diff options
author | Thorsten Leemhuis <fedora@leemhuis.info> | 2020-03-21 06:22:28 +0100 |
---|---|---|
committer | Thorsten Leemhuis <fedora@leemhuis.info> | 2020-03-21 06:22:28 +0100 |
commit | 2b1c0c48627fe757dafbd0c2c51ee6124e15181c (patch) | |
tree | 6622cb6461cae448c5838a049f787c5997f3f987 /s390-Lock-down-the-kernel-when-the-IPL-secure-flag-i.patch | |
parent | 7ffee9e655f6d3c8ae7a1d7006377947be014cc6 (diff) | |
parent | 8323383234985150c0578cc47e885d7d6fe72759 (diff) | |
download | kernel-2b1c0c48627fe757dafbd0c2c51ee6124e15181c.tar.gz kernel-2b1c0c48627fe757dafbd0c2c51ee6124e15181c.tar.xz kernel-2b1c0c48627fe757dafbd0c2c51ee6124e15181c.zip |
merge masterkernel-5.6.0-0.rc6.git2.1.vanilla.knurd.1.fc33kernel-5.6.0-0.rc6.git2.1.vanilla.knurd.1.fc32kernel-5.6.0-0.rc6.git2.1.vanilla.knurd.1.fc31kernel-5.6.0-0.rc6.git2.1.vanilla.knurd.1.fc30
Diffstat (limited to 's390-Lock-down-the-kernel-when-the-IPL-secure-flag-i.patch')
-rw-r--r-- | s390-Lock-down-the-kernel-when-the-IPL-secure-flag-i.patch | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/s390-Lock-down-the-kernel-when-the-IPL-secure-flag-i.patch b/s390-Lock-down-the-kernel-when-the-IPL-secure-flag-i.patch index 0779418b4..70e3f76a8 100644 --- a/s390-Lock-down-the-kernel-when-the-IPL-secure-flag-i.patch +++ b/s390-Lock-down-the-kernel-when-the-IPL-secure-flag-i.patch @@ -3,7 +3,7 @@ From: Jeremy Cline <jcline@redhat.com> Date: Wed, 30 Oct 2019 14:37:49 +0000 Subject: [PATCH] s390: Lock down the kernel when the IPL secure flag is set -Automatically lock down the kernel to LOCKDOWN_CONFIDENTIALITY_MAX if +Automatically lock down the kernel to LOCKDOWN_INTEGRITY_MAX if the IPL secure flag is set. Suggested-by: Philipp Rudo <prudo@redhat.com> @@ -56,7 +56,7 @@ index 9cbf490fd162..0510ecdfc3f6 100644 log_component_list(); + if (ipl_get_secureboot()) -+ security_lock_kernel_down("Secure IPL mode", LOCKDOWN_CONFIDENTIALITY_MAX); ++ security_lock_kernel_down("Secure IPL mode", LOCKDOWN_INTEGRITY_MAX); + /* Have one command line that is parsed and saved in /proc/cmdline */ /* boot_command_line has been already set up in early.c */ |