Re: [RFC PATCH v2] ima,fuse: introduce new fs flag FS_NO_IMA_CACHE

2018-01-22 Thread Mimi Zohar
On Mon, 2018-01-22 at 10:16 +0100, Alban Crequy wrote: > On Fri, Jan 19, 2018 at 5:56 PM, Mimi Zohar wrote: > > On Fri, 2018-01-19 at 11:35 +0100, Alban Crequy wrote: > >> On Thu, Jan 18, 2018 at 10:25 PM, Mimi Zohar > >> wrote: > >> > On Tue, 2018-01-16 at 16:10 +0100, Alban Crequy wrote: > >>

Re: [RFC PATCH v2] ima,fuse: introduce new fs flag FS_NO_IMA_CACHE

2018-01-22 Thread Alban Crequy
On Fri, Jan 19, 2018 at 5:56 PM, Mimi Zohar wrote: > On Fri, 2018-01-19 at 11:35 +0100, Alban Crequy wrote: >> On Thu, Jan 18, 2018 at 10:25 PM, Mimi Zohar >> wrote: >> > On Tue, 2018-01-16 at 16:10 +0100, Alban Crequy wrote: >> >> From: Alban Crequy >> >> >> >> This patch forces files to be re

Re: [RFC PATCH v2] ima,fuse: introduce new fs flag FS_NO_IMA_CACHE

2018-01-19 Thread Mimi Zohar
On Fri, 2018-01-19 at 11:35 +0100, Alban Crequy wrote: > On Thu, Jan 18, 2018 at 10:25 PM, Mimi Zohar wrote: > > On Tue, 2018-01-16 at 16:10 +0100, Alban Crequy wrote: > >> From: Alban Crequy > >> > >> This patch forces files to be re-measured, re-appraised and re-audited > >> on file systems wit

Re: [RFC PATCH v2] ima,fuse: introduce new fs flag FS_NO_IMA_CACHE

2018-01-19 Thread Alban Crequy
On Thu, Jan 18, 2018 at 10:25 PM, Mimi Zohar wrote: > On Tue, 2018-01-16 at 16:10 +0100, Alban Crequy wrote: >> From: Alban Crequy >> >> This patch forces files to be re-measured, re-appraised and re-audited >> on file systems with the feature flag FS_NO_IMA_CACHE. In that way, >> cached integrit

Re: [RFC PATCH v2] ima,fuse: introduce new fs flag FS_NO_IMA_CACHE

2018-01-18 Thread Mimi Zohar
On Tue, 2018-01-16 at 16:10 +0100, Alban Crequy wrote: > From: Alban Crequy > > This patch forces files to be re-measured, re-appraised and re-audited > on file systems with the feature flag FS_NO_IMA_CACHE. In that way, > cached integrity results won't be used. > > For now, this patch adds the

[RFC PATCH v2] ima,fuse: introduce new fs flag FS_NO_IMA_CACHE

2018-01-16 Thread Alban Crequy
From: Alban Crequy This patch forces files to be re-measured, re-appraised and re-audited on file systems with the feature flag FS_NO_IMA_CACHE. In that way, cached integrity results won't be used. For now, this patch adds the new flag only FUSE filesystems. This is needed because the userspace