From: Bruno Meneguele <bmeneg@redhat.com>
To: linux-integrity@vger.kernel.org, linux-kernel@vger.kernel.org
Cc: zohar@linux.ibm.com, Bruno Meneguele <bmeneg@redhat.com>
Subject: [PATCH v2 0/4] integrity: improve user feedback for invalid bootparams
Date: Fri, 4 Sep 2020 16:40:56 -0300 [thread overview]
Message-ID: <20200904194100.761848-1-bmeneg@redhat.com> (raw)
Some boot paramenters under integrity/ don't report any feedback to the user
in case an invalid/unknown option is passed. With this patch, try to be more
informative about what went wrong, including a more strict secure boot
feedback.
Bruno Meneguele (4):
ima: add check for enforced appraise option
integrity: invalid kernel parameters feedback
ima: limit secure boot feedback scope for appraise
integrity: prompt keyring name for unknown key request
security/integrity/digsig_asymmetric.c | 10 ++++++++--
security/integrity/evm/evm_main.c | 3 +++
security/integrity/ima/ima_appraise.c | 27 ++++++++++++++++++--------
security/integrity/ima/ima_main.c | 13 +++++++++----
security/integrity/ima/ima_policy.c | 2 ++
5 files changed, 41 insertions(+), 14 deletions(-)
--
2.26.2
next reply other threads:[~2020-09-04 19:41 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-09-04 19:40 Bruno Meneguele [this message]
2020-09-04 19:40 ` [PATCH v2 1/4] ima: add check for enforced appraise option Bruno Meneguele
2020-09-04 19:40 ` [PATCH v2 2/4] integrity: invalid kernel parameters feedback Bruno Meneguele
2020-09-04 19:40 ` [PATCH v2 3/4] ima: limit secure boot feedback scope for appraise Bruno Meneguele
2020-09-04 21:07 ` Mimi Zohar
2020-09-05 1:17 ` Bruno Meneguele
2020-09-05 1:20 ` [PATCH v3 " Bruno Meneguele
2020-09-11 15:07 ` Mimi Zohar
2020-09-11 18:03 ` Bruno Meneguele
2020-09-04 19:41 ` [PATCH v2 4/4] integrity: prompt keyring name for unknown key request Bruno Meneguele
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20200904194100.761848-1-bmeneg@redhat.com \
--to=bmeneg@redhat.com \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=zohar@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.