Re: [PATCH 2/6] integrity: Linux Integrity Module(LIM)

From: Christoph Hellwig
Date: Wed Dec 03 2008 - 15:38:51 EST


On Wed, Dec 03, 2008 at 02:13:20PM -0600, Serge E. Hallyn wrote:
> > Can you explain what all this template stuff is about? The only method
> > of these ever called is display_template,
>
> I'm not sure what you mean here - must_measure for instance is used (in
> patch 3) in the integrity hooks (i.e. file_mmap) to decide whether or not
> the object (action target) must be measured.

ima_must_measure (or the other implementation bits) are called a lot.
But never through the indirection I quoted.

> > and that seems to be better
> > implented directly as a securityfs file, without the indirection.
>
> That comment doesn't make sense to me (unless you're saying to punt
> on the generic integrity infrastructure and hook all of the IMA
> code straight into the kernel) so I suspect I'm misreading
> something.

ima_measurements_show alaways calls ima_template_show, and both are
implemented inside the ima module. There's absolutely no point for the
indirection here.

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/