diff options
author | Stefan Berger <stefanb@us.ibm.com> | 2016-11-29 10:47:20 -0500 |
---|---|---|
committer | Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> | 2016-11-29 10:47:20 -0500 |
commit | e8e42b31c5a950a7b43d64f4a531ec59750e823e (patch) | |
tree | 13859dcc19a89f0c663b138fb8ccb83368dae99d /.mkosi/mkosi.fedora | |
parent | 664e7984f8a96c1962961fcc1ebe6bd4a0c58c5f (diff) |
ima: Write the policy filename into IMA's sysfs policy file (#4766)
IMA validates file signatures based on the security.ima xattr. As of
Linux-4.7, instead of copying the IMA policy into the securityfs policy,
the IMA policy pathname can be written, allowing the IMA policy file
signature to be validated.
This patch modifies the existing code to first attempt to write the
pathname, but on failure falls back to copying the IMA policy contents.
Diffstat (limited to '.mkosi/mkosi.fedora')
0 files changed, 0 insertions, 0 deletions