Re: [PATCH v2 0/3] initramfs: add support for xattrs in the initial ram disk

From: Mimi Zohar
Date: Mon May 13 2019 - 14:38:21 EST



> > How does this work today then? Is it actually the case that initramfs
> > just cannot be used on an IMA-enabled system, or it can but it leaves
> > the initramfs unverified and we're trying to fix that? I had assumed the
> > latter.
> Oooh, it's done not by starting IMA appraisal later, but by loading a
> default policy to ignore initramfs?

Right, when rootfs is a tmpfs filesystem, it supports xattrs, allowing
for finer grained policies to be defined. ÂThis patch set would allow
a builtin IMA appraise policy to be defined which includes tmpfs.

Mimi