On 12.05.2025 21:56, Kevin Lampis wrote: > The intention of lockdown mode is to prevent attacks from a rogue dom0 > userspace from compromising the system. Lockdown mode can be controlled by a > Kconfig option and a command-line parameter. It is also enabled automatically > when Secure Boot is enabled and it cannot be disabled in that case. > > Ross Lagerwall (2): > efi: Add a function to check if Secure Boot mode is enabled > Add lockdown mode > > Kevin Lampis (1): > Disallow most command-line options when lockdown mode is enabled
This looks to be a plain re-posting, without addressing comments already given. For my part, I'm not going to repeat them on this (now properly threaded) re-submission. Jan