From patchwork Sun Oct 29 01:47:07 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Dimitri John Ledkov X-Patchwork-Id: 1856636 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=lists.ubuntu.com (client-ip=185.125.189.65; helo=lists.ubuntu.com; envelope-from=kernel-team-bounces@lists.ubuntu.com; receiver=patchwork.ozlabs.org) Received: from lists.ubuntu.com (lists.ubuntu.com [185.125.189.65]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4SHzmr4cYTz1yQ9 for ; Sun, 29 Oct 2023 12:47:39 +1100 (AEDT) Received: from localhost ([127.0.0.1] helo=lists.ubuntu.com) by lists.ubuntu.com with esmtp (Exim 4.86_2) (envelope-from ) id 1qwutg-0000TY-UC; Sun, 29 Oct 2023 01:47:25 +0000 Received: from smtp-relay-internal-1.internal ([10.131.114.114] helo=smtp-relay-internal-1.canonical.com) by lists.ubuntu.com with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.86_2) (envelope-from ) id 1qwutZ-0000Mm-3q for kernel-team@lists.ubuntu.com; Sun, 29 Oct 2023 01:47:17 +0000 Received: from mail-lf1-f72.google.com (mail-lf1-f72.google.com [209.85.167.72]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by smtp-relay-internal-1.canonical.com (Postfix) with ESMTPS id A31E13F1D9 for ; Sun, 29 Oct 2023 01:47:16 +0000 (UTC) Received: by mail-lf1-f72.google.com with SMTP id 2adb3069b0e04-507f20a111fso2786357e87.0 for ; Sat, 28 Oct 2023 18:47:16 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1698544035; x=1699148835; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=G7XIRn69pX8rPoMVpkAhBtkbCIlw5+nMjWHdssmFatw=; b=vMfL8C0BNkZFtv8rgxBwDkPqHibY7rrbt/lAJ2kHQN+LJ12lTOZ0AmmncC6/tRF68q vsWXNb0eeBS4Z+Mee1yVPjyumIDJM7a9KONyuYkBiOIviD7vVvMrQxMwioDxrSphL4s/ PlzZSi/W5sI1Eyvllw8lbCIz6hF5oAk5o+M3bWPenDEUTKAEKlB3YVtyYiujQsppmdwe df8zN3ihW9X9f3d1yBeS7jvXwBqSDwvSyPjcWAxzRYrv7wIRnrs1h/RQ7+U8SCOXRvUc MmH+WCOU3ad6Ve63nM+1SVuGOJ73RiGM3BVSDkj7+zfx/qmEHt9DD33jPhJBrCpaOm7b LDRA== X-Gm-Message-State: AOJu0YzgZh1liywZ5T49YDAdWbMgX5RAD2etqvcZjbBlHNxOparOCUak 6MjWqY30AJjEnuaUpymbvICQ8XIygCfSoK5l7PTR3juF7q5GYhr9/ufcxP6KRb7wFFUjX+g3H04 sGPGKr+wTvHPCRZiPIb6/d47n9J966O1IuHq1BcIsNeBAIN6diOWs X-Received: by 2002:ac2:44a3:0:b0:500:a93d:fc78 with SMTP id c3-20020ac244a3000000b00500a93dfc78mr1988362lfm.31.1698544035373; Sat, 28 Oct 2023 18:47:15 -0700 (PDT) X-Google-Smtp-Source: AGHT+IGZbAk9rsAnGAnuBGkEGj3WAem2KNyaQsAM/CNLsulDRCAx/ozGeD2CNdpMoLssy0BpS7eW4Q== X-Received: by 2002:ac2:44a3:0:b0:500:a93d:fc78 with SMTP id c3-20020ac244a3000000b00500a93dfc78mr1988359lfm.31.1698544034906; Sat, 28 Oct 2023 18:47:14 -0700 (PDT) Received: from localhost ([159.148.40.97]) by smtp.gmail.com with ESMTPSA id b18-20020ac25632000000b005059c4517casm848128lff.99.2023.10.28.18.47.14 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 28 Oct 2023 18:47:14 -0700 (PDT) From: Dimitri John Ledkov To: kernel-team@lists.ubuntu.com Subject: [NOBLE][PATCH] UBUNTU: [Config] Switch IMA_DEFAULT_HASH from sha1 to sha256 Date: Sun, 29 Oct 2023 03:47:07 +0200 Message-Id: <20231029014707.264476-1-dimitri.ledkov@canonical.com> X-Mailer: git-send-email 2.34.1 MIME-Version: 1.0 X-BeenThere: kernel-team@lists.ubuntu.com X-Mailman-Version: 2.1.20 Precedence: list List-Id: Kernel team discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: kernel-team-bounces@lists.ubuntu.com Sender: "kernel-team" BugLink: https://bugs.launchpad.net/bugs/2041735 ppc64el already used sha256, sha256 is accelerated on most arches, and is widely used. Signed-off-by: Dimitri John Ledkov Acked-by: Tim Gardner Acked-by: Roxana Nicolescu --- debian.master/config/annotations | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/debian.master/config/annotations b/debian.master/config/annotations index eadc277a74..4bc12c10c7 100644 --- a/debian.master/config/annotations +++ b/debian.master/config/annotations @@ -261,8 +261,8 @@ CONFIG_IMA_APPRAISE note<'LP: #1643652'> CONFIG_IMA_ARCH_POLICY policy<{'amd64': 'y', 'arm64': 'y', 'armhf': 'y', 'ppc64el': 'y', 'riscv64': 'y', 's390x': 'y'}> CONFIG_IMA_ARCH_POLICY note<'LP: #1866909'> -CONFIG_IMA_DEFAULT_HASH_SHA256 policy<{'amd64': 'n', 'arm64': 'n', 'armhf': 'n', 'ppc64el': 'y', 'riscv64': 'n', 's390x': 'n'}> -CONFIG_IMA_DEFAULT_HASH_SHA256 note<'LP: #1643652'> +CONFIG_IMA_DEFAULT_HASH_SHA256 policy<{'amd64': 'y', 'arm64': 'y', 'armhf': 'y', 'ppc64el': 'y', 'riscv64': 'y', 's390x': 'y'}> +CONFIG_IMA_DEFAULT_HASH_SHA256 note<'LP: #2041735'> CONFIG_IMA_KEXEC policy<{'amd64': 'y', 'arm64': 'y', 'ppc64el': 'y', 'riscv64': 'y'}> CONFIG_IMA_KEXEC note<'LP: #1643652'> @@ -6184,8 +6184,8 @@ CONFIG_IMA_APPRAISE_BOOTPARAM policy<{'amd64': 'y', 'arm64': ' CONFIG_IMA_APPRAISE_BUILD_POLICY policy<{'amd64': 'n', 'arm64': 'n', 'armhf': 'n', 'ppc64el': 'n', 'riscv64': 'n', 's390x': 'n'}> CONFIG_IMA_APPRAISE_MODSIG policy<{'amd64': 'y', 'arm64': 'y', 'armhf': 'y', 'ppc64el': 'y', 'riscv64': 'y', 's390x': 'y'}> CONFIG_IMA_BLACKLIST_KEYRING policy<{'amd64': 'n', 'arm64': 'n', 'armhf': 'n', 'ppc64el': 'n', 'riscv64': 'n', 's390x': 'n'}> -CONFIG_IMA_DEFAULT_HASH policy<{'amd64': '"sha1"', 'arm64': '"sha1"', 'armhf': '"sha1"', 'ppc64el': '"sha256"', 'riscv64': '"sha1"', 's390x': '"sha1"'}> -CONFIG_IMA_DEFAULT_HASH_SHA1 policy<{'amd64': 'y', 'arm64': 'y', 'armhf': 'y', 'ppc64el': 'n', 'riscv64': 'y', 's390x': 'y'}> +CONFIG_IMA_DEFAULT_HASH policy<{'amd64': '"sha256"', 'arm64': '"sha256"', 'armhf': '"sha256"', 'ppc64el': '"sha256"', 'riscv64': '"sha256"', 's390x': '"sha256"'}> +CONFIG_IMA_DEFAULT_HASH_SHA1 policy<{'amd64': 'n', 'arm64': 'n', 'armhf': 'n', 'ppc64el': 'n', 'riscv64': 'n', 's390x': 'n'}> CONFIG_IMA_DEFAULT_HASH_SHA512 policy<{'amd64': 'n', 'arm64': 'n', 'armhf': 'n', 'ppc64el': 'n', 'riscv64': 'n', 's390x': 'n'}> CONFIG_IMA_DEFAULT_TEMPLATE policy<{'amd64': '"ima-ng"', 'arm64': '"ima-ng"', 'armhf': '"ima-ng"', 'ppc64el': '"ima-sig"', 'riscv64': '"ima-ng"', 's390x': '"ima-ng"'}> CONFIG_IMA_DISABLE_HTABLE policy<{'amd64': 'n', 'arm64': 'n', 'armhf': 'n', 'ppc64el': 'n', 'riscv64': 'n', 's390x': 'n'}>