x86/ima: check EFI SetupMode too
authorMimi Zohar <zohar@linux.ibm.com>
Wed, 24 Apr 2019 17:05:46 +0000 (13:05 -0400)
committerMimi Zohar <zohar@linux.ibm.com>
Thu, 30 May 2019 03:20:46 +0000 (23:20 -0400)
commit980ef4d22a95a3cd84a9b8ffaa7b81b391d173c6
tree8ee36877dade494ef48deb2a1cfc894300576a14
parent8cdc23a3d9ec0944000ad43bad588e36afdc38cd
x86/ima: check EFI SetupMode too

Checking "SecureBoot" mode is not sufficient, also check "SetupMode".

Fixes: 399574c64eaf ("x86/ima: retry detecting secure boot mode")
Reported-by: Matthew Garrett <mjg59@google.com>
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
arch/x86/kernel/ima_arch.c