* [LTP] [PATCH v2 1/2] ima_setup.sh: Fix check_policy_writable() for kernel < 4.5
@ 2026-08-10 14:33 Petr Vorel
2026-08-10 14:33 ` [LTP] [PATCH v2 2/2] ima_policy.sh: Require kernel 4.5+ for test02 Petr Vorel
` (2 more replies)
0 siblings, 3 replies; 6+ messages in thread
From: Petr Vorel @ 2026-08-10 14:33 UTC (permalink / raw)
To: ltp; +Cc: linux-integrity
Writing into policy via echo on kernel < 4.5 effectively makes policy
not writable (no point to check if the policy is writable). Therefore
skip this extra check in check_policy_writable() on these old kernels.
This change improves IMA testing on kernel < 4.5:
1) Allows to run ima_policy.sh which was previously skipped:
ima_policy 1 TINFO: verify that invalid policy isn't loaded
ima_policy 1 TCONF: IMA policy already loaded and kernel not configured to enable multiple writes to it (need CONFIG_IMA_WRITE_POLICY=y)
2) Fixes failing ima_violations.sh, which was failing due policy was not
writable:
ima_violations 1 TINFO: Tested kernel: Linux susetest 4.4.140
ima_violations 1 TINFO: booted with IMA policy: tcb
ima_violations 1 TINFO: using log /var/log/audit/audit.log
ima_violations 1 TINFO: verify open writers violation
ima_violations 1 TFAIL: open_writers violation not added
ima_violations 2 TINFO: verify ToMToU violation
ima_violations 2 TFAIL: ToMToU violation not added
ima_violations 3 TINFO: verify open_writers using mmapped files
tst_kconfig.c:90: TINFO: Parsing kernel config '/proc/config.gz'
tst_kconfig.c:90: TINFO: Parsing kernel config '/proc/config.gz'
tst_kconfig.c:755: TINFO: CONFIG_FAULT_INJECTION kernel option detected which might slow the execution
tst_kconfig.c:755: TINFO: CONFIG_FAULT_INJECTION kernel option detected which might slow the execution
tst_kconfig.c:90: TINFO: Parsing kernel config '/proc/config.gz'
tst_kconfig.c:755: TINFO: CONFIG_FAULT_INJECTION kernel option detected which might slow the execution
ima_mmap.c:33: TPASS: test completed
ima_violations 3 TFAIL: open_writers violation not added
3) Fixes failing ima_conditionals.sh -r uid and ima_conditionals.sh -r fowner
ima_conditionals 1 TINFO: request 'uid'
tst_security.c:115: TINFO: SecureBoot sysfs file not available
ima_conditionals 1 TINFO: verify measuring user files when requested via uid
tst_rod: Failed to open '/sys/kernel/security/ima/policy' for writing: Permission denied
ima_conditionals 1 TBROK: echo measure uid=65534 > /sys/kernel/security/ima/policy failed
ima_conditionals 1 TINFO: request 'fowner'
tst_security.c:115: TINFO: SecureBoot sysfs file not available
ima_conditionals 1 TINFO: verify measuring user files when requested via fowner
tst_rod: Failed to open '/sys/kernel/security/ima/policy' for writing: Permission denied
ima_conditionals 1 TBROK: echo measure fowner=65534 > /sys/kernel/security/ima/policy failed
Fixes: cd96265e65 ("ima/ima_policy.sh: Improve check of policy writability")
Signed-off-by: Petr Vorel <pvorel@suse.cz>
---
The same in v1.
@Mimi I appreciate your RBT or ABT.
