kernel-packages team mailing list archive
-
kernel-packages team
-
Mailing list archive
-
Message #80640
[Bug 1371316] Re: Please cherry-pick an aufs patch to unbreak it in conjunction with IMA
** Also affects: linux (Ubuntu Precise)
Importance: Undecided
Status: New
** Also affects: linux-lts-trusty (Ubuntu Precise)
Importance: Undecided
Status: New
** Also affects: linux (Ubuntu Trusty)
Importance: Undecided
Status: New
** Also affects: linux-lts-trusty (Ubuntu Trusty)
Importance: Undecided
Status: New
** Changed in: linux (Ubuntu Precise)
Assignee: (unassigned) => Andy Whitcroft (apw)
** Changed in: linux (Ubuntu Trusty)
Assignee: (unassigned) => Andy Whitcroft (apw)
** Changed in: linux (Ubuntu Precise)
Status: New => In Progress
** Changed in: linux (Ubuntu Trusty)
Status: New => In Progress
** Changed in: linux-lts-trusty (Ubuntu Precise)
Status: New => In Progress
** Changed in: linux-lts-trusty (Ubuntu Trusty)
Status: New => In Progress
** Changed in: linux-lts-trusty (Ubuntu)
Status: New => Invalid
** Changed in: linux (Ubuntu)
Status: Incomplete => Invalid
--
You received this bug notification because you are a member of Kernel
Packages, which is subscribed to linux in Ubuntu.
https://bugs.launchpad.net/bugs/1371316
Title:
Please cherry-pick an aufs patch to unbreak it in conjunction with IMA
Status in “linux” package in Ubuntu:
Invalid
Status in “linux-lts-trusty” package in Ubuntu:
Invalid
Status in “linux” source package in Precise:
In Progress
Status in “linux-lts-trusty” source package in Precise:
In Progress
Status in “linux” source package in Trusty:
In Progress
Status in “linux-lts-trusty” source package in Trusty:
In Progress
Bug description:
The trusty kernel misses the following patch that already landed in
utopic with the recent aufs update:
https://github.com/sfjro/aufs3-linux/commit/7aac34b421441b701cd0e6de4685b51e4c462d67
This unbreaks aufs with IMA (Integrity Measurement Architecture)
enabled. When IMA is enabled and mmaps are being tracked, the kernel
hits a lock ordering bug because a needed semaphore is already held.
This patch fixes this issue by not calling out to IMA for the access
to the underlying file. However IMA will still see the access to the
file in the merged aufs, which should be good enough.
Please cherry-pick above patch.
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1371316/+subscriptions
References