Re: [PATCH v2] i386-pc: build verifiers API as module

2021-08-22 Thread Didier Spaier
Le 22/08/2021 à 21:50, Michael Schierl a écrit : On Fri, 16 Apr 2021 22:23:39 +0100, Colin Watson wrote: I have on my to-do list an item to add something to the Debian release notes about this, since that's a way to reach less-engaged users who won't read the GRUB manual or mailing lists.  That

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-08-22 Thread Michael Schierl
Hello, On Fri, 16 Apr 2021 22:23:39 +0100, Colin Watson wrote: I have on my to-do list an item to add something to the Debian release notes about this, since that's a way to reach less-engaged users who won't read the GRUB manual or mailing lists. That will likely help to some extent, althoug

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-04-28 Thread Daniel Kiper
Hi all, On Tue, Apr 20, 2021 at 11:49:09AM +0800, Michael Chang via Grub-devel wrote: > On Wed, Apr 14, 2021 at 03:22:35PM +0200, Daniel Kiper wrote: > > On Tue, Apr 13, 2021 at 12:13:02PM +0800, Michael Chang via Grub-devel > > wrote: > > > On Mon, Apr 12, 2021 at 03:15:53PM +0200, Daniel Kiper

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-04-19 Thread Michael Chang via Grub-devel
On Wed, Apr 14, 2021 at 03:22:35PM +0200, Daniel Kiper wrote: > On Tue, Apr 13, 2021 at 12:13:02PM +0800, Michael Chang via Grub-devel wrote: > > On Mon, Apr 12, 2021 at 03:15:53PM +0200, Daniel Kiper wrote: > > > On Fri, Mar 26, 2021 at 06:01:01PM +0100, Daniel Kiper wrote: > > > > On Wed, Mar 24,

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-04-16 Thread Colin Watson
On Wed, Apr 14, 2021 at 03:22:35PM +0200, Daniel Kiper wrote: > On Tue, Apr 13, 2021 at 12:13:02PM +0800, Michael Chang via Grub-devel wrote: > > On Mon, Apr 12, 2021 at 03:15:53PM +0200, Daniel Kiper wrote: > > > On Fri, Mar 26, 2021 at 06:01:01PM +0100, Daniel Kiper wrote: > > > > After some thin

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-04-14 Thread Daniel Kiper
On Tue, Apr 13, 2021 at 12:13:02PM +0800, Michael Chang via Grub-devel wrote: > On Mon, Apr 12, 2021 at 03:15:53PM +0200, Daniel Kiper wrote: > > On Fri, Mar 26, 2021 at 06:01:01PM +0100, Daniel Kiper wrote: > > > On Wed, Mar 24, 2021 at 12:44:52PM +0800, Michael Chang via Grub-devel > > > wrote:

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-04-12 Thread Michael Chang via Grub-devel
On Mon, Apr 12, 2021 at 03:15:53PM +0200, Daniel Kiper wrote: > On Fri, Mar 26, 2021 at 06:01:01PM +0100, Daniel Kiper wrote: > > On Wed, Mar 24, 2021 at 12:44:52PM +0800, Michael Chang via Grub-devel > > wrote: > > > On Tue, Mar 23, 2021 at 05:33:12PM +0100, Daniel Kiper wrote: > > > > On Mon, Ma

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-04-12 Thread Daniel Kiper
On Fri, Mar 26, 2021 at 06:01:01PM +0100, Daniel Kiper wrote: > On Wed, Mar 24, 2021 at 12:44:52PM +0800, Michael Chang via Grub-devel wrote: > > On Tue, Mar 23, 2021 at 05:33:12PM +0100, Daniel Kiper wrote: > > > On Mon, Mar 22, 2021 at 08:45:27PM +, Colin Watson wrote: > > > > [snip] > > > >

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-03-26 Thread Daniel Kiper
On Wed, Mar 24, 2021 at 11:50:56AM +0800, Michael Chang wrote: > On Tue, Mar 23, 2021 at 05:48:01PM +0100, Daniel Kiper wrote: > > On Tue, Mar 23, 2021 at 12:16:21PM +0800, Michael Chang via Grub-devel > > wrote: > > > On Mon, Mar 22, 2021 at 04:20:00PM +0100, Daniel Kiper wrote: > > > > On Thu, M

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-03-26 Thread Daniel Kiper
On Wed, Mar 24, 2021 at 12:44:52PM +0800, Michael Chang via Grub-devel wrote: > On Tue, Mar 23, 2021 at 05:33:12PM +0100, Daniel Kiper wrote: > > On Mon, Mar 22, 2021 at 08:45:27PM +, Colin Watson wrote: > > [snip] > > > > rounds of security megapatches we've also seen that the amount of > > >

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-03-23 Thread Michael Chang via Grub-devel
On Tue, Mar 23, 2021 at 05:33:12PM +0100, Daniel Kiper wrote: > On Mon, Mar 22, 2021 at 08:45:27PM +, Colin Watson wrote: [snip] > > rounds of security megapatches we've also seen that the amount of > > divergence between upstream and various distributions in > > security-critical code is in

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-03-23 Thread Michael Chang via Grub-devel
On Tue, Mar 23, 2021 at 05:48:01PM +0100, Daniel Kiper wrote: > On Tue, Mar 23, 2021 at 12:16:21PM +0800, Michael Chang via Grub-devel wrote: > > On Mon, Mar 22, 2021 at 04:20:00PM +0100, Daniel Kiper wrote: > > > On Thu, Mar 18, 2021 at 07:30:26PM +0800, Michael Chang via Grub-devel > > > wrote:

