1 # SPDX-License-Identifier: GPL-2.0-only 2 config SECURITY_LOADPIN 3 bool "Pin load of kernel files (module 4 depends on SECURITY && BLOCK 5 help 6 Any files read through the kernel fi 7 (kernel modules, firmware, kexec ima 8 can be pinned to the first filesyste 9 enabled, any files that come from ot 10 rejected. This is best used on syste 11 have a root filesystem backed by a r 12 dm-verity or a CDROM. 13 14 config SECURITY_LOADPIN_ENFORCE 15 bool "Enforce LoadPin at boot" 16 depends on SECURITY_LOADPIN 17 # Module compression breaks LoadPin un 18 # the kernel. 19 depends on !MODULES || (MODULE_COMPRES 20 help 21 If selected, LoadPin will enforce pi 22 selected, it can be enabled at boot 23 "loadpin.enforce=1". 24 25 config SECURITY_LOADPIN_VERITY 26 bool "Allow reading files from certain 27 depends on SECURITY_LOADPIN && DM_VERI 28 help 29 If selected LoadPin can allow readin 30 that use dm-verity. LoadPin maintain 31 digests it considers trusted. A veri 32 considered trusted if its root diges 33 of trusted digests. 34 35 The list of trusted verity can be po 36 on the LoadPin securityfs entry 'dm- 37 expects a file descriptor of a file 38 parameter. The file must be located 39 start with the line: 40 41 # LOADPIN_TRUSTED_VERITY_ROOT_DIGEST 42 43 This is followed by the verity diges 44 line.
Linux® is a registered trademark of Linus Torvalds in the United States and other countries.
TOMOYO® is a registered trademark of NTT DATA CORPORATION.