From: Zorro Lang <zlang@kernel.org>
To: Anand Jain <asj@kernel.org>
Cc: fstests@vger.kernel.org, linux-btrfs@vger.kernel.org,
linux-ext4@vger.kernel.org, linux-xfs@vger.kernel.org,
linux-f2fs-devel@lists.sourceforge.net, djwong@kernel.org
Subject: Re: [PATCH v8 10/13] fstests: verify IMA isolation on cloned filesystems
Date: Wed, 2 Sep 2026 03:58:04 +0800 [thread overview]
Message-ID: <apcmEu9jmi3wljdW@zlang-mailbox> (raw)
In-Reply-To: <e2ba3b5cf7e17bf87e7e832222d72bcbf8b904f8.1784949155.git.asj@kernel.org>
On Sat, Jul 25, 2026 at 03:39:07PM +0800, Anand Jain wrote:
> Add testcase to verify IMA measurement isolation when multiple devices
> share the same FSUUID.
>
> Signed-off-by: Anand Jain <asj@kernel.org>
> ---
> tests/generic/804 | 108 ++++++++++++++++++++++++++++++++++++++++++
> tests/generic/804.out | 10 ++++
> 2 files changed, 118 insertions(+)
> create mode 100644 tests/generic/804
> create mode 100644 tests/generic/804.out
>
> diff --git a/tests/generic/804 b/tests/generic/804
> new file mode 100644
> index 000000000000..ced32e6d79dd
> --- /dev/null
> +++ b/tests/generic/804
> @@ -0,0 +1,108 @@
> +#! /bin/bash
> +# SPDX-License-Identifier: GPL-2.0
> +# Copyright (c) 2026 Anand Jain <asj@kernel.org>. All Rights Reserved.
> +#
> +# FS QA Test 804
> +# Verify IMA isolation on cloned filesystems:
> +# . Mount two devices sharing the same FSUUID (cloned).
> +# . Apply an IMA policy to measure files based on that FSUUID.
> +# . Create unique files on each mount point to trigger measurements.
> +# . Confirm the IMA log correctly attributes events to the respective mounts.
> +
> +. ./common/preamble
> +. ./common/filter
> +
> +_begin_fstest auto quick clone
> +
> +_require_test
> +_require_block_device $TEST_DEV
> +_require_loop
> +
> +_fixed_by_fs_commit btrfs xxxxxxxxxxxx \
> + "btrfs: use on-disk uuid for s_uuid in temp_fsid mounts"
> +_fixed_by_fs_commit btrfs xxxxxxxxxxxx \
> + "btrfs: derive f_fsid from on-disk fsuuid and dev_t"
> +
> +_cleanup()
> +{
> + cd /
> + rm -r -f $tmp.*
> + _unmount $mnt1 2>/dev/null
> + _unmount $mnt2 2>/dev/null
> + _loop_image_destroy "${devs[@]}" 2> /dev/null
> +}
> +
> +# Normalize device names and mount points
> +filter_pool()
> +{
> + sed -e "s|${devs[0]}|DEV1|g" -e "s|$mnt1|MNT1|g" \
> + -e "s|${devs[1]}|DEV2|g" -e "s|$mnt2|MNT2|g" | _filter_spaces
> +}
> +
> +# Core helper to set IMA policy and check measurement logs
> +do_ima()
> +{
> + local ima_policy="/sys/kernel/security/ima/policy"
> + local ima_log="/sys/kernel/security/ima/ascii_runtime_measurements"
> + local fsuuid
> + local mnt=$1
> + local enable=$2
> +
> + # Since the in-memory IMA audit log is only cleared upon reboot,
> + # use unique random filenames to avoid log collisions.
> + local foofile=$(mktemp --dry-run foobar_XXXXX)
> +
> + echo $mnt $enable | filter_pool
> +
> + [ -w "$ima_policy" ] || _notrun "IMA policy not writable"
How about a _require_security_ima to make sure there's securityfs
and IMA supporting in current kernel.
> +
> + fsuuid=$(blkid -s UUID -o value ${devs[0]})
> +
> + # Load IMA policy to measure file access specifically for this
> + # filesystem UUID.
> + if [[ $enable -eq 1 ]]; then
> + echo "measure func=FILE_CHECK fsuuid=$fsuuid" > "$ima_policy" || \
I'm not sure if we should have this test, especially add it into
auto and quick group. Once an IMA policy is loaded, there is no way to
clear or roll it back, and I am concerned it might potentially interfere
with subsequent tests.
Hmm... how about use `unshare` command to rewrite the do_ima as do_ima_in_ns?
For example:
do_ima_in_ns()
{
...
unshare -U -m -p --fork --map-root-user bash <<EOF
mount -t securityfs securityfs /sys/kernel/security
ima_policy="/sys/kernel/security/ima/policy"
ima_log="/sys/kernel/security/ima/ascii_runtime_measurements"
echo "measure func=FILE_CHECK fsuuid=$uuid" > "\$ima_policy" || exit 1
...
EOF
ret=$?
}
Thanks,
Zorro
> + _notrun "Policy rejected"
> + fi
> +
> + # Create a file to trigger measurement and verify its entry in
> + # the IMA log.
