From: Mimi Zohar <zohar@linux.vnet.ibm.com>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: "Kasatkin, Dmitry" <dmitry.kasatkin@intel.com>,
Al Viro <viro@zeniv.linux.org.uk>,
linux-fsdevel <linux-fsdevel@vger.kernel.org>,
LSM List <linux-security-module@vger.kernel.org>,
Linux Kernel Mailing List <linux-kernel@vger.kernel.org>,
James Morris <jmorris@namei.org>
Subject: Re: [PATCH 0/2] ima: policy search speedup
Date: Tue, 11 Dec 2012 13:18:04 -0500 [thread overview]
Message-ID: <1355249884.2356.108.camel@falcor> (raw)
In-Reply-To: <CA+55aFwA3isRny9JyqxzjoysHbRhiKpBheeEi6VZrnWokt521A@mail.gmail.com>
On Tue, 2012-12-11 at 08:59 -0800, Linus Torvalds wrote:
> On Tue, Dec 11, 2012 at 6:08 AM, Mimi Zohar <zohar@linux.vnet.ibm.com> wrote:
> > On Tue, 2012-12-11 at 14:51 +0200, Kasatkin, Dmitry wrote:
> >> >>
> >> >> Two months ago I was asking about it on mailing lists.
> >> >> Suggestion was not to use s_flags, but e.g. s_feature_flags.
>
> Quite frankly, this seems stupid.
>
> Without really knowing the problem space, the sane thing to do would
> seem to be inode->i_flags. At which point it's
>
> (a) faster to test (no need to dereference inode->i_sb)
>
> (b) matches what the integrity layer does with S_IMA (well, there the
> logic is reversed: S_IMA means that it has a integrity structure
> associated with it)
>
> (c) allows you to mark individual inodes as "no checking".
The appraisal policy is based on the object metadata, such as the uid,
so the result is static and can be cached. The measurement policy, on
the other hand, is normally based on the subject (eg. who is
reading/executing) the file. Knowledge of whether the file has been
measured is cached in the iint, but unlike the appraisal policy, not
whether it needs to be measured. Having the flag on a per inode basis,
doesn't really help.
thanks,
Mimi
next prev parent reply other threads:[~2012-12-11 18:18 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-11-22 21:54 [PATCH 0/2] ima: policy search speedup Dmitry Kasatkin
2012-11-22 21:54 ` [PATCH 1/2] vfs: new super block feature flags attribute Dmitry Kasatkin
2012-11-22 21:54 ` [PATCH 2/2] ima: skip policy search for never appraised or measured files Dmitry Kasatkin
2012-11-27 13:42 ` [PATCH 0/2] ima: policy search speedup Kasatkin, Dmitry
2012-12-11 12:51 ` Kasatkin, Dmitry
2012-12-11 14:08 ` Mimi Zohar
2012-12-11 16:59 ` Linus Torvalds
2012-12-11 17:40 ` Kasatkin, Dmitry
2012-12-11 17:55 ` Linus Torvalds
2012-12-11 18:09 ` Eric Paris
2012-12-11 18:35 ` Kasatkin, Dmitry
2012-12-11 19:07 ` Mimi Zohar
2012-12-11 22:16 ` Dave Chinner
2012-12-11 18:10 ` Kasatkin, Dmitry
2012-12-11 18:29 ` Al Viro
2012-12-11 18:12 ` Kasatkin, Dmitry
2012-12-11 18:35 ` Linus Torvalds
2012-12-11 18:53 ` Kasatkin, Dmitry
2012-12-11 18:18 ` Mimi Zohar [this message]
2012-12-11 18:35 ` Eric Paris
2012-12-11 18:59 ` Mimi Zohar
2012-12-11 19:10 ` Linus Torvalds
2012-12-11 19:48 ` Mimi Zohar
2012-12-11 20:05 ` Linus Torvalds
2012-12-11 20:15 ` Eric Paris
2012-12-11 20:31 ` Linus Torvalds
2012-12-11 20:08 ` Eric Paris
2012-12-11 22:57 ` Kasatkin, Dmitry
2012-12-11 23:02 ` Eric Paris
2012-12-12 13:56 ` Kasatkin, Dmitry
2012-12-12 14:25 ` Eric Paris
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1355249884.2356.108.camel@falcor \
--to=zohar@linux.vnet.ibm.com \
--cc=dmitry.kasatkin@intel.com \
--cc=jmorris@namei.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=torvalds@linux-foundation.org \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).