[systemd-devel] Revert commit "ma-setup: simplify"

Mimi Zohar zohar at linux.vnet.ibm.com
Mon Jun 1 05:57:57 PDT 2015


The original systemd IMA module loaded the IMA policy by mmaping the
file into memory and then writing the entire file to
<securityfs>/ima/policy.  By changing this behavior of writing the
entire file,  commit 4dfb18922d5d "ima-setup: simplify"  broke IMA
policy loading.

Please revert commit 4dfb18922d5d1efb13ee459cbf23832277f85ed7 and the
related hunk from commit 7430ec6ac08f2c0416d9f806964c46b30f3862b2.

This bug was reported by Patrick Ohly.

Thanks!

Mimi



More information about the systemd-devel mailing list