ima: add check for enforced appraise option
authorBruno Meneguele <bmeneg@redhat.com>
Fri, 4 Sep 2020 19:40:57 +0000 (16:40 -0300)
committerMimi Zohar <zohar@linux.ibm.com>
Wed, 9 Sep 2020 02:02:57 +0000 (22:02 -0400)
The "enforce" string is allowed as an option for ima_appraise= kernel
paramenter per kernel-paramenters.txt and should be considered on the
parameter setup checking as a matter of completeness. Also it allows futher
checking on the options being passed by the user.

Signed-off-by: Bruno Meneguele <bmeneg@redhat.com>
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
security/integrity/ima/ima_appraise.c

index 372d163..580b771 100644 (file)
@@ -31,6 +31,8 @@ static int __init default_appraise_setup(char *str)
                ima_appraise = IMA_APPRAISE_LOG;
        else if (strncmp(str, "fix", 3) == 0)
                ima_appraise = IMA_APPRAISE_FIX;
+       else if (strncmp(str, "enforce", 7) == 0)
+               ima_appraise = IMA_APPRAISE_ENFORCE;
 #endif
        return 1;
 }