From: Lev Olshvang <levonshe@gmail.com>
To: linux-integrity@vger.kernel.org, zohar@linux.ibm.com
Subject: [RFC] Add more inode fields to inode metadata signature
Date: Tue, 31 Mar 2020 13:05:51 +0300 [thread overview]
Message-ID: <20200331100551.GA8259@kl> (raw)
From b696085c6e65e82237150e13d14736a914a0b394 Mon Sep 17 00:00:00 2001
From: Lev Olshvang <levonshe@gmail.com>
Date: Mon, 30 Mar 2020 16:00:27 +0300
Subject: [PATCH] integrity - add more inode metadata to signature, handle
errors
Add more inode fields to inode HMAC : times and flags.
File flags define (affect) how OS utilities and filesystem treats
them. For example immutable flag preserve file from removal or change.
It is important to verify these flags were not changed.
ctime and mtime may also affect programs that depends on files
timestamps.
File size might be used as a first indicator of file change and spare
from other IMA/EVM checks.
Function hmac_add_misc() ignored errors from crypto functions
This patch changes hmac_add_misc() not to be silent about errors
Signed-off-by: Lev Olshvang <levonshe@gmail.com>
---
security/integrity/evm/evm_crypto.c | 34 ++++++++++++++++++++++++-----
1 file changed, 28 insertions(+), 6 deletions(-)
diff --git a/security/integrity/evm/evm_crypto.c b/security/integrity/evm/evm_crypto.c
index d485f6fc908e..9c71c321e988 100644
--- a/security/integrity/evm/evm_crypto.c
+++ b/security/integrity/evm/evm_crypto.c
@@ -139,15 +139,20 @@ static struct shash_desc *init_desc(char type, uint8_t hash_algo)
* (Additional directory/file metadata needs to be added for more complete
* protection.)
*/
-static void hmac_add_misc(struct shash_desc *desc, struct inode *inode,
+static int hmac_add_misc(struct shash_desc *desc, struct inode *inode,
char type, char *digest)
{
+ int rc = 0;
struct h_misc {
unsigned long ino;
__u32 generation;
uid_t uid;
gid_t gid;
umode_t mode;
+ struct timespec64 ctime;
+ struct timespec64 mtime;
+ __u32 flags;
+ __u32 filesize;
} hmac_misc;
memset(&hmac_misc, 0, sizeof(hmac_misc));
@@ -169,11 +174,26 @@ static void hmac_add_misc(struct shash_desc *desc, struct inode *inode,
hmac_misc.uid = from_kuid(&init_user_ns, inode->i_uid);
hmac_misc.gid = from_kgid(&init_user_ns, inode->i_gid);
hmac_misc.mode = inode->i_mode;
- crypto_shash_update(desc, (const u8 *)&hmac_misc, sizeof(hmac_misc));
+ hmac_misc.flags = inode->i_flags;
+ hmac_misc.ctime = inode->i_ctime;
+ hmac_misc.mtime = inode->i_mtime;
+
+ /* hardly imagine calculating hash for file > 4G */
+ if (likely(inode->i_size < 0xFFFFFFFF))
+ hmac_misc.filesize = (__u32) inode->i_size;
+ else
+ return -E2BIG;
+ rc = crypto_shash_update(desc, (const u8 *)&hmac_misc, sizeof(hmac_misc));
+ if (unlikely(!rc))
+ return rc;
if ((evm_hmac_attrs & EVM_ATTR_FSUUID) &&
- type != EVM_XATTR_PORTABLE_DIGSIG)
- crypto_shash_update(desc, (u8 *)&inode->i_sb->s_uuid, UUID_SIZE);
- crypto_shash_final(desc, digest);
+ type != EVM_XATTR_PORTABLE_DIGSIG) {
+ rc = crypto_shash_update(desc, (u8 *)&inode->i_sb->s_uuid, UUID_SIZE);
+ if (unlikely(!rc))
+ return rc;
+ }
+ rc = crypto_shash_final(desc, digest);
+ return rc;
}
/*
@@ -239,7 +259,9 @@ static int evm_calc_hmac_or_hash(struct dentry *dentry,
if (is_ima)
ima_present = true;
}
- hmac_add_misc(desc, inode, type, data->digest);
+ error = hmac_add_misc(desc, inode, type, data->digest);
+ if (error < 0)
+ return error;
/* Portable EVM signatures must include an IMA hash */
if (type == EVM_XATTR_PORTABLE_DIGSIG && !ima_present)
--
2.17.1
reply other threads:[~2020-03-31 10:05 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20200331100551.GA8259@kl \
--to=levonshe@gmail.com \
--cc=linux-integrity@vger.kernel.org \
--cc=zohar@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).