From: Andy Lutomirski <luto@kernel.org>
To: Roberto Sassu <roberto.sassu@huawei.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>,
LSM List <linux-security-module@vger.kernel.org>,
linux-integrity <linux-integrity@vger.kernel.org>,
initramfs@vger.kernel.org, Linux API <linux-api@vger.kernel.org>,
Linux FS Devel <linux-fsdevel@vger.kernel.org>,
LKML <linux-kernel@vger.kernel.org>,
Mimi Zohar <zohar@linux.vnet.ibm.com>,
silviu.vlasceanu@huawei.com, dmitry.kasatkin@huawei.com,
takondra@cisco.com, kamensky@cisco.com,
"H. Peter Anvin" <hpa@zytor.com>, Arnd Bergmann <arnd@arndb.de>,
Rob Landley <rob@landley.net>,
james.w.mcmechan@gmail.com
Subject: Re: [PATCH v2 0/3] initramfs: add support for xattrs in the initial ram disk
Date: Sat, 11 May 2019 15:44:12 -0700 [thread overview]
Message-ID: <CALCETrXy7gqmmy37=nrMAisGadZ+qbjZjXtWFF8Crq86xNpsfA@mail.gmail.com> (raw)
In-Reply-To: <20190509112420.15671-1-roberto.sassu@huawei.com>
On Thu, May 9, 2019 at 4:27 AM Roberto Sassu <roberto.sassu@huawei.com> wrote:
>
> This patch set aims at solving the following use case: appraise files from
> the initial ram disk. To do that, IMA checks the signature/hash from the
> security.ima xattr. Unfortunately, this use case cannot be implemented
> currently, as the CPIO format does not support xattrs.
>
> This proposal consists in marshaling pathnames and xattrs in a file called
> .xattr-list. They are unmarshaled by the CPIO parser after all files have
> been extracted.
>
> The difference from v1 (https://lkml.org/lkml/2018/11/22/1182) is that all
> xattrs are stored in a single file and not per file (solves the file name
> limitation issue, as it is not necessary to add a suffix to files
> containing xattrs).
>
> The difference with another proposal
> (https://lore.kernel.org/patchwork/cover/888071/) is that xattrs can be
> included in an image without changing the image format, as opposed to
> defining a new one. As seen from the discussion, if a new format has to be
> defined, it should fix the issues of the existing format, which requires
> more time.
I read some of those emails. ISTM that adding TAR support should be
seriously considered. Sure, it's baroque, but it's very, very well
supported, and it does exactly what we need.
--Andy
next prev parent reply other threads:[~2019-05-11 22:44 UTC|newest]
Thread overview: 58+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-05-09 11:24 [PATCH v2 0/3] initramfs: add support for xattrs in the initial ram disk Roberto Sassu
2019-05-09 11:24 ` [PATCH v2 1/3] fs: add ksys_lsetxattr() wrapper Roberto Sassu
2019-05-10 21:28 ` Jann Horn
2019-05-09 11:24 ` [PATCH v2 2/3] initramfs: set extended attributes Roberto Sassu
2019-05-09 11:24 ` [PATCH v2 3/3] initramfs: introduce do_readxattrs() Roberto Sassu
2019-05-10 21:33 ` Jann Horn
2019-05-13 13:03 ` Roberto Sassu
2019-05-09 18:34 ` [PATCH v2 0/3] initramfs: add support for xattrs in the initial ram disk Rob Landley
2019-05-10 6:56 ` Roberto Sassu
2019-05-10 11:49 ` Mimi Zohar
2019-05-10 20:46 ` Rob Landley
2019-05-10 22:38 ` Mimi Zohar
2019-05-11 22:44 ` Andy Lutomirski [this message]
2019-05-12 4:04 ` Rob Landley
2019-05-12 4:12 ` Rob Landley
2019-05-12 9:17 ` Dominik Brodowski
2019-05-12 10:18 ` hpa
2019-05-12 15:31 ` Dominik Brodowski
2019-05-13 0:02 ` Mimi Zohar
2019-05-13 0:21 ` hpa
2019-05-13 0:23 ` hpa
2019-05-12 12:52 ` Mimi Zohar
2019-05-12 17:05 ` Rob Landley
2019-05-12 19:43 ` Arvind Sankar
2019-05-13 7:49 ` Roberto Sassu
2019-05-13 9:07 ` Rob Landley
2019-05-13 12:08 ` Mimi Zohar
2019-05-13 12:47 ` Roberto Sassu
2019-05-13 17:20 ` Arvind Sankar
2019-05-13 17:51 ` Arvind Sankar
2019-05-13 17:52 ` Arvind Sankar
2019-05-13 18:36 ` Mimi Zohar
2019-05-13 18:47 ` Arvind Sankar
2019-05-13 22:09 ` Mimi Zohar
2019-05-14 6:06 ` Rob Landley
2019-05-14 14:44 ` Arvind Sankar
2019-05-14 6:06 ` Rob Landley
2019-05-14 11:52 ` Roberto Sassu
2019-05-14 15:12 ` Rob Landley
2019-05-14 15:27 ` Arvind Sankar
2019-05-14 15:57 ` Arvind Sankar
2019-05-14 17:44 ` Roberto Sassu
2019-05-15 1:00 ` Arvind Sankar
2019-05-14 15:19 ` Andy Lutomirski
2019-05-14 16:33 ` Roberto Sassu
2019-05-14 16:58 ` Greg KH
2019-05-14 17:20 ` Roberto Sassu
2019-05-15 0:25 ` Arvind Sankar
2019-05-14 19:18 ` James Bottomley
2019-05-14 23:39 ` Rob Landley
2019-05-14 23:54 ` James Bottomley
2019-05-15 0:52 ` Arvind Sankar
2019-05-15 11:19 ` Roberto Sassu
2019-05-15 16:08 ` Arvind Sankar
2019-05-15 17:06 ` Roberto Sassu
2019-05-16 5:29 ` Arvind Sankar
2019-05-16 11:42 ` Roberto Sassu
2019-05-16 13:31 ` Mimi Zohar
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='CALCETrXy7gqmmy37=nrMAisGadZ+qbjZjXtWFF8Crq86xNpsfA@mail.gmail.com' \
--to=luto@kernel.org \
--cc=arnd@arndb.de \
--cc=dmitry.kasatkin@huawei.com \
--cc=hpa@zytor.com \
--cc=initramfs@vger.kernel.org \
--cc=james.w.mcmechan@gmail.com \
--cc=kamensky@cisco.com \
--cc=linux-api@vger.kernel.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=rob@landley.net \
--cc=roberto.sassu@huawei.com \
--cc=silviu.vlasceanu@huawei.com \
--cc=takondra@cisco.com \
--cc=viro@zeniv.linux.org.uk \
--cc=zohar@linux.vnet.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).