On Wed, Jul 12, 2017 at 01:56:50PM -0400, Mimi Zohar wrote:
> On Wed, 2017-07-12 at 10:35 -0400, Bruce Fields wrote:
> > On Wed, Jul 12, 2017 at 08:20:21AM -0400, Mimi Zohar wrote:
> > > Right, currently the only way of knowing is by looking at the IMA
> > > measurement list to see if modified
On Wed, Jul 12, 2017 at 01:56:50PM -0400, Mimi Zohar wrote:
> On Wed, 2017-07-12 at 10:35 -0400, Bruce Fields wrote:
> > On Wed, Jul 12, 2017 at 08:20:21AM -0400, Mimi Zohar wrote:
> > > Right, currently the only way of knowing is by looking at the IMA
> > > measurement list to see if modified
On Wed, 2017-07-12 at 10:35 -0400, Bruce Fields wrote:
> On Wed, Jul 12, 2017 at 08:20:21AM -0400, Mimi Zohar wrote:
> > Right, currently the only way of knowing is by looking at the IMA
> > measurement list to see if modified files are re-measured or, as you
> > said, by looking at the code.
>
>
On Wed, 2017-07-12 at 10:35 -0400, Bruce Fields wrote:
> On Wed, Jul 12, 2017 at 08:20:21AM -0400, Mimi Zohar wrote:
> > Right, currently the only way of knowing is by looking at the IMA
> > measurement list to see if modified files are re-measured or, as you
> > said, by looking at the code.
>
>
On Wed, Jul 12, 2017 at 08:20:21AM -0400, Mimi Zohar wrote:
> Right, currently the only way of knowing is by looking at the IMA
> measurement list to see if modified files are re-measured or, as you
> said, by looking at the code.
Who's actually using this, and do they do any kind of checks, or
On Wed, Jul 12, 2017 at 08:20:21AM -0400, Mimi Zohar wrote:
> Right, currently the only way of knowing is by looking at the IMA
> measurement list to see if modified files are re-measured or, as you
> said, by looking at the code.
Who's actually using this, and do they do any kind of checks, or
On Tue, 2017-07-11 at 21:17 -0400, jlay...@redhat.com wrote:
> On Mon, 2017-07-10 at 08:10 -0400, Mimi Zohar wrote:
> > On Fri, 2017-07-07 at 16:35 -0400, Jeff Layton wrote:
> > > On Fri, 2017-07-07 at 15:59 -0400, Mimi Zohar wrote:
> > > > On Fri, 2017-07-07 at 13:49 -0400, Jeff Layton wrote:
> >
On Tue, 2017-07-11 at 21:17 -0400, jlay...@redhat.com wrote:
> On Mon, 2017-07-10 at 08:10 -0400, Mimi Zohar wrote:
> > On Fri, 2017-07-07 at 16:35 -0400, Jeff Layton wrote:
> > > On Fri, 2017-07-07 at 15:59 -0400, Mimi Zohar wrote:
> > > > On Fri, 2017-07-07 at 13:49 -0400, Jeff Layton wrote:
> >
On Mon, 2017-07-10 at 08:10 -0400, Mimi Zohar wrote:
> On Fri, 2017-07-07 at 16:35 -0400, Jeff Layton wrote:
> > On Fri, 2017-07-07 at 15:59 -0400, Mimi Zohar wrote:
> > > On Fri, 2017-07-07 at 13:49 -0400, Jeff Layton wrote:
> > > > On Fri, 2017-07-07 at 13:24 -0400, Mimi Zohar wrote:
> > > > >
On Mon, 2017-07-10 at 08:10 -0400, Mimi Zohar wrote:
> On Fri, 2017-07-07 at 16:35 -0400, Jeff Layton wrote:
> > On Fri, 2017-07-07 at 15:59 -0400, Mimi Zohar wrote:
> > > On Fri, 2017-07-07 at 13:49 -0400, Jeff Layton wrote:
> > > > On Fri, 2017-07-07 at 13:24 -0400, Mimi Zohar wrote:
> > > > >
On Tue, 2017-07-11 at 12:13 -0400, J. Bruce Fields wrote:
> On Fri, Jul 07, 2017 at 10:05:30AM -0400, Jeff Layton wrote:
> > From: Jeff Layton
> >
> > The IMA assessment code tries to use the i_version counter to
> > detect
> > when changes to a file have occurred. Many
On Tue, 2017-07-11 at 12:13 -0400, J. Bruce Fields wrote:
> On Fri, Jul 07, 2017 at 10:05:30AM -0400, Jeff Layton wrote:
> > From: Jeff Layton
> >
> > The IMA assessment code tries to use the i_version counter to
> > detect
> > when changes to a file have occurred. Many filesystems don't
> >
On Tue, 2017-07-11 at 12:13 -0400, J. Bruce Fields wrote:
> On Fri, Jul 07, 2017 at 10:05:30AM -0400, Jeff Layton wrote:
> > From: Jeff Layton
> >
> > The IMA assessment code tries to use the i_version counter to detect
> > when changes to a file have occurred. Many
On Tue, 2017-07-11 at 12:13 -0400, J. Bruce Fields wrote:
> On Fri, Jul 07, 2017 at 10:05:30AM -0400, Jeff Layton wrote:
> > From: Jeff Layton
> >
> > The IMA assessment code tries to use the i_version counter to detect
> > when changes to a file have occurred. Many filesystems don't increment
>
On Fri, Jul 07, 2017 at 10:05:30AM -0400, Jeff Layton wrote:
> From: Jeff Layton
>
> The IMA assessment code tries to use the i_version counter to detect
> when changes to a file have occurred. Many filesystems don't increment
> it properly (or at all) so detecting changes
