From: Mimi Zohar <zohar@linux.ibm.com>
To: Ard Biesheuvel <ardb@kernel.org>
Cc: "Lee, Chun-Yi" <jlee@suse.com>,
linux-efi <linux-efi@vger.kernel.org>,
Dmitry Kasatkin <dmitry.kasatkin@gmail.com>,
X86 ML <x86@kernel.org>, James Morris <jmorris@namei.org>,
Chester Lin <clin@suse.com>,
Catalin Marinas <catalin.marinas@arm.com>,
linux-integrity <linux-integrity@vger.kernel.org>,
Will Deacon <will@kernel.org>,
Linux ARM <linux-arm-kernel@lists.infradead.org>,
"Serge E. Hallyn" <serge@hallyn.com>
Subject: Re: [PATCH v4 0/3] wire up IMA secure boot for arm64
Date: Wed, 04 Nov 2020 14:03:27 -0500 [thread overview]
Message-ID: <c044fc25be309e7b25a4c64845fd753515c84804.camel@linux.ibm.com> (raw)
In-Reply-To: <CAMj1kXEjKt0F8dZBnF=x2ShkxyvoGApXzVA-HMCY2oOj7kuKKg@mail.gmail.com>
On Wed, 2020-11-04 at 19:50 +0100, Ard Biesheuvel wrote:
> On Wed, 4 Nov 2020 at 19:20, Mimi Zohar <zohar@linux.ibm.com> wrote:
> >
> > Hi Ard, Chester,
> >
> > On Mon, 2020-11-02 at 23:37 +0100, Ard Biesheuvel wrote:
> > > This is a follow-up to Chester's series [0] to enable IMA to the secure
> > > boot state of arm64 platforms, which is EFI based.
> > >
> > > This v4 implements the changes I suggested to Chester, in particular:
> > > - disregard MokSbState when factoring out secure boot mode discovery
> > > - turn the x86 IMA arch code into shared code for all architectures.
> > >
> > > This reduces the final patch to a one liner enabling a Kconfig option
> > > for arm64 when EFI is enabled.
> > >
> > > Build tested only.
> >
> > Thank you! This patch set is now queued in the linux-integrity next-
> > integrity-testing branch.
> >
>
> I don't mind per se, but this touches a number of different trees,
> including x86 and arm64, and nobody has acked it yet.
>
> As far as the EFI tree is concerned, it looks like I should be able to
> avoid any conflicts with other stuff that is in flight, and if not, we
> can always use your branch up until the last patch in this serires as
> a shared tag (assuming you won't rebase it).
The next-integrity-testing branch is just a place holder waiting for
additional tags. I've reviewed and tested the patch set on x86. Based
on the secure boot status and how the kernel is configured, the
appropriate policy rules are enabled. Similarly the IMA appraise mode
(ima_appraise=) is working properly. I have not tested on arm64.
I do not have a problem with this patch set being upstream via EFI.
thanks,
Mimi
_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel
next prev parent reply other threads:[~2020-11-04 19:04 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-11-02 22:37 [PATCH v4 0/3] wire up IMA secure boot for arm64 Ard Biesheuvel
2020-11-02 22:37 ` [PATCH v4 1/3] efi: generalize efi_get_secureboot Ard Biesheuvel
2020-11-03 18:48 ` Mimi Zohar
2020-11-03 19:01 ` Ard Biesheuvel
2020-11-03 20:03 ` Mimi Zohar
2020-11-02 22:37 ` [PATCH v4 2/3] ima: generalize x86/EFI arch glue for other EFI architectures Ard Biesheuvel
2020-11-06 3:41 ` Chester Lin
2020-11-06 6:39 ` Ard Biesheuvel
2020-11-02 22:38 ` [PATCH v4 3/3] arm64/ima: add ima_arch support Ard Biesheuvel
2020-11-14 12:18 ` Catalin Marinas
2020-11-04 18:20 ` [PATCH v4 0/3] wire up IMA secure boot for arm64 Mimi Zohar
2020-11-04 18:50 ` Ard Biesheuvel
2020-11-04 19:03 ` Mimi Zohar [this message]
2020-11-04 19:12 ` Ard Biesheuvel
2020-11-04 19:55 ` Mimi Zohar
2020-11-05 7:55 ` Ard Biesheuvel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=c044fc25be309e7b25a4c64845fd753515c84804.camel@linux.ibm.com \
--to=zohar@linux.ibm.com \
--cc=ardb@kernel.org \
--cc=catalin.marinas@arm.com \
--cc=clin@suse.com \
--cc=dmitry.kasatkin@gmail.com \
--cc=jlee@suse.com \
--cc=jmorris@namei.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-efi@vger.kernel.org \
--cc=linux-integrity@vger.kernel.org \
--cc=serge@hallyn.com \
--cc=will@kernel.org \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).