVuU1NMIGJ1aWxkIGluIHhlbi5zcGVjCgogTWFrZWZpbGUub3BlbnNzbC0xLjEu MGkgICAgICAgICB8ICA0ODAgKysrKysrKysrKysrKysKIG9wZW5zc2wtMS4xLjBpLnBhdGNoICAg ICAgICAgICAgfCAgMzc4ICsrKysrKysrKysrCiB0b29scy9saWJ4Yy94Y19rZXhlYy5jICAgICAg ICAgIHwgICA0MSArKwogdG9vbHMvbGlieGMveGVuY3RybC5oICAgICAgICAgICB8ICAgIDQgKwog eGVuLnNwZWMgICAgICAgICAgICAgICAgICAgICAgICB8ICAgNzggKysrCiB4ZW4vYXJjaC94ODYv UnVsZXMubWsgICAgICAgICAgIHwgICAgMiArCiB4ZW4vY29tbW9uL01ha2VmaWxlICAgICAgICAg ICAgIHwgICAgNCArCiB4ZW4vY29tbW9uL1RydXN0ZWRDZXJ0LmggICAgICAgIHwgIDExMyArKysr CiB4ZW4vY29tbW9uL2RsY2wuaCAgICAgICAgICAgICAgIHwgIDMyMyArKysrKysrKysrCiB4ZW4v Y29tbW9uL2tleGVjLmMgICAgICAgICAgICAgIHwgIDEzMSArKystCiB4ZW4vY29tbW9uL3BlY29m Zi5oICAgICAgICAgICAgIHwgIDI4MyArKysrKysrKwogeGVuL2NvbW1vbi9wZWQuYyAgICAgICAg ICAgICAgICB8ICA1NzkgKysrKysrKysrKysrKysrKysKIHhlbi9jb21tb24vcGVkLmggICAgICAg ICAgICAgICAgfCAgMTI4ICsrKysKIHhlbi9jb21tb24vdl9vcGVuc3NsLmMgICAgICAgICAgfCAx MzQ4ICsrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKysrKwogeGVuL2NvbW1vbi94 bWFsbG9jX3Rsc2YuYyAgICAgICB8ICAgMjUgKwogeGVuL2luY2x1ZGUvYXNtLXg4Ni90eXBlcy5o ICAgICB8ICAgIDIgKwogeGVuL2luY2x1ZGUvcHVibGljL2tleGVjLmggICAgICB8ICAgIDQgKy0K IHhlbi9pbmNsdWRlL3hlbi90eXBlcy5oICAgICAgICAgfCAgICAzICsKIHhlbi9pbmNsdWRlL3hl bi94bWFsbG9jLmggICAgICAgfCAgICAxICsKIHhlbi9pbmNsdWRlMi9hc3NlcnQuaCAgICAgICAg ICAgfCAgICAxICsKIHhlbi9pbmNsdWRlMi9iaXRzL3N5c2xvZy1wYXRoLmggfCAgICAxICsKIHhl bi9pbmNsdWRlMi9jdHlwZS5oICAgICAgICAgICAgfCAgICAxICsKIHhlbi9pbmNsdWRlMi9lcnJu by5oICAgICAgICAgICAgfCAgICAxICsKIHhlbi9pbmNsdWRlMi9mZWF0dXJlcy5oICAgICAgICAg fCAgICAxICsKIHhlbi9pbmNsdWRlMi9pbnR0eXBlcy5oICAgICAgICAgfCAgICAxICsKIHhlbi9p bmNsdWRlMi9saW1pdHMuaCAgICAgICAgICAgfCAgICAxICsKIHhlbi9pbmNsdWRlMi9tZW1vcnku aCAgICAgICAgICAgfCAgICAxICsKIHhlbi9pbmNsdWRlMi9zdGRhcmcuaCAgICAgICAgICAgfCAg ICAxICsKIHhlbi9pbmNsdWRlMi9zdGRkZWYuaCAgICAgICAgICAgfCAgICAxICsKIHhlbi9pbmNs dWRlMi9zdGRpbnQuaCAgICAgICAgICAgfCAgICAxICsKIHhlbi9pbmNsdWRlMi9zdGRpby5oICAg ICAgICAgICAgfCAgICAxICsKIHhlbi9pbmNsdWRlMi9zdGRsaWIuaCAgICAgICAgICAgfCAgICAx ICsKIHhlbi9pbmNsdWRlMi9zdHJpbmcuaCAgICAgICAgICAgfCAgICAxICsKIHhlbi9pbmNsdWRl Mi9zdHJpbmdzLmggICAgICAgICAgfCAgICAxICsKIHhlbi9pbmNsdWRlMi9zeXMvdGltZS5oICAg ICAgICAgfCAgICAxICsKIHhlbi9pbmNsdWRlMi9zeXMvdHlwZXMuaCAgICAgICAgfCAgICAxICsK