aboutsummaryrefslogtreecommitdiffstats
path: root/scripts/asn1_compiler.c
diff options
context:
space:
mode:
authorMimi Zohar <[email protected]>2015-06-12 00:48:33 +0000
committerMimi Zohar <[email protected]>2015-06-16 12:18:45 +0000
commit24fd03c87695a76f0517df42a37e51b1597d2c8a (patch)
treea08107bb7ad12b472a5b1b60cea8770211113c31 /scripts/asn1_compiler.c
parentima: extend "mask" policy matching support (diff)
downloadkernel-24fd03c87695a76f0517df42a37e51b1597d2c8a.tar.gz
kernel-24fd03c87695a76f0517df42a37e51b1597d2c8a.zip
ima: update builtin policies
This patch defines a builtin measurement policy "tcb", similar to the existing "ima_tcb", but with additional rules to also measure files based on the effective uid and to measure files opened with the "read" mode bit set (eg. read, read-write). Changing the builtin "ima_tcb" policy could potentially break existing users. Instead of defining a new separate boot command line option each time the builtin measurement policy is modified, this patch defines a single generic boot command line option "ima_policy=" to specify the builtin policy and deprecates the use of the builtin ima_tcb policy. [The "ima_policy=" boot command line option is based on Roberto Sassu's "ima: added new policy type exec" patch.] Signed-off-by: Mimi Zohar <[email protected]> Signed-off-by: Dr. Greg Wettstein <[email protected]> Cc: [email protected]
Diffstat (limited to 'scripts/asn1_compiler.c')
0 files changed, 0 insertions, 0 deletions