Signed module enforcement patches for

Tim Gardner tim.gardner at canonical.com
Thu Jun 16 13:49:35 UTC 2016


These patches in support of
(https://blueprints.launchpad.net/ubuntu/+spec/foundations-x-installing-unsigned-secureboot)
have languished on this list since late April. All of the kernels have
been built and tested by myself and Mathieu Trudel-Lapierre. Andy
Whitcroft has asserted to me in private that they are difficult to
review and can only really be tested for functionality. Furthermore,
this patch set has been released in Xenial in a substantially similar form.

Therefore I propose to apply them for this SRU cycle with the
enforcement config option disabled. This at least exercises some of the
more complex code that accesses the UEFI firmware.

git://kernel.ubuntu.com/rtg/ubuntu-trusty.git
lts-backport-utopic-enforce-signed-modules
git://kernel.ubuntu.com/rtg/ubuntu-wily.git enforce-signed-modules
git://kernel.ubuntu.com/rtg/ubuntu-vivid.git enforce-signed-modules

All opposed say Aye.

rtg
-- 
Tim Gardner tim.gardner at canonical.com




More information about the kernel-team mailing list