arm64/ima: add ima_arch support
authorChester Lin <clin@suse.com>
Fri, 30 Oct 2020 06:08:40 +0000 (14:08 +0800)
committerArd Biesheuvel <ardb@kernel.org>
Tue, 17 Nov 2020 14:09:32 +0000 (15:09 +0100)
Add arm64 IMA arch support. The code and arch policy is mainly inherited
from x86.

Co-developed-by: Chester Lin <clin@suse.com>
Signed-off-by: Chester Lin <clin@suse.com>
Acked-by: Mimi Zohar <zohar@linux.ibm.com>
Acked-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Ard Biesheuvel <ardb@kernel.org>
arch/arm64/Kconfig

index f858c352f72a47cdef887a9a6d291b4f0a65dadd..04e78a367c2c196c6b0b134fe80c0f821cde0d0b 100644 (file)
@@ -1849,6 +1849,7 @@ config EFI
        select EFI_RUNTIME_WRAPPERS
        select EFI_STUB
        select EFI_GENERIC_STUB
+       imply IMA_SECURE_AND_OR_TRUSTED_BOOT
        default y
        help
          This option provides support for runtime services provided