提交 20f482ab 编写于 作者: L Lans Zhang 提交者: Mimi Zohar

ima: allow to check MAY_APPEND

Otherwise some mask and inmask tokens with MAY_APPEND flag may not work
as expected.
Signed-off-by: NLans Zhang <jia.zhang@windriver.com>
Signed-off-by: NMimi Zohar <zohar@linux.vnet.ibm.com>
上级 bc15ed66
...@@ -157,7 +157,8 @@ void ima_add_violation(struct file *file, const unsigned char *filename, ...@@ -157,7 +157,8 @@ void ima_add_violation(struct file *file, const unsigned char *filename,
/** /**
* ima_get_action - appraise & measure decision based on policy. * ima_get_action - appraise & measure decision based on policy.
* @inode: pointer to inode to measure * @inode: pointer to inode to measure
* @mask: contains the permission mask (MAY_READ, MAY_WRITE, MAY_EXECUTE) * @mask: contains the permission mask (MAY_READ, MAY_WRITE, MAY_EXEC,
* MAY_APPEND)
* @func: caller identifier * @func: caller identifier
* @pcr: pointer filled in if matched measure policy sets pcr= * @pcr: pointer filled in if matched measure policy sets pcr=
* *
......
...@@ -309,7 +309,7 @@ int ima_bprm_check(struct linux_binprm *bprm) ...@@ -309,7 +309,7 @@ int ima_bprm_check(struct linux_binprm *bprm)
/** /**
* ima_path_check - based on policy, collect/store measurement. * ima_path_check - based on policy, collect/store measurement.
* @file: pointer to the file to be measured * @file: pointer to the file to be measured
* @mask: contains MAY_READ, MAY_WRITE or MAY_EXECUTE * @mask: contains MAY_READ, MAY_WRITE, MAY_EXEC or MAY_APPEND
* *
* Measure files based on the ima_must_measure() policy decision. * Measure files based on the ima_must_measure() policy decision.
* *
...@@ -319,8 +319,8 @@ int ima_bprm_check(struct linux_binprm *bprm) ...@@ -319,8 +319,8 @@ int ima_bprm_check(struct linux_binprm *bprm)
int ima_file_check(struct file *file, int mask, int opened) int ima_file_check(struct file *file, int mask, int opened)
{ {
return process_measurement(file, NULL, 0, return process_measurement(file, NULL, 0,
mask & (MAY_READ | MAY_WRITE | MAY_EXEC), mask & (MAY_READ | MAY_WRITE | MAY_EXEC |
FILE_CHECK, opened); MAY_APPEND), FILE_CHECK, opened);
} }
EXPORT_SYMBOL_GPL(ima_file_check); EXPORT_SYMBOL_GPL(ima_file_check);
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册