ima_collect_modsig() supplies the file contents to the parsed PKCS#7
message as detached data. If the message already contains embedded data,
pkcs7_supply_detached_data() returns -EINVAL, but IMA discards the error.
ima_modsig_verify() subsequently verifies that embedded data instead of
the file being appraised.
Return binding errors and discard the modsig on failure, preserving
ordinary hashing and security.ima appraisal. Keep digest export optional:
ML-DSA and multiple-signer messages can still verify without it. Leave
d-modsig empty when unavailable instead of dropping the measurement.
Audit binding errors separately so O_DIRECT does not hide their cause.
Fixes: 15588227e086 ("ima: Collect modsig")
Assisted-by: LLM
Signed-off-by: Jérémy Jean <redacted>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260924085516.3111521-2-Jeremy.Jean@oss.cyber.gouv.fr?part=1