From: Vivek Goyal <vgoyal@redhat.com>
To: Andrea Adami <andrea.adami@gmail.com>
Cc: Mimi Zohar <zohar@linux.vnet.ibm.com>,
matthew.garrett@nebula.com, Greg KH <greg@kroah.com>,
d.kasatkin@samsung.com, kexec@lists.infradead.org,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
linux-security-module@vger.kernel.org, ebiederm@xmission.com,
"H. Peter Anvin" <hpa@zytor.com>,
akpm@linux-foundation.org
Subject: Re: [PATCH 00/16] [RFC PATCH] Signed kexec support
Date: Mon, 23 Sep 2013 13:15:15 -0400 [thread overview]
Message-ID: <20130923171515.GD10812@redhat.com> (raw)
In-Reply-To: <CAAQYJAuXy2up+XTE1AAgOg2u7t=LqOFyPv96RP+1avLC45UDJA@mail.gmail.com>
On Wed, Sep 18, 2013 at 04:51:21PM +0200, Andrea Adami wrote:
> Hello,
>
> as one of the developers of kexecboot, a kexec-based
> linux-as-bootloader, I'm following with interest this thread.
> FWIW since the beginning we are compiling kexec-tools statically
> against klibc for size constraints.
Hi Andrea,
Good to know about kexecboot.
FWIW, recently we discussed the kexec/kdump with secureboot issue
at Linux Plumbers and Greg KH suggested that it will be simpler if
we implement a new system call which does the job of loading new
kernel. Effectively that means reimplementing /sbin/kexec in kernel.
This will also mean maintaining two code bases for some time and
slowly deprecating one over a period of time.
I will probably start with something small and post proof of concept
patches for review and see how does that go. This is just heads up
on what I am planning to do.
Thanks
Vivek
next prev parent reply other threads:[~2013-09-23 17:17 UTC|newest]
Thread overview: 40+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-09-10 21:44 [PATCH 00/16] [RFC PATCH] Signed kexec support Vivek Goyal
2013-09-10 21:44 ` [PATCH 01/16] mm: vm_brk(), align the length to page boundary Vivek Goyal
2013-09-10 21:44 ` [PATCH 02/16] integrity: Add a function to determine digital signature length Vivek Goyal
2013-09-10 21:44 ` [PATCH 03/16] ima: Allow adding more memory locking metadata after digital signature v2 Vivek Goyal
2013-09-10 21:44 ` [PATCH 04/16] integrity: Allow digital signature verification with a given keyring ptr Vivek Goyal
2013-09-11 17:34 ` Mimi Zohar
2013-09-10 21:44 ` [PATCH 05/16] integrity: Export a function to retrieve hash algo used in digital signature Vivek Goyal
2013-09-10 21:44 ` [PATCH 06/16] ima: export new IMA functions for signature verification Vivek Goyal
2013-09-10 21:44 ` [PATCH 07/16] mm: Define a task flag MMF_VM_LOCKED for memlocked tasks and don't allow munlock Vivek Goyal
2013-09-10 21:44 ` [PATCH 08/16] binfmt_elf: Elf executable signature verification Vivek Goyal
2013-09-10 21:44 ` [PATCH 09/16] ima: define functions to appraise memory buffer contents Vivek Goyal
2013-09-10 21:44 ` [PATCH 10/16] keyctl: Introduce a new operation KEYCTL_VERIFY_SIGNATURE Vivek Goyal
2013-09-10 21:44 ` [PATCH 11/16] ptrace: Do not allow ptrace() from unsigned process to signed one Vivek Goyal
2013-09-10 21:44 ` [PATCH 12/16] binfmt_elf: Do not mark process signed if binary has elf interpreter Vivek Goyal
2013-09-10 21:44 ` [PATCH 13/16] kexec: Allow only signed processes to call sys_kexec() in secureboot mode Vivek Goyal
2013-09-10 21:44 ` [PATCH 14/16] kexec: Export sysfs attributes for secureboot and secure modules to user space Vivek Goyal
2013-09-10 22:40 ` Greg KH
2013-09-11 13:44 ` Vivek Goyal
2013-09-10 22:57 ` Josh Boyer
2013-09-11 13:51 ` Vivek Goyal
2013-09-10 21:44 ` [PATCH 15/16] bootparam: Pass acpi_rsdp pointer in bootparam Vivek Goyal
2013-09-10 22:52 ` H. Peter Anvin
2013-09-11 11:44 ` Borislav Petkov
2013-09-11 13:45 ` Vivek Goyal
2013-09-11 14:32 ` Borislav Petkov
2013-09-12 7:34 ` Dave Young
2013-09-12 12:53 ` Borislav Petkov
[not found] ` <20130912131930.GC28500@redhat.com>
2013-09-12 14:25 ` Borislav Petkov
2013-09-12 14:34 ` Matthew Garrett
2013-09-12 14:42 ` Borislav Petkov
2013-09-13 7:12 ` Dave Young
2013-09-13 11:26 ` Borislav Petkov
2013-09-10 21:44 ` [PATCH 16/16] mount: Add a flag to not follow symlink at the end of mount point Vivek Goyal
2013-09-12 3:40 ` [PATCH 00/16] [RFC PATCH] Signed kexec support Greg KH
2013-09-12 11:43 ` Vivek Goyal
2013-09-12 16:17 ` Greg KH
2013-09-12 18:24 ` Mimi Zohar
[not found] ` <20130916142852.GB20753@redhat.com>
2013-09-18 14:51 ` Andrea Adami
2013-09-23 17:15 ` Vivek Goyal [this message]
2013-09-16 14:24 ` Vivek Goyal
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20130923171515.GD10812@redhat.com \
--to=vgoyal@redhat.com \
--cc=akpm@linux-foundation.org \
--cc=andrea.adami@gmail.com \
--cc=d.kasatkin@samsung.com \
--cc=ebiederm@xmission.com \
--cc=greg@kroah.com \
--cc=hpa@zytor.com \
--cc=kexec@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=matthew.garrett@nebula.com \
--cc=zohar@linux.vnet.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).