From patchwork Thu May 11 18:50:34 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Tim Gardner X-Patchwork-Id: 1780264 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=lists.ubuntu.com (client-ip=91.189.94.19; helo=huckleberry.canonical.com; envelope-from=kernel-team-bounces@lists.ubuntu.com; receiver=) Authentication-Results: legolas.ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=canonical.com header.i=@canonical.com header.a=rsa-sha256 header.s=20210705 header.b=jw5K7lLM; dkim-atps=neutral Received: from huckleberry.canonical.com (huckleberry.canonical.com [91.189.94.19]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4QHLZf0ssqz214S for ; Fri, 12 May 2023 04:51:05 +1000 (AEST) Received: from localhost ([127.0.0.1] helo=huckleberry.canonical.com) by huckleberry.canonical.com with esmtp (Exim 4.86_2) (envelope-from ) id 1pxBNL-0002iz-F5; Thu, 11 May 2023 18:50:51 +0000 Received: from smtp-relay-internal-1.internal ([10.131.114.114] helo=smtp-relay-internal-1.canonical.com) by huckleberry.canonical.com with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.86_2) (envelope-from ) id 1pxBNK-0002hM-8c for kernel-team@lists.ubuntu.com; Thu, 11 May 2023 18:50:50 +0000 Received: from mail-pl1-f198.google.com (mail-pl1-f198.google.com [209.85.214.198]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by smtp-relay-internal-1.canonical.com (Postfix) with ESMTPS id C44D33F118 for ; Thu, 11 May 2023 18:50:49 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=canonical.com; s=20210705; t=1683831049; bh=BLH2KhscWoA9JX8KGgfivRuWAEgniWCx9+d/GQfbnRA=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=jw5K7lLMpWB6Tjc/wGswFRnwTrJ0zjR+9Yo68aYUDW5/vW7qcwhINtNDLBk5lIQ4F TSWT/lqMYpcBjM9Yw/92VLgcEU67rmZyg2R0774Thx5sccBnzyyAT4tbTT/UjQMeLp syyV7PtFUbLQwvGK7bWOy8XuXCRXE+k/xbfx3HKd0cHPVSK4DHjdwXta3dxm+5CzNy RSNiCzhIhFwjHnS5QvBQBYPuyzrV1Nuq1+rQpEk2YMpWIEw0yxnlk8fH3TFXQLxqil 2ZXrC5OQkn0sgYGf03AN36fb5Vzrp1ctpiZHvy2a1lrOhNgVrBmtVqejx2xfShiyfC wy9xmcR1mfADw== Received: by mail-pl1-f198.google.com with SMTP id d9443c01a7336-1ab032d91a1so54947995ad.1 for ; Thu, 11 May 2023 11:50:49 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1683831048; x=1686423048; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=BLH2KhscWoA9JX8KGgfivRuWAEgniWCx9+d/GQfbnRA=; b=kyYJKIHORyD5Ja4NGzw4mQDOjLwe+rcigsOEUk5T0KR0cuw/Q07N0fDf872dpZlLJD SJLfJzn6M0RtVqptSFmKPPOfsANTaB5ILjAhW0vD44KygnW5R6DrQyzxKjlHlnFdu/nO y5Pfyl92U7Ksyz2lxfvMpVOLS82AeAcN1WVRLQAXNbX18pUY5FdBU62D1hUNSCE07iLw ZGNUontJUXIatT8V/hoSJRaoqh5JVzEDvpYFjdquOar0Q6/bt3PN6G8qfWPEyNNSAfPU nIZ4UEgPM0JsATnSNDxu1B7KlI+5zRbgQrJV46OFnSAu2zzd2KZvvwFRTD090R/p9NpN F+Hw== X-Gm-Message-State: AC+VfDzDwJSr5mKCmEwzesFa8H7Gmtf9YWNC9/kI7tRFGRDIKaysrquc 30W3FWsICP6eUVJnyArhO0RHPb/H2bgtAS0fQcbLYgPgWLjNKOpfXdD8ZkqBXM/ig3YXwY3wUy8 