]> git.ipfire.org Git - people/ms/linux.git/commitdiff
Merge tag 'integrity-v6.0' of git://git.kernel.org/pub/scm/linux/kernel/git/zohar...
authorLinus Torvalds <torvalds@linux-foundation.org>
Tue, 2 Aug 2022 22:21:18 +0000 (15:21 -0700)
committerLinus Torvalds <torvalds@linux-foundation.org>
Tue, 2 Aug 2022 22:21:18 +0000 (15:21 -0700)
Pull integrity updates from Mimi Zohar:
 "Aside from the one EVM cleanup patch, all the other changes are kexec
  related.

  On different architectures different keyrings are used to verify the
  kexec'ed kernel image signature. Here are a number of preparatory
  cleanup patches and the patches themselves for making the keyrings -
  builtin_trusted_keyring, .machine, .secondary_trusted_keyring, and
  .platform - consistent across the different architectures"

* tag 'integrity-v6.0' of git://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity:
  kexec, KEYS, s390: Make use of built-in and secondary keyring for signature verification
  arm64: kexec_file: use more system keyrings to verify kernel image signature
  kexec, KEYS: make the code in bzImage64_verify_sig generic
  kexec: clean up arch_kexec_kernel_verify_sig
  kexec: drop weak attribute from functions
  kexec_file: drop weak attribute from functions
  evm: Use IS_ENABLED to initialize .enabled

1  2 
arch/x86/kernel/kexec-bzimage64.c
security/integrity/evm/evm_main.c

index b9bdb40364a62d1a89b791f8edbb576e14cb48f0,f299b48f9c9f0c4f44724e4c723985a45239d7a2..6b58610a15521da6323b856e14f7dbe8bcb3ed28
@@@ -17,8 -17,6 +17,7 @@@
  #include <linux/kernel.h>
  #include <linux/mm.h>
  #include <linux/efi.h>
- #include <linux/verification.h>
 +#include <linux/random.h>
  
  #include <asm/bootparam.h>
  #include <asm/setup.h>
Simple merge