From: "Colin Walters" <walters@verbum.org>
To: "Miklos Szeredi" <miklos@szeredi.hu>,
"Alexander Larsson" <alexl@redhat.com>
Cc: "Amir Goldstein" <amir73il@gmail.com>,
linux-fsdevel@vger.kernel.org, linux-unionfs@vger.kernel.org
Subject: Re: WIP: verity support for overlayfs
Date: Thu, 09 Mar 2023 10:26:16 -0500 [thread overview]
Message-ID: <b1ec4ce2-1be3-4aaa-9d43-86bcd66b88f0@app.fastmail.com> (raw)
In-Reply-To: <CAJfpeguTqXKuBcR3ZBbpWTPTbhnLja0QkBz3ASa4mgaw+A4-rQ@mail.gmail.com>
On Thu, Mar 9, 2023, at 9:59 AM, Miklos Szeredi wrote:
> On Wed, 8 Mar 2023 at 16:29, Alexander Larsson <alexl@redhat.com> wrote:
>>
>> As was recently discussed in the various threads about composefs we
>> want the ability to specify a fs-verity digest for metacopy files,
>> such that the lower file used for the data is guaranteed to have the
>> specified digest.
>>
>> I wrote an initial version of this here:
>>
>> https://github.com/alexlarsson/linux/tree/overlay-verity
>>
>> I would like some feedback on this approach. Does it make sense?
>>
>> For context, here is the main commit text:
>>
>> This adds support for a new overlay xattr "overlay.verity", which
>> contains a fs-verity digest. This is used for metacopy files, and
>> whenever the lowerdata file is accessed overlayfs can verify that
>> the data file fs-verity digest matches the expected one.
>>
>> By default this is ignored, but if the mount option "verity_policy" is
>> set to "validate" or "require", then all accesses validate any
>> specified digest. If you use "require" it additionally fails to access
>> metacopy file if the verity xattr is missing.
>>
>> The digest is validated during ovl_open() as well as when the lower file
>> is copied up. Additionally the overlay.verity xattr is copied to the
>> upper file during a metacopy operation, in order to later do the validation
>> of the digest when the copy-up happens.
>
> Hmm, so what exactly happens if the file is copied up and then
> modified? The verification will fail, no?
I believe the intention here is to deploy this without a writable upper dir by default, so there's no copy-up, the calling code just gets -EROFS. The intention is to also use this to push the podman/docker/kube style ecosystem away from "mutable by default" container images i.e. to "readonlyRootFilesystem" by default (xref https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ )
But yes, some scenarios will still want a writable upper dir for default, as long as that writable upper dir is discarded across reboots (to aid in anti-persistence). Maybe this needs to be configurable; I could imagine people wanting a writable upper dir, but to still enforce fs-verity for *existing* content. Other cases may want the logic to just strip away the fsverity xattr across copy-up in this case.
next prev parent reply other threads:[~2023-03-09 15:26 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-03-08 15:28 WIP: verity support for overlayfs Alexander Larsson
2023-03-09 14:59 ` Miklos Szeredi
2023-03-09 15:26 ` Colin Walters [this message]
2023-03-09 15:57 ` Alexander Larsson
2023-03-09 15:45 ` Alexander Larsson
2023-03-10 11:22 ` Alexander Larsson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=b1ec4ce2-1be3-4aaa-9d43-86bcd66b88f0@app.fastmail.com \
--to=walters@verbum.org \
--cc=alexl@redhat.com \
--cc=amir73il@gmail.com \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-unionfs@vger.kernel.org \
--cc=miklos@szeredi.hu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).