ima: define kernel parameter 'ima_template=' to change configured default
This patch allows users to specify from the kernel command line the template descriptor, among those defined, that will be used to generate and display measurement entries. If an user specifies a wrong template, IMA reverts to the template descriptor set in the kernel configuration. Signed-off-by: Roberto Sassu <roberto.sassu@polito.it> Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
This commit is contained in:
parent
4286587dcc
commit
9b9d4ce592
@ -1190,6 +1190,11 @@ bytes respectively. Such letter suffixes can also be entirely omitted.
|
|||||||
programs exec'd, files mmap'd for exec, and all files
|
programs exec'd, files mmap'd for exec, and all files
|
||||||
opened for read by uid=0.
|
opened for read by uid=0.
|
||||||
|
|
||||||
|
ima_template= [IMA]
|
||||||
|
Select one of defined IMA measurements template formats.
|
||||||
|
Formats: { "ima" | "ima-ng" }
|
||||||
|
Default: "ima-ng"
|
||||||
|
|
||||||
init= [KNL]
|
init= [KNL]
|
||||||
Format: <full_path>
|
Format: <full_path>
|
||||||
Run specified binary instead of /sbin/init as init
|
Run specified binary instead of /sbin/init as init
|
||||||
|
@ -12,6 +12,8 @@
|
|||||||
* File: ima_template.c
|
* File: ima_template.c
|
||||||
* Helpers to manage template descriptors.
|
* Helpers to manage template descriptors.
|
||||||
*/
|
*/
|
||||||
|
#include <crypto/hash_info.h>
|
||||||
|
|
||||||
#include "ima.h"
|
#include "ima.h"
|
||||||
#include "ima_template_lib.h"
|
#include "ima_template_lib.h"
|
||||||
|
|
||||||
@ -32,6 +34,35 @@ static struct ima_template_field supported_fields[] = {
|
|||||||
};
|
};
|
||||||
|
|
||||||
static struct ima_template_desc *ima_template;
|
static struct ima_template_desc *ima_template;
|
||||||
|
static struct ima_template_desc *lookup_template_desc(const char *name);
|
||||||
|
|
||||||
|
static int __init ima_template_setup(char *str)
|
||||||
|
{
|
||||||
|
struct ima_template_desc *template_desc;
|
||||||
|
int template_len = strlen(str);
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Verify that a template with the supplied name exists.
|
||||||
|
* If not, use CONFIG_IMA_DEFAULT_TEMPLATE.
|
||||||
|
*/
|
||||||
|
template_desc = lookup_template_desc(str);
|
||||||
|
if (!template_desc)
|
||||||
|
return 1;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Verify whether the current hash algorithm is supported
|
||||||
|
* by the 'ima' template.
|
||||||
|
*/
|
||||||
|
if (template_len == 3 && strcmp(str, IMA_TEMPLATE_IMA_NAME) == 0 &&
|
||||||
|
ima_hash_algo != HASH_ALGO_SHA1 && ima_hash_algo != HASH_ALGO_MD5) {
|
||||||
|
pr_err("IMA: template does not support hash alg\n");
|
||||||
|
return 1;
|
||||||
|
}
|
||||||
|
|
||||||
|
ima_template = template_desc;
|
||||||
|
return 1;
|
||||||
|
}
|
||||||
|
__setup("ima_template=", ima_template_setup);
|
||||||
|
|
||||||
static struct ima_template_desc *lookup_template_desc(const char *name)
|
static struct ima_template_desc *lookup_template_desc(const char *name)
|
||||||
{
|
{
|
||||||
|
Loading…
Reference in New Issue
Block a user