On Fri, Jul 07, 2017 at 10:05:30AM -0400, Jeff Layton wrote:
> From: Jeff Layton
>
> The IMA assessment code tries to use the i_version counter to detect
> when changes to a file have occurred. Many filesystems don't increment
> it properly (or at all) so detecting changes with that is not
On Fri, 2017-07-07 at 16:35 -0400, Jeff Layton wrote:
> On Fri, 2017-07-07 at 15:59 -0400, Mimi Zohar wrote:
> > On Fri, 2017-07-07 at 13:49 -0400, Jeff Layton wrote:
> > > On Fri, 2017-07-07 at 13:24 -0400, Mimi Zohar wrote:
> > > > On Fri, 2017-07-07 at 12:57 -0400, Jeff Layton wrote:
> > > > >
On Fri, 2017-07-07 at 16:35 -0400, Jeff Layton wrote:
> On Fri, 2017-07-07 at 15:59 -0400, Mimi Zohar wrote:
> > On Fri, 2017-07-07 at 13:49 -0400, Jeff Layton wrote:
> > > On Fri, 2017-07-07 at 13:24 -0400, Mimi Zohar wrote:
> > > > On Fri, 2017-07-07 at 12:57 -0400, Jeff Layton wrote:
> > > > >
On Fri, 2017-07-07 at 15:59 -0400, Mimi Zohar wrote:
> On Fri, 2017-07-07 at 13:49 -0400, Jeff Layton wrote:
> > On Fri, 2017-07-07 at 13:24 -0400, Mimi Zohar wrote:
> > > On Fri, 2017-07-07 at 12:57 -0400, Jeff Layton wrote:
> > > > On Fri, 2017-07-07 at 10:05 -0400, Jeff Layton wrote:
> > > > >
On Fri, 2017-07-07 at 15:59 -0400, Mimi Zohar wrote:
> On Fri, 2017-07-07 at 13:49 -0400, Jeff Layton wrote:
> > On Fri, 2017-07-07 at 13:24 -0400, Mimi Zohar wrote:
> > > On Fri, 2017-07-07 at 12:57 -0400, Jeff Layton wrote:
> > > > On Fri, 2017-07-07 at 10:05 -0400, Jeff Layton wrote:
> > > > >
On Fri, 2017-07-07 at 13:49 -0400, Jeff Layton wrote:
> On Fri, 2017-07-07 at 13:24 -0400, Mimi Zohar wrote:
> > On Fri, 2017-07-07 at 12:57 -0400, Jeff Layton wrote:
> > > On Fri, 2017-07-07 at 10:05 -0400, Jeff Layton wrote:
> > > > From: Jeff Layton
> > > >
> > > > The IMA
On Fri, 2017-07-07 at 13:49 -0400, Jeff Layton wrote:
> On Fri, 2017-07-07 at 13:24 -0400, Mimi Zohar wrote:
> > On Fri, 2017-07-07 at 12:57 -0400, Jeff Layton wrote:
> > > On Fri, 2017-07-07 at 10:05 -0400, Jeff Layton wrote:
> > > > From: Jeff Layton
> > > >
> > > > The IMA assessment code
On Fri, 2017-07-07 at 13:24 -0400, Mimi Zohar wrote:
> On Fri, 2017-07-07 at 12:57 -0400, Jeff Layton wrote:
> > On Fri, 2017-07-07 at 10:05 -0400, Jeff Layton wrote:
> > > From: Jeff Layton
> > >
> > > The IMA assessment code tries to use the i_version counter to detect
> >
On Fri, 2017-07-07 at 13:24 -0400, Mimi Zohar wrote:
> On Fri, 2017-07-07 at 12:57 -0400, Jeff Layton wrote:
> > On Fri, 2017-07-07 at 10:05 -0400, Jeff Layton wrote:
> > > From: Jeff Layton
> > >
> > > The IMA assessment code tries to use the i_version counter to detect
> > > when changes to a
On Fri, 2017-07-07 at 12:57 -0400, Jeff Layton wrote:
> On Fri, 2017-07-07 at 10:05 -0400, Jeff Layton wrote:
> > From: Jeff Layton
> >
> > The IMA assessment code tries to use the i_version counter to detect
> > when changes to a file have occurred. Many filesystems don't
On Fri, 2017-07-07 at 12:57 -0400, Jeff Layton wrote:
> On Fri, 2017-07-07 at 10:05 -0400, Jeff Layton wrote:
> > From: Jeff Layton
> >
> > The IMA assessment code tries to use the i_version counter to detect
> > when changes to a file have occurred. Many filesystems don't increment
> > it
On Fri, 2017-07-07 at 10:05 -0400, Jeff Layton wrote:
> From: Jeff Layton
>
> The IMA assessment code tries to use the i_version counter to detect
> when changes to a file have occurred. Many filesystems don't increment
> it properly (or at all) so detecting changes with that
On Fri, 2017-07-07 at 10:05 -0400, Jeff Layton wrote:
> From: Jeff Layton
>
> The IMA assessment code tries to use the i_version counter to detect
> when changes to a file have occurred. Many filesystems don't increment
> it properly (or at all) so detecting changes with that is not always
>
From: Jeff Layton
The IMA assessment code tries to use the i_version counter to detect
when changes to a file have occurred. Many filesystems don't increment
it properly (or at all) so detecting changes with that is not always
reliable.
That check should be gated on
From: Jeff Layton
The IMA assessment code tries to use the i_version counter to detect
when changes to a file have occurred. Many filesystems don't increment
it properly (or at all) so detecting changes with that is not always
reliable.
That check should be gated on IS_I_VERSION, as you can't
30 matches
Mail list logo