Received: by 2002:a25:23cc:0:0:0:0:0 with SMTP id j195csp87632ybj; Fri, 8 May 2020 07:08:48 -0700 (PDT) X-Google-Smtp-Source: APiQypKv3bMcqbKN/ubz79su6MHleoIzPoh1fbmYG+j3fQbhotVvXRxFy+/eDT2WKRmVxP4P1gM7 X-Received: by 2002:aa7:9ae5:: with SMTP id y5mr3078950pfp.294.1588946927908; Fri, 08 May 2020 07:08:47 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1588946927; cv=none; d=google.com; s=arc-20160816; b=dLFcoOCYQ7ERSWElyccO8IocXHH+u2zLk9tvroEihkGZQ7HKNFbufYcKrKIbLoLSGf CWYw2l76c2OW/vUujs42q2W3o6qz+tMQUGKi3ZMSWS8dLkRU+8tSp1ze+POAi6zWOjHP QfngnyX9i6PKJGFeBn/Rq6ilaORI9SWVzJdu6uVnA5MCyP9szrmMLlIP0ITk46/fDtml 5MxC0SFDY1ADRiHwOraEDX5tTXitPWRNIbeNy8ftH47uF7MRghIwD4Vmk9A3LOHbDsrd mIBOJBu0p1cbJkGfQcfHG0ZwbeeeQ6oO/g8HXXmHEUGZa8x80nAaJ2rzrFa8d7rfisaQ X2LQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :references:in-reply-to:date:cc:to:from:subject:message-id; bh=+ElaVs8EilIstc3jmVXvmeVnFG8ulXozr7dSTHnHJHU=; b=xbdDxn9e9xFR6lCNft96j9NO7xf1hj4KF6DPLr6bxFK1zJVrjIDEYoS+IqqygJuU+i FyGumDnaWzv8V3tmL3tReA0hQuJqfvAA/NEuYLNwwZouvMgSIk8AQI7NjU3M11OUQ3hm 6ur3mbYaNPqn82kWqJH4L+iN1xzgPXu6IbeJXxeiY4iXXNZdhXddWsufBCfKyUGUpdtP VoWu6po+HnNcxJOjRueegNclnR9ADjxbzbp1fKo6Hs9BWl5lzygwTrT3kRCbejV6dB16 CnSToYXryLUSSDuoQUvZ+mutWFFwkHyItHKqjtUN6ZWBZvpLsTzXl1owA5da1oxvN+/A 41OQ== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=ibm.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id ay15si2219595pjb.73.2020.05.08.07.07.52; Fri, 08 May 2020 07:08:47 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=ibm.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727840AbgEHOCc (ORCPT + 99 others); Fri, 8 May 2020 10:02:32 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]:60260 "EHLO mx0a-001b2d01.pphosted.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726636AbgEHOCc (ORCPT ); Fri, 8 May 2020 10:02:32 -0400 Received: from pps.filterd (m0098404.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.16.0.42/8.16.0.42) with SMTP id 048DYap3030733; Fri, 8 May 2020 10:01:19 -0400 Received: from pps.reinject (localhost [127.0.0.1]) by mx0a-001b2d01.pphosted.com with ESMTP id 30vtsr5dtv-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 08 May 2020 10:01:18 -0400 Received: from m0098404.ppops.net (m0098404.ppops.net [127.0.0.1]) by pps.reinject (8.16.0.36/8.16.0.36) with SMTP id 048DYi4n031919; Fri, 8 May 2020 10:01:17 -0400 Received: from ppma01fra.de.ibm.com (46.49.7a9f.ip4.static.sl-reverse.com [159.122.73.70]) by mx0a-001b2d01.pphosted.com with ESMTP id 30vtsr5dsa-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 08 May 2020 10:01:17 -0400 Received: from pps.filterd (ppma01fra.de.ibm.com [127.0.0.1]) by ppma01fra.de.ibm.com (8.16.0.27/8.16.0.27) with SMTP id 048Dt2vA010653; Fri, 8 May 2020 14:01:14 GMT Received: from b06cxnps3075.portsmouth.uk.ibm.com (d06relay10.portsmouth.uk.ibm.com [9.149.109.195]) by ppma01fra.de.ibm.com with ESMTP id 30s0g5dhkb-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 08 May 2020 14:01:14 +0000 Received: from d06av25.portsmouth.uk.ibm.com (d06av25.portsmouth.uk.ibm.com [9.149.105.61]) by b06cxnps3075.portsmouth.uk.