asus-wmi: Restrict debugfs interface when the kernel is locked down
authorMatthew Garrett <matthew.garrett@nebula.com>
Wed, 5 Apr 2017 16:40:30 +0000 (17:40 +0100)
committerBen Hutchings <ben@decadent.org.uk>
Mon, 17 Jul 2017 02:01:21 +0000 (03:01 +0100)
commitc4d69b837bb6b4a1dbea876fbcea8a9f6423fb06
tree48caf462af4fc7e4f800dda8a5d91d1951a8e780
parent2fed75d67d6570c5c60add892062dd6ef9e2b5bc
asus-wmi: Restrict debugfs interface when the kernel is locked down

We have no way of validating what all of the Asus WMI methods do on a given
machine - and there's a risk that some will allow hardware state to be
manipulated in such a way that arbitrary code can be executed in the
kernel, circumventing module loading restrictions.  Prevent that if the
kernel is locked down.

Signed-off-by: Matthew Garrett <matthew.garrett@nebula.com>
Signed-off-by: David Howells <dhowells@redhat.com>
Gbp-Pq: Topic features/all/lockdown
Gbp-Pq: Name 0053-asus-wmi-Restrict-debugfs-interface-when-the-kernel-.patch
drivers/platform/x86/asus-wmi.c