Compare commits

..

14 commits

Author SHA1 Message Date
Coiby Xu
667e783b37 Fix a typo in changelog
Signed-off-by: Coiby Xu <coxu@redhat.com>
2025-10-27 12:25:09 +08:00
Coiby Xu
3d7171c676 Release 1.6.2-7
Signed-off-by: Coiby Xu <coxu@redhat.com>
2025-10-27 11:53:12 +08:00
Coiby Xu
7e1ffed77c Allow packit to make and propose a build
Currently, only users with commit access to the dist-git repo can make
and propose a build. But packit doesn't have commit access to the repo.
So explicitly allow packit to do make and propose a build.

Fixes: e962d0c ("Use packit to automate ima-evm-utils releasing")
Signed-off-by: Coiby Xu <coxu@redhat.com>
2025-10-27 11:53:12 +08:00
Coiby Xu
47853f2cf6 Use RSAHEADER to tell if a package has been signed
Packages now use RPM v4 signature %{RSAHEADER}. %{SIGPGP} is the name
of the RPM v3 header+payload signature and can't be used to tell if
a package has been signed,

    # uname -r
    6.16.10-200.fc42.x86_64
    # rpm -q --queryformat "%{SIGPGP:pgpsig}\n" --all|grep -c "^(none)$"
    586
    # rpm -q --queryformat "%{RSAHEADER}\n" --all|grep -c "^(none)$"
    5

Signed-off-by: Coiby Xu <coxu@redhat.com>
2025-10-16 17:35:31 +08:00
Coiby Xu
73f30b71db Merge #10 ima-add-sigs: Verify added IMA signature in case the file gets changed 2025-07-31 01:08:04 +00:00
Coiby Xu
aeb208fd06 Merge #9 ima-setup: rebuild all initramfs images to include the integrity dracut module 2025-07-28 01:31:56 +00:00
Coiby Xu
6f19220bcc Fix shellcheck warning and typos
Fix the following shellcheck warning,
    In ima-add-sigs.sh line 135:
    unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{SIGPGP:pgpsig}\n" "$package" | grep "^(none)$" | wc -l)
                                                                                     ^-------------^ SC2126 (style): Consider using 'grep -c' instead of 'grep|wc -l'.
Also fix two typos.

Signed-off-by: Coiby Xu <coxu@redhat.com>
2025-07-25 09:27:54 +08:00
Coiby Xu
48d137ffe5 ima-add-sigs: Verify added IMA signature in case the file gets changed
Resolves: https://issues.redhat.com/browse/RHEL-100320

Some IMA signatures from the RPM database may fail the verification
because they can be changed. For examples, the following files on F41
can't pass IMA signature verification,

    /usr/lib64/gconv/gconv-modules.cache
    /boot/grub2/grubenv
    /var/lib/selinux/targeted/active/commit_num
    /var/lib/selinux/targeted/active/file_contexts
    /etc/ssh/sshd_config
    /etc/yum.repos.d/fedora-updates.repo
    /etc/yum.repos.d/fedora.repo
    /etc/group
    /etc/gshadow

The kernel ima=fix mode won't generate IMA hash reference value for
files with IMA signature. As a result, users can be denied the access to
some files. So remove security.ima if a file fail the verification.
2025-07-25 09:26:55 +08:00
Coiby Xu
ac36e54bee ima-setup: rebuild all initramfs images to include the integrity dracut module
Resolves: https://issues.redhat.com/browse/RHEL-92638

Quoting Raju,
  ima-setup currently only rebuild the initramfs of running kernel, so
  the older kernel's(n-1 or n-2) initramfs does contain an outdated
  information or it does not contain ima module, as a result the system
  fails to boot with older kernel.

  It is always recommended to have at least 2 older kernel's kept
  installed on the system as a fallback option in case if the latest
  kernel fails to boot due to some unforeseen issue. So that we can boot
  the system with older kernel to troubleshoot the can't boot issue with
  older kernel.

Suggested-by: Raju Cheerla <rcheerla@redhat.com>
2025-07-25 09:20:41 +08:00
Fedora Release Engineering
aed78ac85f Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild 2025-07-24 17:36:58 +00:00
Coiby Xu
c68b187d3e Release 1.6.2-5 2025-03-03 10:12:46 +08:00
Coiby Xu
e962d0cac4 Use packit to automate ima-evm-utils releasing
Follow [1] to use packit to automate releasing ima-evm-utils. After finishing
one-time setting up, when there is a new upstream release, here's the
new process of releasing a new version in Fedora,

1. https://release-monitoring.org/ finds a new upstream and notify
   packit

2. packit: automatically create PRs to propose new release for different
   Fedora releases;  also upload new tarballs into lookaside cache.

