All of lore.kernel.org
 help / color / mirror / Atom feed
From: Julian Braha <julianbraha@gmail.com>
To: zohar@linux.ibm.com, roberto.sassu@huawei.com,
	dmitry.kasatkin@gmail.com, paul@paul-moore.com,
	jmorris@namei.org, serge@hallyn.com
Cc: eric.snowberg@oracle.com, linux-integrity@vger.kernel.org,
	linux-security-module@vger.kernel.org,
	linux-kernel@vger.kernel.org,
	Julian Braha <julianbraha@gmail.com>
Subject: [PATCH] ima: clean up IMA_MEASURE_PCR_IDX in Kconfig
Date: Sat, 22 Aug 2026 01:15:45 +0100	[thread overview]
Message-ID: <20260822001545.354195-1-julianbraha@gmail.com> (raw)

The IMA_MEASURE_PCR_IDX option is not visible for users to set, so it
always uses its default, 10. This means that the 'range 8 14' is dead
code, and the "If unsure, use the default 10" in the help text is
misleading because the user *has no other choice*.

During the first patch submission to add this option in 2008 [1],
the submitter originally gave this option a prompt:

"PCR for Aggregate (8 <= Index <= 14)"

then later removed it in the revision, without adjusting the rest of the
option accordingly [2].

Let's clean up this of this IMA_MEASURE_PCR_IDX config option to be
consistent with its current, non-visible state.

This dead range was found by kconfirm, a static analysis tool for Kconfig.

Signed-off-by: Julian Braha <julianbraha@gmail.com>
---
 security/integrity/ima/Kconfig | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/security/integrity/ima/Kconfig b/security/integrity/ima/Kconfig
index b3a9f86809b0..8a67bc1faa4c 100644
--- a/security/integrity/ima/Kconfig
+++ b/security/integrity/ima/Kconfig
@@ -46,12 +46,11 @@ config IMA_KEXEC
 
 config IMA_MEASURE_PCR_IDX
 	int
-	range 8 14
 	default 10
 	help
 	  IMA_MEASURE_PCR_IDX determines the TPM PCR register index
 	  that IMA uses to maintain the integrity aggregate of the
-	  measurement list.  If unsure, use the default 10.
+	  measurement list.
 
 config IMA_LSM_RULES
 	bool
-- 
2.55.0


             reply	other threads:[~2026-08-22  0:15 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-22  0:15 Julian Braha [this message]
2026-08-24 15:00 ` [PATCH] ima: clean up IMA_MEASURE_PCR_IDX in Kconfig Mimi Zohar
2026-08-24 15:54   ` Julian Braha

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260822001545.354195-1-julianbraha@gmail.com \
    --to=julianbraha@gmail.com \
    --cc=dmitry.kasatkin@gmail.com \
    --cc=eric.snowberg@oracle.com \
    --cc=jmorris@namei.org \
    --cc=linux-integrity@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=paul@paul-moore.com \
    --cc=roberto.sassu@huawei.com \
    --cc=serge@hallyn.com \
    --cc=zohar@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.