public inbox for linux-integrity@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH 0/2] evm: disable EVM on overlayfs
@ 2023-12-19 13:48 Mimi Zohar
  2023-12-19 13:49 ` [PATCH 1/2] evm: don't copy up 'security.evm' xattr Mimi Zohar
  2023-12-19 13:49 ` [PATCH 2/2] evm: add support to disable EVM on unsupported filesystems Mimi Zohar
  0 siblings, 2 replies; 5+ messages in thread
From: Mimi Zohar @ 2023-12-19 13:48 UTC (permalink / raw)
  To: linux-unionfs
  Cc: Mimi Zohar, linux-integrity, linux-kernel, Amir Goldstein,
	Christian Brauner, Seth Forshee, Roberto Sassu

EVM verifies the existing 'security.evm' value, before allowing it
to be updated.  The EVM HMAC and the original file signatures contain
filesystem specific metadata (e.g. i_ino, i_generation and s_uuid).

This poses a challenge when transitioning from the lower backing file
to the upper backing file.

Until a complete solution is developed, disable EVM on overlayfs.

Mimi Zohar (2):
  evm: don't copy up 'security.evm' xattr
  evm: add support to disable EVM on unsupported filesystems

 include/linux/evm.h               |  6 +++++
 security/integrity/evm/evm_main.c | 42 ++++++++++++++++++++++++++++++-
 security/security.c               |  4 +++
 3 files changed, 51 insertions(+), 1 deletion(-)

-- 
2.39.3


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2023-12-19 14:47 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-12-19 13:48 [PATCH 0/2] evm: disable EVM on overlayfs Mimi Zohar
2023-12-19 13:49 ` [PATCH 1/2] evm: don't copy up 'security.evm' xattr Mimi Zohar
2023-12-19 14:41   ` Amir Goldstein
2023-12-19 13:49 ` [PATCH 2/2] evm: add support to disable EVM on unsupported filesystems Mimi Zohar
2023-12-19 14:47   ` Amir Goldstein

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox