xref: /linux/Documentation/ABI/testing/ima_policy (revision 4d7d9486c04d917265f64c55bd23b2cc4fe7749c)
118e49b30SMauro Carvalho ChehabWhat:		/sys/kernel/security/*/ima/policy
24af4662fSMimi ZoharDate:		May 2008
34af4662fSMimi ZoharContact:	Mimi Zohar <zohar@us.ibm.com>
44af4662fSMimi ZoharDescription:
54af4662fSMimi Zohar		The Trusted Computing Group(TCG) runtime Integrity
64af4662fSMimi Zohar		Measurement Architecture(IMA) maintains a list of hash
74af4662fSMimi Zohar		values of executables and other sensitive system files
84af4662fSMimi Zohar		loaded into the run-time of this system.  At runtime,
94af4662fSMimi Zohar		the policy can be constrained based on LSM specific data.
104af4662fSMimi Zohar		Policies are loaded into the securityfs file ima/policy
114af4662fSMimi Zohar		by opening the file, writing the rules one at a time and
124af4662fSMimi Zohar		then closing the file.  The new policy takes effect after
134af4662fSMimi Zohar		the file ima/policy is closed.
144af4662fSMimi Zohar
1507f6a794SMimi Zohar		IMA appraisal, if configured, uses these file measurements
1607f6a794SMimi Zohar		for local measurement appraisal.
1707f6a794SMimi Zohar
1834433332SMauro Carvalho Chehab		::
1934433332SMauro Carvalho Chehab
204af4662fSMimi Zohar		  rule format: action [condition ...]
214af4662fSMimi Zohar
22da1b0029SMimi Zohar		  action: measure | dont_measure | appraise | dont_appraise |
23345123d6SJann Horn			  audit | dont_audit | hash | dont_hash
240e5a247cSDmitry Kasatkin		  condition:= base | lsm  [option]
2540224c41SCurtis Veit			base:	[[func=] [mask=] [fsmagic=] [fsuuid=] [fsname=]
2643369273SJann Horn				[fs_subtype=]
2740224c41SCurtis Veit				[uid=] [euid=] [gid=] [egid=]
2840224c41SCurtis Veit				[fowner=] [fgroup=]]
294af4662fSMimi Zohar			lsm:	[[subj_user=] [subj_role=] [subj_type=]
304af4662fSMimi Zohar				 [obj_user=] [obj_role=] [obj_type=]]
3154f03916SMimi Zohar			option:	[digest_type=] [template=] [permit_directio]
3254f03916SMimi Zohar				[appraise_type=] [appraise_flag=]
3354f03916SMimi Zohar				[appraise_algos=] [keyrings=]
3434433332SMauro Carvalho Chehab		  base:
35c418eed8SMichael Weiß			func:= [BPRM_CHECK][MMAP_CHECK][CREDS_CHECK][FILE_CHECK][MODULE_CHECK]
365a9196d7SMimi Zohar				[FIRMWARE_CHECK]
37d9ddf077SMimi Zohar				[KEXEC_KERNEL_CHECK] [KEXEC_INITRAMFS_CHECK]
38c4e43aa2STushar Sugandhi				[KEXEC_CMDLINE] [KEY_CHECK] [CRITICAL_DATA]
394958db32SRoberto Sassu				[SETXATTR_CHECK][MMAP_CHECK_REQPROT]
404351c294SMimi Zohar			mask:= [[^]MAY_READ] [[^]MAY_WRITE] [[^]MAY_APPEND]
414351c294SMimi Zohar			       [[^]MAY_EXEC]
424af4662fSMimi Zohar			fsmagic:= hex value
4385865c1fSDmitry Kasatkin			fsuuid:= file system UUID (e.g 8bcbe394-4f13-4144-be8e-5aa9ea2ce2f6)
444af4662fSMimi Zohar			uid:= decimal value
45139069efSMimi Zohar			euid:= decimal value
4640224c41SCurtis Veit			gid:= decimal value
4740224c41SCurtis Veit			egid:= decimal value
4807f6a794SMimi Zohar			fowner:= decimal value
4940224c41SCurtis Veit			fgroup:= decimal value
504af4662fSMimi Zohar		  lsm:  are LSM specific
5134433332SMauro Carvalho Chehab		  option:
52398c42e2SMimi Zohar			appraise_type:= [imasig] | [imasig|modsig] | [sigv3]
53398c42e2SMimi Zohar			    where 'imasig' is the original or the signature
54398c42e2SMimi Zohar				format v2.
55398c42e2SMimi Zohar			    where 'modsig' is an appended signature,
56de4c44a7SMimi Zohar			    where 'sigv3' is the signature format v3.
57398c42e2SMimi Zohar
58f20765fdSEric Snowberg			appraise_flag:= [check_blacklist] (deprecated)
59f20765fdSEric Snowberg			Setting the check_blacklist flag is no longer necessary.
60f20765fdSEric Snowberg			All appraisal functions set it by default.
6154f03916SMimi Zohar			digest_type:= verity
6254f03916SMimi Zohar			    Require fs-verity's file digest instead of the
6354f03916SMimi Zohar			    regular IMA file hash.
