From 83b610d7edee02804dc1cecab8e151728925e90b Mon Sep 17 00:00:00 2001 From: Coiby Xu Date: Wed, 16 Oct 2024 13:48:01 +0800 Subject: [PATCH 01/16] Skip some file systems for appraisal Resolves: https://issues.redhat.com/browse/RHEL-62817 When 01-appraise-exectuables-and-lib-signatures is enabled, no login screen is available for user to log in. This happens because IMA stops gnome-shell from creating some temp files as can been from the audit log, type=INTEGRITY_DATA msg=audit(1728700747.130:10235): pid=3240 uid=42 auid=4294967295 ses=4294967295 subj=system_u:system_r:xdm_t:s0-s0:c0.c1023 op=appraise_data cause=IMA-signature-required comm="gnome-shell" name="/dev/shm/#3223" dev="tmpfs" ino=3223 res=0 errno=0UID="gdm" AUID="unset" type=INTEGRITY_DATA msg=audit(1728700747.130:10236): pid=3240 uid=42 auid=4294967295 ses=4294967295 subj=system_u:system_r:xdm_t:s0-s0:c0.c1023 op=appraise_data cause=IMA-signature-required comm="gnome-shell" name="/run/user/42/#454" dev="tmpfs" ino=454 res=0 errno=0UID="gdm" AUID="unset" type=INTEGRITY_DATA msg=audit(1728700747.131:10237): pid=3240 uid=42 auid=4294967295 ses=4294967295 subj=system_u:system_r:xdm_t:s0-s0:c0.c1023 op=appraise_data cause=IMA-signature-required comm="gnome-shell" name="memfd:libffi" dev="tmpfs" ino=578 res=0 errno=0UID="gdm" AUID="unset" Skip the file systems as listed in https://www.kernel.org/doc/Documentation/ABI/testing/ima_policy Reported-by: Raju Cheerla --- ima-evm-utils.spec | 2 +- ...01-appraise-exectuables-and-lib-signatures | 2 -- ...-01-appraise-executable-and-lib-signatures | 28 +++++++++++++++++++ policy_list | 2 +- 4 files changed, 30 insertions(+), 4 deletions(-) delete mode 100644 policy-01-appraise-exectuables-and-lib-signatures create mode 100644 policy-01-appraise-executable-and-lib-signatures diff --git a/ima-evm-utils.spec b/ima-evm-utils.spec index 8326d2c..4ad4907 100644 --- a/ima-evm-utils.spec +++ b/ima-evm-utils.spec @@ -18,7 +18,7 @@ Source0: %{url}/ima-evm-utils/releases/download/v%{version}/%{name}-%{version}.t Source2: dracut-98-integrity.conf Source3: ima-add-sigs.sh Source4: ima-setup.sh -Source100: policy-01-appraise-exectuables-and-lib-signatures +Source100: policy-01-appraise-executable-and-lib-signatures Source101: policy-02-keylime-remote-attestation Source200: policy_list diff --git a/policy-01-appraise-exectuables-and-lib-signatures b/policy-01-appraise-exectuables-and-lib-signatures deleted file mode 100644 index afc4530..0000000 --- a/policy-01-appraise-exectuables-and-lib-signatures +++ /dev/null @@ -1,2 +0,0 @@ -appraise func=MMAP_CHECK mask=MAY_EXEC appraise_type=imasig -appraise func=BPRM_CHECK appraise_type=imasig diff --git a/policy-01-appraise-executable-and-lib-signatures b/policy-01-appraise-executable-and-lib-signatures new file mode 100644 index 0000000..53feed5 --- /dev/null +++ b/policy-01-appraise-executable-and-lib-signatures @@ -0,0 +1,28 @@ +# Skip some unsupported filesystems +# This list of the filesystems can be found on +# https://www.kernel.org/doc/Documentation/ABI/testing/ima_policy +# PROC_SUPER_MAGIC +dont_appraise fsmagic=0x9fa0 +# SYSFS_MAGIC +dont_appraise fsmagic=0x62656572 +# DEBUGFS_MAGIC +dont_appraise fsmagic=0x64626720 +# TMPFS_MAGIC +dont_appraise fsmagic=0x01021994 +# RAMFS_MAGIC +dont_appraise fsmagic=0x858458f6 +# DEVPTS_SUPER_MAGIC +dont_appraise fsmagic=0x1cd1 +# BINFMTFS_MAGIC +dont_appraise fsmagic=0x42494e4d +# SECURITYFS_MAGIC +dont_appraise fsmagic=0x73636673 +# SELINUX_MAGIC +dont_appraise fsmagic=0xf97cff8c +# CGROUP_SUPER_MAGIC +dont_appraise fsmagic=0x27e0eb +# NSFS_MAGIC +dont_appraise fsmagic=0x6e736673 + +appraise func=MMAP_CHECK mask=MAY_EXEC appraise_type=imasig +appraise