Thread (31 messages) 31 messages, 4 authors, 2023-03-09

Re: [PATCH v7 0/6] evm: Do HMAC of multiple per LSM xattrs for new inodes

From: Roberto Sassu <hidden>
Date: 2023-03-09 07:56:06
Also in: linux-integrity, lkml, ocfs2-devel, selinux

On Wed, 2023-03-08 at 17:16 -0500, Paul Moore wrote:
On Thu, Dec 1, 2022 at 5:42 AM Roberto Sassu
[off-list ref] wrote:
quoted
From: Roberto Sassu <roberto.sassu@huawei.com>

One of the major goals of LSM stacking is to run multiple LSMs side by side
without interfering with each other. The ultimate decision will depend on
individual LSM decision.

Several changes need to be made to the LSM infrastructure to be able to
support that. This patch set tackles one of them: gives to each LSM the
ability to specify one or multiple xattrs to be set at inode creation
time and, at the same time, gives to EVM the ability to access all those
xattrs and calculate the HMAC on them.
Hi Roberto,

The v7 draft of this patchset had some good discussion, and based on a
quick read of the comments it looks like everyone was eventually
satisfied that the v7 draft was good and no further changes were
necessary, is that correct or do you have an updated draft of this
patchset?
Hi Paul

I addressed few more concerns from Mimi and Casey. I think v8 should be
good to send (unless you have more comments/suggestions).

Thanks

Roberto
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help