Path: csiph.com!news.samoylyk.net!gothmog.csi.it!bofh.it!news.nic.it!robomod From: Cliff Kilby Newsgroups: linux.debian.bugs.dist,linux.debian.kernel Subject: Bug#1114737: Acknowledgement (linux-image-6.12.43+deb13-amd64: CONFIG_TRUSTED_KEYS is not set) Date: Tue, 09 Sep 2025 16:10:01 +0200 Message-ID: References: X-Original-To: 1114737@bugs.debian.org X-Mailbox-Line: From debian-bugs-dist-request@lists.debian.org Tue Sep 9 14:05:10 2025 Old-Return-Path: X-Spam-Flag: NO X-Spam-Score: -0.795 Reply-To: Cliff Kilby , 1114737@bugs.debian.org Resent-To: debian-bugs-dist@lists.debian.org Resent-Cc: debian-kernel@lists.debian.org X-Debian-Pr-Message: followup 1114737 X-Debian-Pr-Package: src:linux X-Debian-Pr-Source: linux X-Gm-Message-State: AOJu0YzplZJwFXgwCQ7DwCZOReShdqR1Okgse4BMocSMefHbz40TAhYw +FkYxIaQsjb6P4QH7tJo6NDQ2tn23AYUi2TZjHRn6aMwbl4QIcZd933P2WgYNMiyCz7PMbEYFUq cIa7XqychML+dEOGUvndTNYioWPNjGDuonOuwvWI= X-Gm-Gg: ASbGnctayeT1uI4+Q0dg0s1eAeev6XJTAwaMLd/LHPmKIav8231m0vpDxFz+DTK3TF6 Ij9BSuhhurcG4XQZoSwlYsa0cot166jitdsTnJ5I9ZyJ60Gf4lGa7lahS38fKThkeoiKdD1gzpH kj/8FDGxwCc6zYucElqtjPCZ1kGLc/wNjqqOVSDvZ7UxeDGGlloFuKW8kbIbmFpMw4Xs1efK+AQ mQ1jYhitMtVns3nQfI= X-Google-SMTP-Source: AGHT+IG1nO2mrvm22D55hgd16wdurWHNIejJgORIoM+4zjGCdBC2+qN665g4duT7KznQJMwiyxsWt9i9p3ObS7b3uDE= X-Received: by 2002:a05:6902:4889:b0:e93:3afc:1889 with SMTP id 3f1490d57ef6-e9f65d195camr11436111276.13.1757426129760; Tue, 09 Sep 2025 06:55:29 -0700 (PDT) MIME-Version: 1.0 X-Gm-Features: Ac12FXwElPGp9gn7QxyVaXDz42HwNmWuvCnSxeTf0A6eD8eXOfBGmaD-YgR7tVs Content-Type: multipart/alternative; boundary="0000000000002ef644063e5ea875" X-Debian-Message: from BTS X-Mailing-List: archive/latest/1924018 List-ID: List-URL: Approved: robomod@news.nic.it Lines: 145 Organization: linux.* mail to news gateway Sender: robomod@news.nic.it X-Original-Date: Tue, 9 Sep 2025 13:55:18 +0000 X-Original-Message-ID: X-Original-References: Xref: csiph.com linux.debian.bugs.dist:1260674 linux.debian.kernel:89140 --0000000000002ef644063e5ea875 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable I went out on a ledge and tried to rebuild the kernel with the single change proposed. # uname -a Linux debian 6.12.43 #2 SMP PREEMPT_DYNAMIC Tue Sep 9 09:24:23 EDT 2025 x86_64 GNU/Linux # grep TRUSTED /boot/config-6.12.43 CONFIG_TRUSTED_KEYS=3Dm # dmesg | grep 'Linux version' [ 0.000000] Linux version 6.12.43 (buildlocal@debian) (gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44) #2 SMP PREEMPT_DYNAMIC Tue Sep 9 09:24:23 EDT 2025 #modinfo trusted filename: /lib/modules/6.12.43/kernel/security/keys/trusted-keys/trusted.ko.xz license: GPL # lsmod | grep trusted trusted 45056 1 dm_crypt asn1_encoder 12288 1 trusted tee 49152 1 trusted # keyctl add trusted kmk "new 32" @u add_key: Invalid argument Ooops. It appears that even with the module, the instruction is wrong. But, at least "trusted" is a type now. So, I can do this. # keyctl add trusted kmk-trusted "new 32 keyhandle=3D0x81000001" @u 964692806 # keyctl describe 964692806 964692806: alswrv-----v------------ 0 0 trusted: kmk-trusted I do not believe that building a local kernel is a long term fix for a security feature that should be available by default. I would still ask that you enable the module build of this module. On Mon, Sep 8, 2025 at 11:19=E2=80=AFPM Debian Bug Tracking System < owner@bugs.debian.org> wrote: > Thank you for filing a new Bug report with Debian. > > You can follow progress on this Bug here: 1114737: > https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1114737. > > This is an automatically generated reply to let you know your message > has been received. > > Your message is being forwarded to the package maintainers and other > interested parties for their attention; they will reply in due course. > > As you requested using X-Debbugs-CC, your message was also forwarded to > cliffjkilby@gmail.com > (after having been given a Bug report number, if it did not have one). > > Your message has been sent to the package maintainer(s): > debian-kernel@lists.debian.org > > If you wish to submit further information on this problem, please > send it to 1114737@bugs.debian.org. > > Please do not send mail to owner@bugs.debian.org unless you wish > to report a problem with the Bug-tracking system. > > -- > 1114737: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1114737 > Debian Bug Tracking System > Contact owner@bugs.debian.org with problems > --0000000000002ef644063e5ea875 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
I went out on a ledge and tried to rebuild the kernel= with the single change proposed.
# uname -a
Linux debian= 6.12.43 #2 SMP PREEMPT_DYNAMIC Tue Sep =C2=A09 09:24:23 EDT 2025 x86_64 GN= U/Linux
# grep TRUSTED /boot/config-6.12.43
CONFIG_TRUSTED_KEY= S=3Dm
# dmesg | grep 'Linux version'
[ =C2=A0 =C2=A00.= 000000] Linux version 6.12.43 (buildlocal@debian) (gcc (Debian 14.2.0-19) 1= 4.2.0, GNU ld (GNU Binutils for Debian) 2.44) #2 SMP PREEMPT_DYNAMIC Tue Se= p =C2=A09 09:24:23 EDT 2025
#modinfo trusted
filename: =C2=A0 = =C2=A0 =C2=A0 /lib/modules/6.12.43/kernel/security/keys/trusted-keys/truste= d.ko.xz
license: =C2=A0 =C2=A0 =C2=A0 =C2=A0GPL
# lsmod | grep= trusted
trusted =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0= 45056 =C2=A01 dm_crypt
asn1_encoder =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 1= 2288 =C2=A01 trusted
tee =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0 =C2=A0 =C2=A049152 =C2=A01 trusted
# keyctl add truste= d kmk "new 32" @u
add_key: Invalid argument

