Enabling the lockdown module required the enabling of module signature checking which in turn marked the kernel as tainted because our kernel was not signed. Currently the kernel only supports signing with already defeated the SHA-1 algorithm which makes the feature less useful in the first place. Also the current model only works when there's a central authority that signs all modules or you compile the kernel yourself and use your own key for the signatures. We could sign all kernel modules distributed with the kernel with a randomly generated key so they could be verified but that would make out-of-tree modules taint the kernel again. Since adding another key to the keyring requires the key used at build time, it would not be possible to add your own keys to the keyring without having the private key and distributing that one would fundamentally break the public key cryptography security model. So to solve this issue and since the modules weren't signed anyway, disable lsm_lockdown and signature checking for now. If you need a locked down kernel, for now please compile it yourself, enable both features and use your own keypair so you can safely sign all in-tree and custom built modules and they can be properly verified. This also adds a patch for iwlwifi that together with upstream reverts solves issues with some Intel wifi chipsets. fixes #18384 fixes #18355
49 lines
1.8 KiB
Diff
49 lines
1.8 KiB
Diff
From 78fe4d666ff244609c7d02bea07a22ce87e56326 Mon Sep 17 00:00:00 2001
|
|
From: Mehmet Akif Tasova <makiftasova@gmail.com>
|
|
Date: Mon, 30 Dec 2019 15:48:16 +0200
|
|
Subject: Revert "iwlwifi: mvm: fix scan config command size"
|
|
|
|
Since v5.4-rc1 was released, iwlwifi started throwing errors when scan
|
|
commands were sent to the firmware with certain devices (depending on
|
|
the OTP burned in the device, which contains the list of available
|
|
channels). For instance:
|
|
|
|
iwlwifi 0000:00:14.3: FW error in SYNC CMD SCAN_CFG_CMD
|
|
|
|
This bug was reported in the ArchLinux bug tracker:
|
|
https://bugs.archlinux.org/task/64703
|
|
|
|
And also in a specific case in bugzilla, when the lar_disabled option
|
|
was set: https://bugzilla.kernel.org/show_bug.cgi?id=205193
|
|
|
|
Revert the commit that introduced this error, by using the number of
|
|
channels from the OTP instead of the number of channels that is
|
|
specified in the FW TLV that tells us how many channels it supports.
|
|
|
|
This reverts commit 06eb547c4ae4382e70d556ba213d13c95ca1801b.
|
|
|
|
Cc: stable@vger.kernel.org # v5.4+
|
|
Signed-off-by: Mehmet Akif Tasova <makiftasova@gmail.com>
|
|
[ Luca: reworded the commit message a bit. ]
|
|
Signed-off-by: Luca Coelho <luciano.coelho@intel.com>
|
|
---
|
|
drivers/net/wireless/intel/iwlwifi/mvm/scan.c | 2 +-
|
|
1 file changed, 1 insertion(+), 1 deletion(-)
|
|
|
|
diff --git a/drivers/net/wireless/intel/iwlwifi/mvm/scan.c b/drivers/net/wireless/intel/iwlwifi/mvm/scan.c
|
|
index fcafa22ec6ce..8aa567d7912c 100644
|
|
--- a/drivers/net/wireless/intel/iwlwifi/mvm/scan.c
|
|
+++ b/drivers/net/wireless/intel/iwlwifi/mvm/scan.c
|
|
@@ -1220,7 +1220,7 @@ static int iwl_mvm_legacy_config_scan(struct iwl_mvm *mvm)
|
|
cmd_size = sizeof(struct iwl_scan_config_v2);
|
|
else
|
|
cmd_size = sizeof(struct iwl_scan_config_v1);
|
|
- cmd_size += num_channels;
|
|
+ cmd_size += mvm->fw->ucode_capa.n_scan_channels;
|
|
|
|
cfg = kzalloc(cmd_size, GFP_KERNEL);
|
|
if (!cfg)
|
|
--
|
|
cgit v1.2.1-1-g437b
|
|
|