ima: detect changes to the backing overlay file
commit b836c4d29f2744200b2af41e14bf50758dddc818 upstream. Commit 18b44bc5 ("ovl: Always reevaluate the file signature for IMA") forced signature re-evaulation on every file access. Instead of always re-evaluating the file's integrity, detect a change to the backing file, by comparing the cached file metadata with the backing file's metadata. Verifying just the i_version has not changed is insufficient. In addition save and compare the i_ino and s_dev as well. Reviewed-by:Amir Goldstein <amir73il@gmail.com> Tested-by:
Eric Snowberg <eric.snowberg@oracle.com> Tested-by:
Raul E Rangel <rrangel@chromium.org> Cc: stable@vger.kernel.org Signed-off-by:
Mimi Zohar <zohar@linux.ibm.com> Signed-off-by:
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
parent
f2f0144e
No related branches found
No related tags found
Showing
- fs/overlayfs/super.c 1 addition, 1 deletionfs/overlayfs/super.c
- security/integrity/ima/ima_api.c 5 additions, 0 deletionssecurity/integrity/ima/ima_api.c
- security/integrity/ima/ima_main.c 15 additions, 1 deletionsecurity/integrity/ima/ima_main.c
- security/integrity/integrity.h 2 additions, 0 deletionssecurity/integrity/integrity.h
Please register or sign in to comment