Thread (11 messages) 11 messages, 3 authors, 2019-06-03

Re: [PATCH v2] Allow to exclude specific file types in LoadPin

From: James Morris <jmorris@namei.org>
Date: 2019-05-30 20:11:58
Also in: linux-doc, lkml

On Thu, 30 May 2019, Ke Wu wrote:
Linux kernel already provide MODULE_SIG and KEXEC_VERIFY_SIG to
make sure loaded kernel module and kernel image are trusted. This
patch adds a kernel command line option "loadpin.exclude" which
allows to exclude specific file types from LoadPin. This is useful
when people want to use different mechanisms to verify module and
kernel image while still use LoadPin to protect the integrity of
other files kernel loads.

Signed-off-by: Ke Wu <redacted>
---
Changelog since v1:
- Mark ignore_read_file_id with __ro_after_init.
- Mark parse_exclude() with __init.
- Use ARRAY_SIZE(ignore_read_file_id) instead of READING_MAX_ID.
Looks good!

Reviewed-by: James Morris <redacted>


-- 
James Morris
[off-list ref]
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help