diff --git a/.gitignore b/.gitignore index 6d559b3..2646509 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1 @@ /ima-evm-utils-*.tar.gz -prepare_sources_result*/ diff --git a/.packit.yaml b/.packit.yaml deleted file mode 100644 index a97cb7f..0000000 --- a/.packit.yaml +++ /dev/null @@ -1,34 +0,0 @@ -# See the documentation for more information: -# https://packit.dev/docs/configuration/ - -specfile_path: ima-evm-util.spec - -# add or remove files that should be synced -files_to_sync: - - .packit.yaml - -# name in upstream package repository or registry (e.g. in PyPI) -upstream_package_name: ima-evm-utils -# downstream (Fedora) RPM package name -downstream_package_name: ima-evm-utils - -jobs: - # This is triggered by https://release-monitoring.org/ - - job: pull_from_upstream - trigger: release - dist_git_branches: - - fedora-all - - # This is triggered at Fedora dist-git for creating koji build after - # PR in src.fedoraproject.org been merged. - - job: koji_build - trigger: commit - allowed_pr_authors: ["all_committers", "packit"] - dist_git_branches: - - fedora-all - - # This is triggered at Fedora messaging bus about koji build finished. - - job: bodhi_update - trigger: commit - allowed_builders: ["all_committers", "packit"] - dist_git_branches: diff --git a/ima-add-sigs.sh b/ima-add-sigs.sh index f0e9dd0..4321ace 100755 --- a/ima-add-sigs.sh +++ b/ima-add-sigs.sh @@ -1,31 +1,16 @@ #!/bin/bash # # This script add IMA signatures to installed RPM package files -usage() { - echo "Add IMA signatures to installed packages." - cat <reinstall_threshold (=20 by default) packages in the RPM - DB missing IMA signatures, reinstalling the packages to add IMA - signatures to the packages. By default, IMA sigatures will be obtained - from the RPM DB. However the RPM DB may not have the signatures. Dectect - this case by checking if there are >reinstall_threshold package missing - IMA signatures. - - --ima_cert - With the signing IMA cert path specified, it will also try to verify the - added IMA signature. - -EOF - exit 1 -} +# Usage: add_ima_sigs.sh [--package=PACKAGE_NAME|ALL] [--ima-cert=IMA_CERT_PATH] [--reinstall_threshold=NUM] +# +# By default, it will add IMA sigantures to all installed package files. Or you +# can provide a package name to only add IMA signature for files of specicifed +# package. If it detects >=20 packages (or 1 package if you specify a package +# name) missing signatures in the RPM database, it will reinstall the packages +# in order to get the IMA signatures. +# +# With the signing IMA cert path specified, it will also try to verify +# the added IMA signature. for _opt in "$@"; do case "$_opt" in @@ -39,7 +24,7 @@ for _opt in "$@"; do ima_cert=${_opt#*=} ;; *) - [[ -n $1 ]] && usage + usage ;; esac done @@ -53,33 +38,10 @@ abort() { exit 1 } -get_system_ima_key() { - source /etc/os-release - local -A name_map=(['Fedora Linux']="fedora" ['Red Hat Enterprise Linux']="redhatimarelease" ['CentOS Stream']='centosimarelease') - local version_id - key_name=${name_map[$NAME]} - version_id=${VERSION_ID/.?