2017-10-20 23:27:48

by James Morris

[permalink] [raw]
Subject: Re: [PATCH 07/27] kexec_file: Disable at runtime if securelevel has been set

On Thu, 19 Oct 2017, David Howells wrote:

> From: Chun-Yi Lee <[email protected]>
>
> When KEXEC_VERIFY_SIG is not enabled, kernel should not loads image
> through kexec_file systemcall if securelevel has been set.
>
> This code was showed in Matthew's patch but not in git:
> https://lkml.org/lkml/2015/3/13/778
>


Reviewed-by: James Morris <[email protected]>

--
James Morris
<[email protected]>


From 1581706022474432608@xxx Thu Oct 19 17:00:09 +0000 2017
X-GM-THRID: 1581706022474432608
X-Gmail-Labels: Inbox,Category Forums