ima: don't measure/appraise files on efivarfs
authorMimi Zohar <zohar@linux.ibm.com>
Wed, 14 Nov 2018 22:24:13 +0000 (17:24 -0500)
committerMimi Zohar <zohar@linux.ibm.com>
Tue, 11 Dec 2018 12:19:46 +0000 (07:19 -0500)
commit060190fbe676268a04a80d5f4b426fc3db9c2401
tree1183ef3c2681e9ffb113a661f70b839c06d45ac6
parent399574c64eaf94e82b7cf056978d7e68748c0f1d
ima: don't measure/appraise files on efivarfs

Update the builtin IMA policies specified on the boot command line
(eg. ima_policy="tcb|appraise_tcb") to permit accessing efivar files.

Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
security/integrity/ima/ima_policy.c