]> git.baikalelectronics.ru Git - kernel.git/commit
ima: re-evaluate files on privileged mounted filesystems
authorMimi Zohar <zohar@linux.vnet.ibm.com>
Wed, 21 Feb 2018 16:35:20 +0000 (11:35 -0500)
committerMimi Zohar <zohar@linux.vnet.ibm.com>
Fri, 23 Mar 2018 10:31:37 +0000 (06:31 -0400)
commiteafe3c23e67cf83d4df8f0383ffeefc39e5cca32
tree80fa2cc61e12a5b5e5647ed29aa31eab9254a037
parent7acedffc3dbbeb526e94875aa87691a830214633
ima: re-evaluate files on privileged mounted filesystems

This patch addresses the fuse privileged mounted filesystems in a "secure"
environment, with a correctly enforced security policy, which is willing
to assume the inherent risk of specific fuse filesystems that are well
defined and properly implemented.

As there is no way for the kernel to detect file changes, the kernel
ignores the cached file integrity results and re-measures, re-appraises,
and re-audits the file.

Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Cc: Miklos Szeredi <miklos@szeredi.hu>
Cc: Seth Forshee <seth.forshee@canonical.com>
Cc: Dongsu Park <dongsu@kinvolk.io>
Cc: Alban Crequy <alban@kinvolk.io>
Acked-by: Serge Hallyn <serge@hallyn.com>
Acked-by: "Eric W. Biederman" <ebiederm@xmission.com>
security/integrity/ima/ima_main.c