Compare commits

..

No commits in common. "rawhide" and "f42" have entirely different histories.

5 changed files with 21 additions and 89 deletions

1
.gitignore vendored
View file

@ -1,2 +1 @@
/ima-evm-utils-*.tar.gz
prepare_sources_result*/

View file

@ -1,34 +0,0 @@
# See the documentation for more information:
# https://packit.dev/docs/configuration/
specfile_path: ima-evm-util.spec
# add or remove files that should be synced
files_to_sync:
- .packit.yaml
# name in upstream package repository or registry (e.g. in PyPI)
upstream_package_name: ima-evm-utils
# downstream (Fedora) RPM package name
downstream_package_name: ima-evm-utils
jobs:
# This is triggered by https://release-monitoring.org/
- job: pull_from_upstream
trigger: release
dist_git_branches:
- fedora-all
# This is triggered at Fedora dist-git for creating koji build after
# PR in src.fedoraproject.org been merged.
- job: koji_build
trigger: commit
allowed_pr_authors: ["all_committers", "packit"]
dist_git_branches:
- fedora-all
# This is triggered at Fedora messaging bus about koji build finished.
- job: bodhi_update
trigger: commit
allowed_builders: ["all_committers", "packit"]
dist_git_branches:

View file

@ -4,7 +4,7 @@
usage() {
echo "Add IMA signatures to installed packages."
cat <<EOF
usage: $0 [--package=PACKAGE_NAME|ALL] [--ima_cert=IMA_CERT_PATH] [--reinstall_threshold=NUM]
usage: $0 [--package=PACKAGE_NAME|ALL] [--ima-cert=IMA_CERT_PATH] [--reinstall_threshold=NUM]
--package
By default, it will add IMA sigantures to all installed package files.
@ -19,7 +19,7 @@ usage: $0 [--package=PACKAGE_NAME|ALL] [--ima_cert=IMA_CERT_PATH] [--reinstall_t
this case by checking if there are >reinstall_threshold package missing
IMA signatures.
--ima_cert
--ima-cert
With the signing IMA cert path specified, it will also try to verify the
added IMA signature.
@ -53,35 +53,12 @@ abort() {
exit 1
}
get_system_ima_key() {
source /etc/os-release
local -A name_map=(['Fedora Linux']="fedora" ['Red Hat Enterprise Linux']="redhatimarelease" ['CentOS Stream']='centosimarelease')
local version_id
key_name=${name_map[$NAME]}
version_id=${VERSION_ID/.?/}
[[ $key_name == fedora ]] && name_suffix=-ima
key_path=/etc/keys/ima/${key_name}-${version_id}${name_suffix}.der
if [[ ! -e $key_path ]]; then
echo "Failed to get system IMA code verification key"
exit 1
fi
echo -n "$key_path"
}
# Add IMA signatures from RPM database
add_from_rpm_db() {
if ! command -v setfattr &>/dev/null; then
abort "Please install attr"
fi
if [[ -e "$ima_cert" ]]; then
verify_ima_cert=$ima_cert
else
verify_ima_cert=$(get_system_ima_key)
fi
# use "|" as deliminator since it won't be used in a filename or signature
while IFS="|" read -r path sig; do
# [[ -z "$sig" ]] somehow doesn't work for some files that don't have IMA
@ -95,22 +72,16 @@ add_from_rpm_db() {
continue
fi
# Skip some files that are created on the fly
if [[ $path == "/usr/share/mime/"* || $path == "/etc/pki/ca-trust/extracted/"* ]]; then
continue
fi
if ! setfattr -n security.ima "$path" -v "0x$sig"; then
echo "Failed to add IMA sig for $path"
fi
if ! evmctl ima_verify -k "$verify_ima_cert" "$path" &>/dev/null; then
setfattr -x security.ima "$path"
# When ima_cert is set, shows the verfication result for users
[[ -e "$ima_cert" ]] && "Failed to verify $path"
continue
[[ -e "$ima_cert" ]] || continue
# TODO
# don't verify the modified files like /etc?
if ! evmctl ima_verify -k "$ima_cert" "$path" &>/dev/null; then
echo "Failed to verify $path"
fi
done < <(rpm -q --queryformat "[%{FILENAMES}|%{FILESIGNATURES}\n]" "$package")
}
@ -132,7 +103,7 @@ if [[ -z $reinstall_threshold ]]; then
fi
fi
unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{RSAHEADER}\n" "$package" | grep -c "^(none)$")
unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{SIGPGP:pgpsig}\n" "$package" | grep "^(none)$" | wc -l)
if [[ $unsigned_packages_in_rpm_db -ge $reinstall_threshold ]]; then
add_by_reinstall

View file

@ -8,7 +8,7 @@
Name: ima-evm-utils
Version: 1.6.2
Release: 7%{?dist}
Release: 4%{?dist}
Summary: IMA/EVM support utilities
License: GPL-2.0-or-later
Url: https://github.com/linux-integrity/
@ -145,15 +145,6 @@ install -D %{SOURCE4} $RPM_BUILD_ROOT%{_bindir}/ima-setup
%{_libdir}/libimaevm.so
%changelog
* Thu Oct 16 2025 Coiby Xu <coxu@redhat.com> - 1.6.2-7
- ima-add-sigs: Use RSAHEADER to tell if a package has been signed
* Thu Jul 24 2025 Fedora Release Engineering <releng@fedoraproject.org> - 1.6.2-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Mon Mar 03 2025 Coiby Xu <coxu@redhat.com> - 1.6.2-5
- release 1.6.2-5
* Fri Jan 17 2025 Fedora Release Engineering <releng@fedoraproject.org> - 1.6.2-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild

View file

@ -33,7 +33,7 @@ for _opt in "$@"; do
--policy=*)
ima_policy_path=${_opt#*=}
if [[ ! -e $ima_policy_path ]]; then
echo "$ima_policy_path doesn't exist"
echo "$policy_file doesn't exist"
exit 1
fi
;;
@ -55,7 +55,7 @@ if test -f /run/ostree-booted; then
echo "You are using OSTree, please enable IMA signatures as part of the OSTree creation process."
else
echo "Adding IMA signatures to installed package files"
if ! ima-add-sigs --reinstall_threshold="$reinstall_threshold"; then
if ! ima-add-sigs; then
echo "Failed to add IMA signatures, abort"
exit 1
fi
@ -120,12 +120,17 @@ load_ima_keys
# automatically when there is a system reboot
if ! lsinitrd --mod | grep -q integrity; then
cp --preserve=xattr /usr/share/ima/dracut-98-integrity.conf /etc/dracut.conf.d/98-integrity.conf
echo "Regenerating all initramfs images to include the dracut integrity module"
if ! dracut -f --regenerate-all; then
echo "Failed to Regenerate all initramfs images"
exit 1
echo "Rebuilding the initramfs of kernel-$(uname -r) to include the dracut integrity module"
dracut -f
if command -v grubby >/dev/null; then
_default_kernel=$(grubby --default-kernel | sed -En "s/.*vmlinuz-(.*)/\1/p")
if [[ $_default_kernel != $(uname -r) ]]; then
echo "Current kernel is no the default kernel ($_default_kernel), include dracut integrity for it as well"
dracut -f --kver "$_default_kernel"
fi
fi
[[ $(uname -m) == s390x ]] && zipl &> /dev/null
fi
if ! load_ima_policy "$ima_policy_path"; then