summaryrefslogtreecommitdiffstats
path: root/scripts
diff options
context:
space:
mode:
authorKP Singh <kpsingh@google.com>2020-11-24 16:12:09 +0100
committerDaniel Borkmann <daniel@iogearbox.net>2020-11-26 00:04:04 +0100
commit27672f0d280a3f286a410a8db2004f46ace72a17 (patch)
tree04cce21fa652d2576937ea9e0b8c6378c7d96062 /scripts
parentima: Implement ima_inode_hash (diff)
downloadlinux-27672f0d280a3f286a410a8db2004f46ace72a17.tar.xz
linux-27672f0d280a3f286a410a8db2004f46ace72a17.zip
bpf: Add a BPF helper for getting the IMA hash of an inode
Provide a wrapper function to get the IMA hash of an inode. This helper is useful in fingerprinting files (e.g executables on execution) and using these fingerprints in detections like an executable unlinking itself. Since the ima_inode_hash can sleep, it's only allowed for sleepable LSM hooks. Signed-off-by: KP Singh <kpsingh@google.com> Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> Acked-by: Yonghong Song <yhs@fb.com> Link: https://lore.kernel.org/bpf/20201124151210.1081188-3-kpsingh@chromium.org
Diffstat (limited to 'scripts')
-rwxr-xr-xscripts/bpf_helpers_doc.py2
1 files changed, 2 insertions, 0 deletions
diff --git a/scripts/bpf_helpers_doc.py b/scripts/bpf_helpers_doc.py
index c5bc947a70ad..8b829748d488 100755
--- a/scripts/bpf_helpers_doc.py
+++ b/scripts/bpf_helpers_doc.py
@@ -436,6 +436,7 @@ class PrinterHelpers(Printer):
'struct xdp_md',
'struct path',
'struct btf_ptr',
+ 'struct inode',
]
known_types = {
'...',
@@ -480,6 +481,7 @@ class PrinterHelpers(Printer):
'struct task_struct',
'struct path',
'struct btf_ptr',
+ 'struct inode',
}
mapped_types = {
'u8': '__u8',