diff mbox series

[SRU,F,1/3] UBUNTU: [Config]: Enable CONFIG_KEXEC_IMAGE_VERIFY_SIG

Message ID 20230825061755.52217-2-chengen.du@canonical.com
State New
Headers show
Series kdump doesn't work with UEFI secure boot and kernel lockdown enabled on ARM64 | expand

Commit Message

Chengen Du Aug. 25, 2023, 6:17 a.m. UTC
This option enables support for kexec image signature verification,
allowing signed kernels to be loaded via the kexec_file_load system
call.

Signed-off-by: Chengen Du <chengen.du@canonical.com>
---
 debian.master/config/annotations | 4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)
diff mbox series

Patch

diff --git a/debian.master/config/annotations b/debian.master/config/annotations
index e5731b2e3a9e..31caf0427389 100644
--- a/debian.master/config/annotations
+++ b/debian.master/config/annotations
@@ -12450,7 +12450,7 @@  CONFIG_ARM_MODULE_PLTS                          policy<{'armhf': 'n'}>
 CONFIG_UACCESS_WITH_MEMCPY                      policy<{'armhf': 'n'}>
 
 # Menu: Processor type and features >> Architecture: arm64
-CONFIG_KEXEC_IMAGE_VERIFY_SIG                   policy<{'arm64': 'n'}>
+CONFIG_KEXEC_IMAGE_VERIFY_SIG                   policy<{'arm64': 'y'}>
 CONFIG_UNMAP_KERNEL_AT_EL0                      policy<{'arm64': 'y'}>
 CONFIG_HARDEN_EL2_VECTORS                       policy<{'arm64': 'y'}>
 CONFIG_ARM64_SSBD                               policy<{'arm64': 'y'}>
@@ -12462,8 +12462,6 @@  CONFIG_ARM64_MODULE_PLTS                        policy<{'arm64': 'y'}>
 CONFIG_ARM64_PSEUDO_NMI                         policy<{'arm64': 'y'}>
 CONFIG_ARM64_DEBUG_PRIORITY_MASKING             policy<{'arm64': 'n'}>
 CONFIG_RANDOMIZE_MODULE_REGION_FULL             policy<{'arm64': 'y'}>
-#
-CONFIG_KEXEC_IMAGE_VERIFY_SIG                   flag<REVIEW>
 
 # Menu: Processor type and features >> Architecture: powerpc
 CONFIG_PPC_TRANSACTIONAL_MEM                    policy<{'ppc64el': 'y'}>