brintos

brintos / linux-shallow public Read only

0
0
Text · 6.3 KiB · c238518 Raw
191 lines · plain
1What:		/sys/kernel/security/*/ima/policy2Date:		May 20083Contact:	Mimi Zohar <zohar@us.ibm.com>4Description:5		The Trusted Computing Group(TCG) runtime Integrity6		Measurement Architecture(IMA) maintains a list of hash7		values of executables and other sensitive system files8		loaded into the run-time of this system.  At runtime,9		the policy can be constrained based on LSM specific data.10		Policies are loaded into the securityfs file ima/policy11		by opening the file, writing the rules one at a time and12		then closing the file.  The new policy takes effect after13		the file ima/policy is closed.14 15		IMA appraisal, if configured, uses these file measurements16		for local measurement appraisal.17 18		::19 20		  rule format: action [condition ...]21 22		  action: measure | dont_measure | appraise | dont_appraise |23			  audit | hash | dont_hash24		  condition:= base | lsm  [option]25			base:	[[func=] [mask=] [fsmagic=] [fsuuid=] [fsname=]26				[uid=] [euid=] [gid=] [egid=]27				[fowner=] [fgroup=]]28			lsm:	[[subj_user=] [subj_role=] [subj_type=]29				 [obj_user=] [obj_role=] [obj_type=]]30			option:	[digest_type=] [template=] [permit_directio]31				[appraise_type=] [appraise_flag=]32				[appraise_algos=] [keyrings=]33		  base:34			func:= [BPRM_CHECK][MMAP_CHECK][CREDS_CHECK][FILE_CHECK][MODULE_CHECK]35				[FIRMWARE_CHECK]36				[KEXEC_KERNEL_CHECK] [KEXEC_INITRAMFS_CHECK]37				[KEXEC_CMDLINE] [KEY_CHECK] [CRITICAL_DATA]38				[SETXATTR_CHECK][MMAP_CHECK_REQPROT]39			mask:= [[^]MAY_READ] [[^]MAY_WRITE] [[^]MAY_APPEND]40			       [[^]MAY_EXEC]41			fsmagic:= hex value42			fsuuid:= file system UUID (e.g 8bcbe394-4f13-4144-be8e-5aa9ea2ce2f6)43			uid:= decimal value44			euid:= decimal value45			gid:= decimal value46			egid:= decimal value47			fowner:= decimal value48			fgroup:= decimal value49		  lsm:  are LSM specific50		  option:51			appraise_type:= [imasig] | [imasig|modsig] | [sigv3]52			    where 'imasig' is the original or the signature53				format v2.54			    where 'modsig' is an appended signature,55			    where 'sigv3' is the signature format v3. (Currently56				limited to fsverity digest based signatures57				stored in security.ima xattr. Requires58				specifying "digest_type=verity" first.)59 60			appraise_flag:= [check_blacklist] (deprecated)61			Setting the check_blacklist flag is no longer necessary.62			All appraisal functions set it by default.63			digest_type:= verity64			    Require fs-verity's file digest instead of the65			    regular IMA file hash.66			keyrings:= list of keyrings67			(eg, .builtin_trusted_keys|.ima). Only valid68			when action is "measure" and func is KEY_CHECK.69			template:= name of a defined IMA template type70			(eg, ima-ng). Only valid when action is "measure".71			pcr:= decimal value72			label:= [selinux]|[kernel_info]|[data_label]73			data_label:= a unique string used for grouping and limiting critical data.74			For example, "selinux" to measure critical data for SELinux.75			appraise_algos:= comma-separated list of hash algorithms76			For example, "sha256,sha512" to only accept to appraise77			files where the security.ima xattr was hashed with one78			of these two algorithms.79 80		  default policy:81			# PROC_SUPER_MAGIC82			dont_measure fsmagic=0x9fa083			dont_appraise fsmagic=0x9fa084			# SYSFS_MAGIC85			dont_measure fsmagic=0x6265657286			