From: Mimi Zohar <zohar@linux.vnet.ibm.com>
To: Matthias Gerstner <mgerstner@suse.de>, linux-integrity@vger.kernel.org
Subject: Re: IMA: Deadlock in ima_appraise_measurement when /bin/kmod carries a digsig in security.evm
Date: Tue, 19 Jun 2018 18:21:15 -0400 [thread overview]
Message-ID: <1529446875.3269.6.camel@linux.vnet.ibm.com> (raw)
In-Reply-To: <20180618145628.GD8123@f195.suse.de>
Hi Matthias,
On Mon, 2018-06-18 at 16:56 +0200, Matthias Gerstner wrote:
> Hello,
>
> I came across a deadlock issue when /bin/kmod carries a digital
> signature in security.evm.
>
> There was a patch suggested on the old linux-ima-devel mailing list here
> <https://sourceforge.net/p/linux-ima/mailman/message/35628097/>, but it
> seems not to have made it into the official tree.
>
> Can anybody tell me what the status of this patch is?
Somehow I missed it. A more generic patch is currently queued, which
should resolve this problem as well. Please try commit fdc33c29b022
("evm: Don't deadlock if a crypto algorithm is unavailable") in the
next-integrity-queued branch.
Mimi
next prev parent reply other threads:[~2018-06-19 22:21 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-06-18 14:56 IMA: Deadlock in ima_appraise_measurement when /bin/kmod carries a digsig in security.evm Matthias Gerstner
2018-06-19 22:21 ` Mimi Zohar [this message]
2018-06-20 10:53 ` Matthias Gerstner
2018-06-22 19:48 ` Mimi Zohar
2018-06-24 22:31 ` Mimi Zohar
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1529446875.3269.6.camel@linux.vnet.ibm.com \
--to=zohar@linux.vnet.ibm.com \
--cc=linux-integrity@vger.kernel.org \
--cc=mgerstner@suse.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.