lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Thu, 9 Nov 2017 17:31:45 +0000 From: David Howells <dhowells@...hat.com> To: linux-security-module@...r.kernel.org Cc: gnomes@...rguk.ukuu.org.uk, linux-efi@...r.kernel.org, dhowells@...hat.com, linux-kernel@...r.kernel.org, jforbes@...hat.com Subject: [PATCH 09/30] hibernate: Disable when the kernel is locked down From: Josh Boyer <jwboyer@...oraproject.org> There is currently no way to verify the resume image when returning from hibernate. This might compromise the signed modules trust model, so until we can work with signed hibernate images we disable it when the kernel is locked down. Signed-off-by: Josh Boyer <jwboyer@...oraproject.org> Signed-off-by: David Howells <dhowells@...hat.com> Reviewed-by: "Lee, Chun-Yi" <jlee@...e.com> cc: linux-pm@...r.kernel.org --- kernel/power/hibernate.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/kernel/power/hibernate.c b/kernel/power/hibernate.c index a5c36e9c56a6..f2eafefeec50 100644 --- a/kernel/power/hibernate.c +++ b/kernel/power/hibernate.c @@ -70,7 +70,7 @@ static const struct platform_hibernation_ops *hibernation_ops; bool hibernation_available(void) { - return (nohibernate == 0); + return nohibernate == 0 && !kernel_is_locked_down("Hibernation"); } /**
Powered by blists - more mailing lists