From: Tushar Sugandhi <tusharsu@linux.microsoft.com>
To: dm-devel@redhat.com, agk@redhat.com, snitzer@redhat.com
Cc: sfr@canb.auug.org.au, zohar@linux.ibm.com,
nramas@linux.microsoft.com, public@thson.de,
tusharsu@linux.microsoft.com, linux-integrity@vger.kernel.org
Subject: [dm-devel] [PATCH 0/6] updates to device mapper target measurement using ima
Date: Fri, 13 Aug 2021 14:37:55 -0700 [thread overview]
Message-ID: <20210813213801.297051-1-tusharsu@linux.microsoft.com> (raw)
There were several improvements suggested for the original device mapper
target measurement patch series [1].
Those improvement suggestions include:
- Prefixing hashes for the DM tables being measured in ima log with the
hash algorithm.
- Adding version information for DM related events being measured in the
ima log.
- Prefixing DM related event names with "dm_".
- Including the verity target attribute - "root_hash_sig_key_desc"
in the ima measurement log.
This series incorporates the above suggestions.
This series also has the following fixes:
- Adding a one-time warning to dmesg during dm_init if
CONFIG_IMA_DISABLE_HTABLE is set to 'n'.
- Updating 'integrity' target to remove the duplicate measurement of
the attribute "mode=%c".
- Indexing various attributes in 'multipath' target, and adding
"nr_priority_groups=%u" attribute to the measurements.
- Fixing 'make htmldocs' warnings in dm-ima.rst.
- Adding missing documentation for the targets - 'cache', 'integrity',
'multipath', and 'snapshot' in dm-ima.rst.
- Updating dm-ima.rst documentation with the grammar for various DM
events and targets in Backus Naur form.
- Updating dm-ima.rst documentation to be consistent with the code
changes described above.
This series is based on top of the following git repo/branch/commit:
Repo: https://git.kernel.org/pub/scm/linux/kernel/git/device-mapper/linux-dm.git
Branch: dm-5.15
Commit: commit 5a2a33884f0b ("dm crypt: Avoid percpu_counter spinlock contention in crypt_page_alloc()")
[1] https://patchwork.kernel.org/project/dm-devel/cover/20210713004904.8808-1-tusharsu@linux.microsoft.com/
Tushar Sugandhi (6):
dm ima: prefix dm table hashes in ima log with hash algorithm
dm ima: add version info to dm related events in ima log
dm ima: prefix ima event name related to device mapper with dm_
dm ima: add a warning in dm_init if duplicate ima events are not
measured
dm ima: update dm target attributes for ima measurements
dm ima: update dm documentation for ima measurement support
.../admin-guide/device-mapper/dm-ima.rst | 827 +++++++++++++-----
drivers/md/dm-ima.c | 94 +-
drivers/md/dm-ima.h | 10 +
drivers/md/dm-integrity.c | 1 -
drivers/md/dm-mpath.c | 26 +-
drivers/md/dm-verity-target.c | 2 +
drivers/md/dm.c | 6 +
7 files changed, 724 insertions(+), 242 deletions(-)
--
2.32.0
--
dm-devel mailing list
dm-devel@redhat.com
https://listman.redhat.com/mailman/listinfo/dm-devel
next reply other threads:[~2021-08-13 21:38 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-08-13 21:37 Tushar Sugandhi [this message]
2021-08-13 21:37 ` [dm-devel] [PATCH 1/6] dm ima: prefix dm table hashes in ima log with hash algorithm Tushar Sugandhi
2021-08-13 21:37 ` [dm-devel] [PATCH 2/6] dm ima: add version info to dm related events in ima log Tushar Sugandhi
2021-08-13 21:37 ` [dm-devel] [PATCH 3/6] dm ima: prefix ima event name related to device mapper with dm_ Tushar Sugandhi
2021-08-13 21:37 ` [dm-devel] [PATCH 4/6] dm ima: add a warning in dm_init if duplicate ima events are not measured Tushar Sugandhi
2021-08-13 21:38 ` [dm-devel] [PATCH 5/6] dm ima: update dm target attributes for ima measurements Tushar Sugandhi
2021-08-13 21:38 ` [dm-devel] [PATCH 6/6] dm ima: update dm documentation for ima measurement support Tushar Sugandhi
2021-08-20 20:19 ` [dm-devel] [PATCH 0/6] updates to device mapper target measurement using ima Mike Snitzer
2021-08-23 17:18 ` Tushar Sugandhi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20210813213801.297051-1-tusharsu@linux.microsoft.com \
--to=tusharsu@linux.microsoft.com \
--cc=agk@redhat.com \
--cc=dm-devel@redhat.com \
--cc=linux-integrity@vger.kernel.org \
--cc=nramas@linux.microsoft.com \
--cc=public@thson.de \
--cc=sfr@canb.auug.org.au \
--cc=snitzer@redhat.com \
--cc=zohar@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).