Skip to content

Commit 658d5c7

Browse files
t-8chmimizohar
authored andcommitted
ima: efi: Drop unnecessary check for CONFIG_MODULE_SIG/CONFIG_KEXEC_SIG
When configuration settings are disabled the guarded functions are defined as empty stubs, so the check is unnecessary. Signed-off-by: Thomas Weißschuh <linux@weissschuh.net> Reviewed-by: Mimi Zohar <zohar@linux.ibm.com> Reviewed-by: Aaron Tomlin <atomlin@atomlin.com> Reviewed-by: Nicolas Schier <nsc@kernel.org> [zohar@linux.ibm.com: fixed merge conflict with commit 63e8a44395a4] Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
1 parent 01baa39 commit 658d5c7

1 file changed

Lines changed: 2 additions & 4 deletions

File tree

security/integrity/ima/ima_efi.c

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -25,10 +25,8 @@ static const char * const sb_arch_rules[] = {
2525
const char * const *arch_get_ima_policy(void)
2626
{
2727
if (IS_ENABLED(CONFIG_IMA_ARCH_POLICY) && arch_get_secureboot()) {
28-
if (IS_ENABLED(CONFIG_MODULE_SIG))
29-
set_module_sig_enforced();
30-
if (IS_ENABLED(CONFIG_KEXEC_SIG))
31-
set_kexec_sig_enforced();
28+
set_module_sig_enforced();
29+
set_kexec_sig_enforced();
3230
return sb_arch_rules;
3331
}
3432
return NULL;

0 commit comments

Comments
 (0)