From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0344A313E2B; Thu, 28 May 2026 04:06:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779941190; cv=none; b=H7vhNHMBfovq7Noc8AEmf+sVmvdPE5L0WePbi0EMnbqbuUn1iJEfjGG5/kbMpYOk7xE7QQitLoiPq2OE+QxMm7idSCHDxjL5Iai76JBLmyGQrNEK71SRf5ZxkDiBVABZHNKwioSrK6TbB6m4f9IL2CoqWVRrow5cZo3qd19MHGA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779941190; c=relaxed/simple; bh=P28PdT8jfxCMGuJdS5XszbV6NyjcvNiWf0TBziQB0iI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=F4Kw5ToHunrcajLLhG5uAY9diSS9tzy2xZ/c+43biXsrR3iN1k14KHu8ryHf2jj3VGKZpW81GKnUk7Zpk0fVQV5hNap22OLRGSQdFEMH2Fe1UpkTVFkoVOJ4N2ZAYVYVE44yJjdXsSzVY6NXdzr5A7YejZfThOqgoURj0Yq70B8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=fVaaesTc; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="fVaaesTc" Received: by smtp.kernel.org (Postfix) with ESMTPSA id E76031F000E9; Thu, 28 May 2026 04:06:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779941188; bh=Dc90uicqWNyrPhT43h4DV8SlP7Nodn9YuJB8Tk87yzw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=fVaaesTcTs2GT9Nd5+xqlFRtuYigGyo5mAXGjBsg8Rrcxu6R760tAzHGSSnAfiohF gv9iZS+Cp9d7f8bOXX8G20GWLRePcTz0kcpjh2ooKgENdHNX+WufXv0PwHoTYu8Ej3 5pTf7NUuMXAhx7iIhOgUflf5Q1Qh2Txyu+IvDB3DrWaSjnp36m8c/PLFi3WreunXaH xwsaBBaOGH8sqzgEXJCIZLEEjQ14p9YPmfUFZhHMxaW0auOKfbH6CGD0DLOF6L82vT XfgO8dycUmKuyCeP3kOsLhO31TbIDZ+s5QRS4uhe0LFp9R/N8li919pIZfPMDQNizx hxnpHheXcL+sw== From: Anand Jain To: fstests@vger.kernel.org Cc: linux-btrfs@vger.kernel.org, linux-ext4@vger.kernel.org, linux-xfs@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, zlang@redhat.com, hch@infradead.org Subject: [PATCH v6 08/11] fstests: verify IMA isolation on cloned filesystems Date: Thu, 28 May 2026 12:05:39 +0800 Message-ID: <8ede46ac75856bcbebdb652f99a0511e8ae1b7b0.1779939330.git.asj@kernel.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Add testcase to verify IMA measurement isolation when multiple devices share the same FSUUID. Signed-off-by: Anand Jain --- tests/generic/804 | 108 ++++++++++++++++++++++++++++++++++++++++++ tests/generic/804.out | 10 ++++ 2 files changed, 118 insertions(+) create mode 100644 tests/generic/804 create mode 100644 tests/generic/804.out diff --git a/tests/generic/804 b/tests/generic/804 new file mode 100644 index 000000000000..31ae77a2f461 --- /dev/null +++ b/tests/generic/804 @@ -0,0 +1,108 @@ +#! /bin/bash +# SPDX-License-Identifier: GPL-2.0 +# Copyright (c) 2026 Anand Jain . All Rights Reserved. +# +# FS QA Test 804 +# Verify IMA isolation on cloned filesystems: +# . Mount two devices sharing the same FSUUID (cloned). +# . Apply an IMA policy to measure files based on that FSUUID. +# . Create unique files on each mount point to trigger measurements. +# . Confirm the IMA log correctly attributes events to the respective mounts. + +. ./common/preamble +. ./common/filter + +_begin_fstest auto quick clone + +_require_test +_require_block_device $TEST_DEV +_require_loop + +[ "$FSTYP" = "btrfs" ] && _fixed_by_kernel_commit xxxxxxxxxxxx \ + "btrfs: use on-disk uuid for s_uuid in temp_fsid mounts" +[ "$FSTYP" = "btrfs" ] && _fixed_by_kernel_commit xxxxxxxxxxxx \ + "btrfs: derive f_fsid from on-disk fsuuid and dev_t" + +_cleanup() +{ + cd / + rm -r -f $tmp.* + _unmount $mnt1 2>/dev/null + _unmount $mnt2 2>/dev/null + _loop_image_destroy "${devs[@]}" 2> /dev/null +} + +# Normalize device names and mount points +filter_pool() +{ + sed -e "s|${devs[0]}|DEV1|g" -e "s|$mnt1|MNT1|g" \ + -e "s|${devs[1]}|DEV2|g" -e "s|$mnt2|MNT2|g" | _filter_spaces +} + +# Core helper to set IMA policy and check measurement logs +do_ima() +{ + local ima_policy="/sys/kernel/security/ima/policy" + local ima_log="/sys/kernel/security/ima/ascii_runtime_measurements" + local fsuuid + local mnt=$1 + local enable=$2 + + # Since the in-memory IMA audit log is only cleared upon reboot, + # use unique random filenames to avoid log collisions. + local foofile=$(mktemp --dry-run foobar_XXXXX) + + echo $mnt $enable | filter_pool + + [ -w "$ima_policy" ] || _notrun "IMA policy not writable" + + fsuuid=$(blkid -s UUID -o value ${devs[0]}) + + # Load IMA policy to measure file access specifically for this + # filesystem UUID. + if [[ $enable -eq 1 ]]; then + echo "measure func=FILE_CHECK fsuuid=$fsuuid" > "$ima_policy" || \ + _notrun "Policy rejected" + fi + + # Create a file to trigger measurement and verify its entry in + # the IMA log. + echo "test_data" > $mnt/$foofile + + # IMA log extract + grep $foofile "$ima_log" | awk '{ print $5 }' | filter_pool | \ + sed "s/$foofile/FOOBAR_FILE/" + + echo "dbg: $mnt $fsuuid $foofile" >> $seqres.full + cat $ima_log | tail -1 >> $seqres.full + echo >> $seqres.full +} + +# Initialize loop base and cloned instances +devs=() +_loop_image_create_clone devs +mnt1=$TEST_DIR/$seq/mnt1 +mnt2=$TEST_DIR/$seq/mnt2 +mkdir -p $mnt1 +mkdir -p $mnt2 + +# Concurrently mount both clones +_mount $(_common_dev_mount_options) $(_clone_mount_option) ${devs[0]} $mnt1 || \ + _fail "Failed to mount dev1" +_mount $(_common_dev_mount_options) $(_clone_mount_option) ${devs[1]} $mnt2 || \ + _fail "Failed to mount dev2" + +# IMA response on baseline and clone configuration +do_ima $mnt1 1 +do_ima $mnt2 0 + +# Cycle mount on the second device. +echo mount cycle +_unmount $mnt2 +_mount $mount_opts ${devs[1]} $mnt2 || _fail "Failed to mount dev2" + +do_ima $mnt1 0 +do_ima $mnt2 0 + +status=0 +exit diff --git a/tests/generic/804.out b/tests/generic/804.out new file mode 100644 index 000000000000..9804181d6c17 --- /dev/null +++ b/tests/generic/804.out @@ -0,0 +1,10 @@ +QA output created by 804 +MNT1 1 +MNT1/FOOBAR_FILE +MNT2 0 +MNT2/FOOBAR_FILE +mount cycle +MNT1 0 +MNT1/FOOBAR_FILE +MNT2 0 +MNT2/FOOBAR_FILE -- 2.43.0