* [PATCH] loadpin: Fix stale KEXEC_VERIFY_SIG reference in documentation
@ 2026-09-05 1:36 Karl Mehltretter
2026-09-05 2:40 ` Randy Dunlap
0 siblings, 1 reply; 2+ messages in thread
From: Karl Mehltretter @ 2026-09-05 1:36 UTC (permalink / raw)
To: Kees Cook
Cc: Karl Mehltretter, Jonathan Corbet, Shuah Khan, Randy Dunlap,
James Morris, Ke Wu, linux-doc, linux-kernel
Commit 99d5cadfde2b ("kexec_file: split KEXEC_VERIFY_SIG into KEXEC_SIG
and KEXEC_SIG_FORCE") removed CONFIG_KEXEC_VERIFY_SIG but left the
LoadPin documentation pointing at it. Refer to CONFIG_KEXEC_SIG instead.
While at it, clean up the grammar of the sentence.
Fixes: 99d5cadfde2b ("kexec_file: split KEXEC_VERIFY_SIG into KEXEC_SIG and KEXEC_SIG_FORCE")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
---
Documentation/admin-guide/LSM/LoadPin.rst | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/Documentation/admin-guide/LSM/LoadPin.rst b/Documentation/admin-guide/LSM/LoadPin.rst
index dd3ca68b5df1..a90fd9dac960 100644
--- a/Documentation/admin-guide/LSM/LoadPin.rst
+++ b/Documentation/admin-guide/LSM/LoadPin.rst
@@ -23,9 +23,9 @@ sysctl allows for easy testing on systems with a mutable filesystem.)
It's also possible to exclude specific file types from LoadPin using kernel
command line option "``loadpin.exclude``". By default, all files are
included, but they can be excluded using kernel command line option such
-as "``loadpin.exclude=kernel-module,kexec-image``". This allows to use
+as "``loadpin.exclude=kernel-module,kexec-image``". This allows using
different mechanisms such as ``CONFIG_MODULE_SIG`` and
-``CONFIG_KEXEC_VERIFY_SIG`` to verify kernel module and kernel image while
-still use LoadPin to protect the integrity of other files kernel loads. The
-full list of valid file types can be found in ``kernel_read_file_str``
-defined in ``include/linux/kernel_read_file.h``.
+``CONFIG_KEXEC_SIG`` to verify kernel modules and kernel images while
+still using LoadPin to protect the integrity of other files the kernel
+loads. The full list of valid file types can be found in
+``kernel_read_file_str`` defined in ``include/linux/kernel_read_file.h``.
--
2.53.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH] loadpin: Fix stale KEXEC_VERIFY_SIG reference in documentation
2026-09-05 1:36 [PATCH] loadpin: Fix stale KEXEC_VERIFY_SIG reference in documentation Karl Mehltretter
@ 2026-09-05 2:40 ` Randy Dunlap
0 siblings, 0 replies; 2+ messages in thread
From: Randy Dunlap @ 2026-09-05 2:40 UTC (permalink / raw)
To: Karl Mehltretter, Kees Cook
Cc: Jonathan Corbet, Shuah Khan, James Morris, Ke Wu, linux-doc,
linux-kernel
On 9/4/26 6:36 PM, Karl Mehltretter wrote:
> Commit 99d5cadfde2b ("kexec_file: split KEXEC_VERIFY_SIG into KEXEC_SIG
> and KEXEC_SIG_FORCE") removed CONFIG_KEXEC_VERIFY_SIG but left the
> LoadPin documentation pointing at it. Refer to CONFIG_KEXEC_SIG instead.
>
> While at it, clean up the grammar of the sentence.
>
> Fixes: 99d5cadfde2b ("kexec_file: split KEXEC_VERIFY_SIG into KEXEC_SIG and KEXEC_SIG_FORCE")
> Assisted-by: LLM
> Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Reviewed-by: Randy Dunlap <rdunlap@infradead.org>
Thanks.
> ---
> Documentation/admin-guide/LSM/LoadPin.rst | 10 +++++-----
> 1 file changed, 5 insertions(+), 5 deletions(-)
>
> diff --git a/Documentation/admin-guide/LSM/LoadPin.rst b/Documentation/admin-guide/LSM/LoadPin.rst
> index dd3ca68b5df1..a90fd9dac960 100644
> --- a/Documentation/admin-guide/LSM/LoadPin.rst
> +++ b/Documentation/admin-guide/LSM/LoadPin.rst
> @@ -23,9 +23,9 @@ sysctl allows for easy testing on systems with a mutable filesystem.)
> It's also possible to exclude specific file types from LoadPin using kernel
> command line option "``loadpin.exclude``". By default, all files are
> included, but they can be excluded using kernel command line option such
> -as "``loadpin.exclude=kernel-module,kexec-image``". This allows to use
> +as "``loadpin.exclude=kernel-module,kexec-image``". This allows using
> different mechanisms such as ``CONFIG_MODULE_SIG`` and
> -``CONFIG_KEXEC_VERIFY_SIG`` to verify kernel module and kernel image while
> -still use LoadPin to protect the integrity of other files kernel loads. The
> -full list of valid file types can be found in ``kernel_read_file_str``
> -defined in ``include/linux/kernel_read_file.h``.
> +``CONFIG_KEXEC_SIG`` to verify kernel modules and kernel images while
> +still using LoadPin to protect the integrity of other files the kernel
> +loads. The full list of valid file types can be found in
> +``kernel_read_file_str`` defined in ``include/linux/kernel_read_file.h``.
--
~Randy
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-05 2:40 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-05 1:36 [PATCH] loadpin: Fix stale KEXEC_VERIFY_SIG reference in documentation Karl Mehltretter
2026-09-05 2:40 ` Randy Dunlap
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox