[PATCH 4.17 143/336] ima: based on policy verify firmware signatures (pre-allocated buffer)