Every time a new architecture defines the IMA architecture specific
functions - arch_ima_get_secureboot() and arch_ima_get_policy(), the IMA
include file needs to be updated. To avoid this "noise", this patch
defines a new IMA Kconfig IMA_SECURE_AND_OR_TRUSTED_BOOT option, allowing
the different architectures to select it.
Suggested-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Nayna Jain <nayna@linux.ibm.com>
Cc: Ard Biesheuvel <ardb@kernel.org>
Cc: Martin Schwidefsky <redacted>
Cc: Philipp Rudo <redacted>
Cc: Michael Ellerman <mpe@ellerman.id.au>
---
arch/powerpc/Kconfig | 2 +-
arch/s390/Kconfig | 1 +
arch/x86/Kconfig | 1 +
include/linux/ima.h | 3 +--
security/integrity/ima/Kconfig | 9 +++++++++
5 files changed, 13 insertions(+), 3 deletions(-)
+
+config IMA_SECURE_AND_OR_TRUSTED_BOOT
+ bool
+ depends on IMA
+ depends on IMA_ARCH_POLICY
+ default n
+ help
+ This option is selected by architectures to enable secure and/or
+ trusted boot based on IMA runtime policies.
Why is the default for this new config "n"?
Is there any reason to not turn on this config if both IMA and
IMA_ARCH_POLICY are set to y?
thanks,
-lakshmi
On Wed, 2020-02-26 at 11:21 -0800, Lakshmi Ramasubramanian wrote:
Hi Nayna,
quoted
+
+config IMA_SECURE_AND_OR_TRUSTED_BOOT
+ bool
+ depends on IMA
+ depends on IMA_ARCH_POLICY
+ default n
+ help
+ This option is selected by architectures to enable secure and/or
+ trusted boot based on IMA runtime policies.
Why is the default for this new config "n"?
Is there any reason to not turn on this config if both IMA and
IMA_ARCH_POLICY are set to y?
Good catch. Having "IMA_SECURE_AND_OR_TRUSTED_BOOT" depend on
"IMA_ARCH_POLICY" doesn't make sense. "IMA_ARCH_POLICY" needs to be
selected.
thanks,
Mimi
On Wed, 2020-02-26 at 15:36 -0500, Mimi Zohar wrote:
On Wed, 2020-02-26 at 11:21 -0800, Lakshmi Ramasubramanian wrote:
quoted
Hi Nayna,
quoted
+
+config IMA_SECURE_AND_OR_TRUSTED_BOOT
+ bool
+ depends on IMA
+ depends on IMA_ARCH_POLICY
+ default n
+ help
+ This option is selected by architectures to enable secure and/or
+ trusted boot based on IMA runtime policies.
Why is the default for this new config "n"?
Is there any reason to not turn on this config if both IMA and
IMA_ARCH_POLICY are set to y?
Good catch. Having "IMA_SECURE_AND_OR_TRUSTED_BOOT" depend on
"IMA_ARCH_POLICY" doesn't make sense. "IMA_ARCH_POLICY" needs to be
selected.
After discussing this some more with Nayna, the new Kconfig indicates
that the architecture defines the arch_ima_get_secureboot() and
arch_get_ima_policy() functions, but doesn't automatically enable
IMA_ARCH_POLICY. The decision to enable IMA_ARCH_POLICY is left up to
whoever is building the kernel. The patch, at least this aspect of
it, is correct.
Mimi
On Wed, 2020-02-26 at 14:10 -0500, Nayna Jain wrote:
quoted hunk
Every time a new architecture defines the IMA architecture specific
functions - arch_ima_get_secureboot() and arch_ima_get_policy(), the IMA
include file needs to be updated. To avoid this "noise", this patch
defines a new IMA Kconfig IMA_SECURE_AND_OR_TRUSTED_BOOT option, allowing
the different architectures to select it.
Suggested-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Nayna Jain <nayna@linux.ibm.com>
Cc: Ard Biesheuvel <ardb@kernel.org>
Cc: Martin Schwidefsky <redacted>
Cc: Philipp Rudo <redacted>
Cc: Michael Ellerman <mpe@ellerman.id.au>
---
arch/powerpc/Kconfig | 2 +-
arch/s390/Kconfig | 1 +
arch/x86/Kconfig | 1 +
include/linux/ima.h | 3 +--
security/integrity/ima/Kconfig | 9 +++++++++
5 files changed, 13 insertions(+), 3 deletions(-)
Not everyone is interested in enabling IMA or requiring IMA runtime
policies. With this patch, enabling IMA_ARCH_POLICY is therefore
still left up to the person building the kernel. As a result, I'm
seeing the following warning, which is kind of cool.
