Re: arm64 crashkernel fails to boot on acpi-only machines due to ACPI regions being no longer mapped as NOMAP

2017-11-15 Thread AKASHI Takahiro
Bhupesh, On Wed, Nov 15, 2017 at 04:28:55PM +0530, Bhupesh Sharma wrote: > (snip) > # dmesg | grep -B 2 -i "ACPI reclaim" > [0.00] efi: 0x3967-0x396b [Runtime Code |RUN| | > | | | | | |WB|WT|WC|UC] > [0.00] efi: 0x396c-0x3970 [Boot

Re: Firmware signing -- Re: [PATCH 00/27] security, efi: Add kernel lockdown

2017-11-15 Thread Mimi Zohar
On Wed, 2017-11-15 at 21:46 +0100, Luis R. Rodriguez wrote: > On Wed, Nov 15, 2017 at 02:56:57PM -0500, Mimi Zohar wrote: > > On Wed, 2017-11-15 at 18:52 +0100, Luis R. Rodriguez wrote: > > > On Wed, Nov 15, 2017 at 06:49:57AM -0500, Mimi Zohar wrote: > > > > On Tue, 2017-11-14 at 21:50 +0100,

Re: Draft manpage explaining kernel lockdown

2017-11-15 Thread Pavel Machek
Hi! > Attached is a draft for a manual page (kernel_lockdown.7) that I intend to > point at from messages emitted when the kernel prohibits something because the > kernel is in 'lockdown' mode, typically triggered by EFI secure > boot. What about livepatching? It allows kernel modifications..

Re: Firmware signing -- Re: [PATCH 00/27] security, efi: Add kernel lockdown

2017-11-15 Thread Luis R. Rodriguez
On Wed, Nov 15, 2017 at 02:56:57PM -0500, Mimi Zohar wrote: > On Wed, 2017-11-15 at 18:52 +0100, Luis R. Rodriguez wrote: > > On Wed, Nov 15, 2017 at 06:49:57AM -0500, Mimi Zohar wrote: > > > On Tue, 2017-11-14 at 21:50 +0100, Luis R. Rodriguez wrote: > > > > > > > Johannes made cfg80211 recently

Re: Firmware signing -- Re: [PATCH 00/27] security, efi: Add kernel lockdown

2017-11-15 Thread Mimi Zohar
On Wed, 2017-11-15 at 18:52 +0100, Luis R. Rodriguez wrote: > On Wed, Nov 15, 2017 at 06:49:57AM -0500, Mimi Zohar wrote: > > On Tue, 2017-11-14 at 21:50 +0100, Luis R. Rodriguez wrote: > > > > > Johannes made cfg80211 recently just use request_firmware() now via > > > commit on > > > linux-next

Re: Firmware signing -- Re: [PATCH 00/27] security, efi: Add kernel lockdown

2017-11-15 Thread Luis R. Rodriguez
On Wed, Nov 15, 2017 at 06:49:57AM -0500, Mimi Zohar wrote: > On Tue, 2017-11-14 at 21:50 +0100, Luis R. Rodriguez wrote: > > > Johannes made cfg80211 recently just use request_firmware() now via commit > > on > > linux-next 90a53e4432 ("cfg80211: implement regdb signature checking") [0] > > as

Re: [v3,2/2] arm64: Add software workaround for Falkor erratum 1041

2017-11-15 Thread Manoj Iyer
On Sun, 12 Nov 2017, Shanker Donthineni wrote: The ARM architecture defines the memory locations that are permitted to be accessed as the result of a speculative instruction fetch from an exception level for which all stages of translation are disabled. Specifically, the core is permitted to

Re: [3/3] arm64: Add software workaround for Falkor erratum 1041

2017-11-15 Thread Manoj Iyer
On Fri, 10 Nov 2017, Manoj Iyer wrote: On Thu, 9 Nov 2017, Manoj Iyer wrote: James, Looks like my VM test raised a false alarm. I retested stock Artful 4.13 kernel (No erratum 1041 patches applied). James, an update on the crash (false alarm). We suspect this is a firmware crash due

Re: Firmware signing -- Re: [PATCH 00/27] security, efi: Add kernel lockdown

2017-11-15 Thread Mimi Zohar
On Tue, 2017-11-14 at 21:50 +0100, Luis R. Rodriguez wrote: > Johannes made cfg80211 recently just use request_firmware() now via commit on > linux-next 90a53e4432 ("cfg80211: implement regdb signature checking") [0] as > he got tired of waiting firmware signing, but note he implemented a

Hello Dear...

2017-11-15 Thread M,Shakour Rosarita
Hello Dear... I know that this message will come to you as a surprise. I hoped that you will not expose or betray this trust and confident that I am about to repose on you, my name is M, Shakour Rosarita. I am 19 years old Girl, female, from Tartu Syria, (never married) 61 kg, white in

Re: arm64 crashkernel fails to boot on acpi-only machines due to ACPI regions being no longer mapped as NOMAP

2017-11-15 Thread Bhupesh Sharma
Hi Ard, Akashi, On 11/14/2017 04:50 PM, Ard Biesheuvel wrote: On 13 November 2017 at 09:27, AKASHI Takahiro wrote: Hi, On Fri, Nov 10, 2017 at 05:41:56PM +0530, Bhupesh Sharma wrote: Resent with Akashi's correct email address. On Fri, Nov 10, 2017 at 5:39 PM,