Link to v1:
https://lore.kernel.org/ltp/20260728114224.1055009-1-pvorel@suse.cz/T/#t
.../kernel/security/integrity/ima/tests/ima_setup.sh | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
diff --git a/testcases/kernel/security/integrity/ima/tests/ima_setup.sh b/testcases/kernel/security/integrity/ima/tests/ima_setup.sh
index b69d7c31d9..19f00532b1 100644
--- a/testcases/kernel/security/integrity/ima/tests/ima_setup.sh
+++ b/testcases/kernel/security/integrity/ima/tests/ima_setup.sh
@@ -95,10 +95,15 @@ require_policy_readable()
check_policy_writable()
{
[ -f $IMA_POLICY ] || return 1
- # workaround for kernels < v4.18 without fix
+
+ # Workaround for kernels < v4.18 without fix
# ffb122de9a60b ("ima: Reflect correct permissions for policy")
- echo "" 2> log > $IMA_POLICY
- grep -q "Device or resource busy" log && return 1
+ # Require >= 4.5 to write multiple times via CONFIG_IMA_WRITE_POLICY
+ # 38d859f991f3 ("IMA: policy can now be updated multiple times")
+ if tst_kvcmp -ge 4.5; then
+ echo "" 2> log > $IMA_POLICY
+ grep -q "Device or resource busy" log && return 1
+ fi
return 0
}
--
2.55.0
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [LTP] [PATCH v2 2/2] ima_policy.sh: Require kernel 4.5+ for test02
2026-08-10 14:33 [LTP] [PATCH v2 1/2] ima_setup.sh: Fix check_policy_writable() for kernel < 4.5 Petr Vorel
@ 2026-08-10 14:33 ` Petr Vorel
2026-08-14 3:12 ` Mimi Zohar
2026-08-10 14:59 ` [LTP] ima_setup.sh: Fix check_policy_writable() for kernel < 4.5 linuxtestproject.agent
2026-08-12 14:44 ` [LTP] [PATCH v2 1/2] " Mimi Zohar
2 siblings, 1 reply; 6+ messages in thread
From: Petr Vorel @ 2026-08-10 14:33 UTC (permalink / raw)
To: ltp; +Cc: linux-integrity
Signed-off-by: Petr Vorel <pvorel@suse.cz>
---
New in v2.
@Mimi I appreciate your RBT or ABT.
testcases/kernel/security/integrity/ima/tests/ima_policy.sh | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/testcases/kernel/security/integrity/ima/tests/ima_policy.sh b/testcases/kernel/security/integrity/ima/tests/ima_policy.sh
index d66f261a81..e6f4ff133a 100755
--- a/testcases/kernel/security/integrity/ima/tests/ima_policy.sh
+++ b/testcases/kernel/security/integrity/ima/tests/ima_policy.sh
@@ -60,6 +60,11 @@ test2()
{
tst_res TINFO "verify that policy file is not opened concurrently and able to loaded multiple times"
+ if tst_kvcmp -lt 4.5; then
+ tst_res TCONF "test requires kernel 4.5+"
+ return
+ fi
+
local p1 p2 rc1 rc2
require_policy_writable
--
2.55.0
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply related [flat|nested] 6+ messages in thread
* Re: [LTP] ima_setup.sh: Fix check_policy_writable() for kernel < 4.5
2026-08-10 14:33 [LTP] [PATCH v2 1/2] ima_setup.sh: Fix check_policy_writable() for kernel < 4.5 Petr Vorel
2026-08-10 14:33 ` [LTP] [PATCH v2 2/2] ima_policy.sh: Require kernel 4.5+ for test02 Petr Vorel
@ 2026-08-10 14:59 ` linuxtestproject.agent
2026-08-12 14:44 ` [LTP] [PATCH v2 1/2] " Mimi Zohar
2 siblings, 0 replies; 6+ messages in thread
From: linuxtestproject.agent @ 2026-08-10 14:59 UTC (permalink / raw)
To: Petr Vorel; +Cc: ltp
Hi Petr,
On Mon, 10 Aug 2026, Petr Vorel wrote:
> ima_setup.sh: Fix check_policy_writable() for kernel < 4.5
--- [PATCH 2/2] ---
> ima_policy.sh: Require kernel 4.5+ for test02
Could the commit message explain that test02 needs repeated policy updates
and that CONFIG_IMA_WRITE_POLICY introduced support for them in kernel 4.5?
Verdict - Needs revision
---
Note:
The agent can sometimes produce false positives although often its
findings are genuine. If you find issues with the review, please
comment this email or ignore the suggestions.
