forked from torvalds/linux
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
powerpc/ima: Add support to initialize ima policy rules
PowerNV systems use a Linux-based bootloader, which rely on the IMA subsystem to enforce different secure boot modes. Since the verification policy may differ based on the secure boot mode of the system, the policies must be defined at runtime. This patch implements arch-specific support to define IMA policy rules based on the runtime secure boot mode of the system. This patch provides arch-specific IMA policies if PPC_SECURE_BOOT config is enabled. Signed-off-by: Nayna Jain <[email protected]> Signed-off-by: Mimi Zohar <[email protected]> Signed-off-by: Michael Ellerman <[email protected]> Link: https://lore.kernel.org/r/[email protected]
- Loading branch information
Showing
4 changed files
with
47 additions
and
2 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,43 @@ | ||
// SPDX-License-Identifier: GPL-2.0 | ||
/* | ||
* Copyright (C) 2019 IBM Corporation | ||
* Author: Nayna Jain | ||
*/ | ||
|
||
#include <linux/ima.h> | ||
#include <asm/secure_boot.h> | ||
|
||
bool arch_ima_get_secureboot(void) | ||
{ | ||
return is_ppc_secureboot_enabled(); | ||
} | ||
|
||
/* | ||
* The "secure_rules" are enabled only on "secureboot" enabled systems. | ||
* These rules verify the file signatures against known good values. | ||
* The "appraise_type=imasig|modsig" option allows the known good signature | ||
* to be stored as an xattr or as an appended signature. | ||
* | ||
* To avoid duplicate signature verification as much as possible, the IMA | ||
* policy rule for module appraisal is added only if CONFIG_MODULE_SIG_FORCE | ||
* is not enabled. | ||
*/ | ||
static const char *const secure_rules[] = { | ||
"appraise func=KEXEC_KERNEL_CHECK appraise_type=imasig|modsig", | ||
#ifndef CONFIG_MODULE_SIG_FORCE | ||
"appraise func=MODULE_CHECK appraise_type=imasig|modsig", | ||
#endif | ||
NULL | ||
}; | ||
|
||
/* | ||
* Returns the relevant IMA arch-specific policies based on the system secure | ||
* boot state. | ||
*/ | ||
const char *const *arch_get_ima_policy(void) | ||
{ | ||
if (is_ppc_secureboot_enabled()) | ||
return secure_rules; | ||
|
||
return NULL; | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters