From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-2.6 required=3.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS, USER_AGENT_SANE_1 autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 853A8C433E0 for ; Fri, 15 May 2020 20:47:07 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by mail.kernel.org (Postfix) with ESMTP id 5F44B20671 for ; Fri, 15 May 2020 20:47:07 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1589575627; bh=o8jhoxy+OmoDCNcJwHU/bJPp4E8NrrFSVYgpX7Vyyc8=; h=Date:From:To:Cc:Subject:References:In-Reply-To:List-ID:From; b=ay29q+q+2iFwnU4YoRmEHMsLJRL30jaJaYXRfuz0hNIKE52eAaFJcWuB+35TJnD58 rD/DveF6GlfseFUdjQ9VTfsBgQVnxTfkAo8EKRXr+BujxmXrx8RTwbd1mDBrV5fyNG bxA8zFKDL+eb1iRj8qxU5/iVT6A6znaNT+KMNCsY= Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726238AbgEOUrE (ORCPT ); Fri, 15 May 2020 16:47:04 -0400 Received: from mail-pl1-f195.google.com ([209.85.214.195]:45269 "EHLO mail-pl1-f195.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726179AbgEOUrD (ORCPT ); Fri, 15 May 2020 16:47:03 -0400 Received: by mail-pl1-f195.google.com with SMTP id u22so1377457plq.12; Fri, 15 May 2020 13:47:03 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:content-transfer-encoding :in-reply-to:user-agent; bh=bl4gmCDPSUzHnX+jLpXyZUJERfeGYaFlQRMMArtCGYw=; b=oeOXGsr4+HBzYqZnxvIM2ZOj7Jn+xUjXCTSOan+GC9hFglZuNbccQlY1DDZsPy7gHl gpbwsRsp+qh0rFDCxsiOOkS+peI3zeLUS4mnTRnkg77WVrnLcvVH0iU4TPHKvNGuSmgs 9OVmoU/wD51jBHwmjVbVf3vvO7fzwNvNSPD7VBmkfIFOE0OP39LctnuYeV5q3gOF4Tt4 B7MkKNpnIa43QOuGsZUp3f4gEZy3g67FNILOxpAXAqnykLHeZKkgeJ4wFqAdUVEcel4Q HK9RStpZDTsaRB8PdEoIqP03zu4AAtSApppguTBnZCKnf+GzLl8rE4F3eLzx/eWD47Sl EOrw== X-Gm-Message-State: AOAM533+AfYSBNNGDenxpFcF+WGyjrtoso8IfhSNCVwXo6tUH5nojLN7 GQuuaVk3jIgTVvne8y56aKs= X-Google-Smtp-Source: ABdhPJzvKeCybmqcU3uCZ47Ca1r5orOtVdlDMNpjFIpmiXjNhQsQ3lh6XlyPvdvbjVArLirXx76prA== X-Received: by 2002:a17:902:7596:: with SMTP id j22mr5189994pll.226.1589575623031; Fri, 15 May 2020 13:47:03 -0700 (PDT) Received: from 42.do-not-panic.com (42.do-not-panic.com. [157.230.128.187]) by smtp.gmail.com with ESMTPSA id e12sm2387775pgv.16.2020.05.15.13.47.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 15 May 2020 13:47:01 -0700 (PDT) Received: by 42.do-not-panic.com (Postfix, from userid 1000) id A324540246; Fri, 15 May 2020 20:47:00 +0000 (UTC) Date: Fri, 15 May 2020 20:47:00 +0000 From: Luis Chamberlain To: Mimi Zohar Cc: Scott Branden , Greg Kroah-Hartman , David Brown , Alexander Viro , Shuah Khan , bjorn.andersson@linaro.org, Shuah Khan , Arnd Bergmann , "Rafael J . Wysocki" , linux-kernel@vger.kernel.org, linux-arm-msm@vger.kernel.org, linux-fsdevel@vger.kernel.org, BCM Kernel Feedback , Olof Johansson , Andrew Morton , Dan Carpenter , Colin Ian King , Kees Cook , Takashi Iwai , linux-kselftest@vger.kernel.org, Andy Gross Subject: Re: [PATCH v5 0/7] firmware: add partial read support in request_firmware_into_buf Message-ID: <20200515204700.GC11244@42.do-not-panic.com> References: <20200508002739.19360-1-scott.branden@broadcom.com> <1589387039.5098.147.camel@kernel.org> MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <1589387039.5098.147.camel@kernel.org> User-Agent: Mutt/1.10.1 (2018-07-13) Sender: linux-fsdevel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-fsdevel@vger.kernel.org On Wed, May 13, 2020 at 12:23:59PM -0400, Mimi Zohar wrote: > Hi Scott, > > On Thu, 2020-05-07 at 17:27 -0700, Scott Branden wrote: > > Please consider this version series ready for upstream acceptance. > > > > This patch series adds partial read support in request_firmware_into_buf. > > In order to accept the enhanced API it has been requested that kernel > > selftests and upstreamed driver utilize the API enhancement and so > > are included in this patch series. > > > > Also in this patch series is the addition of a new Broadcom VK driver > > utilizing the new request_firmware_into_buf enhanced API. > > Up to now, the firmware blob was read into memory allowing IMA to > verify the file signature.  With this change, ima_post_read_file() > will not be able to verify the file signature. > > (I don't think any of the other LSMs are on this hook, but you might > want to Cc the LSM or integrity mailing list.) Scott, so it sounds we need a resolution for pread for IMA for file signature verification. It seems that can be addressed though. Feel free to submit the u32 flag changes which you picked up on though in the meantime. Luis