security/integrity/ima/Kconfig | 1 + 1 file changed, 1 insertion(+)
The IMA_MEASURE_PCR_IDX option is currently not visible in the kconfig
frontend, so it always uses its default, 10. This means that the
'range 8 14' is dead code, and users are unable to specify the pcr index
value.
In a previous discussion, Mimi explained that users should be able to use
this config option to specify the pcr index. [1]
Let's add a prompt for users to specify the pcr index, when EXPERT is
enabled.
This dead range was found by kconfirm, a static analysis tool for Kconfig.
Signed-off-by: Julian Braha <julianbraha@gmail.com>
---
Link: https://lore.kernel.org/all/1feff118-4afa-4b9c-86f1-271a7a88208f@gmail.com/T/#mc4efa2491b4937eb7c9e532c29ffba516a70e662 [1]
---
security/integrity/ima/Kconfig | 1 +
1 file changed, 1 insertion(+)
diff --git a/security/integrity/ima/Kconfig b/security/integrity/ima/Kconfig
index b3a9f86809b0..2d5bb19ea6ac 100644
--- a/security/integrity/ima/Kconfig
+++ b/security/integrity/ima/Kconfig
@@ -46,6 +46,7 @@ config IMA_KEXEC
config IMA_MEASURE_PCR_IDX
int
+ prompt "PCR Index for Aggregate" if EXPERT
range 8 14
default 10
help
--
2.55.0
On Mon, 2026-08-24 at 17:22 +0100, Julian Braha wrote: > The IMA_MEASURE_PCR_IDX option is currently not visible in the kconfig > frontend, so it always uses its default, 10. This means that the > 'range 8 14' is dead code, and users are unable to specify the pcr index > value. > > In a previous discussion, Mimi explained that users should be able to use > this config option to specify the pcr index. [1] > > Let's add a prompt for users to specify the pcr index, when EXPERT is > enabled. > > This dead range was found by kconfirm, a static analysis tool for Kconfig. > > Signed-off-by: Julian Braha <julianbraha@gmail.com> > --- > Link: https://lore.kernel.org/all/1feff118-4afa-4b9c-86f1-271a7a88208f@gmail.com/T/#mc4efa2491b4937eb7c9e532c29ffba516a70e662 [1] > --- > security/integrity/ima/Kconfig | 1 + > 1 file changed, 1 insertion(+) > > diff --git a/security/integrity/ima/Kconfig b/security/integrity/ima/Kconfig > index b3a9f86809b0..2d5bb19ea6ac 100644 > --- a/security/integrity/ima/Kconfig > +++ b/security/integrity/ima/Kconfig > @@ -46,6 +46,7 @@ config IMA_KEXEC > > config IMA_MEASURE_PCR_IDX > int > + prompt "PCR Index for Aggregate" if EXPERT > range 8 14 > default 10 > help Thanks, Julian. The existing Help says, "If unsure, use the default 10." Could we make this recommendation stronger? AI suggested: IMA_MEASURE_PCR_IDX determines the TPM PCR register index that IMA uses to maintain the integrity aggregate of the measurement list. Most attestation tooling expects PCR 10. The default is almost always what you want. Only change this if you know what you are doing. Thanks, Mimi
Hi Mimi, On 9/2/26 01:54, Mimi Zohar wrote: > On Mon, 2026-08-24 at 17:22 +0100, Julian Braha wrote: >> The IMA_MEASURE_PCR_IDX option is currently not visible in the kconfig >> frontend, so it always uses its default, 10. This means that the >> 'range 8 14' is dead code, and users are unable to specify the pcr index >> value. >> >> In a previous discussion, Mimi explained that users should be able to use >> this config option to specify the pcr index. [1] >> >> Let's add a prompt for users to specify the pcr index, when EXPERT is >> enabled. >> >> This dead range was found by kconfirm, a static analysis tool for Kconfig. >> >> Signed-off-by: Julian Braha <julianbraha@gmail.com> >> --- >> Link: https://lore.kernel.org/all/1feff118-4afa-4b9c-86f1-271a7a88208f@gmail.com/T/#mc4efa2491b4937eb7c9e532c29ffba516a70e662 [1] >> --- >> security/integrity/ima/Kconfig | 1 + >> 1 file changed, 1 insertion(+) >> >> diff --git a/security/integrity/ima/Kconfig b/security/integrity/ima/Kconfig >> index b3a9f86809b0..2d5bb19ea6ac 100644 >> --- a/security/integrity/ima/Kconfig >> +++ b/security/integrity/ima/Kconfig >> @@ -46,6 +46,7 @@ config IMA_KEXEC >> >> config IMA_MEASURE_PCR_IDX >> int >> + prompt "PCR Index for Aggregate" if EXPERT >> range 8 14 >> default 10 >> help > > Thanks, Julian. The existing Help says, "If unsure, use the default 10." Could > we make this recommendation stronger? AI suggested: > > IMA_MEASURE_PCR_IDX determines the TPM PCR register index > that IMA uses to maintain the integrity aggregate of the > measurement list. Most attestation tooling expects PCR 10. > > The default is almost always what you want. Only change > this if you know what you are doing. Thank you for your feedback, will include this in v2! - Julian Braha
© 2016 - 2026 Red Hat, Inc.