[PATCH 0/1][Unstable][Disco] lockdown for arm64

dann frazier dann.frazier at canonical.com
Wed Feb 20 15:48:22 UTC 2019


This patch, lifted from Debian (after some fix-up), enforces lockdown on
arm64 when booted in Secure Boot mode. Tested in QEMU.

Linn Crosetto (1):
  UBUNTU: SAUCE: arm64: add kernel config option to lock down when in
    Secure Boot mode

 drivers/firmware/efi/arm-init.c    | 4 ++++
 drivers/firmware/efi/efi.c         | 3 ++-
 drivers/firmware/efi/libstub/fdt.c | 6 ++++++
 include/linux/efi.h                | 1 +
 4 files changed, 13 insertions(+), 1 deletion(-)

-- 
2.20.1




More information about the kernel-team mailing list