From: Linus Torvalds Date: Tue, 30 Jun 2020 19:17:21 +0000 (-0700) Subject: Merge tag 'integrity-v5.8-fix-2' of git://git.kernel.org/pub/scm/linux/kernel/git... X-Git-Tag: v5.15~3470 X-Git-Url: http://review.tizen.org/git/?a=commitdiff_plain;h=b13f40bc69a16e465d21e23ca5adf4bf26365815;p=platform%2Fkernel%2Flinux-starfive.git Merge tag 'integrity-v5.8-fix-2' of git://git./linux/kernel/git/zohar/linux-integrity Pull integrity updates from Mimi Zohar: "Include PCRs 8 & 9 in per TPM 2.0 bank boot_aggregate calculation. Prior to Linux 5.8 the SHA1 "boot_aggregate" value was padded with 0's and extended into the other TPM 2.0 banks. Included in the Linux 5.8 open window, TPM 2.0 PCR bank specific "boot_aggregate" values (PCRs 0 - 7) are calculated and extended into the TPM banks. Distro releases are now shipping grub2 with TPM support, which extend PCRs 8 & 9. I'd like for PCRs 8 & 9 to be included in the new "boot_aggregate" calculations. For backwards compatibility, if the hash is SHA1, these new PCRs are not included in the boot aggregate" * tag 'integrity-v5.8-fix-2' of git://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity: ima: extend boot_aggregate with kernel measurements --- b13f40bc69a16e465d21e23ca5adf4bf26365815