evm: don't copy up 'security.evm' xattr
authorMimi Zohar <zohar@linux.ibm.com>
Tue, 12 Dec 2023 11:12:43 +0000 (06:12 -0500)
committerMimi Zohar <zohar@linux.ibm.com>
Wed, 20 Dec 2023 12:39:52 +0000 (07:39 -0500)
commit40ca4ee3136d2d09977d1cab8c0c0e1582c3359d
tree552c49da9983f04c064d62e019fff50ddcd37d6f
parent4e8daa792742635ea57c625098165eef64661901
evm: don't copy up 'security.evm' xattr

The security.evm HMAC and the original file signatures contain
filesystem specific data.  As a result, the HMAC and signature
are not the same on the stacked and backing filesystems.

Don't copy up 'security.evm'.

Reviewed-by: Amir Goldstein <amir73il@gmail.com>
Reviewed-by: Christian Brauner <brauner@kernel.org>
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
include/linux/evm.h
security/integrity/evm/evm_main.c
security/security.c