Skip to content

Commit

Permalink
ima: fix wrong signed policy requirement when not appraising
Browse files Browse the repository at this point in the history
Kernel booted just with ima_policy=tcb (not with
ima_policy=appraise_tcb) shouldn't require signed policy.

Regression found with LTP test ima_policy.sh.

Fixes: c52657d ("ima: refactor ima_init_policy()")
Cc: stable@vger.kernel.org  (linux-5.0)
Signed-off-by: Petr Vorel <pvorel@suse.cz>
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
  • Loading branch information
Petr Vorel authored and Mimi Zohar committed May 20, 2019
1 parent 558b523 commit f400194
Showing 1 changed file with 4 additions and 3 deletions.
7 changes: 4 additions & 3 deletions security/integrity/ima/ima_policy.c
Original file line number Diff line number Diff line change
Expand Up @@ -498,10 +498,11 @@ static void add_rules(struct ima_rule_entry *entries, int count,

list_add_tail(&entry->list, &ima_policy_rules);
}
if (entries[i].action == APPRAISE)
if (entries[i].action == APPRAISE) {
temp_ima_appraise |= ima_appraise_flag(entries[i].func);
if (entries[i].func == POLICY_CHECK)
temp_ima_appraise |= IMA_APPRAISE_POLICY;
if (entries[i].func == POLICY_CHECK)
temp_ima_appraise |= IMA_APPRAISE_POLICY;
}
}
}

Expand Down

0 comments on commit f400194

Please sign in to comment.