linux/arch/s390
Peter Oberparleiter 3868f91044 s390/hypfs: Enable limited access during lockdown
When kernel lockdown is active, debugfs_locked_down() blocks access to
hypfs files that register ioctl callbacks, even if the ioctl interface
is not required for a function. This unnecessarily breaks userspace
tools that only rely on read operations.

Resolve this by registering a minimal set of file operations during
lockdown, avoiding ioctl registration and preserving access for affected
tooling.

Note that this change restores hypfs functionality when lockdown is
active from early boot (e.g. via lockdown=integrity kernel parameter),
but does not apply to scenarios where lockdown is enabled dynamically
while Linux is running.

Tested-by: Mete Durlu <meted@linux.ibm.com>
Reviewed-by: Vasily Gorbik <gor@linux.ibm.com>
Fixes: 5496197f9b ("debugfs: Restrict debugfs when the kernel is locked down")
Signed-off-by: Peter Oberparleiter <oberpar@linux.ibm.com>
Signed-off-by: Alexander Gordeev <agordeev@linux.ibm.com>
2025-08-21 17:46:14 +02:00
..
appldata
boot s390/mm: Do not map lowcore with identity mapping 2025-08-20 16:37:28 +02:00
configs s390/configs: Set HZ=1000 2025-08-20 16:37:27 +02:00
crypto
hypfs s390/hypfs: Enable limited access during lockdown 2025-08-21 17:46:14 +02:00
include more s390 updates for 6.17 merge window 2025-08-08 06:56:55 +03:00
kernel more s390 updates for 6.17 merge window 2025-08-08 06:56:55 +03:00
kvm
lib
mm more s390 updates for 6.17 merge window 2025-08-08 06:56:55 +03:00
net
pci
purgatory
tools
Kbuild
Kconfig more s390 updates for 6.17 merge window 2025-08-08 06:56:55 +03:00
Kconfig.debug
Makefile
Makefile.postlink