diff --git a/.gitignore b/.gitignore index 2646509..6d559b3 100644 --- a/.gitignore +++ b/.gitignore @@ -1 +1,2 @@ /ima-evm-utils-*.tar.gz +prepare_sources_result*/ diff --git a/.packit.yaml b/.packit.yaml new file mode 100644 index 0000000..a97cb7f --- /dev/null +++ b/.packit.yaml @@ -0,0 +1,34 @@ +# See the documentation for more information: +# https://packit.dev/docs/configuration/ + +specfile_path: ima-evm-util.spec + +# add or remove files that should be synced +files_to_sync: + - .packit.yaml + +# name in upstream package repository or registry (e.g. in PyPI) +upstream_package_name: ima-evm-utils +# downstream (Fedora) RPM package name +downstream_package_name: ima-evm-utils + +jobs: + # This is triggered by https://release-monitoring.org/ + - job: pull_from_upstream + trigger: release + dist_git_branches: + - fedora-all + + # This is triggered at Fedora dist-git for creating koji build after + # PR in src.fedoraproject.org been merged. + - job: koji_build + trigger: commit + allowed_pr_authors: ["all_committers", "packit"] + dist_git_branches: + - fedora-all + + # This is triggered at Fedora messaging bus about koji build finished. + - job: bodhi_update + trigger: commit + allowed_builders: ["all_committers", "packit"] + dist_git_branches: diff --git a/ima-add-sigs.sh b/ima-add-sigs.sh index 6777d4b..f0e9dd0 100755 --- a/ima-add-sigs.sh +++ b/ima-add-sigs.sh @@ -4,7 +4,7 @@ usage() { echo "Add IMA signatures to installed packages." cat <reinstall_threshold package missing IMA signatures. - --ima-cert + --ima_cert With the signing IMA cert path specified, it will also try to verify the added IMA signature. @@ -53,12 +53,35 @@ abort() { exit 1 } +get_system_ima_key() { + source /etc/os-release + local -A name_map=(['Fedora Linux']="fedora" ['Red Hat Enterprise Linux']="redhatimarelease" ['CentOS Stream']='centosimarelease') + local version_id + key_name=${name_map[$NAME]} + version_id=${VERSION_ID/.?/} + + [[ $key_name == fedora ]] && name_suffix=-ima + key_path=/etc/keys/ima/${key_name}-${version_id}${name_suffix}.der + if [[ ! -e $key_path ]]; then + echo "Failed to get system IMA code verification key" + exit 1 + fi + + echo -n "$key_path" +} + # Add IMA signatures from RPM database add_from_rpm_db() { if ! command -v setfattr &>/dev/null; then abort "Please install attr" fi + if [[ -e "$ima_cert" ]]; then + verify_ima_cert=$ima_cert + else + verify_ima_cert=$(get_system_ima_key) + fi + # use "|" as deliminator since it won't be used in a filename or signature while IFS="|" read -r path sig; do # [[ -z "$sig" ]] somehow doesn't work for some files that don't have IMA @@ -72,16 +95,22 @@ add_from_rpm_db() { continue fi + # Skip some files that are created on the fly + if [[ $path == "/usr/share/mime/"* || $path == "/etc/pki/ca-trust/extracted/"* ]]; then + continue + fi + if ! setfattr -n security.ima "$path" -v "0x$sig"; then echo "Failed to add IMA sig for $path" fi - [[ -e "$ima_cert" ]] || continue - # TODO - # don't verify the modified files like /etc? - if ! evmctl ima_verify -k "$ima_cert" "$path" &>/dev/null; then - echo "Failed to verify $path" + if ! evmctl ima_verify -k "$verify_ima_cert" "$path" &>/dev/null; then + setfattr -x security.ima "$path" + # When ima_cert is set, shows the verfication result for users + [[ -e "$ima_cert" ]] && "Failed to verify $path" + continue fi + done < <(rpm -q --queryformat "[%{FILENAMES}|%{FILESIGNATURES}\n]" "$package") } @@ -103,7 +132,7 @@ if [[ -z $reinstall_threshold ]]; then fi fi -unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{SIGPGP:pgpsig}\n" "$package" | grep "^(none)$" | wc -l) +unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{RSAHEADER}\n" "$package" | grep -c "^(none)$") if [[ $unsigned_packages_in_rpm_db -ge $reinstall_threshold ]]; then add_by_reinstall diff --git a/ima-evm-utils.spec b/ima-evm-utils.spec index f05d7ac..29915ec 100644 --- a/ima-evm-utils.spec +++ b/ima-evm-utils.spec @@ -8,7 +8,7 @@ Name: ima-evm-utils Version: 1.6.2 -Release: 4%{?dist} +Release: 7%{?dist} Summary: IMA/EVM support utilities License: GPL-2.0-or-later Url: https://github.com/linux-integrity/ @@ -145,6 +145,15 @@ install -D %{SOURCE4} $RPM_BUILD_ROOT%{_bindir}/ima-setup %{_libdir}/libimaevm.so %changelog +* Thu Oct 16 2025 Coiby Xu - 1.6.2-7 +- ima-add-sigs: Use RSAHEADER to tell if a package has been signed + +* Thu Jul 24 2025 Fedora Release Engineering - 1.6.2-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + +* Mon Mar 03 2025 Coiby Xu - 1.6.2-5 +- release 1.6.2-5 + * Fri Jan 17 2025 Fedora Release Engineering - 1.6.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild diff --git a/ima-setup.sh b/ima-setup.sh index 8e773ad..1450c0a 100755 --- a/ima-setup.sh +++ b/ima-setup.sh @@ -33,7 +33,7 @@ for _opt in "$@"; do --policy=*) ima_policy_path=${_opt#*=} if [[ ! -e $ima_policy_path ]]; then - echo "$policy_file doesn't exist" + echo "$ima_policy_path doesn't exist" exit 1 fi ;; @@ -55,7 +55,7 @@ if test -f /run/ostree-booted; then echo "You are using OSTree, please enable IMA signatures as part of the OSTree creation process." else echo "Adding IMA signatures to installed package files" - if ! ima-add-sigs; then + if ! ima-add-sigs --reinstall_threshold="$reinstall_threshold"; then echo "Failed to add IMA signatures, abort" exit 1 fi @@ -120,17 +120,12 @@ load_ima_keys # automatically when there is a system reboot if ! lsinitrd --mod | grep -q integrity; then cp --preserve=xattr /usr/share/ima/dracut-98-integrity.conf /etc/dracut.conf.d/98-integrity.conf - echo "Rebuilding the initramfs of kernel-$(uname -r) to include the dracut integrity module" - dracut -f - - if command -v grubby >/dev/null; then - _default_kernel=$(grubby --default-kernel | sed -En "s/.*vmlinuz-(.*)/\1/p") - if [[ $_default_kernel != $(uname -r) ]]; then - echo "Current kernel is no the default kernel ($_default_kernel), include dracut integrity for it as well" - dracut -f --kver "$_default_kernel" - fi + echo "Regenerating all initramfs images to include the dracut integrity module" + if ! dracut -f --regenerate-all; then + echo "Failed to Regenerate all initramfs images" + exit 1 fi - + [[ $(uname -m) == s390x ]] && zipl &> /dev/null fi if ! load_ima_policy "$ima_policy_path"; then