From: "H. Peter Anvin" <hpa@zytor.com>
To: Matthew Garrett <mjg59@srcf.ucam.org>
Cc: Yinghai Lu <yinghai@kernel.org>,
Bjorn Helgaas <bhelgaas@google.com>,
linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org,
linux-efi@vger.kernel.org, mfleming@intel.com,
dwmw2@infradead.org, "Eric W. Biederman" <ebiederm@xmission.com>
Subject: Re: Use PCI ROMs from EFI boot services
Date: Wed, 05 Dec 2012 17:21:44 -0800 [thread overview]
Message-ID: <50BFF328.5030406@zytor.com> (raw)
In-Reply-To: <cd3b2e67-92af-494d-ba2d-4179ead6e06b@email.android.com>
On 12/05/2012 05:13 PM, Matthew Garrett wrote:
>
>
> "H. Peter Anvin" <hpa@zytor.com> wrote:
>
>> And that presumably would be something that cannot be exposed to root?
>> If so we may want to use one of the bits in the setup_data type field
>> as
>> a security flag, perhaps...
>
> Yeah, it needs to be hidden from root - but ideally we'd be passing it to the second kernel if we kexec. Alternative would be for it to be capability bounded to a trusted signed kexec binary if we implement Vivek's IMA-based approach.
>
Either way a security flag in the type field makes sense.
-hpa
--
H. Peter Anvin, Intel Open Source Technology Center
I work for Intel. I don't speak on their behalf.
next prev parent reply other threads:[~2012-12-06 1:21 UTC|newest]
Thread overview: 47+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-08-23 16:36 Use PCI ROMs from EFI boot services Matthew Garrett
2012-08-23 16:36 ` [PATCH V3 1/4] EFI: Stash ROMs if they're not in the PCI BAR Matthew Garrett
2012-08-23 23:44 ` Bjorn Helgaas
2012-08-24 4:09 ` Matthew Garrett
2012-09-04 13:45 ` Matthew Garrett
2012-09-06 13:59 ` Bjorn Helgaas
2012-09-06 17:36 ` [PATCH] x86: Fix build warning on 32-bit Matthew Garrett
2012-09-06 20:02 ` Bjorn Helgaas
2012-08-23 16:36 ` [PATCH V3 2/4] PCI: Add pcibios_add_device Matthew Garrett
2012-08-23 16:36 ` [PATCH V3 3/4] PCI: Add support for non-BAR ROMs Matthew Garrett
2012-09-05 2:18 ` Don Dutile
2012-09-05 2:29 ` Matthew Garrett
2012-09-05 12:46 ` Alan Cox
2012-09-05 13:20 ` Matthew Garrett
2012-09-05 13:30 ` Alan Cox
2012-09-05 13:44 ` Matthew Garrett
2012-08-23 16:36 ` [PATCH V3 4/4] X86: Use PCI setup data Matthew Garrett
2012-08-24 9:30 ` Use PCI ROMs from EFI boot services David Woodhouse
2012-08-24 12:53 ` Matthew Garrett
2012-10-25 17:35 ` Bjorn Helgaas
2012-12-03 20:02 ` Seth Forshee
2012-12-05 20:09 ` Bjorn Helgaas
2012-12-05 20:22 ` Matthew Garrett
2012-12-05 22:21 ` Bjorn Helgaas
2012-12-05 21:06 ` David Woodhouse
2012-12-06 0:15 ` Yinghai Lu
2012-12-06 0:18 ` Matthew Garrett
2012-12-06 0:21 ` H. Peter Anvin
2012-12-06 0:30 ` Yinghai Lu
2012-12-06 0:36 ` H. Peter Anvin
2012-12-06 0:57 ` Matthew Garrett
2012-12-06 1:04 ` H. Peter Anvin
2012-12-06 1:13 ` Matthew Garrett
2012-12-06 1:21 ` H. Peter Anvin [this message]
2012-12-06 6:19 ` Matthew Garrett
2012-12-06 1:00 ` Matthew Garrett
2012-12-06 0:22 ` Yinghai Lu
2012-12-06 0:23 ` Eric W. Biederman
2012-12-06 0:36 ` H. Peter Anvin
2012-12-06 0:51 ` Yinghai Lu
2012-12-06 0:52 ` Yinghai Lu
2012-12-06 18:19 ` Bjorn Helgaas
2012-12-06 18:26 ` H. Peter Anvin
2012-12-06 18:54 ` Matthew Garrett
2012-12-06 18:57 ` Yinghai Lu
2012-12-06 21:44 ` Bjorn Helgaas
2012-12-06 0:56 ` H. Peter Anvin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=50BFF328.5030406@zytor.com \
--to=hpa@zytor.com \
--cc=bhelgaas@google.com \
--cc=dwmw2@infradead.org \
--cc=ebiederm@xmission.com \
--cc=linux-efi@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=mfleming@intel.com \
--cc=mjg59@srcf.ucam.org \
--cc=yinghai@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).