All of lore.kernel.org
 help / color / mirror / Atom feed
From: Mimi Zohar <zohar@linux.ibm.com>
To: Julian Braha <julianbraha@gmail.com>,
	roberto.sassu@huawei.com, dmitry.kasatkin@gmail.com,
	paul@paul-moore.com, jmorris@namei.org, serge@hallyn.com
Cc: eric.snowberg@oracle.com, linux-integrity@vger.kernel.org,
	linux-security-module@vger.kernel.org,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH] ima: clean up IMA_MEASURE_PCR_IDX in Kconfig
Date: Mon, 24 Aug 2026 11:00:52 -0400	[thread overview]
Message-ID: <ca87a913bece92019d04ffb2f795f8365fde4a87.camel@linux.ibm.com> (raw)
In-Reply-To: <20260822001545.354195-1-julianbraha@gmail.com>

On Sat, 2026-08-22 at 01:15 +0100, Julian Braha wrote:
> The IMA_MEASURE_PCR_IDX option is not visible for users to set, so it
> always uses its default, 10. This means that the 'range 8 14' is dead
> code, and the "If unsure, use the default 10" in the help text is
> misleading because the user *has no other choice*.
> 
> During the first patch submission to add this option in 2008 [1],
> the submitter originally gave this option a prompt:
> 
> "PCR for Aggregate (8 <= Index <= 14)"
> 
> then later removed it in the revision, without adjusting the rest of the
> option accordingly [2].
> 
> Let's clean up this of this IMA_MEASURE_PCR_IDX config option to be
> consistent with its current, non-visible state.
> 
> This dead range was found by kconfirm, a static analysis tool for Kconfig.
> 
> Signed-off-by: Julian Braha <julianbraha@gmail.com>

The PCR index can be specified as a Kconfig IMA_MEASURE_PCR_IDX and on
individual policy records via the "pcr=" option.

Mimi

  reply	other threads:[~2026-08-24 15:01 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-22  0:15 [PATCH] ima: clean up IMA_MEASURE_PCR_IDX in Kconfig Julian Braha
2026-08-24 15:00 ` Mimi Zohar [this message]
2026-08-24 15:54   ` Julian Braha

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ca87a913bece92019d04ffb2f795f8365fde4a87.camel@linux.ibm.com \
    --to=zohar@linux.ibm.com \
    --cc=dmitry.kasatkin@gmail.com \
    --cc=eric.snowberg@oracle.com \
    --cc=jmorris@namei.org \
    --cc=julianbraha@gmail.com \
    --cc=linux-integrity@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=paul@paul-moore.com \
    --cc=roberto.sassu@huawei.com \
    --cc=serge@hallyn.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.