Skip to content

CREDS_CHECK hook with incorrect credentials #3

@robertosassu

Description

@robertosassu

Based on the discussion here (https://lkml.org/lkml/2025/4/10/1002), we need to address the fact that the VFS no longer recalculates the credentials at each step of the binary handler search. Thus, IMA would not see for example the updated euid/egid because that is calculated later after the interpreter is found.

Paul Moore suggested to have an IMA-specific way of getting the information it was getting before.

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions