[Kernel-packages] [Bug 1244627] Re: Please enable CONFIG_IMA in the ubuntu kernel

2014-02-03 Thread Dave Chiluk
@pkern-k @pkern @smu-u @antarus It just occurred to me that you might not be aware that the 3.13 *(that now has the CONFIG_IMA) kernel available in 14.04 will be available in the update archives for precise shortly after 14.04 release. That's less than 3 months away. -- You received this bug

[Kernel-packages] [Bug 1244627] Re: Please enable CONFIG_IMA in the ubuntu kernel

2014-01-28 Thread Mark Russell
Hi Philipp, 12.04.4 is just the first appearance of the saucy kernel in the install media. As soon as a package is in main, it is supported. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu.

[Kernel-packages] [Bug 1244627] Re: Please enable CONFIG_IMA in the ubuntu kernel

2014-01-27 Thread Philipp Kern
Also I want to make the point, even if it can possibly be discarded quickly, that the saucy stack is, to my knowledge, not supported yet on precise. So changes in there could be held to a different standard than in saucy proper. But I sort of understand if you avoid divergence between saucy's

[Kernel-packages] [Bug 1244627] Re: Please enable CONFIG_IMA in the ubuntu kernel

2014-01-27 Thread Dave Chiluk
@pkern-l linux-generic-lts-saucy is available and supported in precise. The source base between linux-generic-lts-saucy and kernels in saucy are built from the same sources. As for creating a new flavor, creating additional flavors is avoided at all cost. Each additional flavor requires

[Kernel-packages] [Bug 1244627] Re: Please enable CONFIG_IMA in the ubuntu kernel

2014-01-27 Thread Philipp Kern
Oh ok. I was under the impression that it was only supported from 12.04.4, to be released in a week or two. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1244627 Title: Please enable

[Kernel-packages] [Bug 1244627] Re: Please enable CONFIG_IMA in the ubuntu kernel

2014-01-23 Thread Sven Mueller
Would there be a chance to create a -ima flavor of the kernel instead of enabling it in the stock kernel flavor? This should allow for it to go into Trusty and into Saucy as a SRU, if I understand correctly, since it provides a new binary package instead of modifying an existing one (no regression

[Kernel-packages] [Bug 1244627] Re: Please enable CONFIG_IMA in the ubuntu kernel

2014-01-22 Thread Chris J Arges
** Changed in: linux (Ubuntu Saucy) Assignee: Chris J Arges (arges) = Dave Chiluk (chiluk) -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1244627 Title: Please enable CONFIG_IMA in

[Kernel-packages] [Bug 1244627] Re: Please enable CONFIG_IMA in the ubuntu kernel

2014-01-22 Thread Dave Chiluk
As cking noted in #4 this would cause a performance impact for ext2/3. That alone prevents it from moving into the stable saucy kernel. Additionally this is a significant enough change that it would not satisfy the SRU requirements for pushing into the saucy kernel. Please see

[Kernel-packages] [Bug 1244627] Re: Please enable CONFIG_IMA in the ubuntu kernel

2014-01-17 Thread Philipp Kern
Could this be enabled in the saucy LTS backport kernel in precise as well, please? It will take a while until the trusty kernel becomes available there and this blocks our switch to the saucy kernel. Thanks! -- You received this bug notification because you are a member of Kernel Packages, which

[Kernel-packages] [Bug 1244627] Re: Please enable CONFIG_IMA in the ubuntu kernel

2014-01-17 Thread Chris J Arges
** Changed in: linux (Ubuntu Saucy) Assignee: (unassigned) = Chris J Arges (arges) ** Changed in: linux (Ubuntu Saucy) Importance: Undecided = Medium -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu.

[Kernel-packages] [Bug 1244627] Re: Please enable CONFIG_IMA in the ubuntu kernel

2014-01-03 Thread Andy Whitcroft
Investigations and benchmarking are ongoing to confirm/deny that turning this on without enabling is cheap enough to enable in the default configurations. ** Changed in: linux (Ubuntu) Status: Triaged = In Progress ** Changed in: linux (Ubuntu) Assignee: (unassigned) = Colin King

[Kernel-packages] [Bug 1244627] Re: Please enable CONFIG_IMA in the ubuntu kernel

2014-01-03 Thread Colin King
So enabling this consumes an extra sizeof(atomic_t) bytes per inode. Instrumenting the kernel with it enabled we see: * To boot a system: 0.113 MB allocated + 23 x 4K slabs in iint_cache, total: 0.203 MB consumed for ~1288 cached file entries. * Install kernel + headers: 0.401 MB allocated

[Kernel-packages] [Bug 1244627] Re: Please enable CONFIG_IMA in the ubuntu kernel

2014-01-03 Thread Tim Gardner
** Also affects: linux (Ubuntu Trusty) Importance: Medium Assignee: Colin King (colin-king) Status: In Progress -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1244627

[Kernel-packages] [Bug 1244627] Re: Please enable CONFIG_IMA in the ubuntu kernel

2014-01-03 Thread Tim Gardner
** Changed in: linux (Ubuntu Trusty) Status: In Progress = Fix Committed -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1244627 Title: Please enable CONFIG_IMA in the ubuntu

[Kernel-packages] [Bug 1244627] Re: Please enable CONFIG_IMA in the ubuntu kernel

2014-01-03 Thread Kees Cook
For making sure IMA isn't enabled at boot by default, here's some details From http://sourceforge.net/p/linux-ima/wiki/Home/ Enabling IMA IMA was first included in the 2.6.30 kernel. For distros that enable IMA by default in their kernels, collecting IMA measurements simply requires rebooting

[Kernel-packages] [Bug 1244627] Re: Please enable CONFIG_IMA in the ubuntu kernel

2014-01-03 Thread Alec Warner
** Tags removed: raring ** Tags added: saucy -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1244627 Title: Please enable CONFIG_IMA in the ubuntu kernel Status in “linux” package in

[Kernel-packages] [Bug 1244627] Re: Please enable CONFIG_IMA in the ubuntu kernel

2014-01-03 Thread Andy Whitcroft
** Also affects: linux (Ubuntu Saucy) Importance: Undecided Status: New ** Changed in: linux (Ubuntu Saucy) Status: New = Triaged -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu.

[Kernel-packages] [Bug 1244627] Re: Please enable CONFIG_IMA in the ubuntu kernel

2013-12-17 Thread Kees Cook
Moving to main linux package. Waiting for memory benchmark comparison of: - without CONFIG_IMA - with CONFIG_IMA - with CONFIG_IMG + policy ** Package changed: linux-meta-lts-saucy (Ubuntu) = linux (Ubuntu) -- You received this bug notification because you are a member of Kernel Packages,