[PATCH v2] ima: allow users to specify the pcr index with IMA_MEASURE_PCR_IDX
From: Julian Braha
Date: Fri Sep 04 2026 - 08:04:51 EST
The IMA_MEASURE_PCR_IDX option is currently not visible in the kconfig
frontend, so it always uses its default, 10. This means that the
'range 8 14' is dead code, and users are unable to specify the pcr index
value.
In a previous discussion, Mimi explained that users should be able to use
this config option to specify the pcr index. [1]
Let's add a prompt for users to specify the pcr index, when EXPERT is
enabled.
This dead range was found by kconfirm, a static analysis tool for Kconfig.
Link: https://lore.kernel.org/all/1feff118-4afa-4b9c-86f1-271a7a88208f@xxxxxxxxx/T/#mc4efa2491b4937eb7c9e532c29ffba516a70e662 [1]
Signed-off-by: Julian Braha <julianbraha@xxxxxxxxx>
---
Changes since v1:
- updated help text to recommend using the default of 10
v1:
https://lore.kernel.org/all/20260824162215.1572367-1-julianbraha@xxxxxxxxx/
---
security/integrity/ima/Kconfig | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/security/integrity/ima/Kconfig b/security/integrity/ima/Kconfig
index b3a9f86809b0..72654cf797cd 100644
--- a/security/integrity/ima/Kconfig
+++ b/security/integrity/ima/Kconfig
@@ -46,12 +46,16 @@ config IMA_KEXEC
config IMA_MEASURE_PCR_IDX
int
+ prompt "PCR Index for Aggregate" if EXPERT
range 8 14
default 10
help
IMA_MEASURE_PCR_IDX determines the TPM PCR register index
that IMA uses to maintain the integrity aggregate of the
- measurement list. If unsure, use the default 10.
+ measurement list. Most attestation tooling expects PCR 10.
+
+ The default is almost always what you want. Only change this
+ if you know what you are doing.
config IMA_LSM_RULES
bool
--
2.55.0