t/linux: disable IMA

This disables IMA in the kernel config. Currently Metropolis doesn't
utilize any of its features, since integrity is ensured in other ways.

See: https://github.com/monogon-dev/monogon/issues/107
Change-Id: Icc0af8790ef30c2e0497b570abb403cadd89371f
Reviewed-on: https://review.monogon.dev/c/monogon/+/557
Reviewed-by: Lorenz Brun <lorenz@monogon.tech>
diff --git a/third_party/linux/linux-metropolis.config b/third_party/linux/linux-metropolis.config
index b584a0c..41defc2 100644
--- a/third_party/linux/linux-metropolis.config
+++ b/third_party/linux/linux-metropolis.config
@@ -3508,21 +3508,21 @@
 CONFIG_SECURITY_LANDLOCK=y
 CONFIG_INTEGRITY=y
 # CONFIG_INTEGRITY_SIGNATURE is not set
-CONFIG_IMA=y
-CONFIG_IMA_MEASURE_PCR_IDX=10
+CONFIG_IMA=n
+# CONFIG_IMA_MEASURE_PCR_IDX is not set
 # CONFIG_IMA_TEMPLATE is not set
-CONFIG_IMA_NG_TEMPLATE=y
+# CONFIG_IMA_NG_TEMPLATE is not set
 # CONFIG_IMA_SIG_TEMPLATE is not set
-CONFIG_IMA_DEFAULT_TEMPLATE="ima-ng"
+# CONFIG_IMA_DEFAULT_TEMPLATE is not set
 # CONFIG_IMA_DEFAULT_HASH_SHA1 is not set
-CONFIG_IMA_DEFAULT_HASH_SHA256=y
+# CONFIG_IMA_DEFAULT_HASH_SHA256 is not set
 # CONFIG_IMA_DEFAULT_HASH_SHA512 is not set
-CONFIG_IMA_DEFAULT_HASH="sha256"
+# CONFIG_IMA_DEFAULT_HASH is not set
 # CONFIG_IMA_WRITE_POLICY is not set
 # CONFIG_IMA_READ_POLICY is not set
 # CONFIG_IMA_APPRAISE is not set
-CONFIG_IMA_MEASURE_ASYMMETRIC_KEYS=y
-CONFIG_IMA_QUEUE_EARLY_BOOT_KEYS=y
+# CONFIG_IMA_MEASURE_ASYMMETRIC_KEYS is not set
+# CONFIG_IMA_QUEUE_EARLY_BOOT_KEYS is not set
 # CONFIG_IMA_SECURE_AND_OR_TRUSTED_BOOT is not set
 # CONFIG_IMA_DISABLE_HTABLE is not set
 CONFIG_EVM=y