/} - - [[ $key_name == fedora ]] && name_suffix=-ima - key_path=/etc/keys/ima/${key_name}-${version_id}${name_suffix}.der - if [[ ! -e $key_path ]]; then - echo "Failed to get system IMA code verification key" - exit 1 - fi - - echo -n "$key_path" -} - # Add IMA signatures from RPM database add_from_rpm_db() { if ! command -v setfattr &>/dev/null; then - abort "Please install attr" - fi - - if [[ -e "$ima_cert" ]]; then - verify_ima_cert=$ima_cert - else - verify_ima_cert=$(get_system_ima_key) + abort "Please install attr" fi # use "|" as deliminator since it won't be used in a filename or signature @@ -95,22 +57,16 @@ add_from_rpm_db() { continue fi - # Skip some files that are created on the fly - if [[ $path == "/usr/share/mime/"* || $path == "/etc/pki/ca-trust/extracted/"* ]]; then - continue - fi - if ! setfattr -n security.ima "$path" -v "0x$sig"; then echo "Failed to add IMA sig for $path" fi - if ! evmctl ima_verify -k "$verify_ima_cert" "$path" &>/dev/null; then - setfattr -x security.ima "$path" - # When ima_cert is set, shows the verfication result for users - [[ -e "$ima_cert" ]] && "Failed to verify $path" - continue + [[ -e "$ima_cert" ]] || continue + # TODO + # don't verify the modified files like /etc? + if ! evmctl ima_verify -k "$ima_cert" "$path" &>/dev/null; then + echo "Failed to verify $path" fi - done < <(rpm -q --queryformat "[%{FILENAMES}|%{FILESIGNATURES}\n]" "$package") } @@ -124,7 +80,7 @@ if [[ -z $reinstall_threshold ]]; then if [[ $package == "--all" ]]; then reinstall_threshold=20 else - if ! rpm -q --quiet "$package"; then + if ! rpm -q --quiet $package; then dnf install "$package" -yq >/dev/null exit 0 fi @@ -132,7 +88,7 @@ if [[ -z $reinstall_threshold ]]; then fi fi -unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{RSAHEADER}\n" "$package" | grep -c "^(none)$") +unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{SIGPGP:pgpsig}\n" $package | grep "^(none)$" | wc -l) if [[ $unsigned_packages_in_rpm_db -ge $reinstall_threshold ]]; then add_by_reinstall diff --git a/ima-evm-utils.spec b/ima-evm-utils.spec index 29915ec..8326d2c 100644 --- a/ima-evm-utils.spec +++ b/ima-evm-utils.spec @@ -8,7 +8,7 @@ Name: ima-evm-utils Version: 1.6.2 -Release: 7%{?dist} +Release: 2%{?dist} Summary: IMA/EVM support utilities License: GPL-2.0-or-later Url: https://github.com/linux-integrity/ @@ -18,7 +18,7 @@ Source0: %{url}/ima-evm-utils/releases/download/v%{version}/%{name}-%{version}.t Source2: dracut-98-integrity.conf Source3: ima-add-sigs.sh Source4: ima-setup.sh -Source100: policy-01-appraise-executable-and-lib-signatures +Source100: policy-01-appraise-exectuables-and-lib-signatures Source101: policy-02-keylime-remote-attestation Source200: policy_list @@ -145,21 +145,6 @@ install -D %{SOURCE4} $RPM_BUILD_ROOT%{_bindir}/ima-setup %{_libdir}/libimaevm.so %changelog -* Thu Oct 16 2025 Coiby Xu - 1.6.2-7 -- ima-add-sigs: Use RSAHEADER to tell if a package has been signed - -* Thu Jul 24 2025 Fedora Release Engineering - 1.6.2-6 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild - -* Mon Mar 03 2025 Coiby Xu - 1.6.2-5 -- release 1.6.2-5 - -* Fri Jan 17 2025 Fedora Release Engineering - 1.6.2-4 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild - -* Thu Oct 31 2024 Coiby Xu - 1.6.2-3 -- Skip unsupported file systems for sample appraisal rule - * Fri Oct 18 2024 Adam Williamson - 1.6.2-2 - ima-evm-utils-libs obsoletes ima-evm-utils < 1.6 for rhbz#2319827 diff --git a/ima-setup.sh b/ima-setup.sh index 1450c0a..403ca12 100755 --- a/ima-setup.sh +++ b/ima-setup.sh @@ -17,12 +17,8 @@ usage: $0 --policy=IMA_POLICY_PATH [--reinstall_threshold=NUM] /usr/share/ima/policies or you can use your own IMA policy --reinstall_threshold - When there are >reinstall_threshold packages in the RPM DB missing IMA - signatures, reinstalling the packages to add IMA signatures to the - packages. By default, IMA sigatures will be obtained from the RPM DB. - However the RPM DB may not have the signatures. Dectect this case by - checking if there are >reinstall_threshold