3. Maintainer: review(, modify) and merge the PR

4. packit: create a koji build

5. packit: create a Bodhi update

So maintainers only need to do step 3 manually and all the repetitive
work can be left to packit to handle.

After the PR gets merged, two more things need to be done [2],
 - Create a Fedora mapping for the upstream project in
   https://release-monitoring.org/projects
 - Set Monitoring status on the left side at
   https://src.fedoraproject.org/rpms/ima-evm-utils to Monitoring

[1] https://packit.dev/docs/fedora-releases-guide/dist-git-onboarding
[2] https://packit.dev/docs/fedora-releases-guide/dist-git-onboarding#2-monitoring-of-the-package

Signed-off-by: Coiby Xu <coxu@redhat.com>
2025-03-03 10:12:16 +08:00
Coiby Xu
7b800d82d0 ima-setup: fix two shellcheck warnings
Fix the following two shellcheck warnings,

    In ima-setup.sh line 36:
                            echo "$policy_file doesn't exist"
                                  ^----------^ SC2154 (warning): policy_file is referenced but not assigned.

    In ima-setup.sh line 41:
                    reinstall_threshold=${_opt#*=}
                    ^-----------------^ SC2034 (warning): reinstall_threshold appears unused. Verify use (or export if used externally).

Signed-off-by: Coiby Xu <coxu@redhat.com>
2025-02-25 13:25:15 +08:00
Coiby Xu
2f1870b21a ima-setup: run zipl after building initramfs for s390x
Resovles: https://issues.redhat.com/browse/RHEL-74293

Without running zipl, the old initramfs will be booted.

Signed-off-by: Coiby Xu <coxu@redhat.com>
2025-02-25 13:19:14 +08:00
5 changed files with 89 additions and 21 deletions

1
.gitignore vendored
View file

@ -1 +1,2 @@
/ima-evm-utils-*.tar.gz
prepare_sources_result*/

34
.packit.yaml Normal file
View file

@ -0,0 +1,34 @@
# See the documentation for more information:
# https://packit.dev/docs/configuration/
specfile_path: ima-evm-util.spec
# add or remove files that should be synced
files_to_sync:
- .packit.yaml
# name in upstream package repository or registry (e.g. in PyPI)
upstream_package_name: ima-evm-utils
# downstream (Fedora) RPM package name
downstream_package_name: ima-evm-utils
jobs:
# This is triggered by https://release-monitoring.org/
- job: pull_from_upstream
trigger: release
dist_git_branches:
- fedora-all
# This is triggered at Fedora dist-git for creating koji build after
# PR in src.fedoraproject.org been merged.
- job: koji_build
trigger: commit
allowed_pr_authors: ["all_committers", "packit"]
dist_git_branches:
- fedora-all
# This is triggered at Fedora messaging bus about koji build finished.
- job: bodhi_update
trigger: commit
allowed_builders: ["all_committers", "packit"]
dist_git_branches:

