diff options
| author | Mehmet Kayaalp <mkayaalp@linux.vnet.ibm.com> | 2015-11-24 16:18:05 -0500 |
|---|---|---|
| committer | Oleksandr Suvorov <oleksandr.suvorov@toradex.com> | 2020-05-25 13:57:20 +0300 |
| commit | 56809d619de430905699097e6e5b41ef4fe5cb86 (patch) | |
| tree | f821203d71800fc65b991083abfe6555494bd2cd /include/linux/nospec.h | |
| parent | 25e7f6f94e42b16a6d5298122e1e4dee0e6bc5b6 (diff) | |
KEYS: Reserve an extra certificate symbol for inserting without recompiling
commit c4c36105958576fee87d2c75f4b69b6e5bbde772 upstream
Place a system_extra_cert buffer of configurable size, right after the
system_certificate_list, so that inserted keys can be readily processed by
the existing mechanism. Added script takes a key file and a kernel image
and inserts its contents to the reserved area. The
system_certificate_list_size is also adjusted accordingly.
Call the script as:
scripts/insert-sys-cert -b <vmlinux> -c <certfile>
If vmlinux has no symbol table, supply System.map file with -s flag.
Subsequent runs replace the previously inserted key, instead of appending
the new one.
Signed-off-by: Mehmet Kayaalp <mkayaalp@linux.vnet.ibm.com>
Signed-off-by: David Howells <dhowells@redhat.com>
Acked-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Diffstat (limited to 'include/linux/nospec.h')
0 files changed, 0 insertions, 0 deletions
