The IMA_MEASURE_PCR_IDX option is currently not visible in the kconfig
frontend, so it always uses its default, 10. This means that the
'range 8 14' is dead code, and users are unable to specify the pcr index
value.

In a previous discussion, Mimi explained that users should be able to use
this config option to specify the pcr index. [1]

Let's add a prompt for users to specify the pcr index, when EXPERT is
enabled.

This dead range was found by kconfirm, a static analysis tool for Kconfig.

Link: 
https://lore.kernel.org/all/[email protected]/T/#mc4efa2491b4937eb7c9e532c29ffba516a70e662
 [1]
Signed-off-by: Julian Braha <[email protected]>
---
Changes since v1:
- updated help text to recommend using the default of 10

v1:
https://lore.kernel.org/all/[email protected]/
---
 security/integrity/ima/Kconfig | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/security/integrity/ima/Kconfig b/security/integrity/ima/Kconfig
index b3a9f86809b0..72654cf797cd 100644
--- a/security/integrity/ima/Kconfig
+++ b/security/integrity/ima/Kconfig
@@ -46,12 +46,16 @@ config IMA_KEXEC
 
 config IMA_MEASURE_PCR_IDX
        int
+       prompt "PCR Index for Aggregate" if EXPERT
        range 8 14
        default 10
        help
          IMA_MEASURE_PCR_IDX determines the TPM PCR register index
          that IMA uses to maintain the integrity aggregate of the
-         measurement list.  If unsure, use the default 10.
+         measurement list. Most attestation tooling expects PCR 10.
+
+         The default is almost always what you want. Only change this
+         if you know what you are doing.
 
 config IMA_LSM_RULES
        bool
-- 
2.55.0


Reply via email to