View file

@ -4,7 +4,7 @@
usage() {
echo "Add IMA signatures to installed packages."
cat <<EOF
usage: $0 [--package=PACKAGE_NAME|ALL] [--ima-cert=IMA_CERT_PATH] [--reinstall_threshold=NUM]
usage: $0 [--package=PACKAGE_NAME|ALL] [--ima_cert=IMA_CERT_PATH] [--reinstall_threshold=NUM]
--package
By default, it will add IMA sigantures to all installed package files.
@ -19,7 +19,7 @@ usage: $0 [--package=PACKAGE_NAME|ALL] [--ima-cert=IMA_CERT_PATH] [--reinstall_t
this case by checking if there are >reinstall_threshold package missing
IMA signatures.
--ima-cert
--ima_cert
With the signing IMA cert path specified, it will also try to verify the
added IMA signature.
@ -53,12 +53,35 @@ abort() {
exit 1
}
get_system_ima_key() {
source /etc/os-release
local -A name_map=(['Fedora Linux']="fedora" ['Red Hat Enterprise Linux']="redhatimarelease" ['CentOS Stream']='centosimarelease')
local version_id
key_name=${name_map[$NAME]}
version_id=${VERSION_ID/.?/}
[[ $key_name == fedora ]] && name_suffix=-ima
key_path=/etc/keys/ima/${key_name}-${version_id}${name_suffix}.der
if [[ ! -e $key_path ]]; then
echo "Failed to get system IMA code verification key"
exit 1
fi
echo -n "$key_path"
}
# Add IMA signatures from RPM database
add_from_rpm_db() {
if ! command -v setfattr &>/dev/null; then
abort "Please install attr"
fi
if [[ -e "$ima_cert" ]]; then
verify_ima_cert=$ima_cert
else
verify_ima_cert=$(get_system_ima_key)
fi
# use "|" as deliminator since it won't be used in a filename or signature
while IFS="|" read -r path sig; do
# [[ -z "$sig" ]] somehow doesn't work for some files that don't have IMA
@ -72,16 +95,22 @@ add_from_rpm_db() {
continue
fi
# Skip some files that are created on the fly
if [[ $path == "/usr/share/mime/"* || $path == "/etc/pki/ca-trust/extracted/"* ]]; then
continue
fi
if ! setfattr -n security.ima "$path" -v "0x$sig"; then
echo "Failed to add IMA sig for $path"
fi
[[ -e "$ima_cert" ]] || continue
# TODO
# don't verify the modified files like /etc?
if ! evmctl ima_verify -k "$ima_cert" "$path" &>/dev/null; then
echo "Failed to verify $path"
if ! evmctl ima_verify -k "$verify_ima_cert" "$path" &>/dev/null; then
setfattr -x security.ima "$path"
# When ima_cert is set, shows the verfication result for users
[[ -e "$ima_cert" ]] && "Failed to verify $path"
continue
fi
done < <(rpm -q --queryformat "[%{FILENAMES}|%{FILESIGNATURES}\n]" "$package")
}
@ -103,7 +132,7 @@ if [[ -z $reinstall_threshold ]]; then
fi
fi
unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{SIGPGP:pgpsig}\n" "$package" | grep "^(none)$" | wc -l)
unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{RSAHEADER}\n" "$package" | grep -c "^(none)$")
if [[ $unsigned_packages_in_rpm_db -ge $reinstall_threshold ]]; then
add_by_reinstall

View file

@ -8,7 +8,7 @@
Name: ima-evm-utils
Version: 1.6.2
Release: 4%{?dist}
Release: 7%{?dist}
Summary: IMA/EVM support utilities
License: GPL-2.0-or-later
Url: https://github.com/linux-integrity/
@ -145,6 +145,15 @@ install -D %{SOURCE4} $RPM_BUILD_ROOT%{_bindir}/ima-setup
%{_libdir}/libimaevm.so
%changelog
* Thu Oct 16 2025 Coiby Xu <coxu@redhat.com> - 1.6.2-7
- ima-add-sigs: Use RSAHEADER to tell if a package has been signed
* Thu Jul 24 2025 Fedora Release Engineering <releng@fedoraproject.org> - 1.6.2-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Mon Mar 03 2025 Coiby Xu <coxu@redhat.com> - 1.6.2-5
- release 1.6.2-5
* Fri Jan 17 2025 Fedora Release Engineering <releng@fedoraproject.org> - 1.6.2-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild

View file

@ -33,7 +33,7 @@ for _opt in "$@"; do
--policy=*)
ima_policy_path=${_opt#*=}
if [[ ! -e $ima_policy_path ]]; then
echo "$policy_file doesn't exist"
echo "$ima_policy_path doesn't exist"
exit 1
fi
;;
@ -55,7 +55,7 @@ if test -f /run/ostree-booted; then
echo "You are using OSTree, please enable IMA signatures as part of the OSTree creation process."
else
echo "Adding IMA signatures to installed package files"
if ! ima-add-sigs; then
if ! ima-add-sigs --reinstall_threshold="$reinstall_threshold"; then
echo "Failed to add IMA signatures, abort"
exit 1
fi
@ -120,17 +120,12 @@ load_ima_keys
# automatically when there is a system reboot
if ! lsinitrd --mod | grep -q integrity; then
cp --preserve=xattr /usr/share/ima/dracut-98-integrity.conf /etc/dracut.conf.d/98-integrity.conf
echo "Rebuilding the initramfs of kernel-$(uname -r) to include the dracut integrity module"
dracut -f
if command -v grubby >/dev/null; then
_default_kernel=$(grubby --default-kernel | sed -En "s/.*vmlinuz-(.*)/\1/p")
if [[ $_default_kernel != $(uname -r) ]]; then
echo "Current kernel is no the default kernel ($_default_kernel), include dracut integrity for it as well"
dracut -f --kver "$_default_kernel"
fi
echo "Regenerating all initramfs images to include the dracut integrity module"
if ! dracut -f --regenerate-all; then
echo "Failed to Regenerate all initramfs images"
exit 1
fi
[[ $(uname -m) == s390x ]] && zipl &> /dev/null
fi
if ! load_ima_policy "$ima_policy_path"; then