From: Breno Leitao <leitao@debian.org>
To: Mimi Zohar <zohar@linux.ibm.com>
Cc: Frederick Lawler <fred@cloudflare.com>,
Andreas Hindborg <a.hindborg@kernel.org>,
Roberto Sassu <roberto.sassu@huawei.com>,
Dmitry Kasatkin <dmitry.kasatkin@gmail.com>,
Eric Snowberg <eric.snowberg@oracle.com>,
Paul Moore <paul@paul-moore.com>,
James Morris <jmorris@namei.org>,
"Serge E. Hallyn" <serge@hallyn.com>,
linux-kernel@vger.kernel.org, linux-integrity@vger.kernel.org,
linux-security-module@vger.kernel.org,
kernel-team@cloudflare.com
Subject: Re: [PATCH v2 1/2] configfs: move CONFIGFS_MAGIC definition to magic.h
Date: Wed, 26 Aug 2026 01:07:01 -0700 [thread overview]
Message-ID: <ao6ejs3oWcRAea4h@gmail.com> (raw)
In-Reply-To: <46bde670fa25f07cc99dddc61ecc6de4d0ee125e.camel@linux.ibm.com>
On Tue, Aug 25, 2026 at 01:49:53PM -0400, Mimi Zohar wrote:
> On Tue, 2026-08-25 at 11:47 -0500, Frederick Lawler wrote:
> > Hi Breno,
> >
> > On Tue, Aug 25, 2026 at 07:10:02AM -0700, Breno Leitao wrote:
> > > On Wed, Aug 19, 2026 at 06:45:22PM -0500, Frederick Lawler wrote:
> > > > IMA shouldn't measure or appraise configfs, but currently does because
> > > > it's missing from the default exclusion policies. Move CONFIGFS_MAGIC to
> > > > magic.h to expose the file system's magic to IMA, as well as other userland
> > > > applications.
> > > >
> > > > Suggested-by: Mimi Zohar <zohar@linux.ibm.com>
> > > > Signed-off-by: Frederick Lawler <fred@cloudflare.com>
> > >
> > > Do you want this change to go thorugh the configfs tree, or the tree
> > > specific for IMA?
> > > ?
> >
> > Unless you have a user asking for it, I personally think it makes sense
> > for linux-integrity to take it since the two patches are related.
> >
> > I don't mind spinning a v3 for integrity if you choose to take it now.
> >
> > Best,
> > Fred
> >
> > PS. Sorry for not keeping the Reviewed-by tag from v1. I usually
> > forget _something_ with re-spins until after the fact.
>
> Breno, thank you for the Reviewed-by. The patch set didn't quite make it in
> time for the open window, but I plan on upstreaming them. Can we change the
> Reviewed-by to an Acked-by?
Sure. Feel free to do it.
Acked-by: Breno Leitao <leitao@debian.org>
next prev parent reply other threads:[~2026-08-26 8:07 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-19 23:45 [PATCH v2 0/2] ima: don't measure/appraise files on configfs Frederick Lawler
2026-08-19 23:45 ` [PATCH v2 1/2] configfs: move CONFIGFS_MAGIC definition to magic.h Frederick Lawler
2026-08-25 14:10 ` Breno Leitao
2026-08-25 16:47 ` Frederick Lawler
2026-08-25 17:49 ` Mimi Zohar
2026-08-26 8:07 ` Breno Leitao [this message]
2026-08-19 23:45 ` [PATCH v2 2/2] ima: don't measure/appraise files on configfs Frederick Lawler
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ao6ejs3oWcRAea4h@gmail.com \
--to=leitao@debian.org \
--cc=a.hindborg@kernel.org \
--cc=dmitry.kasatkin@gmail.com \
--cc=eric.snowberg@oracle.com \
--cc=fred@cloudflare.com \
--cc=jmorris@namei.org \
--cc=kernel-team@cloudflare.com \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=paul@paul-moore.com \
--cc=roberto.sassu@huawei.com \
--cc=serge@hallyn.com \
--cc=zohar@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.