With the introduction of IMA-appraisal and the need to write file
hashes as security xattrs, IMA needed to take the global i_mutex
lock. process_measurement() took the iint->mutex first and then
the i_mutex, while setxattr, chmod and chown took the locks in
reverse order. To resolve this potential deadlock, the iint->mutex
was removed.
Some filesystems have recently replaced their filesystem dependent
lock with the global i_rwsem (formerly the i_mutex) to read a file.
As a result, when IMA attempts to calculate the file hash, reading
the file attempts to take the i_rwsem again.
To resolve this locking problem, this patch set introduces a new
->integrity_read file operation method. Until all filesystems
define the new ->integrity_read method, files that were previously
measured might not be currently measured and files that were
previously appraised might fail to be appraised properly.
Version 2 of this patch set, introduces measurement entries and
IMA-audit messages containing file hash values containing 0's,
instead of the actual file hash, for files which the file hash
could not be calculated. Like for any other file signature
verification error, file access/execute permission will be denied,
for files in policy that the file hash could not be calculated.
To override the IMA policy, allowing unverified code to be
accessed/executed on filesystems not supported by IMA, version 2 of
this patch set defines a new pseudo policy "action" named
"dont_failsafe" and a new builtin policy named "fs_unsafe", which
can be specified on the boot command line.
Mimi
Changelog v1:
- Don't silently drop file measurements on failure to "collect" the
file hash, add an entry in the measurement list and IMA-audit log
the file.
- Define a pseudo policy action named "dont_failsafe".
- Define a new builtin IMA policy named "fs_unsafe".
- Instead of calling the existing read_iter method, when defined
as generic_file_read_iter(), define an ->integrity_read method
for each file system.
- Expanded/clarified motivation in the patch description for using
the ->read method.
- Use kvec, not iovec. (Reported by zero day testing)
Christoph Hellwig (1):
ima: use fs method to read integrity data
Mimi Zohar (9):
ima: always measure and audit files in policy
ima: define "dont_failsafe" policy action rule
ima: define "fs_unsafe" builtin policy
tmpfs: define integrity_read method
fs: define integrity_read method for ext2, gfs2, f2fs, jfs, ramfs
ocfs2: define integrity_read method
jffs2: define integrity_read method
ubifs: define integrity_read method
ima: use existing read file operation method to calculate file hash
Documentation/ABI/testing/ima_policy | 3 ++-
Documentation/admin-guide/kernel-parameters.txt | 8 ++++++-
fs/btrfs/file.c | 1 +
fs/ext2/file.c | 1 +
fs/ext4/file.c | 1 +
fs/f2fs/file.c | 1 +
fs/gfs2/file.c | 2 ++
fs/jffs2/file.c | 1 +
fs/jfs/file.c | 1 +
fs/ocfs2/file.c | 1 +
fs/ramfs/file-mmu.c | 1 +
fs/ramfs/file-nommu.c | 1 +
fs/ubifs/file.c | 1 +
fs/xfs/xfs_file.c | 21 +++++++++++++++++
include/linux/fs.h | 1 +
mm/shmem.c | 1 +
security/integrity/iint.c | 31 +++++++++++++++++++------
security/integrity/ima/ima.h | 1 +
security/integrity/ima/ima_api.c | 7 ++++--
security/integrity/ima/ima_main.c | 15 +++++++++---
security/integrity/ima/ima_policy.c | 16 ++++++++++++-
21 files changed, 101 insertions(+), 15 deletions(-)
--
2.7.4
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
--
2.7.4
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
All files matching a "measure" rule must be included in the IMA
measurement list, even when the file hash cannot be calculated.
Similarly, all files matching an "audit" rule must be audited, even when
the file hash cannot be calculated.
The file data hash field contained in the IMA measurement list template
data will contain 0's instead of the actual file hash digest.
Mimi Zohar [off-list ref]
---
security/integrity/ima/ima_api.c | 7 +++++--
security/integrity/ima/ima_main.c | 4 ++--
2 files changed, 7 insertions(+), 4 deletions(-)
--
2.7.4
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
From: Christoph Hellwig <hch@lst.de>
Add a new ->integrity_read file operation to read data for integrity
hash collection. This is defined to be equivalent to ->read_iter,
except that it will be called with the i_rwsem held exclusively.
