• Fan Wu's avatar
    fsverity: expose verified fsverity built-in signatures to LSMs · 7c373e4f
    Fan Wu authored
    This patch enhances fsverity's capabilities to support both integrity and
    authenticity protection by introducing the exposure of built-in
    signatures through a new LSM hook. This functionality allows LSMs,
    e.g. IPE, to enforce policies based on the authenticity and integrity of
    files, specifically focusing on built-in fsverity signatures. It enables
    a policy enforcement layer within LSMs for fsverity, offering granular
    control over the usage of authenticity claims. For instance, a policy
    could be established to only permit the execution of all files with
    verified built-in fsverity signatures.
    
    The introduction of a security_inode_setintegrity() hook call within
    fsverity's workflow ensures that the verified built-in signature of a file
    is exposed to LSMs. This enables LSMs to recognize and label fsverity files
    that contain a verified built-in fsverity signature. This hook is invoked
    subsequent to the fsverity_verify_signature() process, guaranteeing the
    signature's verification against fsverity's keyring. This mechanism is
    crucial for maintaining system security, as it operates in kernel space,
    effectively thwarting attempts by malicious binaries to bypass user space
    stack interactions.
    
    The second to last commit in this patch set will add a link to the IPE
    documentation in fsverity.rst.
    Signed-off-by: default avatarDeven Bowers <deven.desai@linux.microsoft.com>
    Signed-off-by: default avatarFan Wu <wufan@linux.microsoft.com>
    Acked-by: default avatarEric Biggers <ebiggers@google.com>
    Signed-off-by: default avatarPaul Moore <paul@paul-moore.com>
    7c373e4f
signature.c 4.27 KB