arm64/ima: add ima_arch support
authorChester Lin <clin@suse.com>
Fri, 30 Oct 2020 06:08:40 +0000 (14:08 +0800)
committerArd Biesheuvel <ardb@kernel.org>
Tue, 17 Nov 2020 14:09:32 +0000 (15:09 +0100)
Add arm64 IMA arch support. The code and arch policy is mainly inherited
from x86.

Co-developed-by: Chester Lin <clin@suse.com>
Signed-off-by: Chester Lin <clin@suse.com>
Acked-by: Mimi Zohar <zohar@linux.ibm.com>
Acked-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Ard Biesheuvel <ardb@kernel.org>
arch/arm64/Kconfig

index f858c35..04e78a3 100644 (file)
@@ -1849,6 +1849,7 @@ config EFI
        select EFI_RUNTIME_WRAPPERS
        select EFI_STUB
        select EFI_GENERIC_STUB
+       imply IMA_SECURE_AND_OR_TRUSTED_BOOT
        default y
        help
          This option provides support for runtime services provided