Linux Integrity Measurement development
 help / color / mirror / Atom feed
* [QUESTION] IMA: kexec appraisal and the unauthenticated target command line
@ 2026-09-24 23:34 Danny Hu
  2026-09-25  2:27 ` Mimi Zohar
  0 siblings, 1 reply; 5+ messages in thread
From: Danny Hu @ 2026-09-24 23:34 UTC (permalink / raw)
  To: linux-integrity
  Cc: Mimi Zohar, roberto.sassu, dmitry.kasatkin, eric.snowberg,
	Pierre De Abreu, Julien Gomes, Kunal Bharathi

Hello,

I have a question about the intended security properties of IMA
appraisal across kexec_file_load(). I am trying to understand why IMA
supports appraisal of the kexec kernel and initramfs through
KEXEC_KERNEL_CHECK and KEXEC_INITRAMFS_CHECK, while KEXEC_CMDLINE is
measurement-only and cannot reject an unauthorized target command
line. Requiring a signer-approved kernel implies that CAP_SYS_BOOT
alone is not sufficient authority to boot a target kernel. Then why
are command-line parameters capable of weakening the target kernel’s
enforcement state not similarly bound to the signer’s approval?

This appears to leave a gap when IMA is the mechanism enforcing kexec
integrity. A caller permitted to perform kexec could use the signed
kernel as a downgrade trampoline:

1. Supply an approved, signed kernel and initramfs.
2. Supply an unauthenticated command line that prevents IMA
enforcement in the target kernel. An example of such is through
“initcall_blacklist=init_ima”.
3. Boot into the approved kernel without effective IMA enforcement.
4. An attacker is then free to execute unsigned code or kexec into any
other unsigned kernel.

A few questions for the IMA maintainers:

- Is the lack of KEXEC_CMDLINE appraisal simply an architectural
constraint of IMA’s inode-based appraisal model, or an intentional
part of the security model?
- Is command-line integrity expected to be provided by another subsystem?
- Have there been any discussions around a concept of “IMA continuity”
across kexec? By continuity, I mean preserving the appraisal invariant
across the transition so that every accepted target kernel
re-establishes equivalent enforcement.
- If policy continuity was not intended, what threat model gives
appraisal of the kernel and initramfs its intended security value when
their execution environment can be weakened through an unauthenticated
command line?

Thank you for any historical context or guidance on the intended design!

Thanks again,
Danny

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-10-06 19:01 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-24 23:34 [QUESTION] IMA: kexec appraisal and the unauthenticated target command line Danny Hu
2026-09-25  2:27 ` Mimi Zohar
2026-09-25 17:08   ` Danny Hu
2026-10-02 18:18   ` Danny Hu
2026-10-06 19:00     ` Mimi Zohar

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox