On Thu, 2026-03-12 at 13:55 -0700, Nathan Chancellor wrote: > On Thu, Mar 12, 2026 at 12:07:41PM -0400, Mimi Zohar wrote: > > I pushed out the patch to next-integrity, but am a bit concerned about the > > definition: > > > > +config HAVE_ARCH_GET_SECUREBOOT > > + def_bool EFI > > + > > What is concerning about the definition with regards to s390? > > > Has anyone actually tested this patch on s390, not just compiled it? If > > so, I'd > > appreciate a tested-by tag. > > It would be good to test (if it is possible to test in QEMU, I am happy > to attempt to do so). As far as I can tell, 31a6a07eefeb placed > arch_get_secureboot() in such a way that the __weak definition would be > used when CONFIG_KEXEC_FILE was disabled, even though ipl_secure_flag > should always be available, which this patch avoids.
Thanks, Nathan. Fortunately I got access to an s390 and was able to test. It seems to be working. Mimi

