Received: by 2002:a05:6358:1087:b0:cb:c9d3:cd90 with SMTP id j7csp3016648rwi; Fri, 21 Oct 2022 10:26:07 -0700 (PDT) X-Google-Smtp-Source: AMsMyM676QkhxJuzEJN3GmePiV0peR7UJomLrHZTrMlq/oVoafQLP8yAatN6jR79pQTNm63rU+uD X-Received: by 2002:a17:907:25cd:b0:77b:9672:38e7 with SMTP id ae13-20020a17090725cd00b0077b967238e7mr17210881ejc.10.1666373167265; Fri, 21 Oct 2022 10:26:07 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1666373167; cv=none; d=google.com; s=arc-20160816; b=XzXfmATnuPiKfNuKs9b5KESnOnPZWnzUawDw+uoSlzhPQT9AWPlm3gurgS5AWeAFTX 0VTQ6GLnywdIdLg4ZQV9hb0zTBP0DPPCHbe5FdjPGlRobsGIAS9eihTAzMDkdkchNR7U fuq7DD9+tzCeTx27Pz3tmfOHFRROi6PGa7yDUo7OsiBSuuQV39klCDLYMgx1gVg93aqt HKbJtWuMNJKJLQ+COYqYT7B8yJayNIcCU4ZEdjUD3O24IvTcddy4UpCZolU/YCPAVmWv infTGbMPtayj7D4vnGgZi7ZKLLpMhtUEHKseLvhlhk+dt92p2VKmqqW/+GUXU2zWZz0N tBng== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:user-agent:in-reply-to:content-disposition :mime-version:references:reply-to:message-id:subject:cc:to:from:date; bh=P+7M4cTY71RzTj+uJ76aYJ4lGFEDmuSInZhWa2UPjUU=; b=eA0HiUeqbP7pLgJXTOnUl6QKhJELC5Xr9OYImx86HmlhoqqxsIPBaAGnrml+1LIwhB Pp3LlxrKZQ9GMAprEd+pKw9jcO5WxK2FTLFb+MzmpsaHReLeXbCNx25UliKnL+ayk3Ln P1SHrGFRI8URZV8fyRd3qLpNP6lpJgvI+Yb/daIQ+f/Sb5nlIVGRxoGPYe1sA15nnFDU n0rKCPUzHY4dMyWSPJv1GQH7oeaDNrW6opPGlTXrxGznrYQW0UStfUzHYho/YFKDGzr+ Rv+zWi6448uMGE8DWWs8YWFOzUVPFlzGHLpDfhFQ1HT9AGgcXZpNfp1YgPzF1MhcuVF2 VypQ== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id dt4-20020a170907728400b00791a2a7e578si9949197ejc.641.2022.10.21.10.25.42; Fri, 21 Oct 2022 10:26:07 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S230220AbiJUQfq (ORCPT + 99 others); Fri, 21 Oct 2022 12:35:46 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:50380 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S230159AbiJUQfp (ORCPT ); Fri, 21 Oct 2022 12:35:45 -0400 X-Greylist: delayed 1798 seconds by postgrey-1.37 at lindbergh.monkeyblade.net; Fri, 21 Oct 2022 09:35:41 PDT Received: from wind.enjellic.com (wind.enjellic.com [76.10.64.91]) by lindbergh.monkeyblade.net (Postfix) with ESMTP id 6E36C203570; Fri, 21 Oct 2022 09:35:39 -0700 (PDT) Received: from wind.enjellic.com (localhost [127.0.0.1]) by wind.enjellic.com (8.15.2/8.15.2) with ESMTP id 29LEroap015522; Fri, 21 Oct 2022 09:53:50 -0500 Received: (from greg@localhost) by wind.enjellic.com (8.15.2/8.15.2/Submit) id 29LErmuU015521; Fri, 21 Oct 2022 09:53:48 -0500 Date: Fri, 21 Oct 2022 09:53:48 -0500 From: "Dr. Greg" To: Kees Cook Cc: Mimi Zohar , Paul Moore , James Morris , "Serge E. Hallyn" , Dmitry Kasatkin , Micka?l Sala?n , Petr Vorel , Borislav Petkov , Takashi Iwai , Jonathan McDowell , linux-security-module@vger.kernel.org, linux-integrity@vger.kernel.org, KP Singh , Casey Schaufler , John Johansen , linux-kernel@vger.kernel.org, linux-hardening@vger.kernel.org Subject: Re: [PATCH 2/9] security: Move trivial IMA hooks into LSM Message-ID: <20221021145348.GA15390@wind.enjellic.com> Reply-To: "Dr. Greg" References: <20221013222702.never.990-kees@kernel.org> <20221013223654.659758-2-keescook@chromium.org> <16e008b3709f3c85dbad1accb9fce8ddad552205.camel@linux.ibm.com> <202210191134.FC646AFC71@keescook> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <202210191134.FC646AFC71@keescook> User-Agent: Mutt/1.4i X-Greylist: Sender passed SPF test, not delayed by milter-greylist-4.2.3 (wind.enjellic.com [127.0.0.1]); Fri, 21 Oct 2022 09:53:50 -0500 (CDT) X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,SPF_HELO_PASS, SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Wed, Oct 19, 2022 at 11:59:40AM -0700, Kees Cook wrote: Good morning, I hope the week is ending well for everyone. > On Wed, Oct 19, 2022 at 10:34:48AM -0400, Mimi Zohar wrote: > > > > The only thing trivial about making IMA and EVM LSMs is moving > > them to LSM hooks. Although static files may be signed and the > > signatures distributed with the file data through the normal > > distribution mechanisms (e.g. RPM), other files cannot be signed > > remotely (e.g. configuration files). For these files, both IMA > > and EVM may be configured to maintain persistent file state stored > > as security xattrs in the form of security.ima file hashes or > > security.evm HMACs. The LSM flexibility of enabling/disabling IMA > > or EVM on a per boot basis breaks this usage, potentially > > preventing subsequent boots. > I'm not suggesting IMA and EVM don't have specific behaviors that > need to be correctly integrated into the LSM infrastructure. In > fact, I spent a lot of time designing that infrastructure to be > flexible enough to deal with these kinds of things. (e.g. plumbing > "enablement", etc.) As I mentioned, this was more of trying to > provide a head-start on the conversion. I don't intend to drive this > -- please take whatever is useful from this example and use it. :) > I'm happy to help construct any missing infrastructure needed > (e.g. LSM_ORDER_LAST, etc). We are 2-3 weeks out from submitting for review and inclusion in the kernel, a new LSM, and an associated userspace stack, that will have a high degree of significance with respect to these conversations. > Kees Cook Best wishes for a pleasant fall weekend. As always, Dr. Greg The Quixote Project - Flailing at the Travails of Cybersecurity