]> git.baikalelectronics.ru Git - kernel.git/commit
ima: prevent new digsig xattr from being replaced
authorMimi Zohar <zohar@linux.vnet.ibm.com>
Tue, 18 Mar 2014 03:24:18 +0000 (23:24 -0400)
committerMimi Zohar <zohar@linux.vnet.ibm.com>
Thu, 12 Jun 2014 21:58:05 +0000 (17:58 -0400)
commit598c6ac3cd92a8e99883839876b6f2451fdd7b55
treeb3b8253420850eb54927da9f68e41d9ad074ac6f
parent7e795b59009f30508f629410a70fcc975c0d32f9
ima: prevent new digsig xattr from being replaced

Even though a new xattr will only be appraised on the next access,
set the DIGSIG flag to prevent a signature from being replaced with
a hash on file close.

Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
security/integrity/ima/ima_appraise.c