On Thu, 2026-03-12 at 13:55 -0700, Nathan Chancellor wrote:
> On Thu, Mar 12, 2026 at 12:07:41PM -0400, Mimi Zohar wrote:
> > I pushed out the patch to next-integrity, but am a bit concerned about the
> > definition:
> > 
> > +config HAVE_ARCH_GET_SECUREBOOT
> > +       def_bool EFI
> > +
> 
> What is concerning about the definition with regards to s390?
> 
> > Has anyone actually tested this patch on s390, not just compiled it?  If 
> > so, I'd
> > appreciate a tested-by tag.
> 
> It would be good to test (if it is possible to test in QEMU, I am happy
> to attempt to do so). As far as I can tell, 31a6a07eefeb placed
> arch_get_secureboot() in such a way that the __weak definition would be
> used when CONFIG_KEXEC_FILE was disabled, even though ipl_secure_flag
> should always be available, which this patch avoids.

Thanks, Nathan.  Fortunately I got access to an s390 and was able to test.  It
seems to be working.

Mimi

Reply via email to