Re: [PATCH v4 0/8] kexec/firmware: support system wide policy requiring signatures

From: Kees Cook
Date: Tue Jun 05 2018 - 08:20:00 EST


On Mon, Jun 4, 2018 at 9:09 PM, Serge E. Hallyn <serge@xxxxxxxxxx> wrote:
> Personally I agree with Eric and prefer a new hook. I don't feel strongly
> enough about it to keep bikeshedding, but since this set already exists,
> it seems like the way to go.

And the new hook is "load stuff without a file descriptor"?

-Kees

--
Kees Cook
Pixel Security