aboutsummaryrefslogtreecommitdiffstats
path: root/security/integrity/ima/ima.h
diff options
context:
space:
mode:
authorMimi Zohar <zohar@linux.vnet.ibm.com>2009-02-04 09:06:58 -0500
committerJames Morris <jmorris@namei.org>2009-02-05 17:05:30 -0500
commit3323eec921efd815178a23107ab63588c605c0b2 (patch)
treebc9e9714ac4881ebc515c1bd155674c52c356d6a /security/integrity/ima/ima.h
parent6146f0d5e47ca4047ffded0fb79b6c25359b386c (diff)
integrity: IMA as an integrity service provider
IMA provides hardware (TPM) based measurement and attestation for file measurements. As the Trusted Computing (TPM) model requires, IMA measures all files before they are accessed in any way (on the integrity_bprm_check, integrity_path_check and integrity_file_mmap hooks), and commits the measurements to the TPM. Once added to the TPM, measurements can not be removed. In addition, IMA maintains a list of these file measurements, which can be used to validate the aggregate value stored in the TPM. The TPM can sign these measurements, and thus the system can prove, to itself and to a third party, the system's integrity in a way that cannot be circumvented by malicious or compromised software. - alloc ima_template_entry before calling ima_store_template() - log ima_add_boot_aggregate() failure - removed unused IMA_TEMPLATE_NAME_LEN - replaced hard coded string length with #define name Signed-off-by: Mimi Zohar <zohar@us.ibm.com> Signed-off-by: James Morris <jmorris@namei.org>
Diffstat (limited to 'security/integrity/ima/ima.h')
-rw-r--r--security/integrity/ima/ima.h135
1 files changed, 135 insertions, 0 deletions
diff --git a/security/integrity/ima/ima.h b/security/integrity/ima/ima.h
new file mode 100644
index 000000000000..bfa72ed41b9b
--- /dev/null
+++ b/security/integrity/ima/ima.h
@@ -0,0 +1,135 @@
1/*
2 * Copyright (C) 2005,2006,2007,2008 IBM Corporation
3 *
4 * Authors:
5 * Reiner Sailer <sailer@watson.ibm.com>
6 * Mimi Zohar <zohar@us.ibm.com>
7 *
8 * This program is free software; you can redistribute it and/or
9 * modify it under the terms of the GNU General Public License as
10 * published by the Free Software Foundation, version 2 of the
11 * License.
12 *
13 * File: ima.h
14 * internal Integrity Measurement Architecture (IMA) definitions
15 */
16
17#ifndef __LINUX_IMA_H
18#define __LINUX_IMA_H
19
20#include <linux/types.h>
21#include <linux/crypto.h>
22#include <linux/security.h>
23#include <linux/hash.h>
24#include <linux/tpm.h>
25#include <linux/audit.h>
26
27enum ima_show_type { IMA_SHOW_BINARY, IMA_SHOW_ASCII };
28enum tpm_pcrs { TPM_PCR0 = 0, TPM_PCR8 = 8 };
29
30/* digest size for IMA, fits SHA1 or MD5 */
31#define IMA_DIGEST_SIZE 20
32#define IMA_EVENT_NAME_LEN_MAX 255
33
34#define IMA_HASH_BITS 9
35#define IMA_MEASURE_HTABLE_SIZE (1 << IMA_HASH_BITS)
36
37/* set during initialization */
38extern int ima_initialized;
39extern int ima_used_chip;
40extern char *ima_hash;
41
42/* IMA inode template definition */
43struct ima_template_data {
44 u8 digest[IMA_DIGEST_SIZE]; /* sha1/md5 measurement hash */
45 char file_name[IMA_EVENT_NAME_LEN_MAX + 1]; /* name + \0 */
46};
47
48struct ima_template_entry {
49 u8 digest[IMA_DIGEST_SIZE]; /* sha1 or md5 measurement hash */
50 char *template_name;
51 int template_len;
52 struct ima_template_data template;
53};
54
55struct ima_queue_entry {
56 struct hlist_node hnext; /* place in hash collision list */
57 struct list_head later; /* place in ima_measurements list */
58 struct ima_template_entry *entry;
59};
60extern struct list_head ima_measurements; /* list of all measurements */
61
62/* declarations */
63void integrity_audit_msg(int audit_msgno, struct inode *inode,
64 const unsigned char *fname, const char *op,
65 const char *cause, int result, int info);
66
67/* Internal IMA function definitions */
68void ima_iintcache_init(void);
69int ima_init(void);
70int ima_add_template_entry(struct ima_template_entry *entry, int violation,
71 const char *op, struct inode *inode);
72int ima_calc_hash(struct file *file, char *digest);
73int ima_calc_template_hash(int template_len, void *template, char *digest);
74int ima_calc_boot_aggregate(char *digest);
75void ima_add_violation(struct inode *inode, const unsigned char *filename,
76 const char *op, const char *cause);
77
78/*
79 * used to protect h_table and sha_table
80 */
81extern spinlock_t ima_queue_lock;
82
83struct ima_h_table {
84 atomic_long_t len; /* number of stored measurements in the list */
85 atomic_long_t violations;
86 struct hlist_head queue[IMA_MEASURE_HTABLE_SIZE];
87};
88extern struct ima_h_table ima_htable;
89
90static inline unsigned long ima_hash_key(u8 *digest)
91{
92 return hash_long(*digest, IMA_HASH_BITS);
93}
94
95/* iint cache flags */
96#define IMA_MEASURED 1
97
98/* integrity data associated with an inode */
99struct ima_iint_cache {
100 u64 version; /* track inode changes */
101 unsigned long flags;
102 u8 digest[IMA_DIGEST_SIZE];
103 struct mutex mutex; /* protects: version, flags, digest */
104 long readcount; /* measured files readcount */
105 long writecount; /* measured files writecount */
106 struct kref refcount; /* ima_iint_cache reference count */
107 struct rcu_head rcu;
108};
109
110/* LIM API function definitions */
111int ima_must_measure(struct ima_iint_cache *iint, struct inode *inode,
112 int mask, int function);
113int ima_collect_measurement(struct ima_iint_cache *iint, struct file *file);
114void ima_store_measurement(struct ima_iint_cache *iint, struct file *file,
115 const unsigned char *filename);
116int ima_store_template(struct ima_template_entry *entry, int violation,
117 struct inode *inode);
118
119/* radix tree calls to lookup, insert, delete
120 * integrity data associated with an inode.
121 */
122struct ima_iint_cache *ima_iint_insert(struct inode *inode);
123struct ima_iint_cache *ima_iint_find_get(struct inode *inode);
124struct ima_iint_cache *ima_iint_find_insert_get(struct inode *inode);
125void ima_iint_delete(struct inode *inode);
126void iint_free(struct kref *kref);
127void iint_rcu_free(struct rcu_head *rcu);
128
129/* IMA policy related functions */
130enum ima_hooks { PATH_CHECK = 1, FILE_MMAP, BPRM_CHECK };
131
132int ima_match_policy(struct inode *inode, enum ima_hooks func, int mask);
133void ima_init_policy(void);
134void ima_update_policy(void);
135#endif