diff options
author | Mimi Zohar <zohar@linux.vnet.ibm.com> | 2015-04-21 22:54:24 +0200 |
---|---|---|
committer | Mimi Zohar <zohar@linux.vnet.ibm.com> | 2015-05-21 19:28:41 +0200 |
commit | cd025f7f94108995383edddfb61fc8afea6c66a9 (patch) | |
tree | 628c70ef33b853ffab7de16d855de5adf1be9d8c /Documentation | |
parent | ima: skip measurement of cgroupfs files and update documentation (diff) | |
download | linux-cd025f7f94108995383edddfb61fc8afea6c66a9.tar.xz linux-cd025f7f94108995383edddfb61fc8afea6c66a9.zip |
ima: do not measure or appraise the NSFS filesystem
Include don't appraise or measure rules for the NSFS filesystem
in the builtin ima_tcb and ima_appraise_tcb policies.
Changelog:
- Update documentation
Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Cc: stable@vger.kernel.org # 3.19
Diffstat (limited to 'Documentation')
-rw-r--r-- | Documentation/ABI/testing/ima_policy | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/Documentation/ABI/testing/ima_policy b/Documentation/ABI/testing/ima_policy index 232e174aa5de..8ae3f57090d4 100644 --- a/Documentation/ABI/testing/ima_policy +++ b/Documentation/ABI/testing/ima_policy @@ -65,6 +65,9 @@ Description: # CGROUP_SUPER_MAGIC dont_measure fsmagic=0x27e0eb dont_appraise fsmagic=0x27e0eb + # NSFS_MAGIC + dont_measure fsmagic=0x6e736673 + dont_appraise fsmagic=0x6e736673 measure func=BPRM_CHECK measure func=FILE_MMAP mask=MAY_EXEC |