+259
−0
+7
−0
Loading
Merge Pull Request from: @zgzxx add IMA digest lists extension issue: https://gitee.com/openeuler/kernel/issues/I91FSN support to measure and appraise files with digest lists Test: The measurement and appraisement functions are verified successfully. Known issue:NA Default config change: if any recommended config change vs upstream default config, please list as git diff format: < CONFIG_INITRAMFS_FILE_METADATA="" < CONFIG_IMA_DIGEST_LIST=y < CONFIG_IMA_DIGEST_LISTS_DIR="/etc/ima/digest_lists" < CONFIG_IMA_STANDARD_DIGEST_DB_SIZE=y < # CONFIG_IMA_MAX_DIGEST_DB_SIZE is not set < # CONFIG_IMA_CUSTOM_DIGEST_DB_SIZE is not set < CONFIG_IMA_DIGEST_DB_MEGABYTES=16 < CONFIG_IMA_PARSER_BINARY_PATH="/usr/bin/upload_digest_lists" < CONFIG_EVM_DEFAULT_HASH_SHA1=n < CONFIG_EVM_DEFAULT_HASH_SHA256=y < CONFIG_EVM_DEFAULT_HASH_SHA512=n < CONFIG_PGP_LIBRARY=y < CONFIG_PGP_KEY_PARSER=y < CONFIG_PGP_PRELOAD=y < CONFIG_PGP_PRELOAD_PUBLIC_KEYS=y Reference:https://lwn.net/Articles/791220/ https://patchwork.kernel.org/project/linux-crypto/cover/20181112102423.30415-1-roberto.sassu@huawei.com/; Link:https://gitee.com/openeuler/kernel/pulls/3880 Reviewed-by:Zhang Jianhua <chris.zjh@huawei.com> Reviewed-by:
Weilong Chen <chenweilong@huawei.com> Reviewed-by:
Zhu Jianwei <zhujianwei7@huawei.com> Reviewed-by:
Zucheng Zheng <zhengzucheng@huawei.com> Signed-off-by:
Zheng Zengkai <zhengzengkai@huawei.com>