Regards,
LTP AI Reviewer
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [LTP] [PATCH v2 1/2] ima_setup.sh: Fix check_policy_writable() for kernel < 4.5
2026-08-10 14:33 [LTP] [PATCH v2 1/2] ima_setup.sh: Fix check_policy_writable() for kernel < 4.5 Petr Vorel
2026-08-10 14:33 ` [LTP] [PATCH v2 2/2] ima_policy.sh: Require kernel 4.5+ for test02 Petr Vorel
2026-08-10 14:59 ` [LTP] ima_setup.sh: Fix check_policy_writable() for kernel < 4.5 linuxtestproject.agent
@ 2026-08-12 14:44 ` Mimi Zohar
2 siblings, 0 replies; 6+ messages in thread
From: Mimi Zohar @ 2026-08-12 14:44 UTC (permalink / raw)
To: Petr Vorel, ltp; +Cc: linux-integrity
On Mon, 2026-08-10 at 16:33 +0200, Petr Vorel wrote:
> Writing into policy via echo on kernel < 4.5 effectively makes policy
> not writable (no point to check if the policy is writable). Therefore
> skip this extra check in check_policy_writable() on these old kernels.
>
> This change improves IMA testing on kernel < 4.5:
>
> 1) Allows to run ima_policy.sh which was previously skipped:
>
> ima_policy 1 TINFO: verify that invalid policy isn't loaded
> ima_policy 1 TCONF: IMA policy already loaded and kernel not configured to enable multiple writes to it (need CONFIG_IMA_WRITE_POLICY=y)
>
> 2) Fixes failing ima_violations.sh, which was failing due policy was not
> writable:
>
> ima_violations 1 TINFO: Tested kernel: Linux susetest 4.4.140
> ima_violations 1 TINFO: booted with IMA policy: tcb
> ima_violations 1 TINFO: using log /var/log/audit/audit.log
> ima_violations 1 TINFO: verify open writers violation
> ima_violations 1 TFAIL: open_writers violation not added
> ima_violations 2 TINFO: verify ToMToU violation
> ima_violations 2 TFAIL: ToMToU violation not added
> ima_violations 3 TINFO: verify open_writers using mmapped files
> tst_kconfig.c:90: TINFO: Parsing kernel config '/proc/config.gz'
> tst_kconfig.c:90: TINFO: Parsing kernel config '/proc/config.gz'
> tst_kconfig.c:755: TINFO: CONFIG_FAULT_INJECTION kernel option detected which might slow the execution
> tst_kconfig.c:755: TINFO: CONFIG_FAULT_INJECTION kernel option detected which might slow the execution
> tst_kconfig.c:90: TINFO: Parsing kernel config '/proc/config.gz'
> tst_kconfig.c:755: TINFO: CONFIG_FAULT_INJECTION kernel option detected which might slow the execution
> ima_mmap.c:33: TPASS: test completed
> ima_violations 3 TFAIL: open_writers violation not added
>
> 3) Fixes failing ima_conditionals.sh -r uid and ima_conditionals.sh -r fowner
>
> ima_conditionals 1 TINFO: request 'uid'
> tst_security.c:115: TINFO: SecureBoot sysfs file not available
> ima_conditionals 1 TINFO: verify measuring user files when requested via uid
> tst_rod: Failed to open '/sys/kernel/security/ima/policy' for writing: Permission denied
> ima_conditionals 1 TBROK: echo measure uid=65534 > /sys/kernel/security/ima/policy failed
>
> ima_conditionals 1 TINFO: request 'fowner'
> tst_security.c:115: TINFO: SecureBoot sysfs file not available
> ima_conditionals 1 TINFO: verify measuring user files when requested via fowner
> tst_rod: Failed to open '/sys/kernel/security/ima/policy' for writing: Permission denied
> ima_conditionals 1 TBROK: echo measure fowner=65534 > /sys/kernel/security/ima/policy failed
>
> Fixes: cd96265e65 ("ima/ima_policy.sh: Improve check of policy writability")
> Signed-off-by: Petr Vorel <pvorel@suse.cz>
> ---
> The same in v1.
>
> @Mimi I appreciate your RBT or ABT.
