From mboxrd@z Thu Jan 1 00:00:00 1970 From: Matthew Garrett Subject: Re: An actual suggestion (Re: [GIT PULL] Kernel lockdown for secure boot) Date: Thu, 05 Apr 2018 00:22:02 +0000 Message-ID: References: <1119.1522858644@warthog.procyon.org.uk> Mime-Version: 1.0 Content-Type: text/plain; charset="UTF-8" Return-path: In-Reply-To: Sender: linux-kernel-owner@vger.kernel.org To: jmorris@namei.org Cc: David Howells , luto@kernel.org, Greg Kroah-Hartman , Theodore Ts'o , Linus Torvalds , Ard Biesheuvel , Alan Cox , Linux Kernel Mailing List , jforbes@redhat.com, linux-man@vger.kernel.org, jlee@suse.com, LSM List , linux-api@vger.kernel.org, Kees Cook , linux-efi List-Id: linux-api@vger.kernel.org On Wed, Apr 4, 2018 at 4:25 PM James Morris wrote: > It's surely reasonable to allow an already secure-booted system to be > debugged without needing to be rebooted. alt-sysrq-x from a physical console will do that.