From: Gabriele Monaco <gmonaco@redhat.com>
To: "igor.stoppa@gmail.com" <igor.stoppa@gmail.com>
Cc: Steven Rostedt <rostedt@goodmis.org>,
Theodore Tso <tytso@mit.edu>,
Miguel Ojeda <miguel.ojeda.sandonis@gmail.com>,
Greg KH <gregkh@linuxfoundation.org>,
ksummit@lists.linux.dev, istoppa@nvidia.com,
Kate Stewart <kstewart@linuxfoundation.org>,
Gabriele Paoloni <gpaoloni@redhat.com>
Subject: Re: [TECH TOPIC] Improving kernel security & integrity by generalizing ad-hoc safety mechanisms
Date: Thu, 10 Sep 2026 12:10:53 +0200 [thread overview]
Message-ID: <a8e733d2c5dfa78fbe45a7d82e502788f4c4cdba.camel@redhat.com> (raw)
In-Reply-To: <CAH2bzCRvGGi_WS4j-5jeWU2uFrFWy_s9ZtMrcT5r+QY+=UdP4w@mail.gmail.com>
On Wed, 2026-09-09 at 19:07 +0300, igor.stoppa@gmail.com wrote:
> On Wed, 9 Sept 2026 at 18:22, Gabriele Monaco <gmonaco@redhat.com> wrote:
>
> > In general I feel anything that tries to validate the kernel from the kernel
> > itself will have this kind of problems. It cannot really be isolated from
> > what it tries to verify.
>
> Well, that is where I beg to differ. We have implemented such a mechanism.
> But I've been repeatedly told that I should provide first the code,
> which right now woulnd't really help much, because it is far from being in a
> reviewable shape.
> So I won't get back there.
>
> You can look at the references from the root mail in this thread,
> or we can move the conversation to a different place, if you want to
> discuss more about it.
Right, I didn't think I had access to the entire conversation but it's all on
lore.
Now I remember, you discussed this at last year's LPC.
RV is indeed not quite a fit for this.
I'll be trying to follow your presentation this year. Also a BoF on this sounds
interesting to get the ball rolling.
Thanks,
Gabriele
next prev parent reply other threads:[~2026-09-10 10:11 UTC|newest]
Thread overview: 37+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-07 16:53 [TECH TOPIC] Improving kernel security & integrity by generalizing ad-hoc safety mechanisms igor.stoppa
2026-09-07 19:46 ` Greg KH
2026-09-07 21:42 ` igor.stoppa
2026-09-08 3:51 ` Theodore Tso
2026-09-08 10:14 ` igor.stoppa
2026-09-08 13:55 ` Theodore Tso
2026-09-08 14:32 ` igor.stoppa
2026-09-08 19:29 ` Steven Rostedt
2026-09-08 21:13 ` igor.stoppa
2026-09-08 23:14 ` Steven Rostedt
2026-09-08 23:48 ` igor.stoppa
2026-09-09 7:44 ` Gabriele Monaco
2026-09-09 9:40 ` igor.stoppa
2026-09-09 15:22 ` Gabriele Monaco
2026-09-09 16:07 ` igor.stoppa
2026-09-09 16:14 ` Steven Rostedt
2026-09-09 16:24 ` igor.stoppa
2026-09-09 16:32 ` Steven Rostedt
2026-09-10 10:10 ` Gabriele Monaco [this message]
2026-09-30 2:57 ` Chuck Wolber
2026-09-30 1:58 ` Chuck Wolber
2026-09-08 5:05 ` Greg KH
2026-09-08 11:26 ` igor.stoppa
2026-09-08 11:54 ` Greg KH
2026-09-08 12:25 ` igor.stoppa
2026-09-08 12:39 ` Greg KH
2026-09-08 12:52 ` igor.stoppa
2026-09-08 13:11 ` Miguel Ojeda
2026-09-08 13:52 ` igor.stoppa
2026-09-08 14:44 ` Theodore Tso
2026-09-08 15:32 ` igor.stoppa
2026-09-08 12:41 ` James Bottomley
2026-09-08 13:03 ` igor.stoppa
2026-09-08 15:40 ` Steven Rostedt
2026-09-08 16:09 ` igor.stoppa
2026-09-08 17:35 ` Steven Rostedt
2026-09-09 1:31 ` Theodore Tso
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=a8e733d2c5dfa78fbe45a7d82e502788f4c4cdba.camel@redhat.com \
--to=gmonaco@redhat.com \
--cc=gpaoloni@redhat.com \
--cc=gregkh@linuxfoundation.org \
--cc=igor.stoppa@gmail.com \
--cc=istoppa@nvidia.com \
--cc=kstewart@linuxfoundation.org \
--cc=ksummit@lists.linux.dev \
--cc=miguel.ojeda.sandonis@gmail.com \
--cc=rostedt@goodmis.org \
--cc=tytso@mit.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox