From mboxrd@z Thu Jan 1 00:00:00 1970 Return-path: Received: from h2.hallyn.com ([78.46.35.8] helo=mail.hallyn.com) by bombadil.infradead.org with esmtps (Exim 4.90_1 #2 (Red Hat Linux)) id 1fQByF-0007ge-59 for kexec@lists.infradead.org; Tue, 05 Jun 2018 13:26:49 +0000 Date: Tue, 5 Jun 2018 08:25:42 -0500 From: "Serge E. Hallyn" Subject: Re: [PATCH v4 0/8] kexec/firmware: support system wide policy requiring signatures Message-ID: <20180605132542.GA26722@mail.hallyn.com> References: <1527616920-5415-1-git-send-email-zohar@linux.vnet.ibm.com> <1528121025.3237.116.camel@linux.vnet.ibm.com> <20180605040920.GA19747@mail.hallyn.com> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "kexec" Errors-To: kexec-bounces+dwmw2=infradead.org@lists.infradead.org To: Kees Cook Cc: Andres Rodriguez , Eric Biederman , Paul Moore , Ard Biesheuvel , Greg Kroah-Hartman , Kexec Mailing List , LKML , David Howells , linux-security-module , "Luis R . Rodriguez" , James Morris , Jessica Yu , Casey Schaufler , linux-integrity , Mimi Zohar , "Serge E. Hallyn" Quoting Kees Cook (keescook@chromium.org): > On Mon, Jun 4, 2018 at 9:09 PM, Serge E. Hallyn wrote: > > Personally I agree with Eric and prefer a new hook. I don't feel strongly > > enough about it to keep bikeshedding, but since this set already exists, > > it seems like the way to go. > > And the new hook is "load stuff without a file descriptor"? Yes. Load stuff based on my own credentials not those attached to a file. _______________________________________________ kexec mailing list kexec@lists.infradead.org http://lists.infradead.org/mailman/listinfo/kexec