File: module-disable-matching-missing-version-crc.patch

package info (click to toggle)
linux 6.17.2-1~exp1
  • links: PTS, VCS
  • area: main
  • in suites: experimental
  • size: 1,734,084 kB
  • sloc: ansic: 26,674,600; asm: 271,176; sh: 147,222; python: 75,910; makefile: 57,291; perl: 36,942; xml: 19,562; cpp: 5,894; yacc: 4,909; lex: 2,943; awk: 1,556; sed: 28; ruby: 25
file content (23 lines) | stat: -rw-r--r-- 800 bytes parent folder | download | duplicates (25)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
From: Ben Hutchings <ben@decadent.org.uk>
Date: Fri, 02 Dec 2016 23:06:18 +0000
Subject: module: Disable matching missing version CRC
Forwarded: not-needed

This partly reverts commit cd3caefb4663e3811d37cc2afad3cce642d60061.
We want to fail closed if a symbol version CRC is missing, as the
alternative may allow subverting module signing.
---
--- a/kernel/module/version.c
+++ b/kernel/module/version.c
@@ -46,9 +46,8 @@ int check_version(const struct load_info
 		goto bad_version;
 	}
 
-	/* Broken toolchain. Warn once, then let it go.. */
-	pr_warn_once("%s: no symbol version for %s\n", info->name, symname);
-	return 1;
+	pr_warn("%s: no symbol version for %s\n", info->name, symname);
+	return 0;
 
 bad_version:
 	pr_warn("%s: disagrees about version of symbol %s\n", info->name, symname);