On 10/22/2012 02:15 PM, Eric W. Biederman wrote: >> >> This is like re-designing the kexec/kdump and I really wish there is >> an easier way to handle the case signed kernels. > > Yes. Which is why either a signed puragtory or a signed /sbin/kexec > look very attractive. > Signed purgatory sounds like The Right Thing. Doing relocation in purgatory should be quite trivial; I'd be happy to work with people if they need pointers how to do it. -hpa