powerpc/ima: Indicate kernel modules appended signatures are enforced
authorMimi Zohar <zohar@linux.ibm.com>
Thu, 31 Oct 2019 03:31:34 +0000 (23:31 -0400)
committerMichael Ellerman <mpe@ellerman.id.au>
Tue, 12 Nov 2019 01:25:50 +0000 (12:25 +1100)
commitd72ea4915c7e6fa5e7b9022a34df66e375bfe46c
treeede50dc372aaae6c783e2dc43cbfee9c238ddaaf
parentdc87f18615db9dc74a75cfb4a57ed33b07a3903a
powerpc/ima: Indicate kernel modules appended signatures are enforced

The arch specific kernel module policy rule requires kernel modules to
be signed, either as an IMA signature, stored as an xattr, or as an
appended signature. As a result, kernel modules appended signatures
could be enforced without "sig_enforce" being set or reflected in
/sys/module/module/parameters/sig_enforce. This patch sets
"sig_enforce".

Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Link: https://lore.kernel.org/r/1572492694-6520-10-git-send-email-zohar@linux.ibm.com
arch/powerpc/kernel/ima_arch.c