From: Ard Biesheuvel Date: Thu, 23 Jan 2020 12:09:35 +0000 (+0100) Subject: x86/ima: Use EFI GetVariable only when available X-Git-Url: http://git.maquefel.me/?a=commitdiff_plain;h=9a440391b560347bf5ee7cb96b63e7e91cedf66a;p=linux.git x86/ima: Use EFI GetVariable only when available Replace the EFI runtime services check with one that tells us whether EFI GetVariable() is implemented by the firmware. Signed-off-by: Ard Biesheuvel --- diff --git a/arch/x86/kernel/ima_arch.c b/arch/x86/kernel/ima_arch.c index 4d4f5d9faac31..cb6ed616a5432 100644 --- a/arch/x86/kernel/ima_arch.c +++ b/arch/x86/kernel/ima_arch.c @@ -19,7 +19,7 @@ static enum efi_secureboot_mode get_sb_mode(void) size = sizeof(secboot); - if (!efi_enabled(EFI_RUNTIME_SERVICES)) { + if (!efi_rt_services_supported(EFI_RT_SUPPORTED_GET_VARIABLE)) { pr_info("ima: secureboot mode unknown, no efi\n"); return efi_secureboot_mode_unknown; }