• Mimi Zohar's avatar
    ima: update builtin policies · 24fd03c8
    Mimi Zohar authored
    This patch defines a builtin measurement policy "tcb", similar to the
    existing "ima_tcb", but with additional rules to also measure files
    based on the effective uid and to measure files opened with the "read"
    mode bit set (eg. read, read-write).
    
    Changing the builtin "ima_tcb" policy could potentially break existing
    users.  Instead of defining a new separate boot command line option each
    time the builtin measurement policy is modified, this patch defines a
    single generic boot command line option "ima_policy=" to specify the
    builtin policy and deprecates the use of the builtin ima_tcb policy.
    
    [The "ima_policy=" boot command line option is based on Roberto Sassu's
    "ima: added new policy type exec" patch.]
    Signed-off-by: default avatarMimi Zohar <zohar@linux.vnet.ibm.com>
    Signed-off-by: default avatarDr. Greg Wettstein <gw@idfusion.org>
    Cc: stable@vger.kernel.org
    24fd03c8
ima_policy.c 21.4 KB