• Mimi Zohar's avatar
    ima: define a new policy condition based on the filesystem name · f1b08bbc
    Mimi Zohar authored
    If/when file data signatures are distributed with the file data, this
    patch will not be needed.  In the current environment where only some
    files are signed, the ability to differentiate between file systems is
    needed.  Some file systems consider the file system magic number
    internal to the file system.
    
    This patch defines a new IMA policy condition named "fsname", based on
    the superblock's file_system_type (sb->s_type) name. This allows policy
    rules to be expressed in terms of the filesystem name.
    
    The following sample rules require file signatures on rootfs files
    executed or mmap'ed.
    
    appraise func=BPRM_CHECK fsname=rootfs appraise_type=imasig
    appraise func=FILE_MMAP fsname=rootfs appraise_type=imasig
    Signed-off-by: default avatarMimi Zohar <zohar@linux.vnet.ibm.com>
    Cc: Dave Chinner <david@fromorbit.com>
    Cc: Theodore Ts'o <tytso@mit.edu>
    f1b08bbc
ima_policy 3.38 KB