> + echo "test_data" > $mnt/$foofile
> +
> + # IMA log extract
> + grep $foofile "$ima_log" | awk '{ print $5 }' | filter_pool | \
> + sed "s/$foofile/FOOBAR_FILE/"
> +
> + echo "dbg: $mnt $fsuuid $foofile" >> $seqres.full
> + cat $ima_log | tail -1 >> $seqres.full
> + echo >> $seqres.full
> +}
> +
> +# Initialize loop base and cloned instances
> +devs=()
> +_loop_image_create_clone devs
> +mnt1=$TEST_DIR/$seq/mnt1
> +mnt2=$TEST_DIR/$seq/mnt2
> +mkdir -p $mnt1
> +mkdir -p $mnt2
> +
> +# Concurrently mount both clones
> +_mount $(_common_dev_mount_options) $(_clone_mount_option) ${devs[0]} $mnt1 || \
> + _fail "Failed to mount dev1"
> +_mount $(_common_dev_mount_options) $(_clone_mount_option) ${devs[1]} $mnt2 || \
> + _fail "Failed to mount dev2"
> +
> +# IMA response on baseline and clone configuration
> +do_ima $mnt1 1
> +do_ima $mnt2 0
> +
> +# Cycle mount on the second device.
> +echo mount cycle
> +_unmount $mnt2
> +_mount $mount_opts ${devs[1]} $mnt2 || _fail "Failed to mount dev2"
> +
> +do_ima $mnt1 0
> +do_ima $mnt2 0
> +
> +status=0
> +exit
> diff --git a/tests/generic/804.out b/tests/generic/804.out
> new file mode 100644
> index 000000000000..9804181d6c17
> --- /dev/null
> +++ b/tests/generic/804.out
> @@ -0,0 +1,10 @@
> +QA output created by 804
> +MNT1 1
> +MNT1/FOOBAR_FILE
> +MNT2 0
> +MNT2/FOOBAR_FILE
> +mount cycle
> +MNT1 0
> +MNT1/FOOBAR_FILE
> +MNT2 0
> +MNT2/FOOBAR_FILE
> --
> 2.43.0
>
next prev parent reply other threads:[~2026-09-01 19:58 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-25 7:38 [PATCH v8 0/13] fstests: add test coverage for cloned filesystem ids Anand Jain
2026-07-25 7:38 ` [PATCH v8 01/13] fstests: add _loop_image_create_clone() helper Anand Jain
2026-09-01 12:33 ` Zorro Lang
2026-09-01 13:52 ` Anand Suveer Jain
2026-07-25 7:38 ` [PATCH v8 02/13] fstests: add _clone_mount_option() helper Anand Jain
2026-09-01 12:39 ` Zorro Lang
2026-09-01 13:54 ` Anand Suveer Jain
2026-07-25 7:39 ` [PATCH v8 03/13] fstests: add FSNOTIFYWAIT_PROG Anand Jain
2026-09-01 15:37 ` Zorro Lang
2026-07-25 7:39 ` [PATCH v8 04/13] fstests: add _require_fanotify_function Anand Jain
2026-09-01 15:42 ` Zorro Lang
2026-09-01 22:39 ` Anand Suveer Jain
2026-07-25 7:39 ` [PATCH v8 05/13] fstests: add _require_unique_f_fsid() helper Anand Jain
2026-09-01 16:09 ` Zorro Lang
2026-07-25 7:39 ` [PATCH v8 06/13] fstests: add SEMANAGE_PROG Anand Jain
2026-07-25 7:39 ` [PATCH v8 07/13] fstests: verify fanotify isolation on cloned filesystems Anand Jain
2026-09-01 18:23 ` Zorro Lang
2026-07-25 7:39 ` [PATCH v8 08/13] fstests: verify f_fsid for " Anand Jain
2026-09-01 18:51 ` Zorro Lang
2026-07-25 7:39 ` [PATCH v8 09/13] fstests: verify libblkid resolution of duplicate UUIDs Anand Jain
2026-09-01 19:12 ` Zorro Lang
2026-07-25 7:39 ` [PATCH v8 10/13] fstests: verify IMA isolation on cloned filesystems Anand Jain
2026-09-01 19:58 ` Zorro Lang [this message]
2026-07-25 7:39 ` [PATCH v8 11/13] fstests: verify exportfs file handles " Anand Jain
2026-09-01 20:29 ` Zorro Lang
2026-09-01 20:30 ` Zorro Lang
2026-07-25 7:39 ` [PATCH v8 12/13] fstests: add _change_metadata_uuid helper Anand Jain
2026-09-01 20:53 ` Zorro Lang
2026-07-25 7:39 ` [PATCH v8 13/13] fstests: test UUID consistency for clones with metadata_uuid Anand Jain
2026-09-01 20:51 ` Zorro Lang
2026-08-31 7:17 ` [PATCH v8 0/13] fstests: add test coverage for cloned filesystem ids Anand Suveer Jain
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=apcmEu9jmi3wljdW@zlang-mailbox \
--to=zlang@kernel.org \
--cc=asj@kernel.org \
--cc=djwong@kernel.org \
--cc=fstests@vger.kernel.org \
--cc=linux-btrfs@vger.kernel.org \
--cc=linux-ext4@vger.kernel.org \
--cc=linux-f2fs-devel@lists.sourceforge.net \
--cc=linux-xfs@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox