Skip to content
This repository was archived by the owner on May 30, 2023. It is now read-only.

Comments

sys-kernel: make lockdown available#553

Merged
vbatts merged 1 commit intomainfrom
vbatts/lockdown
Sep 11, 2020
Merged

sys-kernel: make lockdown available#553
vbatts merged 1 commit intomainfrom
vbatts/lockdown

Conversation

@vbatts
Copy link

@vbatts vbatts commented Aug 27, 2020

This will not be enabled by default, and still requires the "lockdown"
kernel parameter. Users can test by setting in
/usr/share/oem/grub.cfg:

set linux_append="lockdown=integrity"

After this is set, dmesg output you'll see:

[    0.000000] Kernel is locked down from command line; see man
kernel_lockdown.7

Signed-off-by: Vincent Batts vbatts@kinvolk.io

@vbatts vbatts added the enhancement New feature or request label Aug 27, 2020
@dongsupark
Copy link
Contributor

Rebase needed

This will not be enabled by default, and still requires the "lockdown"
kernel parameter. Users can test by setting in
`/usr/share/oem/grub.cfg`:
```
set linux_append="lockdown=integrity"
```

After this is set, dmesg output you'll see:
```
[    0.000000] Kernel is locked down from command line; see man
kernel_lockdown.7
```

Signed-off-by: Vincent Batts <vbatts@kinvolk.io>
@vbatts
Copy link
Author

vbatts commented Sep 8, 2020

rebased

Copy link
Contributor

@dongsupark dongsupark left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good.
Tested with Kernel 5.8.8. It works well as described.

@vbatts vbatts merged commit bb0e3b7 into main Sep 11, 2020
@vbatts vbatts deleted the vbatts/lockdown branch September 11, 2020 11:01
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants