From patchwork Thu Oct 27 10:01:43 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Aditya Garg X-Patchwork-Id: 11713 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:a5d:6687:0:0:0:0:0 with SMTP id l7csp139704wru; Thu, 27 Oct 2022 03:06:20 -0700 (PDT) X-Google-Smtp-Source: AMsMyM4LUc4xuar6PNPNFacbA1I7ebGmynBkD/vZTngA3S1/b+y0RiLdCjY797ExWbRtkMjX9D5g X-Received: by 2002:a05:6402:428d:b0:460:b26c:82a5 with SMTP id g13-20020a056402428d00b00460b26c82a5mr35413923edc.66.1666865179966; Thu, 27 Oct 2022 03:06:19 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1666865179; cv=pass; d=google.com; s=arc-20160816; b=clH6/x3eooYDR93ThlpuVZI7wKjpiqrN6P2ZaPKlMoQ1UjAEw73dpA4y2WY7s7bd8n fIZEOnDjUeOWFftuo4aiufEhdIIjnZD2YcZoHK4JV4uNLAmVq3iJc0G8dU7S8E0xFNqI bGVot8ar+q2pDsEvtiU3hGFKj/WQ4OGY1qiFfVe4BDAv29ZUYN3s59lpKoC6Jo6hRv7r +xT9xRxWF339rQAEesM8J6R6vhOMji9FjW03cm+atv9gpch0BqqypI7LO9KMxmXicSn2 yplv5g2jpOrZS9Yi025m3mDBGcFZARhzZBa3abhGHjikeyLNljDL+d5IDZEw46U5VIG8 GnSQ== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:mime-version:content-transfer-encoding :content-id:content-language:accept-language:message-id:date :thread-index:thread-topic:subject:cc:to:from:dkim-signature; bh=0J/K0jHKE+VWvSv2kPNuWSM721hfnQcQ6L5uCrWFK2c=; b=kbhdv13+aOYJxYJcA/uvWTj8ZuEFKdjG5q3qQ8jeLFx8X+EnxZzzU+qcUCg2VJKsex Y3FSE1bRtDh+Ob76TGCdXMF76GtKP4zIpzkhrqGVxNmG0dApWIrA1uUF/qtEv0uAntBw auft2Djd8zKn6ryzpqsxsSxyIjVBc8Cd4hU7mviw76xTdvO3N0FXo9ckQt7b4onwqN3g nU91OeKuxm+t4/CfBehTjtaU4wpPD3hCZU86aaakrMjj8+TKFTf002CuQAuXndUZhvO2 MmQm5KfPTem5H7B0BbKef6Dd0W0noBiOJmFfe4QCTSS6lciTg0qPu70k/gjqWrLvhaAi cJpA== ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@live.com header.s=selector1 header.b=mu6XZHW0; arc=pass (i=1); spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=live.com Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id ho18-20020a1709070e9200b007a9e6f0f832si1122771ejc.944.2022.10.27.03.05.55; Thu, 27 Oct 2022 03:06:19 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@live.com header.s=selector1 header.b=mu6XZHW0; arc=pass (i=1); spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=live.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S235034AbiJ0KEW (ORCPT + 99 others); Thu, 27 Oct 2022 06:04:22 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:58738 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S235150AbiJ0KEH (ORCPT ); Thu, 27 Oct 2022 06:04:07 -0400 Received: from IND01-BMX-obe.outbound.protection.outlook.com (mail-bmxind01olkn2016.outbound.protection.outlook.com [40.92.103.16]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 047DCBC34; Thu, 27 Oct 2022 03:04:06 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=E+shBmqzFD4ayPbdP4wJY8sIEr5kntGKhOUflNUtrtgVECBYNoWakP56s4RUZrkStPc9zsOLlC0+YXJgkgI8nWwJ3p4zrOartMzqKIA5Qahs56BPQ7EfeOiv7eaVNdIBuC+8Gxz+pF51t6bN6t3++CUhlT1y4AK2JuyDahc4OV8qxzcCUivhw8mMGmtx9DmFrOCBo3a4rn192SBasbITfU3qNfKA42FaijGemvMzDPMpw7fsPGik+mwjHE2W1+LsV2jeq9OR2FePhf0aI9jVrJFDHJlPHr9xW/PD6aNc5JxI6CsBWNo7DWLlS/z/DkfUK7jKTpYd+6tEcwrX3X99sA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=0J/K0jHKE+VWvSv2kPNuWSM721hfnQcQ6L5uCrWFK2c=; b=LvMMOgS1ONxhiy9JhlYp12OBPvIYxbIgtS12nr7wlU06CcOgp9jvywM0t+3XzYWL3Gj+xb+mjtfz7jBm8HFzWeBBD+AWKp8xBz6YubRTAZ9EOx2ANcW/0Blzhl/gZ/0xSx2bHerz8lONKXOuUW4XBdXphWVXiuxeTsM52ivvDbBW6U1MdCUbz7ykjePozL+RifjJnySF5wcKzTiCfw+FweMsyD2Qyf4CXqj5rZt/missO8/Be/sE9yqKjNW9MY/Bx/g6a5sgatM3ajo9vktb/YfPWGMZyXHK5SjedRWywP14NxEwzOzfc2Pu0ZuOMwq/oy5EzNEb375iPEBHj++iPg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=live.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=0J/K0jHKE+VWvSv2kPNuWSM721hfnQcQ6L5uCrWFK2c=; b=mu6XZHW0hMIEr69E+/TLBjqZEOgIWrdNxcBbepRu8NTI3byxAuSXqrPNLPf/likfhRv1h4Mf0ZN3JX9jK1rSMuOX28/ZrZ41XJZhhrb24UX/EaxugQrxTVXsagVSxT8Z8a0nAyqvSpg9SnZyrRhoDlvHg+BBMnNJTBCuj2kKWG+FompBclM/U6xr4cfhENRiQzwK9aUSoo96kRHe1Umtffx0jWb4u8tyvcFoxsGaYOLfe25o0QRjc1UhHQV5zX5YUHwPYNJ84t6PbdzPGfk7SDE6lnjFOo9SYj+2cuzpC3nJGsqFBPWJ2m9vvYLQTfT18KfhUUgouQELUdVlifHPww== Received: from BM1PR01MB0931.INDPRD01.PROD.OUTLOOK.COM (2603:1096:b00:2::9) by MAZPR01MB7794.INDPRD01.PROD.OUTLOOK.COM (2603:1096:a01:22::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5746.28; Thu, 27 Oct 2022 10:01:43 +0000 Received: from BM1PR01MB0931.INDPRD01.PROD.OUTLOOK.COM ([fe80::3dc1:f6bc:49e4:b294]) by BM1PR01MB0931.INDPRD01.PROD.OUTLOOK.COM ([fe80::3dc1:f6bc:49e4:b294%9]) with mapi id 15.20.5746.029; Thu, 27 Oct 2022 10:01:43 +0000 From: Aditya Garg To: "zohar@linux.ibm.com" , "chyishian.jiang@gmail.com" , "linux-kernel@vger.kernel.org" , "jarkko@kernel.org" , "dmitry.kasatkin@gmail.com" , "paul@paul-moore.com" , "jmorris@namei.org" , "serge@hallyn.com" , "linux-integrity@vger.kernel.org" , "keyrings@vger.kernel.org" , "linux-security-module@vger.kernel.org" CC: "stable@vger.kernel.org" , Orlando Chamberlain Subject: [PATCH] efi: Add iMac Pro 2017 to uefi skip cert quirk Thread-Topic: [PATCH] efi: Add iMac Pro 2017 to uefi skip cert quirk Thread-Index: AQHY6esdtcYgI4FYkkmedEvra7eSTA== Date: Thu, 27 Oct 2022 10:01:43 +0000 Message-ID: <8CB9E43B-AB65-4735-BB8D-A8A7A10F9E30@live.com> Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-ms-exchange-messagesentrepresentingtype: 1 x-tmn: [dDbCyKXgOYUmPwvmRCV6wwTMpaoeSwdA] x-ms-publictraffictype: Email x-ms-traffictypediagnostic: BM1PR01MB0931:EE_|MAZPR01MB7794:EE_ x-ms-office365-filtering-correlation-id: 82a215f4-4939-4da4-505d-08dab802405f x-microsoft-antispam: BCL:0; x-microsoft-antispam-message-info: JiNC2Ko5c9NwSt5IQ+Nwz0KbEoO9pbEl0K/cb3ZPUrBeAcXj4eOULGoZCQoGLslw64Dx9TRckSUA9LlsvsNaED8Bc+TzeBHZSJgoH2dWhz2jPe8tqB9qerdY+Qr8oBmTN1j8PEIU0vTyxKaJbCNZeVv8s64bv9A77wzChF+Qs9vm6EO/y3vcV455tRFJt68nTNkCyilJKx3Z2Skk78DI18SUlq4QPCIaoM14LCXfoYEVVRCUZTZxSymPgihXrqfK96l+mixpCLlt4iBkBUmfiFUZt4i2xmxUktP3Y3Qzc6zj5jato620hDQeBXujpnj7RwyoRBxgoGhCpzdXyVNxCM7OUD1n7Io4eGBkSBWz1+GVmUIUCc0hGiNLWUENx5zY/kji+CxrdH4+HovrhySVyVAScgBC/7CnaNAXEp6wmjBR3Xo9uWtRUJohP+wUKq6oIj8Cl3C5u/ao+oFRXWuSfwOuO69HYt+hTaF0FWiMQDf64B7VqHlPUVTrQUdMGh7dIhxpa++969PJVUBYYEUgWEmog2tSWbXcSpQXc1ShwtPRH1rmrwVVJILM+GgNsm6/ukE36/FT4NTkbyJuRmhOTyh7/0xsHc7IZZyHlW3vA+wqrM+fTipGKERC0Zg3qoAAwqh8pE+ONBXmvw4Fma+bfw== x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: