[PATCH v2 2/9] ima: fix updating the ima_appraise flag

2018-05-17 Thread Mimi Zohar
As IMA policy rules are added, a mask of the type of rule (eg. kexec kernel image, firmware, IMA policy) is updated. Based on this mask, integrity decisions can be made quickly. Unlike custom IMA policy rules, which replace the original builtin policy rules and update the mask, the builtin

[PATCH v2 2/9] ima: fix updating the ima_appraise flag

2018-05-17 Thread Mimi Zohar
As IMA policy rules are added, a mask of the type of rule (eg. kexec kernel image, firmware, IMA policy) is updated. Based on this mask, integrity decisions can be made quickly. Unlike custom IMA policy rules, which replace the original builtin policy rules and update the mask, the builtin