Changelog v2:
- change iovec to kvec
Changelog v1:
- update the patch description, removing the concept that the presence of
->integrity_read indicates that the file system can support IMA. (Mimi)
Signed-off-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Mimi Zohar <redacted>
---
fs/btrfs/file.c | 1 +
fs/ext4/file.c | 1 +
fs/xfs/xfs_file.c | 21 +++++++++++++++++++++
include/linux/fs.h | 1 +
security/integrity/iint.c | 20 ++++++++++++++------
5 files changed, 38 insertions(+), 6 deletions(-)
--
2.7.4
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
--
2.7.4
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
@@ -1478,7 +1478,7 @@ ima_policy= [IMA] The builtin policies to load during IMA setup.- Format: "tcb | appraise_tcb | secure_boot"+ Format: "tcb | appraise_tcb | secure_boot | fs_unsafe" The "tcb" policy measures all programs exec'd, files mmap'd for exec, and all files opened with the read
@@ -1493,6 +1493,12 @@ of files (eg. kexec kernel image, kernel modules, firmware, policy, etc) based on file signatures.+ The "fs_unsafe" policy permits normally denied+ access/execute permission for files in policy on IMA+ unsupported filesystems. Note this option, as the+ name implies, is not safe and not recommended for+ any environments other than testing.+ ima_tcb [IMA] Deprecated. Use ima_policy= instead. Load a policy which meets the needs of the Trusted Computing Base. This means IMA will measure all
@@ -200,6 +200,8 @@ static int __init policy_setup(char *str)ima_use_appraise_tcb=1;elseif(strcmp(p,"secure_boot")==0)ima_use_secure_boot=1;+elseif(strcmp(p,"fs_unsafe")==0)+set_failsafe(0);}return1;
--
2.7.4
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
--
2.7.4
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
--
2.7.4
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
--
2.7.4
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
The builtin "ima_tcb" policy measures all files read by root. This
policy includes, for example, files on efivars. Since some files on
these filesystems were previously measured (eg. OsIndicationsSupported),
not measuring them would change the PCR hash value(s), potentially
breaking userspace.
The few filesystems that currently define the ->read file operation
method, either call seq_read() or have a filesystem specific ->read
method. None of them, at least in the fs directory, take the i_rwsem.
For filesystems that do not define the ->integrity_read file operation
method and have a ->read method, this patch calls the ->read method
to calculate the file hash.
Signed-off-by: Mimi Zohar <redacted>
---
security/integrity/iint.c | 17 +++++++++++++----
1 file changed, 13 insertions(+), 4 deletions(-)
@@ -189,20 +189,29 @@ int integrity_kernel_read(struct file *file, loff_t offset,structkveciov={.iov_base=addr,.iov_len=count};structkiocbkiocb;structiov_iteriter;-ssize_tret;+ssize_tret=-EBADF;lockdep_assert_held(&inode->i_rwsem);if(!(file->f_mode&FMODE_READ))return-EBADF;-if(!file->f_op->integrity_read)-return-EBADF;init_sync_kiocb(&kiocb,file);kiocb.ki_pos=offset;iov_iter_kvec(&iter,READ|ITER_KVEC,&iov,1,count);-ret=file->f_op->integrity_read(&kiocb,&iter);+if(file->f_op->integrity_read){+ret=file->f_op->integrity_read(&kiocb,&iter);+}elseif(file->f_op->read){+mm_segment_told_fs;+char__user*buf=(char__user*)addr;++old_fs=get_fs();+set_fs(get_ds());+ret=file->f_op->read(file,buf,count,&offset);+set_fs(old_fs);+}+BUG_ON(ret==-EIOCBQUEUED);returnret;}
--
2.7.4
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
--
2.7.4
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
From: Christoph Hellwig <hch@lst.de> Date: 2017-06-28 14:38:26
On Wed, Jun 21, 2017 at 02:18:22PM -0400, Mimi Zohar wrote:
From: Christoph Hellwig <hch@lst.de>
Add a new ->integrity_read file operation to read data for integrity
hash collection. This is defined to be equivalent to ->read_iter,
except that it will be called with the i_rwsem held exclusively.
Changelog v2:
- change iovec to kvec
Changelog v1:
- update the patch description, removing the concept that the presence of
->integrity_read indicates that the file system can support IMA. (Mimi)
Changelog goes below the ---
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
From: Christoph Hellwig <hch@lst.de> Date: 2017-06-28 14:38:58
On Wed, Jun 21, 2017 at 02:18:25PM -0400, Mimi Zohar wrote:
Define an ->integrity_read file operation method to read data for
integrity hash collection.
should be folded into patch 2.
