You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
IMA: measure.policy: limit dont_measure tmpfs policy to func=FILE_CHECK
add func=FILE_CHECK to dont_measure tmpfs
Similarly to tcb.policy limit dont_measure tmpfs policy to func=FILE_CHECK.
This allows to do extra measurements, e.g. kexec boot command line, see
kernel commit
7eef7c8bac9a ("ima: limit the builtin 'tcb' dont_measure tmpfs policy rule")
Also remove leading 0 from tmpfs magic (to match IMA docs and tcb.policy).
Link: https://lore.kernel.org/ltp/[email protected]/
Suggested-by: Mimi Zohar <[email protected]>
Reviewed-by: Mimi Zohar <[email protected]>
Signed-off-by: Petr Vorel <[email protected]>
0 commit comments