func=BPRM_CHECK appraise_type=imasig diff --git a/policy_list b/policy_list index 23ff71a..af81a74 100644 --- a/policy_list +++ b/policy_list @@ -1,2 +1,2 @@ -01-appraise-exectuables-and-lib-signatures +01-appraise-executable-and-lib-signatures 02-keylime-remote-attestation From 0e28d7448d1ac2608241949a25d6cb245b04874d Mon Sep 17 00:00:00 2001 From: Coiby Xu Date: Wed, 16 Oct 2024 14:10:05 +0800 Subject: [PATCH 02/16] add usage for ima-add-sigs Also format the usage info ima-setup. Signed-off-by: Coiby Xu --- ima-add-sigs.sh | 43 +++++++++++++++++++++++++++++-------------- ima-setup.sh | 8 ++++++-- 2 files changed, 35 insertions(+), 16 deletions(-) diff --git a/ima-add-sigs.sh b/ima-add-sigs.sh index 4321ace..6777d4b 100755 --- a/ima-add-sigs.sh +++ b/ima-add-sigs.sh @@ -1,16 +1,31 @@ #!/bin/bash # # This script add IMA signatures to installed RPM package files -# Usage: add_ima_sigs.sh [--package=PACKAGE_NAME|ALL] [--ima-cert=IMA_CERT_PATH] [--reinstall_threshold=NUM] -# -# By default, it will add IMA sigantures to all installed package files. Or you -# can provide a package name to only add IMA signature for files of specicifed -# package. If it detects >=20 packages (or 1 package if you specify a package -# name) missing signatures in the RPM database, it will reinstall the packages -# in order to get the IMA signatures. -# -# With the signing IMA cert path specified, it will also try to verify -# the added IMA signature. +usage() { + echo "Add IMA signatures to installed packages." + cat <reinstall_threshold (=20 by default) packages in the RPM + DB missing IMA signatures, reinstalling the packages to add IMA + signatures to the packages. By default, IMA sigatures will be obtained + from the RPM DB. However the RPM DB may not have the signatures. Dectect + this case by checking if there are >reinstall_threshold package missing + IMA signatures. + + --ima-cert + With the signing IMA cert path specified, it will also try to verify the + added IMA signature. + +EOF + exit 1 +} for _opt in "$@"; do case "$_opt" in @@ -24,7 +39,7 @@ for _opt in "$@"; do ima_cert=${_opt#*=} ;; *) - usage + [[ -n $1 ]] && usage ;; esac done @@ -41,7 +56,7 @@ abort() { # Add IMA signatures from RPM database add_from_rpm_db() { if ! command -v setfattr &>/dev/null; then - abort "Please install attr" + abort "Please install attr" fi # use "|" as deliminator since it won't be used in a filename or signature @@ -80,7 +95,7 @@ if [[ -z $reinstall_threshold ]]; then if [[ $package == "--all" ]]; then reinstall_threshold=20 else - if ! rpm -q --quiet $package; then + if ! rpm -q --quiet "$package"; then dnf install "$package" -yq >/dev/null exit 0 fi @@ -88,7 +103,7 @@ if [[ -z $reinstall_threshold ]]; then fi fi -unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{SIGPGP:pgpsig}\n" $package | grep "^(none)$" | wc -l) +unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{SIGPGP:pgpsig}\n" "$package" | grep "^(none)$" | wc -l) if [[ $unsigned_packages_in_rpm_db -ge $reinstall_threshold ]]; then add_by_reinstall diff --git a/ima-setup.sh b/ima-setup.sh index 403ca12..8e773ad 100755 --- a/ima-setup.sh +++ b/ima-setup.sh @@ -17,8 +17,12 @@ usage: $0 --policy=IMA_POLICY_PATH [--reinstall_threshold=NUM] /usr/share/ima/policies or you can use your own IMA policy --reinstall_threshold - When there are >reinstall_threshold packages in the RPM DB missing IMA signatures, reinstalling the packages to add IMA signatures to the packages. - By default, IMA sigatures will be obtained from the RPM DB. However the RPM DB may not have the signatures. Dectect this case by checking if there are >reinstall_threshold package missing IMA signatures. + When there are >reinstall_threshold packages in the RPM DB missing IMA + signatures, reinstalling the packages to add IMA signatures to the + packages. By default, IMA sigatures will be obtained from the RPM DB. + However the RPM DB may not have the signatures. Dectect this case by + checking if there are >reinstall_threshold package missing IMA + signatures. EOF exit 1 From 083226d5ef3ba9e11e5ea89562c387f1e5bf68af Mon Sep 17 00:00:00 2001 From: Coiby Xu Date: Thu, 31 Oct 2024 15:02:33 +0800 Subject: [PATCH 03/16] update to 1.6.2-3 --- ima-evm-utils.