[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-Id: <cover.1635948742.git.msuchanek@suse.de>
Date: Wed, 3 Nov 2021 15:27:05 +0100
From: Michal Suchanek <msuchanek@...e.de>
To: keyrings@...r.kernel.org
Cc: Michal Suchanek <msuchanek@...e.de>,
Michael Ellerman <mpe@...erman.id.au>,
Benjamin Herrenschmidt <benh@...nel.crashing.org>,
Paul Mackerras <paulus@...ba.org>,
Heiko Carstens <hca@...ux.ibm.com>,
Vasily Gorbik <gor@...ux.ibm.com>,
Christian Borntraeger <borntraeger@...ibm.com>,
Alexander Gordeev <agordeev@...ux.ibm.com>,
David Howells <dhowells@...hat.com>,
Luis Chamberlain <mcgrof@...nel.org>,
Jessica Yu <jeyu@...nel.org>, Rob Herring <robh@...nel.org>,
Lakshmi Ramasubramanian <nramas@...ux.microsoft.com>,
Thiago Jung Bauermann <bauerman@...ux.ibm.com>,
Hari Bathini <hbathini@...ux.ibm.com>,
Frank van der Linden <fllinden@...zon.com>,
linuxppc-dev@...ts.ozlabs.org, linux-kernel@...r.kernel.org,
linux-s390@...r.kernel.org
Subject: [PATCH 0/3] KEXEC_SIG with appended signature
S390 uses appended signature for kernel but implements the check
separately from module loader.
Support for secure boot on powerpc with appended signature is planned -
grub patches submitted upstream but not yet merged.
This is an attempt at unified appended signature verification.
Thanks
Michal
Michal Suchanek (3):
s390/kexec_file: Don't opencode appended signature verification.
module: strip the signature marker in the verification function.
powerpc/kexec_file: Add KEXEC_SIG support.
arch/powerpc/Kconfig | 11 +++++++
arch/powerpc/kexec/elf_64.c | 14 +++++++++
arch/s390/kernel/machine_kexec_file.c | 42 +++------------------------
include/linux/verification.h | 3 ++
kernel/module-internal.h | 2 --
kernel/module.c | 11 +++----
kernel/module_signing.c | 32 ++++++++++++++------
7 files changed, 59 insertions(+), 56 deletions(-)
--
2.31.1
Powered by blists - more mailing lists