Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
ima: Fix return value of ima_write_policy()
This patch fixes the return value of ima_write_policy() when a new policy is directly passed to IMA and the current policy requires appraisal of the file containing the policy. Currently, if appraisal is not in ENFORCE mode, ima_write_policy() returns 0 and leads user space applications to an endless loop. Fix this issue by denying the operation regardless of the appraisal mode. Cc: [email protected] # 4.10.x Fixes: 19f8a84 ("ima: measure and appraise the IMA policy itself") Signed-off-by: Roberto Sassu <[email protected]> Reviewed-by: Krzysztof Struczynski <[email protected]> Signed-off-by: Mimi Zohar <[email protected]>
- Loading branch information