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/ima-evm-utils.spec b/ima-evm-utils.spec index 4ad4907..621a14c 100644 --- a/ima-evm-utils.spec +++ b/ima-evm-utils.spec @@ -8,7 +8,7 @@ Name: ima-evm-utils Version: 1.6.2 -Release: 2%{?dist} +Release: 3%{?dist} Summary: IMA/EVM support utilities License: GPL-2.0-or-later Url: https://github.com/linux-integrity/ @@ -145,6 +145,9 @@ install -D %{SOURCE4} $RPM_BUILD_ROOT%{_bindir}/ima-setup %{_libdir}/libimaevm.so %changelog +* Thu Oct 31 2024 Coiby Xu - 1.6.2-3 +- Skip unsupported file systems for sample appraisal rule + * Fri Oct 18 2024 Adam Williamson - 1.6.2-2 - ima-evm-utils-libs obsoletes ima-evm-utils < 1.6 for rhbz#2319827 From e15aa409cdd638889523ce2dbdba10990471ff1a Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 17 Jan 2025 07:03:53 +0000 Subject: [PATCH 04/16] Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild --- ima-evm-utils.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/ima-evm-utils.spec b/ima-evm-utils.spec index 621a14c..f05d7ac 100644 --- a/ima-evm-utils.spec +++ b/ima-evm-utils.spec @@ -8,7 +8,7 @@ Name: ima-evm-utils Version: 1.6.2 -Release: 3%{?dist} +Release: 4%{?dist} Summary: IMA/EVM support utilities License: GPL-2.0-or-later Url: https://github.com/linux-integrity/ @@ -145,6 +145,9 @@ install -D %{SOURCE4} $RPM_BUILD_ROOT%{_bindir}/ima-setup %{_libdir}/libimaevm.so %changelog +* Fri Jan 17 2025 Fedora Release Engineering - 1.6.2-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + * Thu Oct 31 2024 Coiby Xu - 1.6.2-3 - Skip unsupported file systems for sample appraisal rule From 2f1870b21accb4393a420cf55cba774dfd2d78ae Mon Sep 17 00:00:00 2001 From: Coiby Xu Date: Tue, 25 Feb 2025 13:17:28 +0800 Subject: [PATCH 05/16] ima-setup: run zipl after building initramfs for s390x Resovles: https://issues.redhat.com/browse/RHEL-74293 Without running zipl, the old initramfs will be booted. Signed-off-by: Coiby Xu --- ima-setup.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ima-setup.sh b/ima-setup.sh index 8e773ad..cf043f5 100755 --- a/ima-setup.sh +++ b/ima-setup.sh @@ -130,7 +130,7 @@ if ! lsinitrd --mod | grep -q integrity; then dracut -f --kver "$_default_kernel" fi fi - + [[ $(uname -m) == s390x ]] && zipl &> /dev/null fi if ! load_ima_policy "$ima_policy_path"; then From 7b800d82d0947fd0e75e92997a3aec7af079c1cc Mon Sep 17 00:00:00 2001 From: Coiby Xu Date: Tue, 25 Feb 2025 13:24:33 +0800 Subject: [PATCH 06/16] ima-setup: fix two shellcheck warnings Fix the following two shellcheck warnings, In ima-setup.sh line 36: echo "$policy_file doesn't exist" ^----------^ SC2154 (warning): policy_file is referenced but not assigned. In ima-setup.sh line 41: reinstall_threshold=${_opt#*=} ^-----------------^ SC2034 (warning): reinstall_threshold appears unused. Verify use (or export if used externally). Signed-off-by: Coiby Xu --- ima-setup.sh | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/ima-setup.sh b/ima-setup.sh index cf043f5..ad2b595 100755 --- a/ima-setup.sh +++ b/ima-setup.sh @@ -33,7 +33,7 @@ for _opt in "$@"; do --policy=*) ima_policy_path=${_opt#*=} if [[ ! -e $ima_policy_path ]]; then - echo "$policy_file