Thread (40 messages) 40 messages, 6 authors, 2022-07-30

Re: [PATCH v4 0/3] initramfs: add support for xattrs in the initial ram disk

From: Mimi Zohar <zohar@linux.ibm.com>
Date: 2019-07-01 13:23:40
Also in: linux-fsdevel, linux-integrity, linux-security-module, lkml

On Thu, 2019-05-23 at 14:18 +0200, Roberto Sassu wrote:
This patch set aims at solving the following use case: appraise files from
the initial ram disk. To do that, IMA checks the signature/hash from the
security.ima xattr. Unfortunately, this use case cannot be implemented
currently, as the CPIO format does not support xattrs.

This proposal consists in including file metadata as additional files named
METADATA!!!, for each file added to the ram disk. The CPIO parser in the
kernel recognizes these special files from the file name, and calls the
appropriate parser to add metadata to the previously extracted file. It has
been proposed to use bit 17:16 of the file mode as a way to recognize files
with metadata, but both the kernel and the cpio tool declare the file mode
as unsigned short.
Thanks, Roberto!

Victor, Taras, Rob, Arvind, Peter, if you're good with this latest
design, could we get some Reviewed-by, Acked-by, or Tested-by?

thanks!

Mimi
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help