mbox series

[EOAN,0/2] Enable lockdown on s390x

Message ID 20190809144947.17705-1-xnox@ubuntu.com
Headers show
Series Enable lockdown on s390x | expand

Message

Dimitri John Ledkov Aug. 9, 2019, 2:49 p.m. UTC
Enable lockdown, and enforce it when booted with secure ipl.

Dimitri John Ledkov (1):
  Ubuntu: [Config] Enable CONFIG_LOCK_DOWN_KERNEL on s390x.

Philipp Rudo (1):
  UBUNTU: SAUCE: (lockdown) s390/ipl: lockdown kernel when booted secure

 arch/s390/include/asm/ipl.h                    | 1 +
 arch/s390/kernel/ipl.c                         | 5 +++++
 debian.master/config/annotations               | 4 ++--
 debian.master/config/s390x/config.common.s390x | 2 +-
 security/lock_down.c                           | 7 +++++++
 5 files changed, 16 insertions(+), 3 deletions(-)

Comments

Seth Forshee Aug. 20, 2019, 9:12 p.m. UTC | #1
On Fri, Aug 09, 2019 at 03:49:45PM +0100, Dimitri John Ledkov wrote:
> Enable lockdown, and enforce it when booted with secure ipl.
> 
> Dimitri John Ledkov (1):
>   Ubuntu: [Config] Enable CONFIG_LOCK_DOWN_KERNEL on s390x.
> 
> Philipp Rudo (1):
>   UBUNTU: SAUCE: (lockdown) s390/ipl: lockdown kernel when booted secure

Applied to eoan/master-next and unstable/master, thanks!