• Tyler Hicks's avatar
    ima: Fail rule parsing when buffer hook functions have an invalid action · 71218343
    Tyler Hicks authored
    Buffer based hook functions, such as KEXEC_CMDLINE and KEY_CHECK, can
    only measure. The process_buffer_measurement() function quietly ignores
    all actions except measure so make this behavior clear at the time of
    policy load.
    
    The parsing of the keyrings conditional had a check to ensure that it
    was only specified with measure actions but the check should be on the
    hook function and not the keyrings conditional since
    "appraise func=KEY_CHECK" is not a valid rule.
    
    Fixes: b0935123 ("IMA: Define a new hook to measure the kexec boot command line arguments")
    Fixes: 5808611c ("IMA: Add KEY_CHECK func to measure keys")
    Signed-off-by: default avatarTyler Hicks <tyhicks@linux.microsoft.com>
    Signed-off-by: default avatarMimi Zohar <zohar@linux.ibm.com>
    71218343
ima_policy.c 45.9 KB