]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
ima: fallback to using i_version to detect file change
authorMimi Zohar <zohar@linux.ibm.com>
Mon, 2 Feb 2026 16:23:47 +0000 (11:23 -0500)
committerMimi Zohar <zohar@linux.ibm.com>
Sun, 8 Mar 2026 12:24:52 +0000 (08:24 -0400)
commit01baa39cf55fbbd0078f28a215157ecd185a5176
tree5a6e9f0fd514a46a25f445b77e9b6661e481ae15
parent0ec959cf4b5a609d7f27bf84064ef5372e30ab80
ima: fallback to using i_version to detect file change

Commit db1d1e8b9867 ("IMA: use vfs_getattr_nosec to get the i_version")
replaced detecting file change based on i_version with
STATX_CHANGE_COOKIE.

On filesystems without STATX_CHANGE_COOKIE enabled, revert back to
detecting file change based on i_version.

On filesystems which do not support either, assume the file changed.

Reported-by: Frederick Lawler <fred@cloudflare.com>
Fixes: db1d1e8b9867 ("IMA: use vfs_getattr_nosec to get the i_version")
Cc: stable@vger.kernel.org
Reviewed-by: Frederick Lawler <fred@cloudflare.com>
Tested-by: Frederick Lawler <fred@cloudflare.com>
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
security/integrity/ima/ima_api.c
security/integrity/ima/ima_main.c