linux-stable/security/integrity
Mimi Zohar 30511f37c9 ima: detect changes to the backing overlay file
[ Upstream commit b836c4d29f ]

Commit 18b44bc5a6 ("ovl: Always reevaluate the file signature for
IMA") forced signature re-evaulation on every file access.

Instead of always re-evaluating the file's integrity, detect a change
to the backing file, by comparing the cached file metadata with the
backing file's metadata.  Verifying just the i_version has not changed
is insufficient.  In addition save and compare the i_ino and s_dev
as well.

Reviewed-by: Amir Goldstein <amir73il@gmail.com>
Tested-by: Eric Snowberg <eric.snowberg@oracle.com>
Tested-by: Raul E Rangel <rrangel@chromium.org>
Cc: stable@vger.kernel.org
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-12-08 08:44:27 +01:00
..
evm evm: Complete description of evm_inode_setattr() 2023-07-27 08:37:06 +02:00
ima ima: detect changes to the backing overlay file 2023-12-08 08:44:27 +01:00
platform_certs efi: Add iMac Pro 2017 to uefi skip cert quirk 2023-01-18 11:41:49 +01:00
Kconfig
Makefile x86/efi: move common keyring handler functions to new file 2021-06-30 08:47:55 -04:00
digsig.c integrity: Fix memory leakage in keyring allocation error path 2023-01-18 11:41:03 +01:00
digsig_asymmetric.c
iint.c ima: annotate iint mutex to avoid lockdep false positive warnings 2023-12-08 08:44:27 +01:00
integrity.h ima: detect changes to the backing overlay file 2023-12-08 08:44:27 +01:00
integrity_audit.c integrity: check the return value of audit_log_start() 2022-02-16 12:52:47 +01:00