Gentoo Archives: gentoo-dev

From: Richard Yao <ryao@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Re: Killing UEFI Secure Boot
Date: Thu, 21 Jun 2012 15:07:59
Message-Id: 4FE33833.90103@gentoo.org
In Reply to: Re: [gentoo-dev] Re: Killing UEFI Secure Boot by Ian Stakenvicius
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 On 06/21/2012 11:00 AM, Ian Stakenvicius wrote:
5 >> A firmware replacement for the BIOS does not need to worry about
6 >> floppy drives, hard drives, optical drives, usb devices, isa
7 >> devices, pci devices and pci express drives, etcetera, because
8 >> those live on buses, which the kernel can detect. It would need
9 >> a device tree to inform the kernel of what buses are available,
10 >> but that would be specific to a given board, rather than what is
11 >> attached to it. If the end user makes hardware changes, the
12 >> kernel should be able to handle that, with the exception of
13 >> changes involving RAM, which I believe go into the device tree.
14 >
15 > I take it the above statement is based on the kernel being
16 > directly placed within the BIOS/firmware/nvram on the board, such
17 > that you couldn't boot anything else but that kernel?
18
19 That is correct.
20
21 > Otherwise I don't see how you could get away with the BIOS not
22 > worrying about all those devices.. IE, I don't forsee many general
23 > x86 users giving up their ability to boot off usb stick or cdrom or
24 > pxe based on a boot-time bios choice, or to boot windows or
25 > alternative linux kernels (which could be located who knows where)
26 > at whim. And I don't see how an alternative BIOS would be able to
27 > provide this ability without dealing with all the things Duncan
28 > mentioned...
29
30 An initramfs should be able to provide all of that functionality.
31 -----BEGIN PGP SIGNATURE-----
32 Version: GnuPG v2.0.17 (GNU/Linux)
33 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
34
35 iQIcBAEBAgAGBQJP4zgzAAoJECDuEZm+6ExkeSUP/0PrjZtnWvbdXpTYwTN/U1wq
36 lVl/nx6mXAq6wwxrhgHMzMvzh68oxqAhZgOASLFoQnO92WbVJzxBZtxBQftR5TGV
37 k5NGVKCLwVkIi7tQGLk3vLHo3l6MnmwCjmfSCSbr7VEqil2hgy5EwhUiWvibzKlp
38 34m9g75Z/JR/dMk7qcG7z2lvJNSDlL2Ufgqi5YPQqqmqsMHGi350ZM91dkilOkV2
39 OtBwJzD+JlvQl+ALBv33KmI37VslcB/ydcx08YfE6BuOkHdusOM6/Den4JUrmS2I
40 WDvcejzgxjneOifoL+0hiM9ooG3L6Q19G3ZNSSqAit85P5ms6Cm9Bul2lO6+EiQu
41 iwYLcH/5nwkVC/8bRaHvzTnSaKyvyip9lKzeZyD9fnsMirxV6R3T3aWyIwhBdb8E
42 pe85C+n4Wd5n4nhuwQW8AP860yftco9aNSrx1uIb+PMEi38+yLTwNjrR/shQ7RcK
43 76mpWIWat/YpLRNF9Va7PN3FaslsTGVyQdgcBtci9S9IXWhwGyc7ZDS7DIq7CYTT
44 9pE9dYqDOmEl0kWt5e4EgrjD4ibwhOsvddBJBcW2spphnRBuHwkzdp7K7pW3KX1z
45 Wj4triKllBLwMJvIcDk6Nv0tm0YO+kzxDhEsjBajjDR48652ijF6RYLi2cV7Ui+9
46 Hnsvgz6oEc7sNL9VbPnZ
47 =Aacv
48 -----END PGP SIGNATURE-----

Replies

Subject Author
Re: [gentoo-dev] Re: Killing UEFI Secure Boot Roy Bamford <neddyseagoon@g.o>