mbox series

[0/1,Unstable,Disco] lockdown for arm64

Message ID 20190220154823.23952-1-dann.frazier@canonical.com
Headers show
Series lockdown for arm64 | expand

Message

dann frazier Feb. 20, 2019, 3:48 p.m. UTC
This patch, lifted from Debian (after some fix-up), enforces lockdown on
arm64 when booted in Secure Boot mode. Tested in QEMU.

Linn Crosetto (1):
  UBUNTU: SAUCE: arm64: add kernel config option to lock down when in
    Secure Boot mode

 drivers/firmware/efi/arm-init.c    | 4 ++++
 drivers/firmware/efi/efi.c         | 3 ++-
 drivers/firmware/efi/libstub/fdt.c | 6 ++++++
 include/linux/efi.h                | 1 +
 4 files changed, 13 insertions(+), 1 deletion(-)

Comments

Seth Forshee Feb. 22, 2019, 10:12 a.m. UTC | #1
On Wed, Feb 20, 2019 at 04:48:22PM +0100, dann frazier wrote:
> This patch, lifted from Debian (after some fix-up), enforces lockdown on
> arm64 when booted in Secure Boot mode. Tested in QEMU.

Applied to disco and unstable, thanks!