• R
    ima: Introduce appraise_exec_tcb policy · 5ddc3553
    Roberto Sassu 提交于
    hulk inclusion
    category: feature
    feature: IMA Digest Lists extension
    bugzilla: 46797
    
    -------------------------------------------------
    
    This patch introduces a new hard-coded policy to appraise executable code:
    
    appraise func=MODULE_CHECK appraise_type=imasig
    appraise func=FIRMWARE_CHECK appraise_type=imasig
    appraise func=KEXEC_KERNEL_CHECK appraise_type=imasig
    appraise func=POLICY_CHECK appraise_type=imasig
    appraise func=DIGEST_LIST_CHECK appraise_type=imasig
    dont_appraise fsmagic=0x9fa0
    dont_appraise fsmagic=0x62656572
    dont_appraise fsmagic=0x64626720
    dont_appraise fsmagic=0x858458f6
    dont_appraise fsmagic=0x1cd1
    dont_appraise fsmagic=0x42494e4d
    dont_appraise fsmagic=0x73636673
    dont_appraise fsmagic=0xf97cff8c
    dont_appraise fsmagic=0x43415d53
    dont_appraise fsmagic=0x6e736673
    dont_appraise fsmagic=0xde5e81e4
    dont_appraise fsmagic=0x27e0eb
    dont_appraise fsmagic=0x63677270
    appraise func=BPRM_CHECK appraise_type=imasig
    appraise func=MMAP_CHECK appraise_type=imasig
    
    The new policy can be selected by specifying ima_policy=appraise_exec_tcb
    in the kernel command line.
    Signed-off-by: NRoberto Sassu <roberto.sassu@huawei.com>
    Signed-off-by: NTianxing Zhang <zhangtianxing3@huawei.com>
    Reviewed-by: NJason Yan <yanaijie@huawei.com>
    Signed-off-by: NZheng Zengkai <zhengzengkai@huawei.com>
    5ddc3553
kernel-parameters.txt 213.7 KB