Re: [PATCH] e1000e: write protect ICHx NVM to prevent maliciouswrite/erase

From: Jiri Kosina
Date: Thu Oct 02 2008 - 06:00:39 EST


On Wed, 1 Oct 2008, Jesse Brandeburg wrote:

> Set the hardware to ignore all write/erase cycles to the GbE region in
> the ICHx NVM. This feature can be disabled by the WriteProtectNVM
> module parameter (enabled by default) only after a hardware reset, but
> the machine must be power cycled before trying to enable writes.

Hi,

thanks. We have been running our tests with complete pileup of 12 patches
from Intel, and the bug didn't trigger so far (and it triggers now pretty
reliably with the unpatched kernel in the setup Karsten has established in
our testing environment).

So the patches really seem, as far as our current testing goes, to
at least workaround the problem.

I will now try to isolate which of the patches really fixes the problem,
so that we could understand better what is going on and who is causing the
corruption.

Do you think it would be possible to adapt this particular patch so that
it spits out watnin/stacktrace when write and/or erase cycle is attempted
but denied?

Thanks,

--
Jiri Kosina
SUSE Labs

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/