• Linus Torvalds's avatar
    Merge tag 'integrity-v6.8' of git://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity · 6c1dd1fe
    Linus Torvalds authored
    Pull integrity updates from Mimi Zohar:
    
     - Add a new IMA/EVM maintainer and reviewer
    
     - Disable EVM on overlayfs
    
       The EVM HMAC and the original file signatures contain filesystem
       specific metadata (e.g. i_ino, i_generation and s_uuid), preventing
       the security.evm xattr from directly being copied up to the overlay.
       Further before calculating and writing out the overlay file's EVM
       HMAC, EVM must first verify the existing backing file's
       'security.evm' value.
    
       For now until a solution is developed, disable EVM on overlayfs.
    
     - One bug fix and two cleanups
    
    * tag 'integrity-v6.8' of git://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity:
      overlay: disable EVM
      evm: add support to disable EVM on unsupported filesystems
      evm: don't copy up 'security.evm' xattr
      MAINTAINERS: Add Eric Snowberg as a reviewer to IMA
      MAINTAINERS: Add Roberto Sassu as co-maintainer to IMA and EVM
      KEYS: encrypted: Add check for strsep
      ima: Remove EXPERIMENTAL from Kconfig
      ima: Reword IMA_KEYRINGS_PERMIT_SIGNED_BY_BUILTIN_OR_SECONDARY
    6c1dd1fe
MAINTAINERS 715 KB