Re: [PATCH v7 4/5] IMA: Add support to limit measuring keys

From: Lakshmi Ramasubramanian
Date: Thu Nov 14 2019 - 13:18:49 EST


On 11/14/2019 6:37 AM, Mimi Zohar wrote:
Keyrings may be created by userspace with any name (e.g. foo, foobar,
...). ÂA keyring name might be a subset of another keyring name. ÂFor
example, with the policy "keyrings=foobar", keys being loaded on "foo"
would also be measured. ÂUsing strstr() will not achieve what is
needed.

Mimi

Very good catch - I missed that :(

Will fix and send an update.

thanks,
-lakshmi