On Tue, Sep 04, 2012 at 10:30:46AM -0600, Shuah Khan wrote: > On Tue, Sep 4, 2012 at 9:55 AM, Matthew Garrett <mjg@xxxxxxxxxx> wrote: > > From: Josh Boyer <jwboyer@xxxxxxxxxx> > > > > This option allows userspace to pass the RSDP address to the kernel. This > > could potentially be used to circumvent the secure boot trust model. > > We ignore the setting if we don't have the CAP_SECURE_FIRMWARE capability. > > Does this mean, acpi_rsdp is disabled on all current platforms that > don't support CAP_SECURE_FIRMWARE? No, if you're not using secure boot then you'll have CAP_SECURE_FIRMWARE. -- Matthew Garrett | mjg59@xxxxxxxxxxxxx -- To unsubscribe from this list: send the line "unsubscribe linux-efi" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html