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
From: Christoph Hellwig <hch@lst.de> Date: 2017-06-28 14:39:14
On Wed, Jun 21, 2017 at 02:18:26PM -0400, Mimi Zohar wrote:
Define ->integrity_read file operation methods to read data for
integrity hash collection.
should be folded into patch 2.
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
From: Christoph Hellwig <hch@lst.de> Date: 2017-06-28 14:39:25
should be folded into patch 2.
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
From: Christoph Hellwig <hch@lst.de> Date: 2017-06-28 14:39:34
should be folded into patch 2.
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
From: Christoph Hellwig <hch@lst.de> Date: 2017-06-28 14:39:45
On Wed, Jun 21, 2017 at 02:18:29PM -0400, Mimi Zohar wrote:
Define an ->integrity_read file operation method to read data for
integrity hash collection.
should be folded into patch 2.
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
From: Christoph Hellwig <hch@lst.de> Date: 2017-06-28 14:41:13
NAK - we'll need an explicit method for the integrity code.
And just curious - what filesystem that you care about actually
implements ->read instead of ->read_iter? We shouldn't be doing that
for real file systems anymore.
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
[Cc'ing linux-ima-users]
On Wed, 2017-06-28 at 16:41 +0200, Christoph Hellwig wrote:
NAK - we'll need an explicit method for the integrity code.
And just curious - what filesystem that you care about actually
implements ->read instead of ->read_iter? We shouldn't be doing that
for real file systems anymore.
Right, pseudo filesystems are using ->read. The existing builtin
measurement policies exclude a number of pseudo filesystems, but not
efivarfs. ?Unfortunately, we do not know what type of custom policies
are currently being used.
The contents of the IMA measurement list are verified against a
reference manifest, provided at registration, or against a white list.
Not measuring files that were previously measured could break
userspace applications.
Let's wait to hear back from the larger IMA community as to whether
there is a need to measure files on pseudo filesystems, before
implementing an explicit method.
Mimi
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
From: Christoph Hellwig <hch@lst.de> Date: 2017-07-05 17:18:59
On Wed, Jul 05, 2017 at 06:02:15PM +0100, Matthew Garrett wrote:
On Wed, Jul 05, 2017 at 10:50:09AM -0400, Mimi Zohar wrote:
quoted
[Cc'ing linux-ima-users]
On Wed, 2017-06-28 at 16:41 +0200, Christoph Hellwig wrote:
quoted
NAK - we'll need an explicit method for the integrity code.
And just curious - what filesystem that you care about actually
implements ->read instead of ->read_iter? We shouldn't be doing that
for real file systems anymore.
Right, pseudo filesystems are using ->read. The existing builtin
measurement policies exclude a number of pseudo filesystems, but not
efivarfs. ?Unfortunately, we do not know what type of custom policies
are currently being used.
efi variables contain information that may influence userspace behaviour
and can also be modified out of band, so I think there's a reasonable
argument that they should be measured.
Then efivars should grow a ->integrity_read method.
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
From: Matthew Garrett <mjg59@srcf.ucam.org> Date: 2017-07-05 17:52:27
On Wed, Jul 05, 2017 at 10:50:09AM -0400, Mimi Zohar wrote:
[Cc'ing linux-ima-users]
On Wed, 2017-06-28 at 16:41 +0200, Christoph Hellwig wrote:
quoted
NAK - we'll need an explicit method for the integrity code.
And just curious - what filesystem that you care about actually
implements ->read instead of ->read_iter? We shouldn't be doing that
for real file systems anymore.
Right, pseudo filesystems are using ->read. The existing builtin
measurement policies exclude a number of pseudo filesystems, but not
efivarfs. ?Unfortunately, we do not know what type of custom policies
are currently being used.
efi variables contain information that may influence userspace behaviour
and can also be modified out of band, so I think there's a reasonable
argument that they should be measured.
--
Matthew Garrett | mjg59 at srcf.ucam.org
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
On Wed, 2017-06-28 at 16:38 +0200, Christoph Hellwig wrote:
On Wed, Jun 21, 2017 at 02:18:25PM -0400, Mimi Zohar wrote:
quoted
Define an ->integrity_read file operation method to read data for
integrity hash collection.
should be folded into patch 2.
I was hoping to get some Acks/sign-off's from the individual
filesystem maintainers before squashing them. ?The next version will
be squashed.
Mimi
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html