From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-1.0 required=3.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id BEDD6C433E0 for ; Wed, 24 Jun 2020 15:33:14 +0000 (UTC) Received: from merlin.infradead.org (merlin.infradead.org [205.233.59.134]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 8892B206FA for ; Wed, 24 Jun 2020 15:33:14 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (2048-bit key) header.d=lists.infradead.org header.i=@lists.infradead.org header.b="lIv3gIwL"; dkim=fail reason="signature verification failed" (1024-bit key) header.d=kernel.org header.i=@kernel.org header.b="1/gbox5R" DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 8892B206FA Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=kernel.org Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=merlin.20170209; h=Sender:Content-Transfer-Encoding: Content-Type:Cc:List-Subscribe:List-Help:List-Post:List-Archive: List-Unsubscribe:List-Id:To:Subject:Message-ID:Date:From:In-Reply-To: References:MIME-Version:Reply-To:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=+u4lIiwddGAiwbJMRYEESaijsf3c6ciL4LwtOWqyg7Y=; b=lIv3gIwLwxqLnxN2ABh6WPFt7 bPYXgYJH7g/jKIdqFuzR61+6a41HE6u9LI18LhkY/gpLzEFa4bJf69SrkyHXOpQumhGM9vtmBypyK Yj90+Qt81JARGgmbRs8x/PmTH05lgPYq6juHaKkO5Mx14GdfhkAX+zHGG9x+Guwpi7j130wrdE2dJ 3jkUl/aRNsEl2S8FTqMGgloJ33RdSERmpmDanMSyKC+KaCv/O43rIj8Q7UI4ZjLPDtNChqG34QN17 ZzJHY9YQXrpUE80EjFpR5zxcq5gYsWEytwLdhrgS+7wct5U+azn/rNvilPsptUqvPjvRA9T06Y0RU tuE71HHnA==; Received: from localhost ([::1] helo=merlin.infradead.org) by merlin.infradead.org with esmtp (Exim 4.92.3 #3 (Red Hat Linux)) id 1jo7Mz-0000wG-4X; Wed, 24 Jun 2020 15:31:25 +0000 Received: from mail.kernel.org ([198.145.29.99]) by merlin.infradead.org with esmtps (Exim 4.92.3 #3 (Red Hat Linux)) id 1jo7Mt-0000uv-Gg for linux-arm-kernel@lists.infradead.org; Wed, 24 Jun 2020 15:31:20 +0000 Received: from mail-oi1-f171.google.com (mail-oi1-f171.google.com [209.85.167.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id A86B220CC7 for ; Wed, 24 Jun 2020 15:31:18 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1593012678; bh=/XOHUfqgbkJQ/VFuvcNxNCzM8LEt5wElAfbZZ/I0QOw=; h=References:In-Reply-To:From:Date:Subject:To:Cc:From; b=1/gbox5RlRrTg4kiGntX+1BFq5EOO4rauIXcE4/g/S2HjduHZ27HO7Fjy+HijbTVB sVuOiSgFcgbSQ3pmCbbNxTv8ndSCUbtspQ8cQSVbB0+WOhS45jjaDROjbJheaBvJPx Jp7yfm6yZTnYcCEC/Dzy+L1wptwcf9GX1xIrcY+o= Received: by mail-oi1-f171.google.com with SMTP id l63so2136881oih.13 for ; Wed, 24 Jun 2020 08:31:18 -0700 (PDT) X-Gm-Message-State: AOAM531alNOlf+GMDfbotGv5g3LRkvS2fYie2xqzduiZ2Xmi42llTGaO p6+mO8QGwlSNxbc0SIHHM48q/+Eonezsi0O4XtU= X-Google-Smtp-Source: ABdhPJyrGY95Bb0CTBeTb4CjO3FI7dpKNkRH6VdRIt+LCKBsYjwk4gHaFIm8ccr4EwcCcNYIphYlt47P29XWTXpZnCA= X-Received: by 2002:aca:b241:: with SMTP id b62mr19630758oif.47.1593012677928; Wed, 24 Jun 2020 08:31:17 -0700 (PDT) MIME-Version: 1.0 References: <20200624014940.1204448-1-keescook@chromium.org> <20200624014940.1204448-4-keescook@chromium.org> <20200624033142.cinvg6rbg252j46d@google.com> <202006232143.66828CD3@keescook> <20200624104356.GA6134@willie-the-truck> <202006240820.A3468F4@keescook> In-Reply-To: <202006240820.A3468F4@keescook> From: Ard Biesheuvel Date: Wed, 24 Jun 2020 17:31:06 +0200 X-Gmail-Original-Message-ID: Message-ID: Subject: Re: [PATCH v3 3/9] efi/libstub: Remove .note.gnu.property To: Kees Cook X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Mark Rutland , linux-arch , linux-efi , Arnd Bergmann , Fangrui Song , Peter Collingbourne , Catalin Marinas , Masahiro Yamada , X86 ML , Nick Desaulniers , Russell King , Linux Kernel Mailing List , clang-built-linux , Arvind Sankar , Ingo Molnar , James Morse , Thomas Gleixner , Borislav Petkov , Will Deacon , Nathan Chancellor , Linux ARM Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org On Wed, 24 Jun 2020 at 17:21, Kees Cook wrote: > > On Wed, Jun 24, 2020 at 12:46:32PM +0200, Ard Biesheuvel wrote: > > I'm not sure if there is a point to having PAC and/or BTI in the EFI > > stub, given that it runs under the control of the firmware, with its > > memory mappings and PAC configuration etc. > > Is BTI being ignored when the firmware runs? > Given that it requires the 'guarded' attribute to be set in the page tables, and the fact that the UEFI spec does not require it for executables that it invokes, nor describes any means of annotating such executables as having been built with BTI annotations, I think we can safely assume that the EFI stub will execute with BTI disabled in the foreseeable future. _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel