# git rev-parse -q --verify f8cf2f16a7c95acce497bfafa90e7c6d8397d653^{commit} f8cf2f16a7c95acce497bfafa90e7c6d8397d653 already have revision, skipping fetch # git checkout -q -f -B kisskb f8cf2f16a7c95acce497bfafa90e7c6d8397d653 # git clean -qxdf # < git log -1 # commit f8cf2f16a7c95acce497bfafa90e7c6d8397d653 # Merge: 4b3f1a1 ab60368 # Author: Linus Torvalds # Date: Sat Apr 7 16:53:59 2018 -0700 # # Merge branch 'next-integrity' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security # # Pull integrity updates from James Morris: # "A mixture of bug fixes, code cleanup, and continues to close # IMA-measurement, IMA-appraisal, and IMA-audit gaps. # # Also note the addition of a new cred_getsecid LSM hook by Matthew # Garrett: # # For IMA purposes, we want to be able to obtain the prepared secid # in the bprm structure before the credentials are committed. Add a # cred_getsecid hook that makes this possible. # # which is used by a new CREDS_CHECK target in IMA: # # In ima_bprm_check(), check with both the existing process # credentials and the credentials that will be committed when the new # process is started. This will not change behaviour unless the # system policy is extended to include CREDS_CHECK targets - # BPRM_CHECK will continue to check the same credentials that it did # previously" # # * 'next-integrity' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security: # ima: Fallback to the builtin hash algorithm # ima: Add smackfs to the default appraise/measure list # evm: check for remount ro in progress before writing # ima: Improvements in ima_appraise_measurement() # ima: Simplify ima_eventsig_init() # integrity: Remove unused macro IMA_ACTION_RULE_FLAGS # ima: drop vla in ima_audit_measurement() # ima: Fix Kconfig to select TPM 2.0 CRB interface # evm: Constify *integrity_status_msg[] # evm: Move evm_hmac and evm_hash from evm_main.c to evm_crypto.c # fuse: define the filesystem as untrusted # ima: fail signature verification based on policy # ima: clear IMA_HASH # ima: re-evaluate files on privileged mounted filesystems # ima: fail file signature verification on non-init mounted filesystems # IMA: Support using new creds in appraisal policy # security: Add a cred_getsecid hook # < /opt/cross/kisskb/br-mipsel-o32-full-2016.08-613-ge98b4dd/bin/mipsel-linux-gcc --version # < git log --format=%s --max-count=1 f8cf2f16a7c95acce497bfafa90e7c6d8397d653 # < make -s -j 48 ARCH=mips O=/kisskb/build/linus_mips-allmodconfig_mipsel CROSS_COMPILE=/opt/cross/kisskb/br-mipsel-o32-full-2016.08-613-ge98b4dd/bin/mipsel-linux- allmodconfig # Added to kconfig CONFIG_BUILD_DOCSRC=n # Added to kconfig CONFIG_MODULE_SIG=n # Added to kconfig CONFIG_SAMPLES=n # Added to kconfig CONFIG_MIPS_CPS_NS16550_BASE=0x1b0003f8 # Added to kconfig CONFIG_MIPS_CPS_NS16550_SHIFT=0 # Added to kconfig # yes \n | make -s -j 48 ARCH=mips O=/kisskb/build/linus_mips-allmodconfig_mipsel CROSS_COMPILE=/opt/cross/kisskb/br-mipsel-o32-full-2016.08-613-ge98b4dd/bin/mipsel-linux- oldconfig yes: standard output: Broken pipe yes: write error # make -s -j 48 ARCH=mips O=/kisskb/build/linus_mips-allmodconfig_mipsel CROSS_COMPILE=/opt/cross/kisskb/br-mipsel-o32-full-2016.08-613-ge98b4dd/bin/mipsel-linux- arch/mips/boot/dts/img/boston.dtb: Warning (pci_bridge): /pci@10000000: missing bus-range for PCI bridge arch/mips/boot/dts/img/boston.dtb: Warning (pci_bridge): /pci@12000000: missing bus-range for PCI bridge arch/mips/boot/dts/img/boston.dtb: Warning (pci_bridge): /pci@14000000: missing bus-range for PCI bridge arch/mips/boot/dts/img/boston.dtb: Warning (pci_device_bus_num): Failed prerequisite 'pci_bridge' /kisskb/src/drivers/input/joystick/analog.c:176:2: warning: #warning Precise timer not defined for this architecture. [-Wcpp] #warning Precise timer not defined for this architecture. ^ In file included from /kisskb/src/include/linux/swab.h:5:0, from /kisskb/src/include/uapi/linux/byteorder/big_endian.h:13, from /kisskb/src/include/linux/byteorder/big_endian.h:5, from /kisskb/src/arch/mips/include/uapi/asm/byteorder.h:13, from /kisskb/src/arch/mips/include/asm/bitops.h:19, from /kisskb/src/include/linux/bitops.h:38, from /kisskb/src/include/linux/kernel.h:11, from /kisskb/src/include/asm-generic/bug.h:18, from /kisskb/src/arch/mips/include/asm/bug.h:42, from /kisskb/src/include/linux/bug.h:5, from /kisskb/src/include/linux/thread_info.h:12, from /kisskb/src/include/asm-generic/current.h:5, from ./arch/mips/include/generated/asm/current.h:1, from /kisskb/src/include/linux/sched.h:12, from /kisskb/src/include/linux/blkdev.h:5, from /kisskb/src/drivers/nvme/host/core.c:15: /kisskb/src/drivers/nvme/host/core.c: In function 'nvme_get_log_ext': /kisskb/src/drivers/nvme/host/core.c:2239:43: warning: right shift count >= width of type [-Wshift-count-overflow] c.get_log_page.lpou = cpu_to_le32(offset >> 32ULL); ^ /kisskb/src/include/uapi/linux/swab.h:114:54: note: in definition of macro '__swab32' #define __swab32(x) (__u32)__builtin_bswap32((__u32)(x)) ^ /kisskb/src/include/linux/byteorder/generic.h:88:21: note: in expansion of macro '__cpu_to_le32' #define cpu_to_le32 __cpu_to_le32 ^ /kisskb/src/drivers/nvme/host/core.c:2239:24: note: in expansion of macro 'cpu_to_le32' c.get_log_page.lpou = cpu_to_le32(offset >> 32ULL); ^ /kisskb/src/drivers/spi/spi-sh-msiof.c:77:0: warning: "STR" redefined #define STR 0x40 /* Status Register */ ^ In file included from /kisskb/src/arch/mips/include/asm/mach-generic/spaces.h:15:0, from /kisskb/src/arch/mips/include/asm/addrspace.h:13, from /kisskb/src/arch/mips/include/asm/barrier.h:11, from /kisskb/src/include/linux/compiler.h:245, from /kisskb/src/arch/mips/include/asm/bitops.h:16, from /kisskb/src/include/linux/bitops.h:38, from /kisskb/src/include/linux/bitmap.h:8, from /kisskb/src/drivers/spi/spi-sh-msiof.c:14: /kisskb/src/arch/mips/include/asm/mipsregs.h:29:0: note: this is the location of the previous definition #define STR(x) __STR(x) ^ In file included from /kisskb/src/arch/mips/include/asm/sibyte/sb1250.h:41:0, from /kisskb/src/drivers/watchdog/sb_wdog.c:58: /kisskb/src/arch/mips/include/asm/sibyte/bcm1480_scd.h:274:0: warning: "M_SPC_CFG_CLEAR" redefined #define M_SPC_CFG_CLEAR M_BCM1480_SPC_CFG_CLEAR ^ In file included from /kisskb/src/arch/mips/include/asm/sibyte/sb1250.h:40:0, from /kisskb/src/drivers/watchdog/sb_wdog.c:58: /kisskb/src/arch/mips/include/asm/sibyte/sb1250_scd.h:405:0: note: this is the location of the previous definition #define M_SPC_CFG_CLEAR _SB_MAKEMASK1(32) ^ In file included from /kisskb/src/arch/mips/include/asm/sibyte/sb1250.h:41:0, from /kisskb/src/drivers/watchdog/sb_wdog.c:58: /kisskb/src/arch/mips/include/asm/sibyte/bcm1480_scd.h:275:0: warning: "M_SPC_CFG_ENABLE" redefined #define M_SPC_CFG_ENABLE M_BCM1480_SPC_CFG_ENABLE ^ In file included from /kisskb/src/arch/mips/include/asm/sibyte/sb1250.h:40:0, from /kisskb/src/drivers/watchdog/sb_wdog.c:58: /kisskb/src/arch/mips/include/asm/sibyte/sb1250_scd.h:406:0: note: this is the location of the previous definition #define M_SPC_CFG_ENABLE _SB_MAKEMASK1(33) ^ FIT description: Linux 4.16.0+ Created: Sun Apr 8 20:10:36 2018 Image 0 (kernel@0) Description: Linux 4.16.0+ Created: Sun Apr 8 20:10:36 2018 Type: Kernel Image Compression: gzip compressed Data Size: 5643186 Bytes = 5510.92 kB = 5.38 MB Architecture: MIPS OS: Linux Load Address: 0x84000000 Entry Point: 0x848f3500 Hash algo: sha1 Hash value: 3d9a9db9da7777fa599d1d3aac68de22e0277f78 Image 1 (fdt@boston) Description: img,boston Device Tree Created: Sun Apr 8 20:10:36 2018 Type: Flat Device Tree Compression: uncompressed Data Size: 3602 Bytes = 3.52 kB = 0.00 MB Architecture: MIPS Hash algo: sha1 Hash value: dabc84017c5ea1c23fdb5a4b25d185bdf81faa6a Image 2 (fdt@ni169445) Description: NI 169445 device tree Created: Sun Apr 8 20:10:36 2018 Type: Flat Device Tree Compression: uncompressed Data Size: 1871 Bytes = 1.83 kB = 0.00 MB Architecture: MIPS Hash algo: sha1 Hash value: 51b89b31605ee62038c8468c429af091dfc75ec7 Default Configuration: 'conf@default' Configuration 0 (conf@default) Description: Generic Linux kernel Kernel: kernel@0 Configuration 1 (conf@boston) Description: Boston Linux kernel Kernel: kernel@0 FDT: fdt@boston Configuration 2 (conf@ni169445) Description: NI 169445 Linux Kernel Kernel: kernel@0 FDT: fdt@ni169445 WARNING: modpost: missing MODULE_LICENSE() in drivers/rtc/rtc-goldfish.o see include/linux/module.h for more information Completed OK # rm -rf /kisskb/build/linus_mips-allmodconfig_mipsel # Build took: 0:15:58.491935