Re: [PATCH 21/21] MODSIGN: Apply signature checking to modules on module load [ver #3]

2011-12-14 Thread David Howells
Rusty Russell wrote: > > > We can have false positives, but at worst that make us report EINVAL > > > (bad signature) instead of ENOENT (no signature). > > > > EKEYREJECTED please; that way it's the same as RHEL does now. > > OK, sure (who knew that was there?). Second paragraph in the descrip

Re: [PATCH 21/21] MODSIGN: Apply signature checking to modules on module load [ver #3]

2011-12-14 Thread Rusty Russell
On Mon, 12 Dec 2011 16:11:27 +, David Howells wrote: > Rusty Russell wrote: > > > OK, then you need to generate stripped modules as part of the build, > > too. It's a bit of a pain, sure, but hardly a showstopper. > > They'd have to be maximally stripped so that mkinitrd doesn't do anythin