From mboxrd@z Thu Jan 1 00:00:00 1970 Return-path: Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by bombadil.infradead.org with esmtps (Exim 4.90_1 #2 (Red Hat Linux)) id 1h2FjC-0002bY-Tb for kexec@lists.infradead.org; Fri, 08 Mar 2019 13:40:00 +0000 Received: from pps.filterd (m0098396.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.16.0.27/8.16.0.27) with SMTP id x28DVFgt083793 for ; Fri, 8 Mar 2019 08:39:56 -0500 Received: from e06smtp07.uk.ibm.com (e06smtp07.uk.ibm.com [195.75.94.103]) by mx0a-001b2d01.pphosted.com with ESMTP id 2r3s3gs4x7-1 (version=TLSv1.2 cipher=AES256-GCM-SHA384 bits=256 verify=NOT) for ; Fri, 08 Mar 2019 08:39:56 -0500 Received: from localhost by e06smtp07.uk.ibm.com with IBM ESMTP SMTP Gateway: Authorized Use Only! Violators will be prosecuted for from ; Fri, 8 Mar 2019 13:39:53 -0000 Subject: Re: [PATCH 3/3] x86/ima: retry detecting secure boot mode From: Mimi Zohar Date: Fri, 08 Mar 2019 08:39:37 -0500 In-Reply-To: References: <1542657371-7019-1-git-send-email-zohar@linux.ibm.com> <1542657371-7019-4-git-send-email-zohar@linux.ibm.com> <1551998897.31706.461.camel@linux.ibm.com> Mime-Version: 1.0 Message-Id: <1552052377.4134.23.camel@linux.ibm.com> List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 Sender: "kexec" Errors-To: kexec-bounces+dwmw2=infradead.org@lists.infradead.org To: Matthew Garrett Cc: linux-efi , Nayna Jain , kexec@lists.infradead.org, Linux Kernel Mailing List , David Howells , Seth Forshee , LSM List , Justin Forbes , linux-integrity T24gVGh1LCAyMDE5LTAzLTA3IGF0IDE0OjUwIC0wODAwLCBNYXR0aGV3IEdhcnJldHQgd3JvdGU6 Cj4gT24gVGh1LCBNYXIgNywgMjAxOSBhdCAyOjQ4IFBNIE1pbWkgWm9oYXIgPHpvaGFyQGxpbnV4 LmlibS5jb20+IHdyb3RlOgo+ID4gSSBhZGRlZCB0aGlzIGxhc3QgYXR0ZW1wdCBiZWNhdXNlIEkn bSBzZWVpbmcgdGhpcyBvbiBteSBsYXB0b3AsIHdpdGgKPiA+IHNvbWUgb2xkZXIsIGJ1Z2d5IGZp cm13YXJlLgo+IAo+IElzIHRoZSBpc3N1ZSB0aGF0IGl0IGdpdmVzIGluY29ycmVjdCByZXN1bHRz IG9uIHRoZSBmaXJzdCByZWFkLCBvciBpcwo+IHRoZSBpc3N1ZSB0aGF0IGl0IGdpdmVzIGluY29y cmVjdCByZXN1bHRzIGJlZm9yZSBFeGl0Qm9vdFNlcnZpY2VzKCkgaXMKPiBjYWxsZWQ/IElmIHRo ZSBmb3JtZXIgdGhlbiB3ZSBzaG91bGQgcmVhZCB0d2ljZSBpbiB0aGUgYm9vdCBzdHViLCBpZgo+ IHRoZSBsYXR0ZXIgdGhlbiB3ZSBzaG91bGQgZmlndXJlIG91dCBhIHdheSB0byBkbyB0aGlzIGlt bWVkaWF0ZWx5Cj4gYWZ0ZXIgRXhpdEJvb3RTZXJ2aWNlcygpIGluc3RlYWQuCgpEZXRlY3Rpbmcg dGhlIHNlY3VyZSBib290IG1vZGUgaXNuJ3QgdGhlIHByb2JsZW0uIMKgT24gYm9vdCwgSSBhbQpz ZWVpbmcgIkVGSSBzdHViOiBVRUZJIFNlY3VyZSBCb290IGlzIGVuYWJsZWQiLCBidXQgc2V0dXBf YXJjaCgpIGVtaXRzCiJTZWN1cmUgYm9vdCBjb3VsZCBub3QgYmUgZGV0ZXJtaW5lZCIuCgpJbiBl ZmlfbWFpbigpIHRoZSBzZWN1cmVfYm9vdCBtb2RlIGlzIGluaXRpYWxseSB1bnNldCwgc28KZWZp X2dldF9zZWN1cmVib290KCkgaXMgY2FsbGVkLiDCoGVmaV9nZXRfc2VjdXJlYm9vdCgpIHJldHVy bnMgdGhlCnNlY3VyZV9ib290IG1vZGUgY29ycmVjdGx5IGFzIGVuYWJsZWQuIMKgVGhlIHByb2Js ZW0gc2VlbXMgdG8gYmUgaW4Kc2F2aW5nIHRoZSBzZWN1cmVfYm9vdCBtb2RlIGZvciBsYXRlciB1 c2UuCgpNaW1pCgoKX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f X18Ka2V4ZWMgbWFpbGluZyBsaXN0CmtleGVjQGxpc3RzLmluZnJhZGVhZC5vcmcKaHR0cDovL2xp c3RzLmluZnJhZGVhZC5vcmcvbWFpbG1hbi9saXN0aW5mby9rZXhlYwo= From mboxrd@z Thu Jan 1 00:00:00 1970 From: Mimi Zohar Subject: Re: [PATCH 3/3] x86/ima: retry detecting secure boot mode Date: Fri, 08 Mar 2019 08:39:37 -0500 Message-ID: <1552052377.4134.23.camel@linux.ibm.com> References: <1542657371-7019-1-git-send-email-zohar@linux.ibm.com> <1542657371-7019-4-git-send-email-zohar@linux.ibm.com> <1551998897.31706.461.camel@linux.ibm.com> Mime-Version: 1.0 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: 8bit Return-path: In-Reply-To: Sender: linux-kernel-owner@vger.kernel.org To: Matthew Garrett Cc: Justin Forbes , linux-integrity , LSM List , linux-efi , Linux Kernel Mailing List , David Howells , Seth Forshee , kexec@lists.infradead.org, Nayna Jain List-Id: linux-efi@vger.kernel.org On Thu, 2019-03-07 at 14:50 -0800, Matthew Garrett wrote: > On Thu, Mar 7, 2019 at 2:48 PM Mimi Zohar wrote: > > I added this last attempt because I'm seeing this on my laptop, with > > some older, buggy firmware. > > Is the issue that it gives incorrect results on the first read, or is > the issue that it gives incorrect results before ExitBootServices() is > called? If the former then we should read twice in the boot stub, if > the latter then we should figure out a way to do this immediately > after ExitBootServices() instead. Detecting the secure boot mode isn't the problem.  On boot, I am seeing "EFI stub: UEFI Secure Boot is enabled", but setup_arch() emits "Secure boot could not be determined". In efi_main() the secure_boot mode is initially unset, so efi_get_secureboot() is called.  efi_get_secureboot() returns the secure_boot mode correctly as enabled.  The problem seems to be in saving the secure_boot mode for later use. Mimi