From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752036AbcDRXA6 (ORCPT ); Mon, 18 Apr 2016 19:00:58 -0400 Received: from e28smtp05.in.ibm.com ([125.16.236.5]:39280 "EHLO e28smtp05.in.ibm.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751451AbcDRXA5 (ORCPT ); Mon, 18 Apr 2016 19:00:57 -0400 X-IBM-Helo: d28relay05.in.ibm.com X-IBM-MailFrom: zohar@linux.vnet.ibm.com X-IBM-RcptTo: linux-kernel@vger.kernel.org;linux-security-module@vger.kernel.org Message-ID: <1461020430.2423.36.camel@linux.vnet.ibm.com> Subject: Re: [PATCH] IMA: add INTEGRITY_ASYMMETRIC_KEYS dependency From: Mimi Zohar To: Arnd Bergmann Cc: Dmitry Kasatkin , James Morris , "Serge E. Hallyn" , Petko Manolov , David Howells , linux-ima-devel@lists.sourceforge.net, linux-ima-user@lists.sourceforge.net, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org Date: Mon, 18 Apr 2016 19:00:30 -0400 In-Reply-To: <1460838870-1251174-1-git-send-email-arnd@arndb.de> References: <1460838870-1251174-1-git-send-email-arnd@arndb.de> Content-Type: text/plain; charset="UTF-8" X-Mailer: Evolution 3.12.11 (3.12.11-1.fc21) Mime-Version: 1.0 Content-Transfer-Encoding: 7bit X-TM-AS-MML: disable x-cbid: 16041823-0017-0000-0000-00001E17CBD1 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hi Arnd, On Sat, 2016-04-16 at 22:33 +0200, Arnd Bergmann wrote: > The newly added CONFIG_IMA_KEYRINGS_PERMIT_SIGNED_BY_BUILTIN_OR_SECONDARY > option only makes sense in combination with INTEGRITY_ASYMMETRIC_KEYS, > otherwise we get a build error: > > warning: (IMA_KEYRINGS_PERMIT_SIGNED_BY_BUILTIN_OR_SECONDARY) selects INTEGRITY_TRUSTED_KEYRING which has unmet direct dependencies (INTEGRITY && SYSTEM_TRUSTED_KEYRING && INTEGRITY_ASYMMETRIC_KEYS) > security/integrity/evm/evm_main.c: In function 'evm_load_x509': > security/integrity/evm/evm_main.c:494:7: error: implicit declaration of function 'integrity_load_x509' > rc = integrity_load_x509(INTEGRITY_KEYRING_EVM, CONFIG_EVM_X509_PATH); > > This adds a Kconfig dependency. > > Signed-off-by: Arnd Bergmann > Fixes: 9e1bbe8b8992 ("IMA: Use the the system trusted keyrings instead of .ima_mok") > --- > security/integrity/ima/Kconfig | 1 + > 1 file changed, 1 insertion(+) > > diff --git a/security/integrity/ima/Kconfig b/security/integrity/ima/Kconfig > index aab9b0a53edf..5487827fa86c 100644 > --- a/security/integrity/ima/Kconfig > +++ b/security/integrity/ima/Kconfig > @@ -159,6 +159,7 @@ config IMA_KEYRINGS_PERMIT_SIGNED_BY_BUILTIN_OR_SECONDARY > bool "Permit keys validly signed by a built-in or secondary CA cert (EXPERIMENTAL)" > depends on SYSTEM_TRUSTED_KEYRING > depends on SECONDARY_TRUSTED_KEYRING > + depends on INTEGRITY_ASYMMETRIC_KEYS > select INTEGRITY_TRUSTED_KEYRING > default n > help Good catch! Thank you for reporting the problem. Enabling this Kconfig option only makes sense if IMA_TRUSTED_KEYRING is enabled. I think adding that dependency will resolve the build issues. Mimi