Skip to content
Commit 566be59a authored by Mimi Zohar's avatar Mimi Zohar
Browse files

evm: permit mode bits to be updated



Before permitting 'security.evm' to be updated, 'security.evm' must
exist and be valid.  In the case that there are no existing EVM protected
xattrs, it is safe for posix acls to update the mode bits.

To differentiate between no 'security.evm' xattr and no xattrs used to
calculate 'security.evm', this patch defines INTEGRITY_NOXATTR.

Signed-off-by: default avatarMimi Zohar <zohar@us.ibm.com>
parent bf6d0f5d
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment