[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <1378385681.13193.27.camel@x230>
Date: Thu, 5 Sep 2013 12:54:41 +0000
From: Matthew Garrett <matthew.garrett@...ula.com>
To: Matt Fleming <matt@...sole-pimps.org>
CC: "linux-kernel@...r.kernel.org" <linux-kernel@...r.kernel.org>,
"linux-efi@...r.kernel.org" <linux-efi@...r.kernel.org>,
"keescook@...omium.org" <keescook@...omium.org>,
"hpa@...or.com" <hpa@...or.com>
Subject: Re: [PATCH V3 11/11] Add option to automatically enforce module
signatures when in Secure Boot mode
On Thu, 2013-09-05 at 11:16 +0100, Matt Fleming wrote:
> I'd advise checking efi_enabled(EFI_BOOT) along with .secure_boot to
> guard against garbage values in boot_params.
We've called sanitize_boot_params(), so we can assert that there are no
garbage values.
--
Matthew Garrett <matthew.garrett@...ula.com>
Powered by blists - more mailing lists