Re: [PATCH v3 5/6] ima: Defer fixing security.ima to __fput()

2025-01-31 Thread Mimi Zohar
On Wed, 2025-01-22 at 18:24 +0100, Roberto Sassu wrote: > From: Roberto Sassu > > IMA-Appraisal implements a fix mode, selectable from the kernel command > line by specifying ima_appraise=fix. > > The fix mode is meant to be used in a TOFU (trust on first use) model, > where systems are supposed

[PATCH v3 5/6] ima: Defer fixing security.ima to __fput()

2025-01-22 Thread Roberto Sassu
From: Roberto Sassu IMA-Appraisal implements a fix mode, selectable from the kernel command line by specifying ima_appraise=fix. The fix mode is meant to be used in a TOFU (trust on first use) model, where systems are supposed to work under controlled conditions before the real enforcement start