k2NDrAtXAD0V1l9T7SWdgtVgI5bUfm4/c31KG1mdKUfeKpStG2g== X-Received: by 2002:a17:902:d491:b0:1ab:26a8:5401 with SMTP id c17-20020a170902d49100b001ab26a85401mr32530005plg.31.1683831048150; Thu, 11 May 2023 11:50:48 -0700 (PDT) X-Google-Smtp-Source: ACHHUZ6l9tZeGDsC6+LDfUUvyRKyixpENhzQXXG+qKDUomKUrru35EKFsdJV1SplcIValjS5o+ESiA== X-Received: by 2002:a17:902:d491:b0:1ab:26a8:5401 with SMTP id c17-20020a170902d49100b001ab26a85401mr32529964plg.31.1683831047549; Thu, 11 May 2023 11:50:47 -0700 (PDT) Received: from smtp.gmail.com (174-045-099-030.res.spectrum.com. [174.45.99.30]) by smtp.gmail.com with ESMTPSA id q13-20020a170902bd8d00b001a285269b70sm6237861pls.280.2023.05.11.11.50.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 11 May 2023 11:50:46 -0700 (PDT) From: Tim Gardner To: kernel-team@lists.ubuntu.com Subject: [PATCH][kinetic/linux-kvm] UBUNTU: [Config] CONFIG_DM_VERITY=m Date: Thu, 11 May 2023 12:50:34 -0600 Message-Id: <20230511185040.220555-3-tim.gardner@canonical.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20230511185040.220555-1-tim.gardner@canonical.com> References: <20230511185040.220555-1-tim.gardner@canonical.com> MIME-Version: 1.0 X-BeenThere: kernel-team@lists.ubuntu.com X-Mailman-Version: 2.1.20 Precedence: list List-Id: Kernel team discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: kernel-team-bounces@lists.ubuntu.com Sender: "kernel-team" BugLink: https://bugs.launchpad.net/bugs/2019040 Signed-off-by: Tim Gardner --- debian.kvm/config/annotations | 6 ++++++ debian.kvm/config/config.common.ubuntu | 5 ++++- 2 files changed, 10 insertions(+), 1 deletion(-) diff --git a/debian.kvm/config/annotations b/debian.kvm/config/annotations index 8518e947569d..f1716d95880d 100644 --- a/debian.kvm/config/annotations +++ b/debian.kvm/config/annotations @@ -2,6 +2,12 @@ # FORMAT: 3 # ARCH: x86 +CONFIG_DM_VERITY policy<{'amd64': 'm'}> +CONFIG_DM_VERITY_FEC policy<{'amd64': 'n'}> +CONFIG_DM_VERITY_VERIFY_ROOTHASH_SIG policy<{'amd64': 'y'}> +CONFIG_DM_VERITY_VERIFY_ROOTHASH_SIG_SECONDARY_KEYRING policy<{'amd64': 'y'}> +CONFIG_DM_VERITY note + CONFIG_DUMMY policy<{'amd64': 'm'}> CONFIG_DUMMY mark note diff --git a/debian.kvm/config/config.common.ubuntu b/debian.kvm/config/config.common.ubuntu index 2b89914a7518..3cf18a9c6508 100644 --- a/debian.kvm/config/config.common.ubuntu +++ b/debian.kvm/config/config.common.ubuntu @@ -765,7 +765,10 @@ CONFIG_DM_PERSISTENT_DATA=m # CONFIG_DM_THIN_PROVISIONING is not set # CONFIG_DM_UEVENT is not set # CONFIG_DM_UNSTRIPED is not set -# CONFIG_DM_VERITY is not set +CONFIG_DM_VERITY=m +# CONFIG_DM_VERITY_FEC is not set +CONFIG_DM_VERITY_VERIFY_ROOTHASH_SIG=y +CONFIG_DM_VERITY_VERIFY_ROOTHASH_SIG_SECONDARY_KEYRING=y # CONFIG_DM_WRITECACHE is not set # CONFIG_DM_ZERO is not set # CONFIG_DNOTIFY is not set