Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1696369

Re: [RFC PATCH 1/5] ima: extend clone() with IMA namespace support

From James Bottomley <James.Bottomley@HansenPartnership.com>
Newsgroups linux.kernel
Subject Re: [RFC PATCH 1/5] ima: extend clone() with IMA namespace support
Date 2017-07-25 22:40 +0200
Message-ID <u7eMA-7zW-65@gated-at.bofh.it> (permalink)
References (2 earlier) <u7chI-5RB-15@gated-at.bofh.it> <u7d46-6px-7@gated-at.bofh.it> <u7dnr-6Lb-1@gated-at.bofh.it> <u7dns-6Lb-3@gated-at.bofh.it> <u7e0c-701-69@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Tue, 2017-07-25 at 15:48 -0400, Mimi Zohar wrote:
> On Tue, 2017-07-25 at 12:08 -0700, James Bottomley wrote:
> > 
> > On Tue, 2017-07-25 at 14:04 -0500, Serge E. Hallyn wrote:
> > > 
> > > On Tue, Jul 25, 2017 at 11:49:14AM -0700, James Bottomley wrote:
> > > > 
> > > > 
> > > > On Tue, 2017-07-25 at 12:53 -0500, Serge E. Hallyn wrote:
[...]
> > > > the latter, it does seem that this should be a property of
> > > > either the mount or user ns rather than its own separate ns.  I
> > > > could see a use where even a container might want multiple ima
> > > > keyrings within the container (say containerised apache service
> > > > with multiple tenants), so instinct tells me that mount ns is
> > > > the correct granularity for this.
> > > 
> > > I wonder whether we could use echo 1 >
> > > /sys/kernel/security/ima/newns
> > > as the trigger for requesting a new ima ns on the next
> > > clone(CLONE_NEWNS).
> > 
> > I could go with that, but what about the trigger being installing
> > or updating the keyring?  That's the only operation that needs
> > namespace separation, so on mount ns clone, you get a pointer to
> > the old ima_ns until you do something that requires a new key,
> > which then triggers the copy of the namespace and installing it?
> 
> It isn't just the keyrings that need to be namespaced, but the
> measurement list and policy as well.

OK, so trigger to do a just in time copy would be new key or new
policy.  The measurement list is basically just a has of a file taken
at a policy point.  Presumably it doesn't change if we install a new
policy or key, so it sounds like it should be tied to the underlying
mount point?  I'm thinking if we set up a hundred mount ns each
pointing to /var/container, we don't want /var/container/bin/something
to have 100 separate measurements each with the same hash.

> IMA-measurement, IMA-appraisal and IMA-audit are all policy based.
> 
> As soon as the namespace starts, measurements should be added to the
> namespace specific measurement list, not it's parent.

Would the measurement in a child namespace yield a different
measurement in the parent?  I'm thinking not, because a measurement is
just a hash.  Now if the signature of the hash in the xattr needs a
different key, obviously this differs, but the expensive part
(computing the hash) shouldn't change.

James


> Mimi
> 
> _______________________________________________
> Containers mailing list
> Containers@lists.linux-foundation.org
> https://lists.linuxfoundation.org/mailman/listinfo/containers

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[RFC PATCH 1/5] ima: extend clone() with IMA namespace support Mehmet Kayaalp <mkayaalp@linux.vnet.ibm.com> - 2017-07-21 01:00 +0200
  Re: [RFC PATCH 1/5] ima: extend clone() with IMA namespace support "Serge E. Hallyn" <serge@hallyn.com> - 2017-07-25 20:00 +0200
    Re: [RFC PATCH 1/5] ima: extend clone() with IMA namespace support James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-07-25 20:50 +0200
      Re: [RFC PATCH 1/5] ima: extend clone() with IMA namespace support "Serge E. Hallyn" <serge@hallyn.com> - 2017-07-25 21:10 +0200
        Re: [RFC PATCH 1/5] ima: extend clone() with IMA namespace support James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-07-25 21:10 +0200
          Re: [RFC PATCH 1/5] ima: extend clone() with IMA namespace support Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-07-25 21:50 +0200
            Re: [RFC PATCH 1/5] ima: extend clone() with IMA namespace support Stefan Berger <stefanb@linux.vnet.ibm.com> - 2017-07-25 22:20 +0200
              Re: [RFC PATCH 1/5] ima: extend clone() with IMA namespace support "Serge E. Hallyn" <serge@hallyn.com> - 2017-07-25 22:50 +0200
                Re: [RFC PATCH 1/5] ima: extend clone() with IMA namespace support Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-07-25 23:00 +0200
                Re: [RFC PATCH 1/5] ima: extend clone() with IMA namespace support "Serge E. Hallyn" <serge@hallyn.com> - 2017-07-25 23:10 +0200
                Re: [RFC PATCH 1/5] ima: extend clone() with IMA namespace support Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-07-26 00:30 +0200
                Re: [Linux-ima-devel] [RFC PATCH 1/5] ima: extend clone() with IMA  namespace support Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-07-27 16:50 +0200
                Re: [Linux-ima-devel] [RFC PATCH 1/5] ima: extend clone() with IMA  namespace support Stefan Berger <stefanb@linux.vnet.ibm.com> - 2017-07-27 19:50 +0200
                Re: [Linux-ima-devel] [RFC PATCH 1/5] ima: extend clone() with IMA  namespace support Stefan Berger <stefanb@linux.vnet.ibm.com> - 2017-07-27 23:00 +0200
                Re: [Linux-ima-devel] [RFC PATCH 1/5] ima: extend clone() with IMA  namespace support Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-07-31 13:40 +0200
                Re: [RFC PATCH 1/5] ima: extend clone() with IMA namespace support Stefan Berger <stefanb@linux.vnet.ibm.com> - 2017-07-25 23:40 +0200
            Re: [RFC PATCH 1/5] ima: extend clone() with IMA namespace support James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-07-25 22:40 +0200
              Re: [RFC PATCH 1/5] ima: extend clone() with IMA namespace support Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-07-25 22:50 +0200

csiph-web