64e9085e0aSLakshmi Ramasubramanian			keyrings:= list of keyrings
65e9085e0aSLakshmi Ramasubramanian			(eg, .builtin_trusted_keys|.ima). Only valid
66e9085e0aSLakshmi Ramasubramanian			when action is "measure" and func is KEY_CHECK.
6719453ce0SMatthew Garrett			template:= name of a defined IMA template type
6819453ce0SMatthew Garrett			(eg, ima-ng). Only valid when action is "measure".
69fc26bd50SEric Richter			pcr:= decimal value
70b3f82afcSRaphael Gianotti			label:= [selinux]|[kernel_info]|[data_label]
7147d76a48STushar Sugandhi			data_label:= a unique string used for grouping and limiting critical data.
72fdd1ffe8SLakshmi Ramasubramanian			For example, "selinux" to measure critical data for SELinux.
73583a80aeSTHOBY Simon			appraise_algos:= comma-separated list of hash algorithms
74583a80aeSTHOBY Simon			For example, "sha256,sha512" to only accept to appraise
75583a80aeSTHOBY Simon			files where the security.ima xattr was hashed with one
76583a80aeSTHOBY Simon			of these two algorithms.
774af4662fSMimi Zohar
784af4662fSMimi Zohar		  default policy:
794af4662fSMimi Zohar			# PROC_SUPER_MAGIC
804af4662fSMimi Zohar			dont_measure fsmagic=0x9fa0
8107f6a794SMimi Zohar			dont_appraise fsmagic=0x9fa0
824af4662fSMimi Zohar			# SYSFS_MAGIC
834af4662fSMimi Zohar			dont_measure fsmagic=0x62656572
8407f6a794SMimi Zohar			dont_appraise fsmagic=0x62656572
854af4662fSMimi Zohar			# DEBUGFS_MAGIC
864af4662fSMimi Zohar			dont_measure fsmagic=0x64626720
8707f6a794SMimi Zohar			dont_appraise fsmagic=0x64626720
884af4662fSMimi Zohar			# TMPFS_MAGIC
894af4662fSMimi Zohar			dont_measure fsmagic=0x01021994
9007f6a794SMimi Zohar			dont_appraise fsmagic=0x01021994
9107f6a794SMimi Zohar			# RAMFS_MAGIC
9207f6a794SMimi Zohar			dont_appraise fsmagic=0x858458f6
936438de9fSRoberto Sassu			# DEVPTS_SUPER_MAGIC
946438de9fSRoberto Sassu			dont_measure fsmagic=0x1cd1
956438de9fSRoberto Sassu			dont_appraise fsmagic=0x1cd1
966438de9fSRoberto Sassu			# BINFMTFS_MAGIC
976438de9fSRoberto Sassu			dont_measure fsmagic=0x42494e4d
986438de9fSRoberto Sassu			dont_appraise fsmagic=0x42494e4d
994af4662fSMimi Zohar			# SECURITYFS_MAGIC
1004af4662fSMimi Zohar			dont_measure fsmagic=0x73636673
10107f6a794SMimi Zohar			dont_appraise fsmagic=0x73636673
1026438de9fSRoberto Sassu			# SELINUX_MAGIC
1036438de9fSRoberto Sassu			dont_measure fsmagic=0xf97cff8c
1046438de9fSRoberto Sassu			dont_appraise fsmagic=0xf97cff8c
1056438de9fSRoberto Sassu			# CGROUP_SUPER_MAGIC
1066438de9fSRoberto Sassu			dont_measure fsmagic=0x27e0eb
1076438de9fSRoberto Sassu			dont_appraise fsmagic=0x27e0eb
108cd025f7fSMimi Zohar			# NSFS_MAGIC
109cd025f7fSMimi Zohar			dont_measure fsmagic=0x6e736673
110cd025f7fSMimi Zohar			dont_appraise fsmagic=0x6e736673
111*8e22ce50SFrederick Lawler			# CONFIGFS_MAGIC
112*8e22ce50SFrederick Lawler			dont_measure fsmagic=0x62656570
113*8e22ce50SFrederick Lawler			dont_appraise fsmagic=0x62656570
1144af4662fSMimi Zohar
1154af4662fSMimi Zohar			measure func=BPRM_CHECK
1164af4662fSMimi Zohar			measure func=FILE_MMAP mask=MAY_EXEC
1171e93d005SMimi Zohar			measure func=FILE_CHECK mask=MAY_READ uid=0
1185a9196d7SMimi Zohar			measure func=MODULE_CHECK
1195a9196d7SMimi Zohar			measure func=FIRMWARE_CHECK
12007f6a794SMimi Zohar			appraise fowner=0
1214af4662fSMimi Zohar
1224af4662fSMimi Zohar		The default policy measures all executables in bprm_check,
1234af4662fSMimi Zohar		all files mmapped executable in file_mmap, and all files
12407f6a794SMimi Zohar		open for read by root in do_filp_open.  The default appraisal
12507f6a794SMimi Zohar		policy appraises all files owned by root.
