]>
git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blob - security/lock_down.c
1 /* Lock down the kernel
3 * Copyright (C) 2016 Red Hat, Inc. All Rights Reserved.
4 * Written by David Howells (dhowells@redhat.com)
6 * This program is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU General Public Licence
8 * as published by the Free Software Foundation; either version
9 * 2 of the Licence, or (at your option) any later version.
12 #include <linux/security.h>
13 #include <linux/export.h>
14 #include <linux/efi.h>
16 static __ro_after_init
bool kernel_locked_down
;
19 * Put the kernel into lock-down mode.
21 static void __init
lock_kernel_down(const char *where
)
23 if (!kernel_locked_down
) {
24 kernel_locked_down
= true;
25 pr_notice("Kernel is locked down from %s; see man kernel_lockdown.7\n",
30 static int __init
lockdown_param(char *ignored
)
32 lock_kernel_down("command line");
36 early_param("lockdown", lockdown_param
);
39 * Lock the kernel down from very early in the arch setup. This must happen
40 * prior to things like ACPI being initialised.
42 void __init
init_lockdown(void)
44 #ifdef CONFIG_LOCK_DOWN_IN_EFI_SECURE_BOOT
45 if (efi_enabled(EFI_SECURE_BOOT
))
46 lock_kernel_down("EFI secure boot");
51 * kernel_is_locked_down - Find out if the kernel is locked down
52 * @what: Tag to use in notice generated if lockdown is in effect
54 bool __kernel_is_locked_down(const char *what
, bool first
)
56 if (what
&& first
&& kernel_locked_down
)
57 pr_notice("Lockdown: %s is restricted; see man kernel_lockdown.7\n",
59 return kernel_locked_down
;
61 EXPORT_SYMBOL(__kernel_is_locked_down
);