package missing IMA - signatures. + When there are >reinstall_threshold packages in the RPM DB missing IMA signatures, reinstalling the packages to add IMA signatures to the packages. + By default, IMA sigatures will be obtained from the RPM DB. However the RPM DB may not have the signatures. Dectect this case by checking if there are >reinstall_threshold package missing IMA signatures. EOF exit 1 @@ -33,7 +29,7 @@ for _opt in "$@"; do --policy=*) ima_policy_path=${_opt#*=} if [[ ! -e $ima_policy_path ]]; then - echo "$ima_policy_path doesn't exist" + echo "$policy_file doesn't exist" exit 1 fi ;; @@ -55,7 +51,7 @@ if test -f /run/ostree-booted; then echo "You are using OSTree, please enable IMA signatures as part of the OSTree creation process." else echo "Adding IMA signatures to installed package files" - if ! ima-add-sigs --reinstall_threshold="$reinstall_threshold"; then + if ! ima-add-sigs; then echo "Failed to add IMA signatures, abort" exit 1 fi @@ -120,12 +116,17 @@ load_ima_keys # automatically when there is a system reboot if ! lsinitrd --mod | grep -q integrity; then cp --preserve=xattr /usr/share/ima/dracut-98-integrity.conf /etc/dracut.conf.d/98-integrity.conf - echo "Regenerating all initramfs images to include the dracut integrity module" - if ! dracut -f --regenerate-all; then - echo "Failed to Regenerate all initramfs images" - exit 1 + echo "Rebuilding the initramfs of kernel-$(uname -r) to include the dracut integrity module" + dracut -f + + if command -v grubby >/dev/null; then + _default_kernel=$(grubby --default-kernel | sed -En "s/.*vmlinuz-(.*)/\1/p") + if [[ $_default_kernel != $(uname -r) ]]; then + echo "Current kernel is no the default kernel ($_default_kernel), include dracut integrity for it as well" + dracut -f --kver "$_default_kernel" + fi fi - [[ $(uname -m) == s390x ]] && zipl &> /dev/null + fi if ! load_ima_policy "$ima_policy_path"; then diff --git a/policy-01-appraise-exectuables-and-lib-signatures b/policy-01-appraise-exectuables-and-lib-signatures new file mode 100644 index 0000000..afc4530 --- /dev/null +++ b/policy-01-appraise-exectuables-and-lib-signatures @@ -0,0 +1,2 @@ +appraise func=MMAP_CHECK mask=MAY_EXEC appraise_type=imasig +appraise func=BPRM_CHECK appraise_type=imasig diff --git a/policy-01-appraise-executable-and-lib-signatures b/policy-01-appraise-executable-and-lib-signatures deleted file mode 100644 index 53feed5..0000000 --- a/policy-01-appraise-executable-and-lib-signatures +++ /dev/null @@ -1,28 +0,0 @@ -# Skip some unsupported filesystems -# This list of the filesystems can be found on -# https://www.kernel.org/doc/Documentation/ABI/testing/ima_policy -# PROC_SUPER_MAGIC -dont_appraise fsmagic=0x9fa0 -# SYSFS_MAGIC -dont_appraise fsmagic=0x62656572 -# DEBUGFS_MAGIC -dont_appraise fsmagic=0x64626720 -# TMPFS_MAGIC -dont_appraise fsmagic=0x01021994 -# RAMFS_MAGIC -dont_appraise fsmagic=0x858458f6 -# DEVPTS_SUPER_MAGIC -dont_appraise fsmagic=0x1cd1 -# BINFMTFS_MAGIC -dont_appraise fsmagic=0x42494e4d -# SECURITYFS_MAGIC -dont_appraise fsmagic=0x73636673 -# SELINUX_MAGIC -dont_appraise fsmagic=0xf97cff8c -# CGROUP_SUPER_MAGIC -dont_appraise fsmagic=0x27e0eb -# NSFS_MAGIC -dont_appraise fsmagic=0x6e736673 - -appraise func=MMAP_CHECK mask=MAY_EXEC appraise_type=imasig -appraise func=BPRM_CHECK appraise_type=imasig diff --git a/policy_list b/policy_list index af81a74..23ff71a 100644 --- a/policy_list +++ b/policy_list @@ -1,2 +1,2 @@ -01-appraise-executable-and-lib-signatures +01-appraise-exectuables-and-lib-signatures 02-keylime-remote-attestation