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 048E1CFE43319440 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 8 May 2020 14:01:12 GMT Received: from d06av25.portsmouth.uk.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id E49F311C064; Fri, 8 May 2020 14:01:11 +0000 (GMT) Received: from d06av25.portsmouth.uk.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 2A93011C052; Fri, 8 May 2020 14:01:08 +0000 (GMT) Received: from localhost.localdomain (unknown [9.85.139.55]) by d06av25.portsmouth.uk.ibm.com (Postfix) with ESMTP; Fri, 8 May 2020 14:01:08 +0000 (GMT) Message-ID: <1588946467.5146.6.camel@linux.ibm.com> Subject: Re: [PATCH v5 0/6] Add support for O_MAYEXEC From: Mimi Zohar To: "Lev R. Oshvang ." , =?ISO-8859-1?Q?Micka=EBl_Sala=FCn?= Cc: David Laight , "linux-kernel@vger.kernel.org" , Aleksa Sarai , Alexei Starovoitov , Al Viro , Andy Lutomirski , Christian Heimes , Daniel Borkmann , Deven Bowers , Eric Chiang , Florian Weimer , James Morris , Jan Kara , Jann Horn , Jonathan Corbet , Kees Cook , Lakshmi Ramasubramanian , Matthew Garrett , Matthew Wilcox , Michael Kerrisk , =?ISO-8859-1?Q?Micka=EBl_Sala=FCn?= , Philippe =?ISO-8859-1?Q?Tr=E9buchet?= , Scott Shell , Sean Christopherson , Shuah Khan , Steve Dower , Steve Grubb , Thibaut Sautereau , Vincent Strubel , "kernel-hardening@lists.openwall.com" , "linux-api@vger.kernel.org" , "linux-integrity@vger.kernel.org" , "linux-security-module@vger.kernel.org" , "linux-fsdevel@vger.kernel.org" Date: Fri, 08 May 2020 10:01:07 -0400 In-Reply-To: References: <20200505153156.925111-1-mic@digikod.net> <20b24b9ca0a64afb9389722845738ec8@AcuMS.aculab.com> <907109c8-9b19-528a-726f-92c3f61c1563@digikod.net> <64426377-7fc4-6f37-7371-2e2a584e3032@digikod.net> <635df0655b644408ac4822def8900383@AcuMS.aculab.com> <1ced6f5f-7181-1dc5-2da7-abf4abd5ad23@digikod.net> Content-Type: text/plain; charset="UTF-8" X-Mailer: Evolution 3.20.5 (3.20.5-1.fc24) Mime-Version: 1.0 Content-Transfer-Encoding: 8bit X-TM-AS-GCONF: 00 X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.216,18.0.676 definitions=2020-05-08_13:2020-05-08,2020-05-08 signatures=0 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 mlxlogscore=932 lowpriorityscore=0 spamscore=0 mlxscore=0 malwarescore=0 clxscore=1011 adultscore=0 phishscore=0 priorityscore=1501 bulkscore=0 impostorscore=0 suspectscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2003020000 definitions=main-2005080116 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Fri, 2020-05-08 at 10:15 +0300, Lev R. Oshvang . wrote: > I can suggest something better ( I believe) > Some time ago I proposed patch to IMA - Add suffix in IMA policy rule criteria > It allows IMA to verify scripts, configuration files and even single file. > It is very simple and does not depend on open flags. > Mimi Zohar decided not to include this patch on the reason it tries to > protect the file name. > ( Why ??). Your patch relies on the filename, but does nothing to protect it.  Mimi