On Mon, 2026-07-13 at 13:55 -0400, Mimi Zohar wrote:
> On Mon, 2026-07-13 at 10:09 +0200, Enrico Bravi wrote:
> > This series aims to introduce integrity measurements when the IMA policy is
> > written on the securityfs file.
> > In particular, when a signed policy is not mandatory, it can be written
> > directly on the securityfs file. This allows to override the boot policy
> > at the first write, and append new policy rules at the subsequent writes (if
> > CONFIG_IMA_WRITE_POLICY=y). In this case new policy can be loaded
> > without being measured.
> > 
> > The patch #1 introduces a new critical-data record for the newly loaded
> > policy. The measurement is performed over the textual representation of the
> > new policy once it becomes effective (after ima_update_policy()). As
> > suggested by Mimi, the new critical-data rule is added to the arch
> > specific policy rules (only when a signed policy is not mandatory).
> > 
> > The patch #2, following what was suggested by Roberto, measures the input
> > buffer sent to the securityfs policy file, regardless of whether the new
> > policy will be accepted or not. This is done by calling
> > process_buffer_measurement(), enabling POLICY_CHECK in ima_match_rules() and
> > ima_match_rule_data() in order to catch it when 'measure func=POLICY_CHECK'
> > is defined (e.g., ima_policy=tcb).
> > 
> > Changes in v6:
> >  - Fixed a merge conflict.
> >  - Initialized struct seq_file file.
> >  - Fixed some lines longer than 80 characters.
> >  - Moved from vmalloc() to kmalloc().
> >  - Corrected POLICY_CHECK behaviour in ima_match_rules().
> 
> Thanks, Enrico.  The patches are now queued.

Thank you Mimi.

Enrico

Reply via email to