aboutsummaryrefslogtreecommitdiff
path: root/tools/perf/scripts/python/export-to-postgresql.py
diff options
context:
space:
mode:
authorMimi Zohar <[email protected]>2018-02-21 11:33:37 -0500
committerMimi Zohar <[email protected]>2018-03-23 06:31:37 -0400
commit57b56ac6fecb05c3192586e4892572dd13d972de (patch)
tree125efeee62e9ec9a3fc99a761151569cdba7e26c /tools/perf/scripts/python/export-to-postgresql.py
parentd906c10d8a31654cb9167c9a2ebc7d3e43820bad (diff)
ima: fail file signature verification on non-init mounted filesystems
FUSE can be mounted by unprivileged users either today with fusermount installed with setuid, or soon with the upcoming patches to allow FUSE mounts in a non-init user namespace. This patch addresses the new unprivileged non-init mounted filesystems, which are untrusted, by failing the signature verification. This patch defines two new flags SB_I_IMA_UNVERIFIABLE_SIGNATURE and SB_I_UNTRUSTED_MOUNTER. Signed-off-by: Mimi Zohar <[email protected]> Cc: Miklos Szeredi <[email protected]> Cc: Seth Forshee <[email protected]> Cc: Dongsu Park <[email protected]> Cc: Alban Crequy <[email protected]> Acked-by: Serge Hallyn <[email protected]> Acked-by: "Eric W. Biederman" <[email protected]>
Diffstat (limited to 'tools/perf/scripts/python/export-to-postgresql.py')
0 files changed, 0 insertions, 0 deletions