From: Mimi Zohar <zohar@linux.ibm.com>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: linux-integrity <linux-integrity@vger.kernel.org>,
linux-kernel <linux-kernel@vger.kernel.org>,
Roberto Sassu <roberto.sassu@huaweicloud.com>
Subject: [GIT PULL] integrity: subsystem fixes for v6.16
Date: Tue, 27 May 2025 18:08:35 -0400 [thread overview]
Message-ID: <283be073924bd046f180880b5912338744550884.camel@linux.ibm.com> (raw)
Hi Linus,
Carrying the IMA measurement list across kexec is not a new feature, but is
updated to address a couple of issues:
- Carrying the IMA measurement list across kexec required knowing apriori all
the file measurements between the "kexec load" and "kexec execute" in order to
measure them before the "kexec load". Any delay between the "kexec load" and
"kexec exec" exacerbated the problem.
- Any file measurements post "kexec load" were not carried across kexec,
resulting in the measurement list being out of sync with the TPM PCR.
With these changes, the buffer for the IMA measurement list is still allocated
at "kexec load", but copying the IMA measurement list is deferred to after
quiescing the TPM.
Two new kexec critical data records are defined.
Note:
- The IMA kexec segment hash is not calculated or verified.
thanks,
Mimi
The following changes since commit b4432656b36e5cc1d50a1f2dc15357543add530e:
Linux 6.15-rc4 (2025-04-27 15:19:23 -0700)
are available in the Git repository at:
https://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity.git/ tags/integrity-v6.16
for you to fetch changes up to fe3aebf27dc1875b2a0d13431e2e8cf3cf350cca:
ima: do not copy measurement list to kdump kernel (2025-05-14 06:40:09 -0400)
----------------------------------------------------------------
integrity-v6.16
----------------------------------------------------------------
Steven Chen (10):
ima: rename variable the seq_file "file" to "ima_kexec_file"
ima: define and call ima_alloc_kexec_file_buf()
kexec: define functions to map and unmap segments
ima: kexec: skip IMA segment validation after kexec soft reboot
ima: kexec: define functions to copy IMA log at soft boot
ima: kexec: move IMA log copy from kexec load to execute
ima: verify if the segment size has changed
ima: make the kexec extra memory configurable
ima: measure kexec load and exec events as critical data
ima: do not copy measurement list to kdump kernel
include/linux/ima.h | 3 +
include/linux/kexec.h | 9 ++
kernel/kexec_core.c | 54 ++++++++++
kernel/kexec_file.c | 33 ++++++-
security/integrity/ima/Kconfig | 11 +++
security/integrity/ima/ima.h | 6 ++
security/integrity/ima/ima_kexec.c | 196 ++++++++++++++++++++++++++++++-------
security/integrity/ima/ima_queue.c | 5 +
8 files changed, 283 insertions(+), 34 deletions(-)
next reply other threads:[~2025-05-27 22:08 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-05-27 22:08 Mimi Zohar [this message]
2025-05-28 15:42 ` pr-tracker-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=283be073924bd046f180880b5912338744550884.camel@linux.ibm.com \
--to=zohar@linux.ibm.com \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=roberto.sassu@huaweicloud.com \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®