提交 f4bd857b 编写于 作者: M Mimi Zohar 提交者: James Morris

integrity: IMA policy open

Sequentialize access to the policy file
- permit multiple attempts to replace default policy with a valid policy
Signed-off-by: NMimi Zohar <zohar@us.ibm.com>
Acked-by: NSerge Hallyn <serue@us.ibm.com>
Signed-off-by: NJames Morris <jmorris@namei.org>
上级 4af4662f
...@@ -277,16 +277,30 @@ static struct dentry *runtime_measurements_count; ...@@ -277,16 +277,30 @@ static struct dentry *runtime_measurements_count;
static struct dentry *violations; static struct dentry *violations;
static struct dentry *ima_policy; static struct dentry *ima_policy;
static atomic_t policy_opencount = ATOMIC_INIT(1);
/*
* ima_open_policy: sequentialize access to the policy file
*/
int ima_open_policy(struct inode * inode, struct file * filp)
{
if (atomic_dec_and_test(&policy_opencount))
return 0;
return -EBUSY;
}
/* /*
* ima_release_policy - start using the new measure policy rules. * ima_release_policy - start using the new measure policy rules.
* *
* Initially, ima_measure points to the default policy rules, now * Initially, ima_measure points to the default policy rules, now
* point to the new policy rules, and remove the securityfs policy file. * point to the new policy rules, and remove the securityfs policy file,
* assuming a valid policy.
*/ */
static int ima_release_policy(struct inode *inode, struct file *file) static int ima_release_policy(struct inode *inode, struct file *file)
{ {
if (!valid_policy) { if (!valid_policy) {
ima_delete_rules(); ima_delete_rules();
valid_policy = 1;
atomic_set(&policy_opencount, 1);
return 0; return 0;
} }
ima_update_policy(); ima_update_policy();
...@@ -296,6 +310,7 @@ static int ima_release_policy(struct inode *inode, struct file *file) ...@@ -296,6 +310,7 @@ static int ima_release_policy(struct inode *inode, struct file *file)
} }
static struct file_operations ima_measure_policy_ops = { static struct file_operations ima_measure_policy_ops = {
.open = ima_open_policy,
.write = ima_write_policy, .write = ima_write_policy,
.release = ima_release_policy .release = ima_release_policy
}; };
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册