Thread (32 messages) 32 messages, 4 authors, 2017-02-03

[PATCH 6/7] efi: Handle secure boot from UEFI-2.6 [ver #7]

From: Ard Biesheuvel <hidden>
Date: 2017-02-01 14:44:52
Also in: linux-efi, lkml

On 1 February 2017 at 12:33, David Howells [off-list ref] wrote:
Ard Biesheuvel [off-list ref] wrote:
quoted
So this patch should take AuditMode into account, but not DeployedMode, i.e.,

SecureBoot == 0x1
SetupMode == 0x0
AuditMode == 0x0 (or non-existent)
If we're in audit mode or setup mode SecureBoot==0 and SetupMode==1 according
to the flowchart, so the check of AuditMode would seem redundant.

Further, the checks above don't seem to differentiate deployed mode from user
mode.  Should they?
From the OS pov, UserMode and DeployedMode are the same, the only
difference being that AuditMode may be entered from UserMode simply by
setting the variable to 0x1 (which can only be done before
ExitBootServices()). And since AuditMode implies SetupMode (according
to the diagram), you are right that we don't need to care about
AuditMode either. AFAICT, that makes the entire patch unnecessary, so
let's drop it for now.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help