On Sun, Sep 9, 2012 at 6:46 PM, Rusty Russell <[email protected]> wrote: > Kees Cook <[email protected]> writes: >> On Fri, Sep 7, 2012 at 10:12 AM, Mimi Zohar <[email protected]> wrote: >>> This method is a consistent and extensible approach to verifying the >>> integrity of file data/metadata, including kernel modules. The only >>> downside to this approach, I think, is that it requires changes to the >>> userspace tool. >> >> I'm fine with this -- it's an expected change that I'll pursue with >> glibc, kmod, etc. Without the userspace changes, nothing will use the >> new syscall. :) I've already got kmod (and older module-init-tools) >> patched to do this locally. > > A syscall is the right way to do this. But does it need to be done? > > 1) Do the LSM guys really want this hook?
The LSM hook half has already been acked by Serge and Eric, and I want to use it in Yama as well. > 2) Do we have a userspace which uses it? Chrome OS will be using it; I have patches for kmod and module-init-tools already. > If yes to both, and noone comes up with any creative complaints, I will > take the patch. Sound good; thanks! -Kees -- Kees Cook Chrome OS Security -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to [email protected] More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/

