All of lore.kernel.org
 help / color / mirror / Atom feed
From: Mimi Zohar <zohar-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
Cc: initramfs-u79uwXL29TY76Z2rM5mHXA@public.gmane.org,
	harald-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org,
	Stefan Berger <stefanb-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
Subject: Re: [PATCH] dracut-install: preserve extended attributes when copying files
Date: Fri, 11 Nov 2016 14:11:40 -0500	[thread overview]
Message-ID: <1478891500.31015.52.camel@linux.vnet.ibm.com> (raw)
In-Reply-To: <1477422589-21327-1-git-send-email-stefanb-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>

Hi Harold,

Thank you for upstreaming commit 479b5cd "98integrity: support
validating the IMA policy file signature".   Do you have any
comments/concerns about this patch?

thanks,

Mimi

On Tue, 2016-10-25 at 15:09 -0400, Stefan Berger wrote:
> From: Stefan Berger <stefanb-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
> 
> Preserve extended attributes when copying files using dracut-install.
> 
> The copying of extended attributes avoids file execution denials when
> the Linux Integrity Measurement's Appraisal mode is active. In that mode
> executables need their file signatures copied. In particular, this patch
> solves the problem that dependent libaries are not included in the
> initramfs since the copied programs could not be executed due to missing
> signatures. The following audit record shows the type of failure that
> is now prevented:
> 
> type=INTEGRITY_DATA msg=audit(1477409025.492:30065): pid=922 uid=0
>  auid=4294967295 ses=4294967295
>  subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
>  op="appraise_data" cause="IMA-signature-required"
>  comm="ld-linux-x86-64"
>  name="/var/tmp/dracut.R6ySa4/initramfs/usr/bin/journalctl"
>  dev="dm-0" ino=37136 res=0
> 
> Signed-off-by: Stefan Berger <stefanb-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
> ---
>  install/dracut-install.c | 4 ++--
>  1 file changed, 2 insertions(+), 2 deletions(-)
> 
> diff --git a/install/dracut-install.c b/install/dracut-install.c
> index fe30bba..c0f1c17 100644
> --- a/install/dracut-install.c
> +++ b/install/dracut-install.c
> @@ -294,7 +294,7 @@ static int cp(const char *src, const char *dst)
>   normal_copy:
>          pid = fork();
>          if (pid == 0) {
> -                execlp("cp", "cp", "--reflink=auto", "--sparse=auto", "--preserve=mode,timestamps", "-fL", src, dst,
> +                execlp("cp", "cp", "--reflink=auto", "--sparse=auto", "--preserve=mode,timestamps,xattr", "-fL", src, dst,
>                         NULL);
>                  _exit(EXIT_FAILURE);
>          }
> @@ -302,7 +302,7 @@ static int cp(const char *src, const char *dst)
>          while (waitpid(pid, &ret, 0) < 0) {
>                  if (errno != EINTR) {
>                          ret = -1;
> -                        log_error("Failed: cp --reflink=auto --sparse=auto --preserve=mode,timestamps -fL %s %s", src,
> +                        log_error("Failed: cp --reflink=auto --sparse=auto --preserve=mode,timestamps,xattr -fL %s %s", src,
>                                    dst);
>                          break;
>                  }


  parent reply	other threads:[~2016-11-11 19:11 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-10-25 19:09 [PATCH] dracut-install: preserve extended attributes when copying files Stefan Berger
     [not found] ` <1477422589-21327-1-git-send-email-stefanb-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2016-10-25 20:05   ` Dracut GitHub Import Bot
2016-11-11 19:11   ` Mimi Zohar [this message]
     [not found]     ` <1478891500.31015.52.camel-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2016-11-15  9:41       ` Harald Hoyer

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1478891500.31015.52.camel@linux.vnet.ibm.com \
    --to=zohar-23vcf4htsmix0ybbhkvfkdbpr1lh4cv8@public.gmane.org \
    --cc=harald-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org \
    --cc=initramfs-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
    --cc=stefanb-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.