Hi Matthew, On Wed, 2017-11-15 at 13:05 -0800, Matthew Garrett wrote: > Add a --portable argument that generates EVM signatures without using > the inode number and generation or fs UUID. Thanks, Matthew. This patch doesn't seem to be based on the upstream git repo. A 'z' option crept in; and a "printf" was removed that isn't in upstream. "evm_immutable" should have been in a testing branch until the kernel code was upstreamed. Not knowing where it is being used, I'm kind of hesitant to remove it. For now, at least, please make sure that the "evm_immutable" and "evm_portable" flags are mutually exclusive. thanks, Mimi