mirror of
https://github.com/Fishwaldo/linux-bl808.git
synced 2025-06-17 20:25:19 +00:00
integrity: provide a hook to load keys when rootfs is ready
Keys can only be loaded once the rootfs is mounted. Initcalls are not suitable for that. This patch defines a special hook to load the x509 public keys onto the IMA keyring, before attempting to access any file. The keys are required for verifying the file's signature. The hook is called after the root filesystem is mounted and before the kernel calls 'init'. Changes in v3: * added more explanation to the patch description (Mimi) Changes in v2: * Hook renamed as 'integrity_load_keys()' to handle both IMA and EVM keys by integrity subsystem. * Hook patch moved after defining loading functions Signed-off-by: Dmitry Kasatkin <d.kasatkin@samsung.com> Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
This commit is contained in:
parent
fd5f4e9054
commit
c9cd2ce2bc
3 changed files with 22 additions and 1 deletions
|
@ -78,6 +78,7 @@
|
|||
#include <linux/context_tracking.h>
|
||||
#include <linux/random.h>
|
||||
#include <linux/list.h>
|
||||
#include <linux/integrity.h>
|
||||
|
||||
#include <asm/io.h>
|
||||
#include <asm/bugs.h>
|
||||
|
@ -1026,8 +1027,11 @@ static noinline void __init kernel_init_freeable(void)
|
|||
* Ok, we have completed the initial bootup, and
|
||||
* we're essentially up and running. Get rid of the
|
||||
* initmem segments and start the user-mode stuff..
|
||||
*
|
||||
* rootfs is available now, try loading the public keys
|
||||
* and default modules
|
||||
*/
|
||||
|
||||
/* rootfs is available now, try loading default modules */
|
||||
integrity_load_keys();
|
||||
load_default_modules();
|
||||
}
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue