[PATCH 4.14 112/246] ima: based on policy verify firmware signatures (pre-allocated buffer)