[PATCH v7 6/8] IMA: extend critical data hook to limit the measurement based on a label

Tushar Sugandhi tusharsu at linux.microsoft.com
Fri Dec 11 01:29:47 UTC 2020



On 2020-12-10 3:19 p.m., Tyler Hicks wrote:
> On 2020-12-09 11:42:10, Tushar Sugandhi wrote:
>> The IMA hook ima_measure_critical_data() does not support a way to
>> specify the source of the critical data provider. Thus, the data
>> measurement cannot be constrained based on the data source label
>> in the IMA policy.
>>
>> Extend the IMA hook ima_measure_critical_data() to support passing
>> the data source label as an input parameter, so that the policy rule can
>> be used to limit the measurements based on the label.
>>
>> Signed-off-by: Tushar Sugandhi <tusharsu at linux.microsoft.com>
> 
> Reviewed-by: Tyler Hicks <tyhicks at linux.microsoft.com>
> 
> Tyler
> 
Thanks for the review.
~Tushar



More information about the Linux-security-module-archive mailing list