dont_appraise fsmagic=0x6265657287			# DEBUGFS_MAGIC88			dont_measure fsmagic=0x6462672089			dont_appraise fsmagic=0x6462672090			# TMPFS_MAGIC91			dont_measure fsmagic=0x0102199492			dont_appraise fsmagic=0x0102199493			# RAMFS_MAGIC94			dont_appraise fsmagic=0x858458f695			# DEVPTS_SUPER_MAGIC96			dont_measure fsmagic=0x1cd197			dont_appraise fsmagic=0x1cd198			# BINFMTFS_MAGIC99			dont_measure fsmagic=0x42494e4d100			dont_appraise fsmagic=0x42494e4d101			# SECURITYFS_MAGIC102			dont_measure fsmagic=0x73636673103			dont_appraise fsmagic=0x73636673104			# SELINUX_MAGIC105			dont_measure fsmagic=0xf97cff8c106			dont_appraise fsmagic=0xf97cff8c107			# CGROUP_SUPER_MAGIC108			dont_measure fsmagic=0x27e0eb109			dont_appraise fsmagic=0x27e0eb110			# NSFS_MAGIC111			dont_measure fsmagic=0x6e736673112			dont_appraise fsmagic=0x6e736673113 114			measure func=BPRM_CHECK115			measure func=FILE_MMAP mask=MAY_EXEC116			measure func=FILE_CHECK mask=MAY_READ uid=0117			measure func=MODULE_CHECK118			measure func=FIRMWARE_CHECK119			appraise fowner=0120 121		The default policy measures all executables in bprm_check,122		all files mmapped executable in file_mmap, and all files123		open for read by root in do_filp_open.  The default appraisal124		policy appraises all files owned by root.125 126		Examples of LSM specific definitions:127 128		SELinux::129 130			dont_measure obj_type=var_log_t131			dont_appraise obj_type=var_log_t132			dont_measure obj_type=auditd_log_t133			dont_appraise obj_type=auditd_log_t134			measure subj_user=system_u func=FILE_CHECK mask=MAY_READ135			measure subj_role=system_r func=FILE_CHECK mask=MAY_READ136 137		Smack::138 139			measure subj_user=_ func=FILE_CHECK mask=MAY_READ140 141		Example of measure rules using alternate PCRs::142 143			measure func=KEXEC_KERNEL_CHECK pcr=4144			measure func=KEXEC_INITRAMFS_CHECK pcr=5145 146		Example of appraise rule allowing modsig appended signatures:147 148			appraise func=KEXEC_KERNEL_CHECK appraise_type=imasig|modsig149 150		Example of measure rule using KEY_CHECK to measure all keys:151 152			measure func=KEY_CHECK153 154		Example of measure rule using KEY_CHECK to only measure155		keys added to .builtin_trusted_keys or .ima keyring:156 157			measure func=KEY_CHECK keyrings=.builtin_trusted_keys|.ima158 159		Example of the special SETXATTR_CHECK appraise rule, that160		restricts the hash algorithms allowed when writing to the161		security.ima xattr of a file:162 163			appraise func=SETXATTR_CHECK appraise_algos=sha256,sha384,sha512164 165		Example of a 'measure' rule requiring fs-verity's digests166		with indication of type of digest in the measurement list.167 168			measure func=FILE_CHECK digest_type=verity \169				template=ima-ngv2170 171		Example of 'measure' and 'appraise' rules requiring fs-verity172		signatures (format version 3) stored in security.ima xattr.173 174		The 'measure' rule specifies the 'ima-sigv3' template option,175		which includes the indication of type of digest and the file176		signature in the measurement list.177 178			measure func=BPRM_CHECK digest_type=verity \179				template=ima-sigv3180 181 182		The 'appraise' rule specifies the type and signature format183		version (sigv3) required.184 185			appraise func=BPRM_CHECK digest_type=verity \186				appraise_type=sigv3187 188		All of these policy rules could, for example, be constrained189		either based on a filesystem's UUID (fsuuid) or based on LSM190		labels.191