On Wed, 2019-11-13 at 12:52 -0800, Lakshmi Ramasubramanian wrote: > On 11/13/19 12:09 PM, Mimi Zohar wrote: > > > > All that is is needed is the key and public_key structures, which are > > defined in include/linux/keys.h and include/crypto/public_key.h. If > > the keys subsystem is disabled, then the new IMA hook won't be called. > > There's no need for a new Kconfig option or a new file. > > > > Please move the hook to just after ima_kexec_cmdline(). > > > > Mimi > > Yes - IMA hook won't be called when KEYS subsystem is disabled. > > But, build dependency is breaking since "struct key" is not defined > without CONFIG_KEYS. > > Sasha was able to craft a .config that enabled IMA without enabling KEYS > and found the build break. Yes, thanks for pointing out the "#ifdef CONFIG_KEYS" in keys.h. A separate file is needed, as you pointed out, but still no need for a new Kconfig. The ima/Makefile can be based on CONFIG_KEYS. Mimi