Ooops. It appears that even with the module, the instruction is wron= g. But, at least "trusted" is a type now. So, I can do this.

# keyctl add trusted kmk-trusted "new 32 keyhandl= e=3D0x81000001" @u
964692806
# keyctl describe =C2=A09646= 92806
964692806: alswrv-----v------------ =C2=A0 =C2=A0 0 =C2=A0 =C2=A0 = 0 trusted: kmk-trusted

I do not believe that build= ing a local kernel is a long term fix for a security feature that should be= available by default. I would still ask that you enable the module build o= f this module.


On Mon, Sep 8, 2025 at 11:19=E2=80= =AFPM Debian Bug Tracking System <owner@bugs.debian.org> wrote:
Thank you for filing a new Bug re= port with Debian.

You can follow progress on this Bug here: 1114737: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1114737= .

This is an automatically generated reply to let you know your message
has been received.

Your message is being forwarded to the package maintainers and other
interested parties for their attention; they will reply in due course.

As you requested using X-Debbugs-CC, your message was also forwarded to
=C2=A0 cliffjkil= by@gmail.com
(after having been given a Bug report number, if it did not have one).

Your message has been sent to the package maintainer(s):
=C2=A0d= ebian-kernel@lists.debian.org

If you wish to submit further information on this problem, please
send it to 111= 4737@bugs.debian.org.

Please do not send mail to owner@bugs.debian.org unless you wish
to report a problem with the Bug-tracking system.

--
1114737: https://bugs.debian.org/cgi-bin/= bugreport.cgi?bug=3D1114737
Debian Bug Tracking System
Contact owner@bu= gs.debian.org with problems
--0000000000002ef644063e5ea875--