On Tue, 2023-01-24 at 14:36 +1000, Nicholas Piggin wrote:
> On Fri Jan 20, 2023 at 5:43 PM AEST, Andrew Donnellan wrote:
> > From: Russell Currey
> >
> > Before interacting with the PLPKS, we ask the hypervisor to
> > generate a
> > password for the current boot, which is then required for most
Andrew Donnellan writes:
> On Tue, 2023-01-24 at 14:36 +1000, Nicholas Piggin wrote:
>>
>> > + prop = of_find_property(of_chosen, "ibm,plpks-pw", );
>> > + if (prop) {
>> > + ospasswordlength = (u16)len;
>> > + ospassword = kzalloc(ospasswordlength,
On Tue, 2023-01-24 at 14:36 +1000, Nicholas Piggin wrote:
>
> > + prop = of_find_property(of_chosen, "ibm,plpks-pw", );
> > + if (prop) {
> > + ospasswordlength = (u16)len;
> > + ospassword = kzalloc(ospasswordlength, GFP_KERNEL);
> > + if
On Fri Jan 20, 2023 at 5:43 PM AEST, Andrew Donnellan wrote:
> From: Russell Currey
>
> Before interacting with the PLPKS, we ask the hypervisor to generate a
> password for the current boot, which is then required for most further
> PLPKS operations.
>
> If we kexec into a new kernel, the new
From: Russell Currey
Before interacting with the PLPKS, we ask the hypervisor to generate a
password for the current boot, which is then required for most further
PLPKS operations.
If we kexec into a new kernel, the new kernel will try and fail to
generate a new password, as the password has