lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date:	Thu, 04 Jul 2013 03:56:23 +0100
From:	Ben Hutchings <ben@...adent.org.uk>
To:	Sherry Hurwitz <sherry.hurwitz@....com>
Cc:	David Woodhouse <dwmw2@...radead.org>,
	linux-kernel@...r.kernel.org, amd64-microcode@...64.org
Subject: Re: [PATCH 1/1] linux-firmware: Add AMD microcode patch firmware
 files

On Fri, 2013-06-28 at 14:27 -0500, Sherry Hurwitz wrote:
> For AMD Families 10h ~ 14h Processors
> file:   amd-ucode/microcode_amd.bin
> md5sum: 55ae79b82cbfddcf7142058be3c9ec2d
> 
> For AMD Family 15h Processors
> file:   amd-ucode/microcode_amd_fam15h.bin
> md5sum: 122ac7e56442c2b7c28eb26978b2d57c
> 
> Signed-off-by: Sherry Hurwitz <sherry.hurwitz@....com>
> ---
>  LICENSE.amd-ucode                  |   64 ++++++++++++++++++++++++++++++++++++
>  WHENCE                             |    9 +++++
>  amd-ucode/microcode_amd.bin        |  Bin 0 -> 12684 bytes
>  amd-ucode/microcode_amd_fam15h.bin |  Bin 0 -> 7876 bytes
>  4 files changed, 73 insertions(+)
>  create mode 100644 LICENSE.amd-ucode
>  create mode 100644 amd-ucode/microcode_amd.bin
>  create mode 100644 amd-ucode/microcode_amd_fam15h.bin
[...]
> --- a/WHENCE
> +++ b/WHENCE
> @@ -2169,3 +2169,12 @@ File: go7007/wis-startrek.fw
>  Licence: Redistributable. See LICENCE.go7007_firmware for details
>  
>  --------------------------------------------------------------------------
> +
> +Driver: microcode_amd - AMD CPU Microcode Update Driver for Linux
> +
> +File: amd-ucode/microcode_amd.bin
> +File: amd-ucode/microcode_amd_fam15h.bin
> +
> +License: Redistributable. See LICENSE.amd-ucode for details
[...]

Please include the version number.

I notice that the download page on amd64.org also has GPG signatures.
Perhaps those should be included too?

(Actually, I would like to see verifiable signatures on all binary
firmware, but I don't think that can be made a requirement any time
soon.  Key 9F94BC90 isn't signed by another published key, so I still
have no reason to trust its identity.)

Ben.

-- 
Ben Hutchings
Tomorrow will be cancelled due to lack of interest.

Download attachment "signature.asc" of type "application/pgp-signature" (829 bytes)

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