Re: [PATCH] e1000e: write protect ICHx NVM to prevent malicious write/erase

From: Arjan van de Ven
Date: Wed Oct 01 2008 - 21:33:53 EST


Linus Torvalds wrote:

On Wed, 1 Oct 2008, Jesse Brandeburg wrote:
From: Bruce Allan <bruce.w.allan@xxxxxxxxx>

Set the hardware to ignore all write/erase cycles to the GbE region in
the ICHx NVM. This feature can be disabled by the WriteProtectNVM module
parameter (enabled by default) only after a hardware reset, but
the machine must be power cycled before trying to enable writes.

Thanks, applied.

One thing that I did notice when I looked at the driver is that I don't see any serialization what-so-ever around a lot of the special accesses.


there's quite a few of that yes.
These are all fixed afaik but these fixes are being queued for 2.6.28 rather than being snuck in late into .27
(the patches have been posted to lkml a few times the last week)
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/