Fwd: [PATCH 0/7] firmware validation

Tim Gardner tim.gardner at canonical.com
Wed Jul 16 14:33:08 UTC 2014


I think this means that we need to start thinking about how to sign and
package firmware.

-------- Original Message --------
Subject: [PATCH 0/7] firmware validation
Date: Mon, 14 Jul 2014 14:38:10 -0700
From: Kees Cook <keescook at chromium.org>
To: linux-kernel at vger.kernel.org
CC: Kees Cook <keescook at chromium.org>, Ming Lei
<ming.lei at canonical.com>, "Luis R. Rodriguez" <mcgrof at suse.com>, Greg
Kroah-Hartman <gregkh at linuxfoundation.org>, James Morris
<james.l.morris at oracle.com>, David Howells <dhowells at redhat.com>,
linux-doc at vger.kernel.org, linux-security-module at vger.kernel.org,
linux-firmware at kernel.org, linux-wireless <linux-wireless at vger.kernel.org>

This creates a new LSM hook to validate the contents (and origin) of
component firmware being provided to the kernel from userspace via the
request_firmware() interface.

Additionally creates a test module and test cases for all of the existing
interfaces as well as the new "fd" interface.

-Kees

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/






More information about the kernel-team mailing list