ima: based on policy verify firmware signatures (pre-allocated buffer)
authorMimi Zohar <zohar@linux.vnet.ibm.com>
Fri, 27 Apr 2018 18:31:40 +0000 (14:31 -0400)
committerMimi Zohar <zohar@linux.vnet.ibm.com>
Tue, 22 May 2018 11:34:47 +0000 (07:34 -0400)
commitfd90bc559bfba743ae8de87ff23b92a5e4668062
tree12561da2e2ac7837496afc9a8409e9a7059a87c4
parentf1b08bbcbdaf3160fa95ec95a760a49adf312b67
ima: based on policy verify firmware signatures (pre-allocated buffer)

Don't differentiate, for now, between kernel_read_file_id READING_FIRMWARE
and READING_FIRMWARE_PREALLOC_BUFFER enumerations.

Fixes: a098ecd firmware: support loading into a pre-allocated buffer (since 4.8)
Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Cc: Luis R. Rodriguez <mcgrof@suse.com>
Cc: David Howells <dhowells@redhat.com>
Cc: Kees Cook <keescook@chromium.org>
Cc: Serge E. Hallyn <serge@hallyn.com>
Cc: Stephen Boyd <stephen.boyd@linaro.org>
security/integrity/ima/ima_main.c