WARNING: unmet direct dependencies detected for
IMA_SECURE_AND_OR_TRUSTED_BOOT
Depends on [n]: INTEGRITY [=y] && IMA [=y] && IMA_ARCH_POLICY [=n]
Selected by [y]:
- X86 [=y] && EFI [=y]
Ard, Michael, Martin, just making sure this type of warning is
acceptable before upstreaming this patch. I would appreciate your
tags.
thanks!
Mimi
On Mon, 2 Mar 2020 at 15:48, Mimi Zohar [off-list ref] wrote:
On Wed, 2020-02-26 at 14:10 -0500, Nayna Jain wrote:
quoted
Every time a new architecture defines the IMA architecture specific
functions - arch_ima_get_secureboot() and arch_ima_get_policy(), the IMA
include file needs to be updated. To avoid this "noise", this patch
defines a new IMA Kconfig IMA_SECURE_AND_OR_TRUSTED_BOOT option, allowing
the different architectures to select it.
Suggested-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Nayna Jain <nayna@linux.ibm.com>
Cc: Ard Biesheuvel <ardb@kernel.org>
Cc: Martin Schwidefsky <redacted>
Cc: Philipp Rudo <redacted>
Cc: Michael Ellerman <mpe@ellerman.id.au>
---
arch/powerpc/Kconfig | 2 +-
arch/s390/Kconfig | 1 +
arch/x86/Kconfig | 1 +
include/linux/ima.h | 3 +--
security/integrity/ima/Kconfig | 9 +++++++++
5 files changed, 13 insertions(+), 3 deletions(-)
Not everyone is interested in enabling IMA or requiring IMA runtime
policies. With this patch, enabling IMA_ARCH_POLICY is therefore
still left up to the person building the kernel. As a result, I'm
seeing the following warning, which is kind of cool.
WARNING: unmet direct dependencies detected for
IMA_SECURE_AND_OR_TRUSTED_BOOT
Depends on [n]: INTEGRITY [=y] && IMA [=y] && IMA_ARCH_POLICY [=n]
Selected by [y]:
- X86 [=y] && EFI [=y]
Ard, Michael, Martin, just making sure this type of warning is
acceptable before upstreaming this patch. I would appreciate your
tags.
Ehm, no, warnings like these are not really acceptable. It means there
is an inconsistency in the way the Kconfig dependencies are defined.
Does this help:
select IMA_SECURE_AND_OR_TRUSTED_BOOT if EFI && IMA_ARCH_POLICY
?
On Mon, 2020-03-02 at 15:52 +0100, Ard Biesheuvel wrote:
On Mon, 2 Mar 2020 at 15:48, Mimi Zohar [off-list ref] wrote:
quoted
On Wed, 2020-02-26 at 14:10 -0500, Nayna Jain wrote:
quoted
Every time a new architecture defines the IMA architecture specific
functions - arch_ima_get_secureboot() and arch_ima_get_policy(), the IMA
include file needs to be updated. To avoid this "noise", this patch
defines a new IMA Kconfig IMA_SECURE_AND_OR_TRUSTED_BOOT option, allowing
the different architectures to select it.
Suggested-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Nayna Jain <nayna@linux.ibm.com>
Cc: Ard Biesheuvel <ardb@kernel.org>
Cc: Martin Schwidefsky <redacted>
Cc: Philipp Rudo <redacted>
Cc: Michael Ellerman <mpe@ellerman.id.au>
---
arch/powerpc/Kconfig | 2 +-
arch/s390/Kconfig | 1 +
arch/x86/Kconfig | 1 +
include/linux/ima.h | 3 +--
security/integrity/ima/Kconfig | 9 +++++++++
5 files changed, 13 insertions(+), 3 deletions(-)
Not everyone is interested in enabling IMA or requiring IMA runtime
policies. With this patch, enabling IMA_ARCH_POLICY is therefore
still left up to the person building the kernel. As a result, I'm
seeing the following warning, which is kind of cool.
