From patchwork Tue Apr 17 22:56:01 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Matthew Garrett X-Patchwork-Id: 10347025 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id E8D4060365 for ; Tue, 17 Apr 2018 22:56:18 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id E84292785D for ; Tue, 17 Apr 2018 22:56:18 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id DCE7727F8C; Tue, 17 Apr 2018 22:56:18 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-15.5 required=2.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,MAILING_LIST_MULTI,RCVD_IN_DNSWL_HI, USER_IN_DEF_DKIM_WL autolearn=ham version=3.3.1 Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 877762785D for ; Tue, 17 Apr 2018 22:56:18 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752085AbeDQW4S (ORCPT ); Tue, 17 Apr 2018 18:56:18 -0400 Received: from mail-yw0-f202.google.com ([209.85.161.202]:48064 "EHLO mail-yw0-f202.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751879AbeDQW4R (ORCPT ); Tue, 17 Apr 2018 18:56:17 -0400 Received: by mail-yw0-f202.google.com with SMTP id i204so13456005ywb.14 for ; Tue, 17 Apr 2018 15:56:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:date:in-reply-to:message-id:references:subject:from:to :cc; bh=OYEXhwuZMqsfY2LFEq/A1qPDHFYsOfx2gr8TKf49S6A=; b=bDdo8yGDpiLWotkazdK90Afh6JvUQLN22JTk+N7HUwfBZ9qe1fUsmqVgZHjsdcDHzI pyT4uhfKfn/pEDJn+8zU7m51yU5xtIwPBe0uo7vqC5VBk0Htm6dmuD3dKlrEa0mvgEWl pegVDc6BviUHR1G5Li9ysa7ePLIAcHBDZXVIkCOAGXasztRC1n/YD6HYsQjq9LKVoVpX qodIWvNZDAbqwkMmm2/Ae9nXKthL1xktQ/elFJoUdK3a14683r7MkacO4u/1HnGdcMUP JATZSEDp3X7zpGuyx1IcNlSuJsGMpMtVOBlEIhnJDMexGuvSs9qm1Y+da6fBvcUBXTim rqpA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:date:in-reply-to:message-id :references:subject:from:to:cc; bh=OYEXhwuZMqsfY2LFEq/A1qPDHFYsOfx2gr8TKf49S6A=; b=Y++6iD6xSx5MFnakAyVvvkoEi4sxyhf+BGQzTXP+TGTMXVtykZ6gv/jnAUcZySminw Ek5aZfS8uU6VESr5LVMbdU1E8zkJY9A7owYmLvmETXiXvPqF3xDOWGb3kbCYaDFuPR4P eICOSV8iEZzDhjGTU+0/DlAIzC63bNy602oX1Jmk8jE9SKj3tvG5I8eoresbwM8eenRM exDhj8ZtKTymlI4Gjq1/R+kPyD/9qU6O5oZm1Z6wghjrxMiJ+BYt/bWJW3ZE5MJEdssx odJ17Vh+BXgyWF2x7otfvg9KFEnCIzZoI4e1t4VShBJxiubvmyFEIJLRcnwpKLc/+MJ/ N1vA== X-Gm-Message-State: ALQs6tBkjZb+cQyYoiif7b/DVcVjzXpZjP3ZVnur1RI4AECIVOpVbM8Z mRgsEbLvgJJkpsycVcKh1j57iKJCpwmVFMgp+eUn/by8RC/hYbAAOMEE6AZQ5fCrXP7WoTzy3Qm ZayCh9F8UFPpXal8kzUm5SfQu5P/gYmZ9wOo= X-Google-Smtp-Source: AIpwx4/b2NJTKGdZymgcO1MjdLaTZQR5yYS9/pUC+qNp64OarzaDa0qMfxqCCLE2pLi1g7gVmC+PwV9Ghhj6LeXPzs1NSQ== MIME-Version: 1.0 X-Received: by 2002:a25:bf91:: with SMTP id l17-v6mr1332307ybk.32.1524005776598; Tue, 17 Apr 2018 15:56:16 -0700 (PDT) Date: Tue, 17 Apr 2018 15:56:01 -0700 In-Reply-To: <20180417225601.6965-1-mjg59@google.com> Message-Id: <20180417225601.6965-2-mjg59@google.com> References: <20180417225601.6965-1-mjg59@google.com> X-Mailer: git-send-email 2.17.0.484.g0c8726318c-goog Subject: [USER] [PATCH 2/2] Add security.apparmor to the set of extended attributes used by EVM From: Matthew Garrett To: linux-integrity@vger.kernel.org Cc: zohar@linux.vnet.ibm.com, Matthew Garrett Sender: linux-integrity-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-integrity@vger.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP The kernel is taking security.apparmor into account when validating EVM, so evmctl should be doing the same. Signed-off-by: Matthew Garrett --- src/evmctl.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/src/evmctl.c b/src/evmctl.c index 43d261f..e350f69 100644 --- a/src/evmctl.c +++ b/src/evmctl.c @@ -69,6 +69,7 @@ static char *evm_default_xattrs[] = { XATTR_NAME_SELINUX, XATTR_NAME_SMACK, + XATTR_NAME_APPARMOR, XATTR_NAME_IMA, XATTR_NAME_CAPS, NULL @@ -80,6 +81,7 @@ static char *evm_extra_smack_xattrs[] = { XATTR_NAME_SMACKEXEC, XATTR_NAME_SMACKTRANSMUTE, XATTR_NAME_SMACKMMAP, + XATTR_NAME_APPARMOR, XATTR_NAME_IMA, XATTR_NAME_CAPS, NULL