doesn't exist" + echo "$ima_policy_path doesn't exist" exit 1 fi ;; @@ -55,7 +55,7 @@ if test -f /run/ostree-booted; then echo "You are using OSTree, please enable IMA signatures as part of the OSTree creation process." else echo "Adding IMA signatures to installed package files" - if ! ima-add-sigs; then + if ! ima-add-sigs --reinstall_threshold="$reinstall_threshold"; then echo "Failed to add IMA signatures, abort" exit 1 fi From e962d0cac47c3b2fc587f46a2e3547a28ffe526d Mon Sep 17 00:00:00 2001 From: Coiby Xu Date: Mon, 3 Mar 2025 10:05:13 +0800 Subject: [PATCH 07/16] Use packit to automate ima-evm-utils releasing Follow [1] to use packit to automate releasing ima-evm-utils. After finishing one-time setting up, when there is a new upstream release, here's the new process of releasing a new version in Fedora, 1. https://release-monitoring.org/ finds a new upstream and notify packit 2. packit: automatically create PRs to propose new release for different Fedora releases; also upload new tarballs into lookaside cache. 3. Maintainer: review(, modify) and merge the PR 4. packit: create a koji build 5. packit: create a Bodhi update So maintainers only need to do step 3 manually and all the repetitive work can be left to packit to handle. After the PR gets merged, two more things need to be done [2], - Create a Fedora mapping for the upstream project in https://release-monitoring.org/projects - Set Monitoring status on the left side at https://src.fedoraproject.org/rpms/ima-evm-utils to Monitoring [1] https://packit.dev/docs/fedora-releases-guide/dist-git-onboarding [2] https://packit.dev/docs/fedora-releases-guide/dist-git-onboarding#2-monitoring-of-the-package Signed-off-by: Coiby Xu --- .gitignore | 1 + .packit.yaml | 34 ++++++++++++++++++++++++++++++++++ 2 files changed, 35 insertions(+) create mode 100644 .packit.yaml diff --git a/.gitignore b/.gitignore index 2646509..6d559b3 100644 --- a/.gitignore +++ b/.gitignore @@ -1 +1,2 @@ /ima-evm-utils-*.tar.gz +prepare_sources_result*/ diff --git a/.packit.yaml b/.packit.yaml new file mode 100644 index 0000000..3360032 --- /dev/null +++ b/.packit.yaml @@ -0,0 +1,34 @@ +# See the documentation for more information: +# https://packit.dev/docs/configuration/ + +specfile_path: ima-evm-util.spec + +# add or remove files that should be synced +files_to_sync: + - .packit.yaml + +# name in upstream package repository or registry (e.g. in PyPI) +upstream_package_name: ima-evm-utils +# downstream (Fedora) RPM package name +downstream_package_name: ima-evm-utils + +jobs: + # This is triggered by https://release-monitoring.org/ + - job: pull_from_upstream + trigger: release + dist_git_branches: + - fedora-all + + # This is triggered at Fedora dist-git for creating koji build after + # PR in src.fedoraproject.org been merged. + - job: koji_build + trigger: commit + allowed_pr_authors: ["all_committers"] + dist_git_branches: + - fedora-all + + # This is triggered at Fedora messaging bus about koji build finished. + - job: bodhi_update + trigger: commit + allowed_builders: ["all_committers"] + dist_git_branches: From c68b187d3e7bb7abad42de4581975353ec042582 Mon Sep 17 00:00:00 2001 From: Coiby Xu Date: Mon, 3 Mar 2025 10:08:19 +0800 Subject: [PATCH 08/16] Release 1.6.2-5 --- ima-evm-utils.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/ima-evm-utils.spec b/ima-evm-utils.spec index f05d7ac..c3e8815 100644 --- a/ima-evm-utils.spec +++ b/ima-evm-utils.spec @@ -8,7 +8,7 @@ Name: ima-evm-utils Version: 1.6.2 -Release: 4%{?dist} +Release: 5%{?dist} Summary: IMA/EVM support utilities License: GPL-2.0-or-later Url: https://github.com/linux-integrity/ @@ -145,6 +145,9 @@ install -D %{SOURCE4} $RPM_BUILD_ROOT%{_bindir}/ima-setup %{_libdir}/libimaevm.so %changelog +* Mon Mar 03 2025 Coiby Xu - 1.6.2-5 +- release 1.6.2-5 + * Fri Jan 17 2025 Fedora Release Engineering - 1.6.