x86/microcode/AMD: Load only SHA256-checksummed patches
authorBorislav Petkov (AMD) <bp@alien8.de>
Thu, 23 Jan 2025 13:44:53 +0000 (14:44 +0100)
committerBorislav Petkov (AMD) <bp@alien8.de>
Sat, 22 Feb 2025 10:46:05 +0000 (11:46 +0100)
commit50cef76d5cb0e199cda19f026842560f6eedc4f7
treeb9604abfb23760323b271db05a82b36599793939
parent037e81fb9d2dfe7b31fd97e5f578854e38f09887
x86/microcode/AMD: Load only SHA256-checksummed patches

Load patches for which the driver carries a SHA256 checksum of the patch
blob.

This can be disabled by adding "microcode.amd_sha_check=off" on the
kernel cmdline. But it is highly NOT recommended.

Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
arch/x86/Kconfig
arch/x86/kernel/cpu/microcode/amd.c
arch/x86/kernel/cpu/microcode/amd_shas.c [new file with mode: 0644]