From: Lakshmi Ramasubramanian <nramas@linux.microsoft.com>
To: Thore Sommer <public@thson.de>,
dm-devel@redhat.com, agk@redhat.com, snitzer@redhat.com
Cc: tusharsu@linux.microsoft.com, linux-integrity@vger.kernel.org
Subject: Re: [RFC PATCH 0/3] dm ima: allow targets to remeasure their state
Date: Fri, 6 May 2022 13:16:07 -0700 [thread overview]
Message-ID: <9fefc681-c8dd-0312-2d6b-ffe3fec05dcf@linux.microsoft.com> (raw)
In-Reply-To: <20220106203436.281629-1-public@thson.de>
Hi Thore,
On 1/6/2022 12:34 PM, Thore Sommer wrote:
> The current DM IMA events do not cover the case where a device changes
> their attributes to indicate a state change.
It would be good to state here what issue(s) are caused, if any, or what
data\event we might be missing as a result of not measuring the device
attribute changes. And, then state the benefits of the changes you have
implemented in this patch series.
This adds a new event
> (dm_target_update) which allows targets to remeasure their table entries.
> The event includes the dm version, device metadata and the target data.
>
> Currently only verity supports this event to ensure that device corruption
> can be detected using IMA which is useful for remote attestation.
Using the term "currently" in this context seems to indicate that this
is the current state (existing behavior) in the Linux kernel
implementation. You could instead reword it to indicate that your
proposed measurement change is used by verity to add support for
detecting device corruption.
>
> The current implementation does not update the active table hash because
> it would require to rehash the entire table on every target change.
Similar to the above comment - could be reworded to indicate this is the
proposed change and not the existing behavior.
thanks,
-lakshmi
>
> Thore Sommer (3):
> dm ima: allow targets to remeasure their table entry
> dm verity: add support for IMA target update event
> dm ima: add documentation target update event
>
> .../admin-guide/device-mapper/dm-ima.rst | 33 ++++++++
> drivers/md/dm-ima.c | 76 +++++++++++++++++++
> drivers/md/dm-ima.h | 2 +
> drivers/md/dm-verity-target.c | 6 ++
> 4 files changed, 117 insertions(+)
>
next prev parent reply other threads:[~2022-05-06 20:16 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-01-06 20:34 [RFC PATCH 0/3] dm ima: allow targets to remeasure their state Thore Sommer
2022-01-06 20:34 ` [RFC PATCH 1/3] dm ima: allow targets to remeasure their table entry Thore Sommer
2022-05-06 20:25 ` Lakshmi Ramasubramanian
2022-05-09 9:55 ` Thore Sommer
2022-05-09 17:07 ` Lakshmi Ramasubramanian
2022-01-06 20:34 ` [RFC PATCH 2/3] dm verity: add support for IMA target update event Thore Sommer
2022-05-06 20:35 ` Lakshmi Ramasubramanian
2022-05-09 9:33 ` Thore Sommer
2022-01-06 20:34 ` [RFC PATCH 3/3] dm ima: add documentation " Thore Sommer
2022-05-06 20:16 ` Lakshmi Ramasubramanian [this message]
2022-05-09 9:12 ` [RFC PATCH 0/3] dm ima: allow targets to remeasure their state Thore Sommer
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=9fefc681-c8dd-0312-2d6b-ffe3fec05dcf@linux.microsoft.com \
--to=nramas@linux.microsoft.com \
--cc=agk@redhat.com \
--cc=dm-devel@redhat.com \
--cc=linux-integrity@vger.kernel.org \
--cc=public@thson.de \
--cc=snitzer@redhat.com \
--cc=tusharsu@linux.microsoft.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).