Re: [PATCH V3 11/11] Add option to automatically enforce modulesignatures when in Secure Boot mode

From: Matthew Garrett
Date: Thu Sep 05 2013 - 08:54:50 EST


On Thu, 2013-09-05 at 11:16 +0100, Matt Fleming wrote:

> I'd advise checking efi_enabled(EFI_BOOT) along with .secure_boot to
> guard against garbage values in boot_params.

We've called sanitize_boot_params(), so we can assert that there are no
garbage values.

--
Matthew Garrett <matthew.garrett@xxxxxxxxxx>
¢éì®&Þ~º&¶¬–+-±éÝ¥Šw®žË±Êâmébžìdz¹Þ)í…æèw*jg¬±¨¶‰šŽŠÝj/êäz¹ÞŠà2ŠÞ¨è­Ú&¢)ß«a¶Úþø®G«éh®æj:+v‰¨Šwè†Ù>Wš±êÞiÛaxPjØm¶Ÿÿà -»+ƒùdš_