]> git.baikalelectronics.ru Git - kernel.git/commit
powerpc/ima: Indicate kernel modules appended signatures are enforced
authorMimi Zohar <zohar@linux.ibm.com>
Thu, 31 Oct 2019 03:31:34 +0000 (23:31 -0400)
committerMichael Ellerman <mpe@ellerman.id.au>
Tue, 12 Nov 2019 01:25:50 +0000 (12:25 +1100)
commit9e9dc8483ae9a8243ab1c9c0546cae0924c53f05
treeede50dc372aaae6c783e2dc43cbfee9c238ddaaf
parent5180f1328863cdc245a1b6f1c1c80b8cee3a338e
powerpc/ima: Indicate kernel modules appended signatures are enforced

The arch specific kernel module policy rule requires kernel modules to
be signed, either as an IMA signature, stored as an xattr, or as an
appended signature. As a result, kernel modules appended signatures
could be enforced without "sig_enforce" being set or reflected in
/sys/module/module/parameters/sig_enforce. This patch sets
"sig_enforce".

Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Link: https://lore.kernel.org/r/1572492694-6520-10-git-send-email-zohar@linux.ibm.com
arch/powerpc/kernel/ima_arch.c