STX: IMA appraisal for file execution still logged via 'fm event-list' every 20 minutes after the file is deleted
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
StarlingX |
Invalid
|
Low
|
zhao.shuai |
Bug Description
Brief Description
-----------------
Create a new root file and delete it, IMA event in fm event-list is still generated every 20 minutes.
| 2018-10-
Severity
--------
Minor
Steps to Reproduce
------------------
1. sudo touch /home/wrsroot/TEMP
2. sudo chmod 755 /home/wrsroot/TEMP
3. Append content to monitored file
echo "ls" | sudo -S tee -a /home/wrsroot/TEMP
4.Execute created file
sudo /home/wrsroot/TEMP
5. sudo rm /home/wrsroot/TEMP
Expected Behavior
------------------
4. Following event should be logged after executing the file
500.500 | Host controller-1 has IMA Appraisal failure for service /usr/bin/sudo when executing file /home/wrsroot/TEMP, reason = IMA-signature-
5.a /var/log/ima.log no longer generates log for deleted file
5.b fm event-list no longer logs event for deleted file
Actual Behavior
----------------
4. as expected
5.a as expected
5.b The same IMA event is logged in fm event-list every 20 minutes even after deleting the file
-------
| 2018-10-
| 2018-10-
| 2018-10-
Reproducibility
---------------
Reproducible
System Configuration
-------
Two node system
Branch/Pull Time/Commit
-------
STX.18.10 "2018-10-
Timestamp/Logs
--------------
2018-10-
2018-10-
tags: |
added: stx.2019.05 removed: stx.2019.03 |
Changed in starlingx: | |
assignee: | Paul-Emile Element (paul-emileelement) → nobody |
tags: | added: stx.helpwanted |
Changed in starlingx: | |
assignee: | nobody → Bruce Jones (brucej) |
Changed in starlingx: | |
assignee: | Bruce Jones (brucej) → Cindy Xie (xxie1) |
Changed in starlingx: | |
assignee: | Cindy Xie (xxie1) → chen haochuan (martin1982) |
tags: |
added: stx.2.0 removed: stx.2019.05 |
tags: | added: stx.retestneeded |
tags: | removed: stx.2.0 |
Changed in starlingx: | |
assignee: | chen haochuan (martin1982) → zhao.shuai (zhao.shuai) |
tags: | removed: stx.retestneeded |
This maybe expected behavior; assigning to the design prime to review/confirm.