Re: [PATCH] ima: Fix undefined arch_ima_get_secureboot() and co
From: Mimi Zohar <zohar@linux.ibm.com>
Date: 2021-12-14 15:31:36
Also in:
lkml
From: Mimi Zohar <zohar@linux.ibm.com>
Date: 2021-12-14 15:31:36
Also in:
lkml
Hi Takashi, On Mon, 2021-12-13 at 17:11 +0100, Takashi Iwai wrote:
Currently arch_ima_get_secureboot() and arch_get_ima_policy() are defined only when CONFIG_IMA is set, and this makes the code calling those functions without CONFIG_IMA failing. Although there is no such in-tree users, but the out-of-tree users already hit it. Move the declaration and the dummy definition of those functions outside ifdef-CONFIG_IMA block for fixing the undefined symbols. Signed-off-by: Takashi Iwai <redacted>
Before lockdown was upstreamed, we made sure that IMA and lockdown could co-exist. This patch makes the stub functions available even when IMA is not configured. Do the remaining downstream patches require IMA to be disabled or can IMA co-exist? thanks, Mimi