That's part of what I meant. Under what circumstances would you want that? In particular, I would expect the kernel command line to form an essential part of the trust chain; if you can change the kernel command line, even if you can't change the kernel, that seems like enough to break security.
Power management, mobile and firmware developer on Linux. Security developer at Aurora. Ex-biologist. mjg59 on Twitter. Content here should not be interpreted as the opinion of my employer. Also on Mastodon.
no subject
Date: 2015-09-28 05:29 pm (UTC)