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild From aed78ac85f6828d91491d656a97015c446797201 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 24 Jul 2025 17:36:58 +0000 Subject: [PATCH 09/16] Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild --- ima-evm-utils.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/ima-evm-utils.spec b/ima-evm-utils.spec index c3e8815..d8add48 100644 --- a/ima-evm-utils.spec +++ b/ima-evm-utils.spec @@ -8,7 +8,7 @@ Name: ima-evm-utils Version: 1.6.2 -Release: 5%{?dist} +Release: 6%{?dist} Summary: IMA/EVM support utilities License: GPL-2.0-or-later Url: https://github.com/linux-integrity/ @@ -145,6 +145,9 @@ install -D %{SOURCE4} $RPM_BUILD_ROOT%{_bindir}/ima-setup %{_libdir}/libimaevm.so %changelog +* Thu Jul 24 2025 Fedora Release Engineering - 1.6.2-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + * Mon Mar 03 2025 Coiby Xu - 1.6.2-5 - release 1.6.2-5 From ac36e54bee77c82bd7f48a507d014a1ec0055645 Mon Sep 17 00:00:00 2001 From: Coiby Xu Date: Thu, 10 Jul 2025 16:53:18 +0800 Subject: [PATCH 10/16] ima-setup: rebuild all initramfs images to include the integrity dracut module Resolves: https://issues.redhat.com/browse/RHEL-92638 Quoting Raju, ima-setup currently only rebuild the initramfs of running kernel, so the older kernel's(n-1 or n-2) initramfs does contain an outdated information or it does not contain ima module, as a result the system fails to boot with older kernel. It is always recommended to have at least 2 older kernel's kept installed on the system as a fallback option in case if the latest kernel fails to boot due to some unforeseen issue. So that we can boot the system with older kernel to troubleshoot the can't boot issue with older kernel. Suggested-by: Raju Cheerla --- ima-setup.sh | 13 ++++--------- 1 file changed, 4 insertions(+), 9 deletions(-) diff --git a/ima-setup.sh b/ima-setup.sh index ad2b595..1450c0a 100755 --- a/ima-setup.sh +++ b/ima-setup.sh @@ -120,15 +120,10 @@ load_ima_keys # automatically when there is a system reboot if ! lsinitrd --mod | grep -q integrity; then cp --preserve=xattr /usr/share/ima/dracut-98-integrity.conf /etc/dracut.conf.d/98-integrity.conf - echo "Rebuilding the initramfs of kernel-$(uname -r) to include the dracut integrity module" - dracut -f - - if command -v grubby >/dev/null; then - _default_kernel=$(grubby --default-kernel | sed -En "s/.*vmlinuz-(.*)/\1/p") - if [[ $_default_kernel != $(uname -r) ]]; then - echo "Current kernel is no the default kernel ($_default_kernel), include dracut integrity for it as well" - dracut -f --kver "$_default_kernel" - fi + echo "Regenerating all initramfs images to include the dracut integrity module" + if ! dracut -f --regenerate-all; then + echo "Failed to Regenerate all initramfs images" + exit 1 fi [[ $(uname -m) == s390x ]] && zipl &> /dev/null fi From 48d137ffe5c95ed7dfc6d2960646432ce266d51f Mon Sep 17 00:00:00 2001 From: Coiby Xu Date: Thu, 10 Jul 2025 16:36:44 +0800 Subject: [PATCH 11/16] ima-add-sigs: Verify added IMA signature in case the file gets changed Resolves: https://issues.redhat.com/browse/RHEL-100320 Some IMA signatures from the RPM database may fail the verification because they can be changed. For examples, the following files on F41 can't pass IMA signature verification, /usr/lib64/gconv/gconv-modules.cache /boot/grub2/grubenv /var/lib/selinux/targeted/active/commit_num /var/lib/selinux/targeted/active/file_contexts /etc/ssh/sshd_config /etc/yum.repos.d/fedora-updates.repo /etc/yum.repos.d/fedora.repo /etc/group /etc/gshadow The kernel ima=fix mode won't generate IMA hash reference value for files with IMA signature. As a result, users can be denied the access to some files. So remove security.ima if a file fail the verification. --- ima-add-sigs.sh | 39 ++++++++++++++++++++++++++++++++++----- 1 file changed, 34 insertions(+), 5 deletions(-) diff --git a/ima-add-sigs.sh b/ima-add-sigs.sh index 6777d4b..890eacb 100755 --- a/ima-add-sigs.sh +++ b/ima-add-sigs.sh @@ -53,12 +53,35 @@ abort() { exit 1 } +get_system_ima_key() { + source /etc/os-release + local -A name_map=(['Fedora Linux']="fedora" ['Red Hat Enterprise Linux']="redhatimarelease" ['CentOS Stream']='centosimarelease') + local version_id + key_name=${name_map[$NAME]} + version_id=${VERSION_ID/.?/} + + [[ $key_name == fedora ]] && name_suffix=-ima + key_path=/etc/keys/ima/${key_name}-${version_id}${name_suffix}.der + if [[ ! -e $key_path ]]; then + echo "Failed to get system IMA code verification key" + exit 1 + fi + + echo -n "$key_path" +} + # Add IMA signatures from RPM database add_from_rpm_db() { if ! command -v setfattr &>/dev/null; then abort "Please install attr" fi + if [[ -e "$ima_cert" ]]; then + verify_ima_cert=$ima_cert + else + verify_ima_cert=$(get_system_ima_key) + fi + # use "|" as deliminator since it won't be used in a filename or signature while IFS="|" read -r path sig; do # [[ -z "$sig" ]] somehow doesn't work for some files that don't have IMA @@ -72,16 +95,22 @@ add_from_rpm_db() { continue fi + # Skip some files that are created on the fly + if [[ $path == "/usr/share/mime/"* || $path == "/etc/pki/ca-trust/extracted/"* ]]; then + continue + fi + if ! setfattr -n security.ima "$path" -v "0x$sig"; then echo "Failed to add IMA sig for $path" fi - [[ -e "$ima_cert" ]] || continue - # TODO - # don't verify the modified files like /etc? - if ! evmctl ima_verify -k "$ima_cert" "$path" &>/dev/null; then - echo "Failed to verify $path" + if ! evmctl ima_verify -k "$verify_ima_cert" "$path" &>/dev/null; then + setfattr -x security.ima "$path" + # When ima_cert is set, shows the verfication result for users + [[ -e "$ima_cert" ]] && "Failed to verify $path" + continue fi + done < <(rpm -q --queryformat "[%{FILENAMES}|%{FILESIGNATURES}\n]" "$package") } From 6f19220bcc3c5061ac44dd37f9e7abb1c8620a79 Mon Sep 17 00:00:00 2001 From: Coiby Xu Date: Fri, 25 Jul 2025 09:11:06 +0800 Subject: [PATCH 12/16] Fix shellcheck warning and typos Fix the following shellcheck warning, In ima-add-sigs.sh line 135: unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{SIGPGP:pgpsig}\n" "$package" | grep "^(none)$" | wc -l) ^-------------^ SC2126 (style): Consider using 'grep -c' instead of 'grep|wc -l'. Also fix two typos. Signed-off-by: Coiby Xu --- ima-add-sigs.sh | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/ima-add-sigs.sh b/ima-add-sigs.sh index 890eacb..6be5c48 100755 --- a/ima-add-sigs.sh +++ b/ima-add-sigs.sh @@ -4,7 +4,7 @@ usage() { echo "Add IMA signatures to installed packages." cat <reinstall_threshold package missing IMA signatures. - --ima-cert + --ima_cert With the signing IMA cert path specified, it will also try to verify the added IMA signature. @@ -132,7 +132,7 @@ if [[ -z $reinstall_threshold ]]; then fi fi -unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{SIGPGP:pgpsig}\n" "$package" | grep "^(none)$" | wc -l) +unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{SIGPGP:pgpsig}\n" "$package" | grep -c "^(none)$") if [[ $unsigned_packages_in_rpm_db -ge $reinstall_threshold ]]; then add_by_reinstall From 47853f2cf6575812d28093b750be2f2e897c153d Mon Sep 17 00:00:00 2001 From: Coiby Xu Date: Thu, 16 Oct 2025 17:29:52 +0800 Subject: [PATCH 13/16] Use RSAHEADER to tell if a package has been signed Packages now use RPM v4 signature %{RSAHEADER}. %{SIGPGP} is the name of the RPM v3 header+payload signature and can't be used to tell if a package has been signed, # uname -r 6.16.10-200.fc42.x86_64 # rpm -q --queryformat "%{SIGPGP:pgpsig}\n" --all|grep -c "^(none)$" 586 # rpm -q --queryformat "%{RSAHEADER}\n" --all|grep -c "^(none)$" 5 Signed-off-by: Coiby Xu --- ima-add-sigs.