iint.c 1.3 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061
  1. // SPDX-License-Identifier: GPL-2.0-only
  2. /*
  3. * Copyright (C) 2008 IBM Corporation
  4. *
  5. * Authors:
  6. * Mimi Zohar <zohar@us.ibm.com>
  7. *
  8. * File: integrity_iint.c
  9. * - initialize the integrity directory in securityfs
  10. * - load IMA and EVM keys
  11. */
  12. #include <linux/security.h>
  13. #include "integrity.h"
  14. struct dentry *integrity_dir;
  15. /*
  16. * integrity_kernel_read - read data from the file
  17. *
  18. * This is a function for reading file content instead of kernel_read().
  19. * It does not perform locking checks to ensure it cannot be blocked.
  20. * It does not perform security checks because it is irrelevant for IMA.
  21. *
  22. */
  23. int integrity_kernel_read(struct file *file, loff_t offset,
  24. void *addr, unsigned long count)
  25. {
  26. return __kernel_read(file, addr, count, &offset);
  27. }
  28. /*
  29. * integrity_load_keys - load integrity keys hook
  30. *
  31. * Hooks is called from init/main.c:kernel_init_freeable()
  32. * when rootfs is ready
  33. */
  34. void __init integrity_load_keys(void)
  35. {
  36. ima_load_x509();
  37. if (!IS_ENABLED(CONFIG_IMA_LOAD_X509))
  38. evm_load_x509();
  39. }
  40. static int __init integrity_fs_init(void)
  41. {
  42. integrity_dir = securityfs_create_dir("integrity", NULL);
  43. if (IS_ERR(integrity_dir)) {
  44. int ret = PTR_ERR(integrity_dir);
  45. if (ret != -ENODEV)
  46. pr_err("Unable to create integrity sysfs dir: %d\n",
  47. ret);
  48. integrity_dir = NULL;
  49. return ret;
  50. }
  51. return 0;
  52. }
  53. late_initcall(integrity_fs_init)