Received: by 10.223.164.202 with SMTP id h10csp2622869wrb; Sun, 12 Nov 2017 14:06:17 -0800 (PST) X-Google-Smtp-Source: AGs4zMZc5hWgZSGW9RyKeuwPiUlXYKuAZqgoX5iSMkSRRJxoesknAXWWQ26mCSVTSJS8sZIBoUZu X-Received: by 10.84.176.163 with SMTP id v32mr7109090plb.175.1510524377499; Sun, 12 Nov 2017 14:06:17 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1510524377; cv=none; d=google.com; s=arc-20160816; b=pWhJO0QeNGgYCyL4RZHu9B1/4czG1hWy/QdT745Mtr8Q2SHQ2L0Dmkm3q4S5AK6UeV osMJoUGJ/xe8f1/+P2zHb3j9Jt6SQ7Vk0iHQQZpdY/r/DHVHTackESA0VzugXWIK8YrS xdNhWJCeVrY8CdNeQy6fzXWJusUDZJ3LPOvCf4zGplaCnWHoyDZn6aPd+/c5mk7ChcYr lfYcjV50KL5noIgnFeeU46zMR+YZ9OTffbzJjJgkCNbp1HPeW7ftjtVt4WB0lgz+Nh4Q G4B/+bKQ9AjFb0AqJZlbAcwFk6BKDqE5eBTkhdae+SKetuXPpwUVqFouSPhflVE8NlnJ yg1w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:user-agent:message-id :subject:cc:to:from:date:arc-authentication-results; bh=M3adMgoGqv0zfS/zPkV0AkLzKpEco37SYWB7iEJIsM0=; b=CLScq5SHAVa9hJkQjjnnqR21CJ9mlgggxjqGk6gpqSZ2Uva6DSXKwJJhxOIRtsdJ0B Hd3CGF1f2v8ISHix7y3/pFM4qQ+w7gCRdE/RyYOK2BdSHgQT2netFXM0SFGJiyqQA5Ty vv4zU2X7VOl4Aq7K3huYiVe18i5KgCMg2hSydJK/HRFoNWVAfemLb0wiU+c5MMMu3I3+ H4IDVlRTqiyGoLIXIrOTpJ2ZmFuDn6TZryLUxt7aaRnsMPeh5Ep8IfrKUhL1KqlrZUL1 y0xrLaG8qQC1Kom6G5/UCNUiD1QyHpedUivEj8/3t1OUhJbfjuAMKy3MxIEgK682fnpv lFTQ== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=oracle.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id h82si6544730pfa.196.2017.11.12.14.06.03; Sun, 12 Nov 2017 14:06:17 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=oracle.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751113AbdKLWFX (ORCPT + 87 others); Sun, 12 Nov 2017 17:05:23 -0500 Received: from userp1040.oracle.com ([156.151.31.81]:32819 "EHLO userp1040.oracle.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1750761AbdKLWFV (ORCPT ); Sun, 12 Nov 2017 17:05:21 -0500 Received: from aserv0021.oracle.com (aserv0021.oracle.com [141.146.126.233]) by userp1040.oracle.com (Sentrion-MTA-4.3.2/Sentrion-MTA-4.3.2) with ESMTP id vACM5I4K020496 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Sun, 12 Nov 2017 22:05:19 GMT Received: from aserv0122.oracle.com (aserv0122.oracle.com [141.146.126.236]) by aserv0021.oracle.com (8.14.4/8.14.4) with ESMTP id vACM5IjK029912 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Sun, 12 Nov 2017 22:05:18 GMT Received: from abhmp0007.oracle.com (abhmp0007.oracle.com [141.146.116.13]) by aserv0122.oracle.com (8.14.4/8.14.4) with ESMTP id vACM5I1N029379; Sun, 12 Nov 2017 22:05:18 GMT Received: from t440 (/58.166.67.31) by default (Oracle Beehive Gateway v4.0) with ESMTP ; Sun, 12 Nov 2017 14:05:17 -0800 Date: Mon, 13 Nov 2017 09:05:13 +1100 (AEDT) From: James Morris X-X-Sender: james.l.morris@localhost To: Linus Torvalds cc: linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, linux-integrity Subject: [GIT PULL] Security subsystem: integrity updates for v4.15 Message-ID: User-Agent: Alpine 2.20 (LFD 67 2015-01-07) MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII X-Source-IP: aserv0021.oracle.com [141.146.126.233] Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hi Linus, Please pull these fixes for the Integrity subsystem. (From Mimi) "There is a mixture of bug fixes, code cleanup, preparatory code for new functionality and new functionality. Commit 26ddabfe96bb "evm: enable EVM when X509 certificate is loaded" enabled EVM without loading a symmetric key, but was limited to defining the x509 certificate pathname at build. Included in this set of patches is the ability of enabling EVM, without loading the EVM symmetric key, from userspace. New is the ability to prevent the loading of an EVM symmetric key." --- The following changes since commit 34d8751fd4ffa34e85ee7e85d34168b3f3f62b42: MAINTAINERS: update the IMA, EVM, trusted-keys, encrypted-keys entries (2017-11-06 02:21:44 +1100) are available in the git repository at: git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security.git next-integrity for you to fetch changes up to e5729f86a2987c9404f9b2fb494b9a6fc4412baf: ima: Remove redundant conditional operator (2017-11-08 15:16:36 -0500) ---------------------------------------------------------------- Boshi Wang (1): ima: fix hash algorithm initialization Bruno E. O. Meneguele (2): module: export module signature enforcement status ima: check signature enforcement against cmdline param instead of CONFIG Christoph Hellwig (1): integrity: use kernel_read_file_from_path() to read x509 certs Matthew Garrett (3): EVM: Include security.apparmor in EVM measurements EVM: Allow userspace to signal an RSA key has been loaded EVM: Only complain about a missing HMAC key once Mimi Zohar (4): vfs: fix mounting a filesystem with i_version ima: don't remove the securityfs policy file ima: always measure and audit files in policy ima: call ima_file_free() prior to calling fasync Thiago Jung Bauermann (1): ima: Remove redundant conditional operator Thomas Meyer (1): ima: Fix bool initialization/comparison Documentation/ABI/testing/evm | 47 ++++++++++++++++-------- fs/file_table.c | 2 +- fs/namespace.c | 3 +- include/linux/fs.h | 1 + include/linux/module.h | 7 ++++ include/uapi/linux/xattr.h | 3 ++ kernel/module.c | 10 ++++++ security/integrity/digsig.c | 14 +++++--- security/integrity/evm/evm.h | 3 ++ security/integrity/evm/evm_crypto.c | 2 +- security/integrity/evm/evm_main.c | 3 ++ security/integrity/evm/evm_secfs.c | 29 ++++++++------- security/integrity/iint.c | 49 ------------------------- security/integrity/ima/ima_api.c | 67 ++++++++++++++++++++++------------- security/integrity/ima/ima_appraise.c | 4 +-- security/integrity/ima/ima_crypto.c | 10 ++++++ security/integrity/ima/ima_fs.c | 6 ++-- security/integrity/ima/ima_main.c | 23 +++++++----- security/integrity/ima/ima_policy.c | 6 ++-- security/integrity/integrity.h | 2 -- 20 files changed, 165 insertions(+), 126 deletions(-) From 1584507425746874409@xxx Sun Nov 19 15:07:16 +0000 2017 X-GM-THRID: 1584506143564114719 X-Gmail-Labels: Inbox,Category Forums,HistoricalUnread