# git rev-parse -q --verify f1f2f614d535564992f32e720739cb53cf03489f^{commit} f1f2f614d535564992f32e720739cb53cf03489f already have revision, skipping fetch # git checkout -q -f -B kisskb f1f2f614d535564992f32e720739cb53cf03489f # git clean -qxdf # < git log -1 # commit f1f2f614d535564992f32e720739cb53cf03489f # Merge: 298fb76a5583 2a7f0e53daf2 # Author: Linus Torvalds # Date: Fri Sep 27 19:37:27 2019 -0700 # # Merge branch 'next-integrity' of git://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity # # Pull integrity updates from Mimi Zohar: # "The major feature in this time is IMA support for measuring and # appraising appended file signatures. In addition are a couple of bug # fixes and code cleanup to use struct_size(). # # In addition to the PE/COFF and IMA xattr signatures, the kexec kernel # image may be signed with an appended signature, using the same # scripts/sign-file tool that is used to sign kernel modules. # # Similarly, the initramfs may contain an appended signature. # # This contained a lot of refactoring of the existing appended signature # verification code, so that IMA could retain the existing framework of # calculating the file hash once, storing it in the IMA measurement list # and extending the TPM, verifying the file's integrity based on a file # hash or signature (eg. xattrs), and adding an audit record containing # the file hash, all based on policy. (The IMA support for appended # signatures patch set was posted and reviewed 11 times.) # # The support for appended signature paves the way for adding other # signature verification methods, such as fs-verity, based on a single # system-wide policy. The file hash used for verifying the signature and # the signature, itself, can be included in the IMA measurement list" # # * 'next-integrity' of git://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity: # ima: ima_api: Use struct_size() in kzalloc() # ima: use struct_size() in kzalloc() # sefltest/ima: support appended signatures (modsig) # ima: Fix use after free in ima_read_modsig() # MODSIGN: make new include file self contained # ima: fix freeing ongoing ahash_request # ima: always return negative code for error # ima: Store the measurement again when appraising a modsig # ima: Define ima-modsig template # ima: Collect modsig # ima: Implement support for module-style appended signatures # ima: Factor xattr_verify() out of ima_appraise_measurement() # ima: Add modsig appraise_type option for module-style appended signatures # integrity: Select CONFIG_KEYS instead of depending on it # PKCS#7: Introduce pkcs7_get_digest() # PKCS#7: Refactor verify_pkcs7_signature() # MODSIGN: Export module signature definitions # ima: initialize the "template" field with the default template # < /opt/cross/kisskb/gcc-4.6.3-nolibc/mips-linux/bin/mips-linux-gcc --version # < /opt/cross/kisskb/gcc-4.6.3-nolibc/mips-linux/bin/mips-linux-ld --version # < git log --format=%s --max-count=1 f1f2f614d535564992f32e720739cb53cf03489f # < make -s -j 120 ARCH=mips O=/kisskb/build/linus_ip22_defconfig_mips CROSS_COMPILE=/opt/cross/kisskb/gcc-4.6.3-nolibc/mips-linux/bin/mips-linux- ip22_defconfig # make -s -j 120 ARCH=mips O=/kisskb/build/linus_ip22_defconfig_mips CROSS_COMPILE=/opt/cross/kisskb/gcc-4.6.3-nolibc/mips-linux/bin/mips-linux- /kisskb/src/arch/mips/vdso/Makefile:61: MIPS VDSO requires binutils >= 2.25 :1511:2: warning: #warning syscall clone3 not implemented [-Wcpp] /kisskb/src/arch/mips/vdso/Makefile:61: MIPS VDSO requires binutils >= 2.25 /kisskb/build/tmp/cc6baJX7.s: Assembler messages: /kisskb/build/tmp/cc6baJX7.s:513: Error: can't resolve `_start' {*UND* section} - `L0' {.text section} /kisskb/build/tmp/cc6baJX7.s:727: Error: can't resolve `_start' {*UND* section} - `L0' {.text section} /kisskb/build/tmp/cc6baJX7.s:1058: Error: can't resolve `_start' {*UND* section} - `L0' {.text section} /kisskb/build/tmp/cc6baJX7.s:1279: Error: can't resolve `_start' {*UND* section} - `L0' {.text section} make[3]: *** [/kisskb/src/scripts/Makefile.build:266: arch/mips/vdso/vgettimeofday.o] Error 1 make[3]: *** Waiting for unfinished jobs.... make[2]: *** [/kisskb/src/scripts/Makefile.build:509: arch/mips/vdso] Error 2 make[2]: *** Waiting for unfinished jobs.... /kisskb/src/kernel/printk/printk.c: In function 'devkmsg_sysctl_set_loglvl': /kisskb/src/kernel/printk/printk.c:204:16: warning: 'old' may be used uninitialized in this function [-Wuninitialized] make[1]: *** [/kisskb/src/Makefile:1670: arch/mips] Error 2 make[1]: *** Waiting for unfinished jobs.... /kisskb/src/fs/proc/inode.c: In function 'proc_reg_open': /kisskb/src/include/linux/list.h:65:12: warning: 'pdeo' may be used uninitialized in this function [-Wuninitialized] /kisskb/src/fs/proc/inode.c:338:21: note: 'pdeo' was declared here /kisskb/src/fs/udf/unicode.c: In function 'udf_name_conv_char': /kisskb/src/fs/udf/unicode.c:132:8: warning: 'c' may be used uninitialized in this function [-Wuninitialized] /kisskb/src/drivers/net/tun.c: In function 'tun_get_user': /kisskb/src/drivers/net/tun.c:1836:30: warning: 'copylen' may be used uninitialized in this function [-Wuninitialized] /kisskb/src/drivers/net/tun.c:1749:46: warning: 'linear' may be used uninitialized in this function [-Wuninitialized] make: *** [Makefile:179: sub-make] Error 2 Command 'make -s -j 120 ARCH=mips O=/kisskb/build/linus_ip22_defconfig_mips CROSS_COMPILE=/opt/cross/kisskb/gcc-4.6.3-nolibc/mips-linux/bin/mips-linux- ' returned non-zero exit status 2 # rm -rf /kisskb/build/linus_ip22_defconfig_mips # Build took: 0:00:37.657761