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ima-add-sigs.sh b/ima-add-sigs.sh index 6be5c48..f0e9dd0 100755 --- a/ima-add-sigs.sh +++ b/ima-add-sigs.sh @@ -132,7 +132,7 @@ if [[ -z $reinstall_threshold ]]; then fi fi -unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{SIGPGP:pgpsig}\n" "$package" | grep -c "^(none)$") +unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{RSAHEADER}\n" "$package" | grep -c "^(none)$") if [[ $unsigned_packages_in_rpm_db -ge $reinstall_threshold ]]; then add_by_reinstall From 7e1ffed77c9c75a3068cffd4ecd10cc2d7984cf3 Mon Sep 17 00:00:00 2001 From: Coiby Xu Date: Mon, 27 Oct 2025 11:48:53 +0800 Subject: [PATCH 14/16] Allow packit to make and propose a build Currently, only users with commit access to the dist-git repo can make and propose a build. But packit doesn't have commit access to the repo. So explicitly allow packit to do make and propose a build. Fixes: e962d0c ("Use packit to automate ima-evm-utils releasing") Signed-off-by: Coiby Xu --- .packit.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.packit.yaml b/.packit.yaml index 3360032..a97cb7f 100644 --- a/.packit.yaml +++ b/.packit.yaml @@ -23,12 +23,12 @@ jobs: # PR in src.fedoraproject.org been merged. - job: koji_build trigger: commit - allowed_pr_authors: ["all_committers"] + allowed_pr_authors: ["all_committers", "packit"] dist_git_branches: - fedora-all # This is triggered at Fedora messaging bus about koji build finished. - job: bodhi_update trigger: commit - allowed_builders: ["all_committers"] + allowed_builders: ["all_committers", "packit"] dist_git_branches: From 3d7171c676d2290952cf481fae31ed0a347a3344 Mon Sep 17 00:00:00 2001 From: Coiby Xu Date: Thu, 16 Oct 2025 17:36:34 +0800 Subject: [PATCH 15/16] Release 1.6.2-7 Signed-off-by: Coiby Xu --- ima-evm-utils.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/ima-evm-utils.spec b/ima-evm-utils.spec index d8add48..49588a3 100644 --- a/ima-evm-utils.spec +++ b/ima-evm-utils.spec @@ -8,7 +8,7 @@ Name: ima-evm-utils Version: 1.6.2 -Release: 6%{?dist} +Release: 7%{?dist} Summary: IMA/EVM support utilities License: GPL-2.0-or-later Url: https://github.com/linux-integrity/ @@ -145,6 +145,9 @@ install -D %{SOURCE4} $RPM_BUILD_ROOT%{_bindir}/ima-setup %{_libdir}/libimaevm.so %changelog +* Thu Oct 16 2025 Coiby Xu - 1.6.2-7 +- Use RSAHEADER to tell if a package has been signedn + * Thu Jul 24 2025 Fedora Release Engineering - 1.6.2-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild From 667e783b37838ccb6a2cb2198a22f280b2bb5548 Mon Sep 17 00:00:00 2001 From: Coiby Xu Date: Mon, 27 Oct 2025 12:25:09 +0800 Subject: [PATCH 16/16] Fix a typo in changelog Signed-off-by: Coiby Xu --- ima-evm-utils.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ima-evm-utils.spec b/ima-evm-utils.spec index 49588a3..29915ec 100644 --- a/ima-evm-utils.spec +++ b/ima-evm-utils.spec @@ -146,7 +146,7 @@ install -D %{SOURCE4} $RPM_BUILD_ROOT%{_bindir}/ima-setup %changelog * Thu Oct 16 2025 Coiby Xu - 1.6.2-7 -- Use RSAHEADER to tell if a package has been signedn +- ima-add-sigs: Use RSAHEADER to tell if a package has been signed * Thu Jul 24 2025 Fedora Release Engineering - 1.6.2-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild