From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from list by lists.gnu.org with archive (Exim 4.90_1) id 1oRcjX-0006FH-36 for mharc-grub-devel@gnu.org; Fri, 26 Aug 2022 13:03:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:50262) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1oRcjM-0006Dh-IX for grub-devel@gnu.org; Fri, 26 Aug 2022 13:02:55 -0400 Received: from mail-ed1-x52c.google.com ([2a00:1450:4864:20::52c]:37579) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1oRcjK-0007eM-LQ for grub-devel@gnu.org; Fri, 26 Aug 2022 13:02:52 -0400 Received: by mail-ed1-x52c.google.com with SMTP id b16so2849643edd.4 for ; Fri, 26 Aug 2022 10:02:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc; bh=csQq6ppAXjFXxUHZsIs/vFXpbjpmWsnzbLlbojDWnI8=; b=TAH3ByzMx+6djRAlEtc/wvR5zh980MKE/kasMUkmc395Y1S3G/Y7Zz/tnlvn4mQHIp FUOhRvtbAs23gBmb2J8ZXoAi84GjMHan/aiFWEfyLAIuHapJcMEF2a3MfNakuJVhkq7l 95eWG1JWdy2w/0F9L5z2k9g01ULK8vON3FNS/9xQfzCe9Ew8Me94YDt9vlHjbVTzH+BB nJc8sZNCnot6Ledt4azTNiqmJtY62hJ5jRwssTB9pc26mzRUJTy8WdRNMSFEUheNJ7PE 9UYNkxL/IYBRcfxpx+U17Lqm/6Gj7tlB8XKUIUJGVgWQYdObi0F1wkSD1gsiqDnlvpUv 3CcQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc; bh=csQq6ppAXjFXxUHZsIs/vFXpbjpmWsnzbLlbojDWnI8=; b=oMl6BMqCkvQQhIcZqMqWmHgUTR/ipo6A2uDBoIJewz99uO9Zl37xeQkC3r+NvGhMPh Tmj04Itv8YJIJ96zgl5T58DIEnhmiG2JyVugBEY47UyKksMux7j746NbDKbbA2pExPbw C3vugm0pEPoAvwNqd+3XHH9x6iH1BprbyFIMnVrG5ybztkVcuthsG2VzPByN7zkpFNm8 NfmA8oIkzZ1X8Au4Qa5mKt2ees7TZLEYHZlWN33uNpovserX6njZpY0j+l37eXxiXehh TOU4Gziccs0zIcHqxdHzP26nQhzsKMwycYL8BD82y5OSc41Dz9bUYnBORXk3U2dSn9fm O5xA== X-Gm-Message-State: ACgBeo0SKZzNe/9J7aKhSiWj/Cu73mntZlnYvMXWDfjRV0i0uBRf7gOG hcQc6NW3JUwkNCCtk5oPm097YNXOBE0jai6fqnw= X-Google-Smtp-Source: AA6agR5hnliDrsyV12l9pH8Uq0zTYdbscNwK4I8yrGONTIOj92JcQw5w+aFVqYeLUcZQyEuGZE3xJwcH5/8tRJsmmtc= X-Received: by 2002:a05:6402:28c8:b0:43e:8622:1c21 with SMTP id ef8-20020a05640228c800b0043e86221c21mr7356464edb.135.1661533368899; Fri, 26 Aug 2022 10:02:48 -0700 (PDT) MIME-Version: 1.0 References: <20220819135755.vpfkmfyvysmdbzov@tomti.i.net-space.pl> <0F68F479-0EC8-4BF8-B21D-81B5FC725226@physik.fu-berlin.de> <20220819180916.GG2668594@tack.einval.com> <7412a75d-5541-4f2a-0220-95cbf61c2974@physik.fu-berlin.de> In-Reply-To: <7412a75d-5541-4f2a-0220-95cbf61c2974@physik.fu-berlin.de> From: "Vladimir 'phcoder' Serbinenko" Date: Fri, 26 Aug 2022 19:02:38 +0200 Message-ID: Subject: Re: [PATCH] Remove HFS support To: John Paul Adrian Glaubitz Cc: The development of GNU GRUB Content-Type: multipart/alternative; boundary="0000000000003c5bd305e727e222" Received-SPF: pass client-ip=2a00:1450:4864:20::52c; envelope-from=phcoder@gmail.com; helo=mail-ed1-x52c.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: grub-devel@gnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: The development of GNU GRUB List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 26 Aug 2022 17:03:00 -0000 --0000000000003c5bd305e727e222 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Le ven. 26 ao=C3=BBt 2022, 17:46, John Paul Adrian Glaubitz < glaubitz@physik.fu-berlin.de> a =C3=A9crit : > Hi Vladimir! > > On 8/19/22 21:01, Vladimir 'phcoder' Serbinenko wrote: > > But booting old machines is still desirable for GRUB. Is there a reason > why > > HFS is actively bad for modern machines? Especially if it's disabled in > case > > of lockdown. > > > > Can I have more details about your security concerns? I may consider > rewriting > > parts of HFS code to improve it. > > FWIW, in case you would be really interested on improving the HFS code, i= t > should > be no problem to collect some funds in the PowerPC community to > financially support > that task, e.g. through a Bountysource campaign. > > We have done this in the past to support similar projects in GCC and LLVM= . > > What do you think? > I have checked HFS code in general and it looks pretty neat safe for few bugs like cache collision. If I can get these fuses I can probably fix them. I'm currently on weekend and my laptop has died but I can have a look using my phone + VPS > > Thanks, > Adrian > > -- > .''`. John Paul Adrian Glaubitz > : :' : Debian Developer > `. `' Physicist > `- GPG: 62FF 8A75 84E0 2956 9546 0006 7426 3B37 F5B5 F913 > > > --0000000000003c5bd305e727e222 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable


Le ven. 26 ao=C3=BBt 2022, 17:46, John Paul Adrian Gla= ubitz <glaubitz@physik.f= u-berlin.de> a =C3=A9crit=C2=A0:
Hi Vladimir!

On 8/19/22 21:01, Vladimir 'phcoder' Serbinenko wrote:
> But booting old machines is still desirable for GRUB. Is there a reaso= n why
> HFS is actively bad for modern machines? Especially if it's disabl= ed in case
> of lockdown.
>
> Can I have more details about your security concerns? I may consider r= ewriting
> parts of HFS code to improve it.

FWIW, in case you would be really interested on improving the HFS code, it = should
be no problem to collect some funds in the PowerPC community to financially= support
that task, e.g. through a Bountysource campaign.

We have done this in the past to support similar projects in GCC and LLVM.<= br>
What do you think?
I have che= cked HFS code in general and it looks pretty neat safe for few bugs like ca= che collision. If I can get these fuses I can probably fix them. I'm cu= rrently on weekend and my laptop has died but I can have a look using my ph= one + VPS

Thanks,
Adrian

--
=C2=A0 .''`.=C2=A0 John Paul Adrian Glaubitz
: :' :=C2=A0 Debian Developer
`. `'=C2=A0 =C2=A0Physicist
=C2=A0 =C2=A0`-=C2=A0 =C2=A0 GPG: 62FF 8A75 84E0 2956 9546=C2=A0 0006 7426 = 3B37 F5B5 F913


--0000000000003c5bd305e727e222--