From: Mimi Zohar <zohar@linux.ibm.com>
To: Roberto Sassu <roberto.sassu@huaweicloud.com>,
Casey Schaufler <casey@schaufler-ca.com>,
dmitry.kasatkin@gmail.com, paul@paul-moore.com,
jmorris@namei.org, serge@hallyn.com,
stephen.smalley.work@gmail.com, eparis@parisplace.org
Cc: reiserfs-devel@vger.kernel.org, linux-kernel@vger.kernel.org,
linux-integrity@vger.kernel.org,
linux-security-module@vger.kernel.org, selinux@vger.kernel.org,
bpf@vger.kernel.org, kpsingh@kernel.org, keescook@chromium.org,
nicolas.bouchinet@clip-os.org,
Roberto Sassu <roberto.sassu@huawei.com>,
Mengchi Cheng <mengcc@amazon.com>,
miklos@szeredi.hu, linux-unionfs@vger.kernel.org,
kamatam@amazon.com, yoonjaeh@amazon.com
Subject: Re: [PATCH] Smack modifications for: security: Allow all LSMs to provide xattrs for inode_init_security hook
Date: Thu, 20 Apr 2023 06:44:00 -0400 [thread overview]
Message-ID: <97849695ef53ab3186e59d8a2c6b74812f13ee19.camel@linux.ibm.com> (raw)
In-Reply-To: <a98ddf946c474a3500bdcd72766c6cb0043278ff.camel@huaweicloud.com>
On Thu, 2023-04-20 at 10:50 +0200, Roberto Sassu wrote:
> >
> > It's possible. It's been a long time since I've looked at this.
> > I'm tempted to take a change to make overlayfs work upstream and
> > then worry about the ima changes. There seems to be a lot more
> > going on with the ima changes than is obvious from what's in the
> > Smack code.
It doesn't sound like the patch set introduces the overlayfs bug.
The security_inode_init_security() change to initialize multiple LSMs
and IMA xattrs and include them in the EVM hmac calculation is straight
forward.
In addition, the patch set creates the infrastructure for allowing
multiple per LSM xattrs, as requested, to be initialized in
security_inode_init_security() and included in the EVM hmac.
Mimi
> We could also set only SMACK64 in smack_inode_init_security(), and move
> SMACKTRANSMUTE64 later, when we figure out how to fix the case of
> overlayfs.
>
> IMA and EVM would work in both cases.
next prev parent reply other threads:[~2023-04-20 10:46 UTC|newest]
Thread overview: 44+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-03-31 12:32 [PATCH v10 0/4] evm: Do HMAC of multiple per LSM xattrs for new inodes Roberto Sassu
2023-03-31 12:32 ` [PATCH v10 1/4] reiserfs: Add security prefix to xattr name in reiserfs_security_write() Roberto Sassu
2023-04-04 18:25 ` Paul Moore
2023-03-31 12:32 ` [PATCH v10 2/4] security: Allow all LSMs to provide xattrs for inode_init_security hook Roberto Sassu
2023-04-04 18:54 ` Paul Moore
2023-04-05 2:08 ` Casey Schaufler
2023-04-05 9:43 ` Roberto Sassu
2023-04-05 19:59 ` Paul Moore
2023-04-05 20:43 ` Casey Schaufler
2023-04-05 20:49 ` Paul Moore
2023-04-05 21:07 ` Casey Schaufler
2023-04-06 9:14 ` Roberto Sassu
2023-04-06 16:17 ` Casey Schaufler
2023-04-06 9:08 ` Roberto Sassu
2023-04-11 7:22 ` Mimi Zohar
2023-04-11 7:53 ` Roberto Sassu
2023-04-11 16:42 ` Casey Schaufler
2023-04-11 17:23 ` [PATCH] Smack modifications for: " Roberto Sassu
2023-04-11 17:54 ` Casey Schaufler
2023-04-12 7:22 ` Roberto Sassu
2023-04-12 20:29 ` Casey Schaufler
2023-04-13 7:11 ` Roberto Sassu
2023-04-17 16:41 ` Casey Schaufler
2023-04-18 7:05 ` Roberto Sassu
2023-04-18 16:02 ` Casey Schaufler
2023-04-19 13:46 ` Roberto Sassu
2023-04-19 19:25 ` Mengchi Cheng
2023-04-20 8:48 ` Roberto Sassu
2023-05-08 12:29 ` Roberto Sassu
2023-05-09 23:44 ` Mengchi Cheng
2023-05-09 23:56 ` Casey Schaufler
2023-04-19 21:00 ` Casey Schaufler
2023-04-20 8:50 ` Roberto Sassu
2023-04-20 10:44 ` Mimi Zohar [this message]
2023-04-20 14:10 ` Roberto Sassu
2023-04-11 17:25 ` [PATCH v10 2/4] " Roberto Sassu
2023-04-11 17:40 ` Casey Schaufler
2023-03-31 12:32 ` [PATCH v10 3/4] evm: Align evm_inode_init_security() definition with LSM infrastructure Roberto Sassu
2023-04-04 18:56 ` Paul Moore
2023-04-11 7:22 ` Mimi Zohar
2023-04-11 7:58 ` Roberto Sassu
2023-03-31 12:32 ` [PATCH v10 4/4] evm: Support multiple LSMs providing an xattr Roberto Sassu
2023-04-11 7:22 ` Mimi Zohar
2023-04-03 10:36 ` [PATCH v10 0/4] evm: Do HMAC of multiple per LSM xattrs for new inodes Mimi Zohar
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=97849695ef53ab3186e59d8a2c6b74812f13ee19.camel@linux.ibm.com \
--to=zohar@linux.ibm.com \
--cc=bpf@vger.kernel.org \
--cc=casey@schaufler-ca.com \
--cc=dmitry.kasatkin@gmail.com \
--cc=eparis@parisplace.org \
--cc=jmorris@namei.org \
--cc=kamatam@amazon.com \
--cc=keescook@chromium.org \
--cc=kpsingh@kernel.org \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=linux-unionfs@vger.kernel.org \
--cc=mengcc@amazon.com \
--cc=miklos@szeredi.hu \
--cc=nicolas.bouchinet@clip-os.org \
--cc=paul@paul-moore.com \
--cc=reiserfs-devel@vger.kernel.org \
--cc=roberto.sassu@huawei.com \
--cc=roberto.sassu@huaweicloud.com \
--cc=selinux@vger.kernel.org \
--cc=serge@hallyn.com \
--cc=stephen.smalley.work@gmail.com \
--cc=yoonjaeh@amazon.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).