mbox series

[RFC,0/2] ima: Fix detection of read/write violations on stacked filesystems

Message ID 20240412140122.2607743-1-stefanb@linux.ibm.com (mailing list archive)
Headers show
Series ima: Fix detection of read/write violations on stacked filesystems | expand

Message

Stefan Berger April 12, 2024, 2:01 p.m. UTC
This series fixes the detection of read/write violations on stacked
filesystems. To be able to access the relevant dentries necessary to
detect files opened for writing on a stacked filesystem a new d_real_type
D_REAL_FILEDATA is introduced that allows callers to access all relevant
files involved in a stacked filesystem.

  Stefan

Stefan Berger (2):
  ovl: Define D_REAL_FILEDATA for d_real to return dentry with data
  ima: Fix detection of read/write violations on stacked filesystems

 fs/overlayfs/super.c              |  6 ++++++
 include/linux/dcache.h            |  1 +
 security/integrity/ima/ima_main.c | 27 ++++++++++++++++++++++-----
 3 files changed, 29 insertions(+), 5 deletions(-)