IHhlbi9pbmNsdWRlMi9zeXNsb2cuaCAgICAgICAgICAgfCAgICAxICsKIHhlbi9pbmNsdWRlMi90 aW1lLmggICAgICAgICAgICAgfCAgICAxICsKIHhlbi9pbmNsdWRlMi91bmlzdGQuaCAgICAgICAg ICAgfCAgICAxICsKIHhlbi9pbmNsdWRlMi94ZW5vc3NsLmggICAgICAgICAgfCAgMTMwICsrKysK IDQwIGZpbGVzIGNoYW5nZWQsIDQwNzQgaW5zZXJ0aW9ucygrKSwgMyBkZWxldGlvbnMoLSkKIGNy ZWF0ZSBtb2RlIDEwMDY0NCBNYWtlZmlsZS5vcGVuc3NsLTEuMS4waQogY3JlYXRlIG1vZGUgMTAw NjQ0IG9wZW5zc2wtMS4xLjBpLnBhdGNoCiBjcmVhdGUgbW9kZSAxMDA2NDQgeGVuL2NvbW1vbi9U cnVzdGVkQ2VydC5oCiBjcmVhdGUgbW9kZSAxMDA3NTUgeGVuL2NvbW1vbi9kbGNsLmgKIGNyZWF0 ZSBtb2RlIDEwMDY0NCB4ZW4vY29tbW9uL3BlY29mZi5oCiBjcmVhdGUgbW9kZSAxMDA2NDQgeGVu L2NvbW1vbi9wZWQuYwogY3JlYXRlIG1vZGUgMTAwNjQ0IHhlbi9jb21tb24vcGVkLmgKIGNyZWF0 ZSBtb2RlIDEwMDY0NCB4ZW4vY29tbW9uL3Zfb3BlbnNzbC5jCiBjcmVhdGUgbW9kZSAxMDA2NDQg eGVuL2luY2x1ZGUyL2Fzc2VydC5oCiBjcmVhdGUgbW9kZSAxMDA2NDQgeGVuL2luY2x1ZGUyL2Jp dHMvc3lzbG9nLXBhdGguaAogY3JlYXRlIG1vZGUgMTAwNjQ0IHhlbi9pbmNsdWRlMi9jdHlwZS5o CiBjcmVhdGUgbW9kZSAxMDA2NDQgeGVuL2luY2x1ZGUyL2Vycm5vLmgKIGNyZWF0ZSBtb2RlIDEw MDY0NCB4ZW4vaW5jbHVkZTIvZmVhdHVyZXMuaAogY3JlYXRlIG1vZGUgMTAwNjQ0IHhlbi9pbmNs dWRlMi9pbnR0eXBlcy5oCiBjcmVhdGUgbW9kZSAxMDA2NDQgeGVuL2luY2x1ZGUyL2xpbWl0cy5o CiBjcmVhdGUgbW9kZSAxMDA2NDQgeGVuL2luY2x1ZGUyL21lbW9yeS5oCiBjcmVhdGUgbW9kZSAx MDA2NDQgeGVuL2luY2x1ZGUyL3N0ZGFyZy5oCiBjcmVhdGUgbW9kZSAxMDA2NDQgeGVuL2luY2x1 ZGUyL3N0ZGRlZi5oCiBjcmVhdGUgbW9kZSAxMDA2NDQgeGVuL2luY2x1ZGUyL3N0ZGludC5oCiBj cmVhdGUgbW9kZSAxMDA2NDQgeGVuL2luY2x1ZGUyL3N0ZGlvLmgKIGNyZWF0ZSBtb2RlIDEwMDY0 NCB4ZW4vaW5jbHVkZTIvc3RkbGliLmgKIGNyZWF0ZSBtb2RlIDEwMDY0NCB4ZW4vaW5jbHVkZTIv c3RyaW5nLmgKIGNyZWF0ZSBtb2RlIDEwMDY0NCB4ZW4vaW5jbHVkZTIvc3RyaW5ncy5oCiBjcmVh dGUgbW9kZSAxMDA2NDQgeGVuL2luY2x1ZGUyL3N5cy90aW1lLmgKIGNyZWF0ZSBtb2RlIDEwMDY0 NCB4ZW4vaW5jbHVkZTIvc3lzL3R5cGVzLmgKIGNyZWF0ZSBtb2RlIDEwMDY0NCB4ZW4vaW5jbHVk ZTIvc3lzbG9nLmgKIGNyZWF0ZSBtb2RlIDEwMDY0NCB4ZW4vaW5jbHVkZTIvdGltZS5oCiBjcmVh dGUgbW9kZSAxMDA2NDQgeGVuL2luY2x1ZGUyL3VuaXN0ZC5oCiBjcmVhdGUgbW9kZSAxMDA2NDQg eGVuL2luY2x1ZGUyL3hlbm9zc2wuaAoKLS0gCjIuNy40CgoKX19fX19fX19fX19fX19fX19fX19f X19fX19fX19fX19fX19fX19fX19fX19fX18KWGVuLWRldmVsIG1haWxpbmcgbGlzdApYZW4tZGV2 ZWxAbGlzdHMueGVucHJvamVjdC5vcmcKaHR0cHM6Ly9saXN0cy54ZW5wcm9qZWN0Lm9yZy9tYWls bWFuL2xpc3RpbmZvL3hlbi1kZXZlbA==