Thread (58 messages) 58 messages, 10 authors, 2019-06-25

Re: [PATCH V31 07/25] kexec_file: Restrict at runtime if the kernel is locked down

From: Matthew Garrett <hidden>
Date: 2019-06-25 00:02:43
Also in: kexec, linux-security-module, lkml

On Mon, Jun 24, 2019 at 2:27 PM Mimi Zohar [off-list ref] wrote:
I agree with Dave.  There should be a stub lockdown function to
prevent enforcing lockdown when it isn't enabled.
Sorry, when what isn't enabled? If no LSMs are enforcing lockdown then
the check will return 0. The goal here is for distributions to be able
to ship a kernel that has CONFIG_KEXEC_SIG=y, CONFIG_KEXEC_SIG_FORCE=n
and at runtime be able to enforce a policy that requires signatures on
kexec payloads.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help