oDuTxBmGS2JwxhsKiIshO+Q2UdXYSfFeWebfh4xL0743pOMxXBRJg7UImMsfIl7P9UkfEOud8G7Xi4zaqkjJoI0pePji+QCk7/WtQ7TPD+w7ms1lBcnxMFrONvsTxmsDu7GzjzvPfZcxLa0NOmpJma7XMp9SkEEDpPjz58yoOHgkKHhWtHyLVl5YCOEorVD0IdcYDmqUdaFqNmvUP1Ys0T65vPuGlgTAUudPDvVHCGPbhZ6CwGLEhZcVQStANopcwQuqeYiHKPvjCTEns7Emerz3GWEc/F/28mcrnVPPahctkgxlP/joQjXOrh5zsZavsGd+dOjvVXMwJTLo/qFYrXx1DMGJlbuY+UuUCwicBciMEAzrIQ0QSePdJOn9erDn03vY7cr5i0GZgTUxvMHnYEg9C+zpgsNZorqvLZe9tP1tSDHOCV51ckOZRL1NiSXc8+p0w+q3R4PACtHgf/jq8aC7R55CrtH1gYxVDdMvbnpVpRShDFhtpL3Szb37gpVRSxGcpVidgSN8mfWwC8nXQXrfCfC6a9YSMHzENZHLvE2TUuFCk84KoJoUpvWcuFJdZ3wEOQx93TXetWhEX66D/cyxfFvE7bWc5UR9Cl9CkRJSYFQkW+jIQ1lvybt9OtlD3i9KD0X5CrnSs+F8OGOL2nTH+QbHHYQQgAN759Haq80/FNGADoimmeahFOdJsZkJ9Z68ADY/acvEmR1RJhCoU0orAh8wg0Hu4UxjX6mP3SWVO9PEmxNJSCZbCKh1eIAh+R7VvhKg5AWMfG6JVFVb63GkRgW+25tbaiqqhBvBAHtekNI0/KxaqOSZTdIfKtmgdrjygRPjyeh/4I8uXozXhKDQCAqzDIdpG2PJ+G5ceLwKlBgD0VZtRtuoeKtWEj2SJrLlP3MMzUk89ULNp+c0hhkdWSCI8LywRb30Kwn46DZJuQczAnOm0T1kheL9bxXKX6byaMda2pPwmOrL3rlbiPkal+6gqqqeuDuhdnWh5r5+K9fxlj0/CNDSBdrSkwew+5iHsNVehfY81dlqQf1+FC7iqYuCS4jzUuLqYSUzs7AccIkSrJDO0AbkPChnK0oSuJf9HD0kSzSMXASOHtSJcdHPVjzQ6Tcx5K0Ay5w7cXNZI06/6ZVJOsSoIMOme1G6mvkkC2Y7yG4AlhMbxr/yu0S+xBWSUzKaP+rxbtKw/s0UZ3S/NClHFwn7BpXY6wdpfUA8DyNyKfI2DGNYwJojbmiEkN4AViLK7b8t6TnLK4tarlTTCn7/W5BSQPW77kKcQ/rBmO+nmwMN9Lhd0y4LXg== Content-ID: MIME-Version: 1.0 X-OriginatorOrg: sct-15-20-4755-11-msonline-outlook-42ed3.templateTenant X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: BM1PR01MB0931.INDPRD01.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000 X-MS-Exchange-CrossTenant-Network-Message-Id: 82a215f4-4939-4da4-505d-08dab802405f X-MS-Exchange-CrossTenant-originalarrivaltime: 27 Oct 2022 10:01:43.5311 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000 X-MS-Exchange-Transport-CrossTenantHeadersStamped: MAZPR01MB7794 X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FREEMAIL_ENVFROM_END_DIGIT, FREEMAIL_FROM,SPF_HELO_PASS,SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= X-GMAIL-THRID: =?utf-8?q?1747834488999663327?= X-GMAIL-MSGID: =?utf-8?q?1747834822758461863?= From: Aditya Garg The iMac Pro 2017 is also a T2 Mac. Thus add it to the list of uefi skip cert. Cc: stable@vger.kernel.org Signed-off-by: Aditya Garg --- security/integrity/platform_certs/load_uefi.c | 1 + 1 file changed, 1 insertion(+) diff --git a/security/integrity/platform_certs/load_uefi.c b/security/integrity/platform_certs/load_uefi.c index b78753d27d8ea6..d1fdd113450a63 100644 --- a/security/integrity/platform_certs/load_uefi.c +++ b/security/integrity/platform_certs/load_uefi.c @@ -35,6 +35,7 @@ static const struct dmi_system_id uefi_skip_cert[] = { { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "MacPro7,1") }, { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "iMac20,1") }, { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "iMac20,2") }, + { UEFI_QUIRK_SKIP_CERT("Apple Inc.", "iMacPro1,1") }, { } };