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-03-23 Thread Lennart Sorensen
On Tue, Mar 23, 2021 at 05:33:12PM +0100, Daniel Kiper wrote: > How long are you going to support such systems? 1, 5 or 10 years? This > approach makes GRUB upstream as a hostage of small MBR gaps users. > Anyway, I think we have to make users aware that small MBR gaps are not > supported any longe

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-03-23 Thread Daniel Kiper
On Tue, Mar 23, 2021 at 01:27:15PM +, Colin Watson wrote: > On Tue, Mar 23, 2021 at 12:37:20PM +0100, Javier Martinez Canillas wrote: > > On 3/23/21 5:16 AM, Michael Chang wrote > > > Afterall, keeping existing running system to survive update (NOT new > > > install) is really an important thin

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-03-23 Thread Daniel Kiper
On Tue, Mar 23, 2021 at 12:16:21PM +0800, Michael Chang via Grub-devel wrote: > On Mon, Mar 22, 2021 at 04:20:00PM +0100, Daniel Kiper wrote: > > On Thu, Mar 18, 2021 at 07:30:26PM +0800, Michael Chang via Grub-devel > > wrote: > > [snip] > > > NAK for this patch and others "fixing" small MBR gaps

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-03-23 Thread Daniel Kiper
On Mon, Mar 22, 2021 at 08:45:27PM +, Colin Watson wrote: > On Mon, Mar 22, 2021 at 03:19:06PM -0500, Glenn Washburn wrote: > > On Mon, 22 Mar 2021 16:16:26 + > > Colin Watson wrote: > > > On Mon, Mar 22, 2021 at 04:20:00PM +0100, Daniel Kiper wrote: > > > > NAK for this patch and others "

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-03-23 Thread Javier Martinez Canillas
On 3/23/21 2:27 PM, Colin Watson wrote: > On Tue, Mar 23, 2021 at 12:37:20PM +0100, Javier Martinez Canillas wrote: [snip] >> >> For this particular case, it might be better for distros to just revert >> commit >> 9e95f45ceee ("verifiers: Move verifiers API to kernel image") instead of >> makin

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-03-23 Thread Colin Watson
On Tue, Mar 23, 2021 at 12:37:20PM +0100, Javier Martinez Canillas wrote: > On 3/23/21 5:16 AM, Michael Chang wrote > > Afterall, keeping existing running system to survive update (NOT new > > install) is really an important thing as many can't afford that to > > happen. If we can make it any bette

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-03-23 Thread Javier Martinez Canillas
On 3/23/21 5:16 AM, Michael Chang wrote [snip] > > Afterall, keeping existing running system to survive update (NOT new > install) is really an important thing as many can't afford that to > happen. If we can make it any better to reduce the cost please consider > to do it. It doesn't conflict w

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-03-22 Thread Michael Chang via Grub-devel
On Mon, Mar 22, 2021 at 04:20:00PM +0100, Daniel Kiper wrote: > On Thu, Mar 18, 2021 at 07:30:26PM +0800, Michael Chang via Grub-devel wrote: [snip] > NAK for this patch and others "fixing" small MBR gaps. I am not going to > deal with this kind of issues any longer because a few folks in the > w

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-03-22 Thread James Bottomley
On Mon, 2021-03-22 at 15:19 -0500, Glenn Washburn wrote: > On Mon, 22 Mar 2021 16:16:26 + > Colin Watson wrote: > > > On Mon, Mar 22, 2021 at 04:20:00PM +0100, Daniel Kiper wrote: > > > NAK for this patch and others "fixing" small MBR gaps. I am not > > > going to deal with this kind of issue

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-03-22 Thread Colin Watson
On Mon, Mar 22, 2021 at 03:19:06PM -0500, Glenn Washburn wrote: > On Mon, 22 Mar 2021 16:16:26 + > Colin Watson wrote: > > On Mon, Mar 22, 2021 at 04:20:00PM +0100, Daniel Kiper wrote: > > > NAK for this patch and others "fixing" small MBR gaps. I am not > > > going to deal with this kind of i

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-03-22 Thread Glenn Washburn
On Mon, 22 Mar 2021 16:16:26 + Colin Watson wrote: > On Mon, Mar 22, 2021 at 04:20:00PM +0100, Daniel Kiper wrote: > > NAK for this patch and others "fixing" small MBR gaps. I am not > > going to deal with this kind of issues any longer because a few > > folks in the world cannot/do not want/

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-03-22 Thread Colin Watson
On Mon, Mar 22, 2021 at 04:16:26PM +, Colin Watson wrote: > On Mon, Mar 22, 2021 at 04:20:00PM +0100, Daniel Kiper wrote: > > NAK for this patch and others "fixing" small MBR gaps. I am not going to > > deal with this kind of issues any longer because a few folks in the > > world cannot/do not

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-03-22 Thread Colin Watson
On Mon, Mar 22, 2021 at 04:20:00PM +0100, Daniel Kiper wrote: > NAK for this patch and others "fixing" small MBR gaps. I am not going to > deal with this kind of issues any longer because a few folks in the > world cannot/do not want/... reinstall their systems. Sorry guys. I'd just like to say th

Re: [PATCH v2] i386-pc: build verifiers API as module

2021-03-22 Thread Daniel Kiper
On Thu, Mar 18, 2021 at 07:30:26PM +0800, Michael Chang via Grub-devel wrote: > Given no core functions on i386-pc would require verifiers to work and > the only consumer of the verifier API is the pgp module, it looks good > to me that we can move the verifiers out of the kernel image and let > mo

[PATCH v2] i386-pc: build verifiers API as module

2021-03-18 Thread Michael Chang via Grub-devel
Given no core functions on i386-pc would require verifiers to work and the only consumer of the verifier API is the pgp module, it looks good to me that we can move the verifiers out of the kernel image and let moddep.lst to auto-load it when pgp is loaded on i386-pc platform. This helps to reduce