Received: by 2002:a25:4158:0:0:0:0:0 with SMTP id o85csp5956733yba; Mon, 13 May 2019 22:08:05 -0700 (PDT) X-Google-Smtp-Source: APXvYqyvSvUytao+NrhqPFjS1did3wMbhn95aqk/3w6yhjy7SK/X5L/TVioir9NaD+UmmqwtTC+B X-Received: by 2002:a17:902:7594:: with SMTP id j20mr35951559pll.78.1557810485279; Mon, 13 May 2019 22:08:05 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1557810485; cv=none; d=google.com; s=arc-20160816; b=pvA6CCzjD5V6ihPQc6KbLoOYHLrRpyopU/V4JWk7TNVKtOfeigiK14O+ShfBkpPQzz kxzKaE6FTlTZznCjbk1W6MchVMPHahuYjzSwaZI8yLJJJ10GH12Jgmp5e5NX/hXG/WXv 7r4s2Ee+A2DvgqyWk5Hl+hWWRrzQB6OtPLi652iZMtIWXS/1hUYQkpYxGGyp3patofSV lQW9Tngv7l1Er9/KxPt4d8Ui9iD7FOD93C7Q5CVX/mdLnOvX+RTIHx9zbsSkwnEj3pTd SSHOcuBvuT9ZZosLl1VkhpKBOYtkFq7FxaR4D/4G1CdJ3blu+Kb0hzrO1uCOeUlsg6Z1 bClQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:dkim-signature; bh=Q7ivzidNqiF6L5Pdt29c2H0Kj0g0EzNa6q9k46tNNOA=; b=Iti90j0C+37KKq6J07MgjdVYzNbJNMCBNXXB2SJybwPch1kV5numQ3T+L4i/2vkA4V /SIRUrcfaioj+Sy4tqbdwzhh212rwuqjivx87l+818h8JPmMYG+g6WmduzyHnmHJX8H3 GhfPev9m9btnOALMMAvBJtrCsaRqdgGq/j7k6MIqJwNVHn/ZWVV/BdQt2XKVvuOS58i8 dBmt6iFCcdxrZ7/Y7UtiivoUjmgsnyRtQd3N7yhf0N9Rd2bT+z19gc00lcbo9aLetJp3 K8QehkyiKWmMeNtQe3YcxN0NhS7+cW6d8UWOeTumnUiXtiz8kLBdAJfNuJE4l2WP18Oe 74pg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=XTnawXYq; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id i38si6479054plb.132.2019.05.13.22.07.49; Mon, 13 May 2019 22:08:05 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=XTnawXYq; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726607AbfENFG4 (ORCPT + 99 others); Tue, 14 May 2019 01:06:56 -0400 Received: from mail-pg1-f196.google.com ([209.85.215.196]:39621 "EHLO mail-pg1-f196.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1725935AbfENFG4 (ORCPT ); Tue, 14 May 2019 01:06:56 -0400 Received: by mail-pg1-f196.google.com with SMTP id w22so7957825pgi.6; Mon, 13 May 2019 22:06:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=Q7ivzidNqiF6L5Pdt29c2H0Kj0g0EzNa6q9k46tNNOA=; b=XTnawXYqf3R9HsqS96E5qSl06en1GGyJWROir0uXJ4H3z/SYsSv0byyYFtn97lRKqs qQYfpVXf3tM7x/Kivn0rIX1mNhYKE+8imiCpmMVNw5iU5VVgEywypIlUlL2Mkt/pD+8F NUHgoobnCSE3qLigkRuIUg4NF6UktCoJSU8XNtI8V/e6fa1cMtEqnVx3+rC8o7HI2mDd O1NmT2yytRMubHtdZk1HtBBV25qlF1KO4xhoIosFCwIg51FS2JDCP4T7szBFsmoh14mZ mw8+fMsNI2CDyMfIc66Ei1NyrpTK/sfcRk3SUTcuYbx2Pz6QIOkGL8n54CuRu7V+zdni 2oEQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=Q7ivzidNqiF6L5Pdt29c2H0Kj0g0EzNa6q9k46tNNOA=; b=VVw1lYZmEHiAKuZG5MYCLxjZdnPHUmB/zhCBvyeiIa2WOz1jHRaOQ0mIIS8Qn6ktzu 51xY6K9ZVXvL27xNnbmUXHfLtPXbO88icegkF7B7i9RGFeor82K7IR1fWVXDYtwCEdyP 2cpINagHxyZITmUUOLtzO+XuBReL1669De59E1kC894lFtby5TvgK3n2MxqXeL5peJnm umP7Hzgtb1xlbojFgayE2YwzcGH75phaTcmmft1oC7DWsfaZdEHT0Ljd4Mr0zrNB0pGb QqfGQf2hSoxkI5u2Zi28ozXR3Z8NMwOKM0MVbJ83x53UobU74LYqJKGD7V9f+q334tiq Q4lg== X-Gm-Message-State: APjAAAXZd8Zffqu72vIduI7QFQFHF0jppBUwmkuW1y6PtcrbLEiw4R+q Yu2XPX9G4Lo7JVNTPLI7Jm6sRD1jTQfTKNFv2MM= X-Received: by 2002:a62:ed1a:: with SMTP id u26mr31636146pfh.229.1557810415272; Mon, 13 May 2019 22:06:55 -0700 (PDT) MIME-Version: 1.0 References: <20190510223744.10154-1-prsriva02@gmail.com> <20190510223744.10154-3-prsriva02@gmail.com> <45344b2f-d9ea-f7df-e45f-18037e2ba5ca@huawei.com> In-Reply-To: <45344b2f-d9ea-f7df-e45f-18037e2ba5ca@huawei.com> From: prakhar srivastava Date: Mon, 13 May 2019 22:07:08 -0700 Message-ID: Subject: Re: [PATCH 2/3 v5] add a new template field buf to contain the buffer To: Roberto Sassu Cc: linux-integrity@vger.kernel.org, inux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, Mimi Zohar , ebiederm@xmission.com, vgoyal@redhat.com, Prakhar Srivastava Content-Type: text/plain; charset="UTF-8" Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, May 13, 2019 at 6:48 AM Roberto Sassu wrote: > > On 5/11/2019 12:37 AM, Prakhar Srivastava wrote: > > From: Prakhar Srivastava > > > > The buffer(cmdline args) added to the ima log cannot be attested > > without having the actual buffer. Thus to make the measured buffer > > available to store/read a new ima template (buf) is added. > > Hi Prakhar > > please fix the typos. More comments below. > > > > + buffer_event_data->type = IMA_XATTR_BUFFER; > > + buffer_event_data->buf_length = size; > > + memcpy(buffer_event_data->buf, buf, size); > > + > > + event_data.xattr_value = (struct evm_ima_xattr_data *)buffer_event_data; > > + event_data.xattr_len = alloc_length; > > I would prefer that you introduce two new fields in the ima_event_data > structure. You can initialize them directly with the parameters of > process_buffer_measurement(). I will make the edits, this will definitely save the kzalloc in this code path. > > ima_write_template_field_data() will make > a copy. > Since event_data->type is used to distinguish what the template field should contain. Removing the type and subsequent check in the template_init, buf template fmt will result in the whole event_Data structure being added to the log, which is not the expected output. For buffer entries, the buf templet fmt will contains the buffer itself. > > > + .field_show = ima_show_template_buf}, > > Please update Documentation/security/IMA-templates.rst Will update the documentation. Thanks, Prakhar Srivastava > > Thanks > > Roberto