All of lore.kernel.org
 help / color / mirror / Atom feed
From: Kees Cook <keescook@chromium.org>
To: Scott Branden <scott.branden@broadcom.com>
Cc: linux-efi@vger.kernel.org,
	"Rafael J. Wysocki" <rafael@kernel.org>,
	Peter Zijlstra <peterz@infradead.org>,
	linux-fsdevel@vger.kernel.org,
	Stephen Boyd <stephen.boyd@linaro.org>,
	SeongJae Park <sjpark@amazon.de>,
	Mimi Zohar <zohar@linux.ibm.com>,
	David Howells <dhowells@redhat.com>,
	Tushar Sugandhi <tusharsu@linux.microsoft.com>,
	Peter Jones <pjones@redhat.com>,
	linux-kselftest@vger.kernel.org,
	"Joel Fernandes (Google)" <joel@joelfernandes.org>,
	Shuah Khan <shuah@kernel.org>, Ard Biesheuvel <ardb@kernel.org>,
	Thomas Cedeno <thomascedeno@google.com>,
	linux-security-module@vger.kernel.org,
	Anders Roxell <anders.roxell@linaro.org>,
	Paul Moore <paul@paul-moore.com>,
	Mauro Carvalho Chehab <mchehab+huawei@kernel.org>,
	Michael Ellerman <mpe@ellerman.id.au>,
	Nayna Jain <nayna@linux.ibm.com>,
	Matthew Garrett <matthewgarrett@google.com>,
	James Morris <jmorris@namei.org>,
	Lakshmi Ramasubramanian <nramas@linux.microsoft.com>,
	Aaron Goidel <acgoide@tycho.nsa.gov>,
	"Serge E. Hallyn" <serge@hallyn.com>,
	Wenwen Wang <wenwen@cs.uga.edu>,
	selinux@vger.kernel.org, Jessica Yu <jeyu@kernel.org>,
	Hans de Goede <hdegoede@redhat.com>,
	Alexander Viro <viro@zeniv.linux.org.uk>,
	Matthieu Baerts <matthieu.baerts@tessares.net>,
	KP Singh <kpsingh@chromium.org>,
	Eric Paris <eparis@parisplace.org>,
	linux-integrity@vger.kernel.org,
	Florent Revest <revest@google.com>,
	Andrea Righi <andrea.righi@canonical.com>,
	Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	Stephen Smalley <stephen.smalley.work@gmail.com>,
	Randy Dunlap <rdunlap@infradead.org>,
	kexec@lists.infradead.org, linux-kernel@vger.kernel.org,
	Luis Chamberlain <mcgrof@kernel.org>,
	Eric Biederman <ebiederm@xmission.com>,
	Dave Olsthoorn <dave@bewaar.me>,
	Dmitry Kasatkin <dmitry.kasatkin@gmail.com>,
	Casey Schaufler <casey@schaufler-ca.com>,
	Joe Perches <joe@perches.com>,
	Andrew Morton <akpm@linux-foundation.org>,
	Thiago Jung Bauermann <bauerman@linux.ibm.com>
Subject: Re: [PATCH v2 15/18] fs/kernel_file_read: Add "offset" arg for partial reads
Date: Thu, 23 Jul 2020 12:17:43 -0700	[thread overview]
Message-ID: <202007231215.D6E097C@keescook> (raw)
In-Reply-To: <354ec0c3-b56d-f5b5-574f-4032fee0b55a@broadcom.com>

On Wed, Jul 22, 2020 at 11:23:43PM -0700, Scott Branden wrote:
> I made an adjustment in the logic of the driver with use of
> request_partial_firmware_into_buf and now everything is working.

Excellent! Was there something wrong with how I ported the
request_partial_firmware_into_buf() changes? (Should the behavior be
changed in some way? I didn't change the self-tests, so I thought the
behavior matched your original series.)

> So only issue I find with this entire patch series is the problem
> of security failing without the workaround below.

Yup; I'm trying to reproduce this now too...

-- 
Kees Cook

_______________________________________________
kexec mailing list
kexec@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/kexec

  reply	other threads:[~2020-07-23 19:17 UTC|newest]