1264af4662fSMimi Zohar
1274af4662fSMimi Zohar		Examples of LSM specific definitions:
1284af4662fSMimi Zohar
12934433332SMauro Carvalho Chehab		SELinux::
13034433332SMauro Carvalho Chehab
1314af4662fSMimi Zohar			dont_measure obj_type=var_log_t
13207f6a794SMimi Zohar			dont_appraise obj_type=var_log_t
1334af4662fSMimi Zohar			dont_measure obj_type=auditd_log_t
13407f6a794SMimi Zohar			dont_appraise obj_type=auditd_log_t
1351e93d005SMimi Zohar			measure subj_user=system_u func=FILE_CHECK mask=MAY_READ
1361e93d005SMimi Zohar			measure subj_role=system_r func=FILE_CHECK mask=MAY_READ
1374af4662fSMimi Zohar
13834433332SMauro Carvalho Chehab		Smack::
13934433332SMauro Carvalho Chehab
1401e93d005SMimi Zohar			measure subj_user=_ func=FILE_CHECK mask=MAY_READ
141fc26bd50SEric Richter
14234433332SMauro Carvalho Chehab		Example of measure rules using alternate PCRs::
143fc26bd50SEric Richter
144fc26bd50SEric Richter			measure func=KEXEC_KERNEL_CHECK pcr=4
145fc26bd50SEric Richter			measure func=KEXEC_INITRAMFS_CHECK pcr=5
1469044d627SThiago Jung Bauermann
1479044d627SThiago Jung Bauermann		Example of appraise rule allowing modsig appended signatures:
1489044d627SThiago Jung Bauermann
1499044d627SThiago Jung Bauermann			appraise func=KEXEC_KERNEL_CHECK appraise_type=imasig|modsig
1505808611cSLakshmi Ramasubramanian
1515808611cSLakshmi Ramasubramanian		Example of measure rule using KEY_CHECK to measure all keys:
1525808611cSLakshmi Ramasubramanian
1535808611cSLakshmi Ramasubramanian			measure func=KEY_CHECK
154e9085e0aSLakshmi Ramasubramanian
155e9085e0aSLakshmi Ramasubramanian		Example of measure rule using KEY_CHECK to only measure
156e9085e0aSLakshmi Ramasubramanian		keys added to .builtin_trusted_keys or .ima keyring:
157e9085e0aSLakshmi Ramasubramanian
158e9085e0aSLakshmi Ramasubramanian			measure func=KEY_CHECK keyrings=.builtin_trusted_keys|.ima
1594f2946aaSTHOBY Simon
1604f2946aaSTHOBY Simon		Example of the special SETXATTR_CHECK appraise rule, that
1614f2946aaSTHOBY Simon		restricts the hash algorithms allowed when writing to the
1624f2946aaSTHOBY Simon		security.ima xattr of a file:
1634f2946aaSTHOBY Simon
1644f2946aaSTHOBY Simon			appraise func=SETXATTR_CHECK appraise_algos=sha256,sha384,sha512
16554f03916SMimi Zohar
16654f03916SMimi Zohar		Example of a 'measure' rule requiring fs-verity's digests
16754f03916SMimi Zohar		with indication of type of digest in the measurement list.
16854f03916SMimi Zohar
16954f03916SMimi Zohar			measure func=FILE_CHECK digest_type=verity \
17054f03916SMimi Zohar				template=ima-ngv2
171398c42e2SMimi Zohar
172398c42e2SMimi Zohar		Example of 'measure' and 'appraise' rules requiring fs-verity
173398c42e2SMimi Zohar		signatures (format version 3) stored in security.ima xattr.
174398c42e2SMimi Zohar
175398c42e2SMimi Zohar		The 'measure' rule specifies the 'ima-sigv3' template option,
176398c42e2SMimi Zohar		which includes the indication of type of digest and the file
177398c42e2SMimi Zohar		signature in the measurement list.
178398c42e2SMimi Zohar
179398c42e2SMimi Zohar			measure func=BPRM_CHECK digest_type=verity \
180398c42e2SMimi Zohar				template=ima-sigv3
181398c42e2SMimi Zohar
182398c42e2SMimi Zohar
183398c42e2SMimi Zohar		The 'appraise' rule specifies the type and signature format
184398c42e2SMimi Zohar		version (sigv3) required.
185398c42e2SMimi Zohar
186398c42e2SMimi Zohar			appraise func=BPRM_CHECK digest_type=verity \
187398c42e2SMimi Zohar				appraise_type=sigv3
188398c42e2SMimi Zohar
189de4c44a7SMimi Zohar		Example of a regular IMA file hash 'appraise' rule requiring
190de4c44a7SMimi Zohar		signature version 3 format stored in security.ima xattr.
191de4c44a7SMimi Zohar
192de4c44a7SMimi Zohar			appraise func=BPRM_CHECK appraise_type=sigv3
193de4c44a7SMimi Zohar
194398c42e2SMimi Zohar		All of these policy rules could, for example, be constrained
195398c42e2SMimi Zohar		either based on a filesystem's UUID (fsuuid) or based on LSM
196398c42e2SMimi Zohar		labels.
197