]> git.baikalelectronics.ru Git - kernel.git/commit
ima: based on policy require signed firmware (sysfs fallback)
authorMimi Zohar <zohar@linux.vnet.ibm.com>
Fri, 13 Jul 2018 18:06:00 +0000 (14:06 -0400)
committerJames Morris <james.morris@microsoft.com>
Mon, 16 Jul 2018 19:31:57 +0000 (12:31 -0700)
commitc87a1e8b3ae7da47388895962d9867bd1af74905
treeff667da0a4a8e305409d7c5323c58c7852e40e3b
parent696cd0655171c9947fc2605f71676e8a176f7afd
ima: based on policy require signed firmware (sysfs fallback)

With an IMA policy requiring signed firmware, this patch prevents
the sysfs fallback method of loading firmware.

Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Reviewed-by: Kees Cook <keescook@chromium.org>
Cc: Luis R. Rodriguez <mcgrof@suse.com>
Cc: Matthew Garrett <mjg59@google.com>
Signed-off-by: James Morris <james.morris@microsoft.com>
security/integrity/ima/ima_main.c