Thread overview: 38+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-07-22 19:30 [PATCH v2 00/18] Introduce partial kernel_read_file() support Kees Cook
2020-07-22 19:30 ` [PATCH v2 01/18] test_firmware: Test platform fw loading on non-EFI systems Kees Cook
2020-07-23 17:32   ` Scott Branden
2020-07-29  0:48   ` Luis Chamberlain
2020-09-09 22:18     ` Kees Cook
2020-07-22 19:30 ` [PATCH v2 02/18] selftest/firmware: Add selftest timeout in settings Kees Cook
2020-07-23  6:38   ` SeongJae Park
2020-07-23 17:34   ` Scott Branden
2020-07-22 19:30 ` [PATCH v2 03/18] firmware_loader: EFI firmware loader must handle pre-allocated buffer Kees Cook
2020-07-22 19:30 ` [PATCH v2 04/18] fs/kernel_read_file: Remove FIRMWARE_PREALLOC_BUFFER enum Kees Cook
2020-07-22 19:30 ` [PATCH v2 05/18] fs/kernel_read_file: Remove FIRMWARE_EFI_EMBEDDED enum Kees Cook
2020-07-22 19:30 ` [PATCH v2 06/18] fs/kernel_read_file: Split into separate include file Kees Cook
2020-07-22 19:30 ` [PATCH v2 07/18] fs/kernel_read_file: Split into separate source file Kees Cook
2020-07-22 19:30 ` [PATCH v2 08/18] fs/kernel_read_file: Remove redundant size argument Kees Cook
2020-07-23 17:35   ` Scott Branden
2020-07-22 19:30 ` [PATCH v2 09/18] fs/kernel_read_file: Switch buffer size arg to size_t Kees Cook
2020-07-23 17:36   ` Scott Branden
2020-07-22 19:30 ` [PATCH v2 10/18] fs/kernel_read_file: Add file_size output argument Kees Cook
2020-07-23 17:36   ` Scott Branden
2020-07-22 19:30 ` [PATCH v2 11/18] LSM: Introduce kernel_post_load_data() hook Kees Cook
2020-07-23 17:39   ` Scott Branden
2020-07-22 19:30 ` [PATCH v2 12/18] firmware_loader: Use security_post_load_data() Kees Cook
2020-07-22 19:30 ` [PATCH v2 13/18] module: Call security_kernel_post_load_data() Kees Cook
2020-07-22 19:30 ` [PATCH v2 14/18] LSM: Add "contents" flag to kernel_read_file hook Kees Cook
2020-07-22 19:30 ` [PATCH v2 15/18] fs/kernel_file_read: Add "offset" arg for partial reads Kees Cook
2020-07-22 22:29   ` Scott Branden
2020-07-23  6:23     ` Scott Branden
2020-07-23 19:17       ` Kees Cook [this message]
2020-07-24  5:46         ` Scott Branden
2020-07-23 19:15     ` Kees Cook
2020-07-24  5:41       ` Scott Branden
2020-07-24 18:23         ` Kees Cook
2020-07-24 18:39           ` Kees Cook
2020-07-24 19:03             ` Scott Branden
2020-07-24 19:26               ` Kees Cook
2020-07-22 19:30 ` [PATCH v2 16/18] firmware: Store opt_flags in fw_priv Kees Cook
2020-07-22 19:30 ` [PATCH v2 17/18] firmware: Add request_partial_firmware_into_buf() Kees Cook
2020-07-22 19:30 ` [PATCH v2 18/18] test_firmware: Test partial read support Kees Cook

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=202007231215.D6E097C@keescook \
    --to=keescook@chromium.org \
    --cc=acgoide@tycho.nsa.gov \
    --cc=akpm@linux-foundation.org \
    --cc=anders.roxell@linaro.org \
    --cc=andrea.righi@canonical.com \
    --cc=ardb@kernel.org \
    --cc=bauerman@linux.ibm.com \
    --cc=casey@schaufler-ca.com \
    --cc=dave@bewaar.me \
    --cc=dhowells@redhat.com \
    --cc=dmitry.kasatkin@gmail.com \
    --cc=ebiederm@xmission.com \
    --cc=eparis@parisplace.org \
    --cc=gregkh@linuxfoundation.org \
    --cc=hdegoede@redhat.com \
    --cc=jeyu@kernel.org \
    --cc=jmorris@namei.org \
    --cc=joe@perches.com \
    --cc=joel@joelfernandes.org \
    --cc=kexec@lists.infradead.org \
    --cc=kpsingh@chromium.org \
    --cc=linux-efi@vger.kernel.org \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-integrity@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-kselftest@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=matthewgarrett@google.com \
    --cc=matthieu.baerts@tessares.net \
    --cc=mcgrof@kernel.org \
    --cc=mchehab+huawei@kernel.org \
    --cc=mpe@ellerman.id.au \
    --cc=nayna@linux.ibm.com \
    --cc=nramas@linux.microsoft.com \
    --cc=paul@paul-moore.com \
    --cc=peterz@infradead.org \
    --cc=pjones@redhat.com \
    --cc=rafael@kernel.org \
    --cc=rdunlap@infradead.org \
    --cc=revest@google.com \
    --cc=scott.branden@broadcom.com \
    --cc=selinux@vger.kernel.org \
    --cc=serge@hallyn.com \
    --cc=shuah@kernel.org \
    --cc=sjpark@amazon.de \
    --cc=stephen.boyd@linaro.org \
    --cc=stephen.smalley.work@gmail.com \
    --cc=thomascedeno@google.com \
    --cc=tusharsu@linux.microsoft.com \
    --cc=viro@zeniv.linux.org.uk \
    --cc=wenwen@cs.uga.edu \
    --cc=zohar@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.