diff options
author | Ramji Jiyani <ramjiyani@google.com> | 2022-09-21 13:52:15 -0700 |
---|---|---|
committer | Ramji Jiyani <ramjiyani@google.com> | 2022-09-30 17:41:39 +0000 |
commit | c09f10c778ea446ea0d2a3fc83df832b0596dafd (patch) | |
tree | 6852c73256defb732d7001adf2d75f85b29ab2ba | |
parent | 94442686bcdeb7759b3b02fd806ff05dbdeb8ac9 (diff) |
Revert "ANDROID: GKI: Disable security lockdown for unsigned modules"
This reverts commit 1694ef383e3029777999a05d1a9b6a7d5693a1d2.
Reason for revert: Part of old protected/unprotected module implemenation.
It is being replaced by a new design listed as option 2A at
go/gki-modules-build-integration
Bug: 232430739
Test: TH
Signed-off-by: Ramji Jiyani <ramjiyani@google.com>
Change-Id: I2ca2de69317e223adc554edc127016f7adc1fb7b
-rw-r--r-- | kernel/module.c | 8 |
1 files changed, 0 insertions, 8 deletions
diff --git a/kernel/module.c b/kernel/module.c index 4976b27357d3..03181b1acc89 100644 --- a/kernel/module.c +++ b/kernel/module.c @@ -2960,15 +2960,7 @@ static int module_sig_check(struct load_info *info, int flags) return -EKEYREJECTED; } -/* - * ANDROID: GKI: Do not prevent loading of unsigned modules; - * as all modules except GKI modules are not signed. - */ -#ifndef CONFIG_MODULE_SIG_PROTECT return security_locked_down(LOCKDOWN_MODULE_SIGNATURE); -#else - return 0; -#endif } #else /* !CONFIG_MODULE_SIG */ static int module_sig_check(struct load_info *info, int flags) |