WARNING: unmet direct dependencies detected for
IMA_SECURE_AND_OR_TRUSTED_BOOT
Depends on [n]: INTEGRITY [=y] && IMA [=y] && IMA_ARCH_POLICY [=n]
Selected by [y]:
- X86 [=y] && EFI [=y]
Ard, Michael, Martin, just making sure this type of warning is
acceptable before upstreaming this patch. I would appreciate your
tags.
Ehm, no, warnings like these are not really acceptable. It means there
is an inconsistency in the way the Kconfig dependencies are defined.
Does this help:
select IMA_SECURE_AND_OR_TRUSTED_BOOT if EFI && IMA_ARCH_POLICY
?
Yes, that's fine for x86. Michael, Martin, do you want something
similar or would you prefer actually selecting IMA_ARCH_POLICY?
Mimi
Not everyone is interested in enabling IMA or requiring IMA runtime
policies. With this patch, enabling IMA_ARCH_POLICY is therefore
still left up to the person building the kernel. As a result, I'm
seeing the following warning, which is kind of cool.
WARNING: unmet direct dependencies detected for
IMA_SECURE_AND_OR_TRUSTED_BOOT
Depends on [n]: INTEGRITY [=y] && IMA [=y] && IMA_ARCH_POLICY [=n]
Selected by [y]:
- X86 [=y] && EFI [=y]
Ard, Michael, Martin, just making sure this type of warning is
acceptable before upstreaming this patch. I would appreciate your
tags.
Ehm, no, warnings like these are not really acceptable. It means there
is an inconsistency in the way the Kconfig dependencies are defined.
Does this help:
select IMA_SECURE_AND_OR_TRUSTED_BOOT if EFI && IMA_ARCH_POLICY
?
Yes, that's fine for x86. Michael, Martin, do you want something
similar or would you prefer actually selecting IMA_ARCH_POLICY?
For s390 something like
select IMA_SECURE_AND_OR_TRUSTED_BOOT if IMA_ARCH_POLICY
should be fine.
Thanks,
Heiko
From: Michael Ellerman <mpe@ellerman.id.au> Date: 2020-03-02 23:24:05
Mimi Zohar [off-list ref] writes:
On Mon, 2020-03-02 at 15:52 +0100, Ard Biesheuvel wrote:
quoted
On Mon, 2 Mar 2020 at 15:48, Mimi Zohar [off-list ref] wrote:
quoted
On Wed, 2020-02-26 at 14:10 -0500, Nayna Jain wrote:
quoted
Every time a new architecture defines the IMA architecture specific
functions - arch_ima_get_secureboot() and arch_ima_get_policy(), the IMA
include file needs to be updated. To avoid this "noise", this patch
defines a new IMA Kconfig IMA_SECURE_AND_OR_TRUSTED_BOOT option, allowing
the different architectures to select it.
Suggested-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Nayna Jain <nayna@linux.ibm.com>
Cc: Ard Biesheuvel <ardb@kernel.org>
Cc: Martin Schwidefsky <redacted>
Cc: Philipp Rudo <redacted>
Cc: Michael Ellerman <mpe@ellerman.id.au>
---
arch/powerpc/Kconfig | 2 +-
arch/s390/Kconfig | 1 +
arch/x86/Kconfig | 1 +
include/linux/ima.h | 3 +--
security/integrity/ima/Kconfig | 9 +++++++++
5 files changed, 13 insertions(+), 3 deletions(-)
Not everyone is interested in enabling IMA or requiring IMA runtime
policies. With this patch, enabling IMA_ARCH_POLICY is therefore
still left up to the person building the kernel. As a result, I'm
seeing the following warning, which is kind of cool.
WARNING: unmet direct dependencies detected for
IMA_SECURE_AND_OR_TRUSTED_BOOT
Depends on [n]: INTEGRITY [=y] && IMA [=y] && IMA_ARCH_POLICY [=n]
Selected by [y]:
- X86 [=y] && EFI [=y]
Ard, Michael, Martin, just making sure this type of warning is
acceptable before upstreaming this patch. I would appreciate your
tags.
Ehm, no, warnings like these are not really acceptable. It means there
is an inconsistency in the way the Kconfig dependencies are defined.
Does this help:
select IMA_SECURE_AND_OR_TRUSTED_BOOT if EFI && IMA_ARCH_POLICY
?
Yes, that's fine for x86. Michael, Martin, do you want something
similar or would you prefer actually selecting IMA_ARCH_POLICY?