>
> Link to v1:
> https://lore.kernel.org/ltp/20260728114224.1055009-1-pvorel@suse.cz/T/#t
>
> .../kernel/security/integrity/ima/tests/ima_setup.sh | 11 ++++++++---
> 1 file changed, 8 insertions(+), 3 deletions(-)
>
> diff --git a/testcases/kernel/security/integrity/ima/tests/ima_setup.sh b/testcases/kernel/security/integrity/ima/tests/ima_setup.sh
> index b69d7c31d9..19f00532b1 100644
> --- a/testcases/kernel/security/integrity/ima/tests/ima_setup.sh
> +++ b/testcases/kernel/security/integrity/ima/tests/ima_setup.sh
> @@ -95,10 +95,15 @@ require_policy_readable()
> check_policy_writable()
> {
> [ -f $IMA_POLICY ] || return 1
> - # workaround for kernels < v4.18 without fix
> +
> + # Workaround for kernels < v4.18 without fix
> # ffb122de9a60b ("ima: Reflect correct permissions for policy")
> - echo "" 2> log > $IMA_POLICY
> - grep -q "Device or resource busy" log && return 1
> + # Require >= 4.5 to write multiple times via CONFIG_IMA_WRITE_POLICY
> + # 38d859f991f3 ("IMA: policy can now be updated multiple times")
> + if tst_kvcmp -ge 4.5; then
> + echo "" 2> log > $IMA_POLICY
> + grep -q "Device or resource busy" log && return 1
> + fi
> return 0
> }
>
Thanks, Petr.
Reviewed-by: Mimi Zohar <zohar@linux.ibm.com
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [LTP] [PATCH v2 2/2] ima_policy.sh: Require kernel 4.5+ for test02
2026-08-10 14:33 ` [LTP] [PATCH v2 2/2] ima_policy.sh: Require kernel 4.5+ for test02 Petr Vorel
@ 2026-08-14 3:12 ` Mimi Zohar
2026-08-14 5:50 ` Petr Vorel
0 siblings, 1 reply; 6+ messages in thread
From: Mimi Zohar @ 2026-08-14 3:12 UTC (permalink / raw)
To: Petr Vorel, ltp; +Cc: linux-integrity
On Mon, 2026-08-10 at 16:33 +0200, Petr Vorel wrote:
> Signed-off-by: Petr Vorel <pvorel@suse.cz>
> ---
> New in v2.
>
> @Mimi I appreciate your RBT or ABT.
Thanks, Petr.
Reviewed-by: Mimi Zohar <zohar@linux.ibm.com>
>
> testcases/kernel/security/integrity/ima/tests/ima_policy.sh | 5 +++++
> 1 file changed, 5 insertions(+)
>
> diff --git a/testcases/kernel/security/integrity/ima/tests/ima_policy.sh b/testcases/kernel/security/integrity/ima/tests/ima_policy.sh
> index d66f261a81..e6f4ff133a 100755
> --- a/testcases/kernel/security/integrity/ima/tests/ima_policy.sh
> +++ b/testcases/kernel/security/integrity/ima/tests/ima_policy.sh
> @@ -60,6 +60,11 @@ test2()
> {
> tst_res TINFO "verify that policy file is not opened concurrently and able to loaded multiple times"
>
> + if tst_kvcmp -lt 4.5; then
> + tst_res TCONF "test requires kernel 4.5+"
> + return
> + fi
> +
> local p1 p2 rc1 rc2
>
> require_policy_writable
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [LTP] [PATCH v2 2/2] ima_policy.sh: Require kernel 4.5+ for test02
2026-08-14 3:12 ` Mimi Zohar
@ 2026-08-14 5:50 ` Petr Vorel
0 siblings, 0 replies; 6+ messages in thread
From: Petr Vorel @ 2026-08-14 5:50 UTC (permalink / raw)
To: Mimi Zohar; +Cc: linux-integrity, ltp
Hi Mimi,
thanks for your review, pushed!
Kind regards,
Petr
--
Mailing list info: https://lists.linux.it/listinfo/ltp
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-08-14 5:51 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-10 14:33 [LTP] [PATCH v2 1/2] ima_setup.sh: Fix check_policy_writable() for kernel < 4.5 Petr Vorel
2026-08-10 14:33 ` [LTP] [PATCH v2 2/2] ima_policy.sh: Require kernel 4.5+ for test02 Petr Vorel
2026-08-14 3:12 ` Mimi Zohar
2026-08-14 5:50 ` Petr Vorel
2026-08-10 14:59 ` [LTP] ima_setup.sh: Fix check_policy_writable() for kernel < 4.5 linuxtestproject.agent
2026-08-12 14:44 ` [LTP] [PATCH v2 1/2] " Mimi Zohar
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox