Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #89149

Bug#1114737: Acknowledgement (linux-image-6.12.43+deb13-amd64: CONFIG_TRUSTED_KEYS is not set)

Path csiph.com!weretis.net!feeder8.news.weretis.net!srl.newsdeef.eu!news.corradoroberto.it!gothmog.csi.it!bofh.it!news.nic.it!robomod
From Cliff Kilby <cliffjkilby@gmail.com>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#1114737: Acknowledgement (linux-image-6.12.43+deb13-amd64: CONFIG_TRUSTED_KEYS is not set)
Date Tue, 09 Sep 2025 19:40:01 +0200
Message-ID <LtatX-e5b8-1@gated-at.bofh.it> (permalink)
References <LsTjr-dThK-1@gated-at.bofh.it> <Lt7cJ-e32s-9@gated-at.bofh.it> <Lt7cJ-e32s-7@gated-at.bofh.it> <LsTjr-dThK-1@gated-at.bofh.it> <Lt7cJ-e32s-7@gated-at.bofh.it>
X-Mailbox-Line From debian-bugs-dist-request@lists.debian.org Tue Sep 9 17:33:10 2025
Old-Return-Path <debbugs@buxtehude.debian.org>
X-Spam-Flag NO
X-Spam-Score -0.795
Reply-To Cliff Kilby <cliffjkilby@gmail.com>, 1114737@bugs.debian.org
Resent-To debian-bugs-dist@lists.debian.org
Resent-Cc debian-kernel@lists.debian.org
X-Debian-Pr-Message followup 1114737
X-Debian-Pr-Package src:linux
X-Debian-Pr-Source linux
X-Gm-Message-State AOJu0YxUkJbVPrVbuvtXpAEdxAoUiaomO9sa8OQvNV/903+a8brv+BI7 GV9B2HY8HZuVQItSfEitF5GeF8PvmOBlkbypVpLK/7M2wc39LGrZ/4slgjtu3pSicPkR3YUh6Pi UPMH2+iA02YE3Sfu1DYHP+YjHZQL978PSL5KSjEA=
X-Gm-Gg ASbGncvU4cu182eRrFSIr+Gpfi99lSbYkq6pr1C8/BBuRsoMt1QP8BJpDQP9lqtAQOc ns1qvuEHyDKBSE/4IiY9g2UAoZg8J236CkmGqrwpYFprBx46U7Y329cBnJ24KJ1QyWO0KSJJ1qe IWf3Zsf+ZrzoUx3RYxMdgV9Ghmr6tPybtES+nBTFE1Dm//HOLuqDj3yExrsK2sxzGlu6a0GEhsc I2gj9250k5expVOfJI=
X-Google-SMTP-Source AGHT+IE02otB2LHc7ID2tuqgIfz3Dly4DQu8lUWWq0mB4HkvD8ojY2mWloCFAKBRgnz4+W1LngEhqC/lAlvqywmq4io=
X-Received by 2002:a05:6902:2a4a:b0:e96:edb1:83e1 with SMTP id 3f1490d57ef6-e9f68b96b2dmr10199666276.30.1757439114365; Tue, 09 Sep 2025 10:31:54 -0700 (PDT)
MIME-Version 1.0
X-Gm-Features AS18NWDURiNg0XMjGgZ7O9IC6rnhaq7sXKtA9fQZQbpHns6E0qJxbjSejqLHxec
Content-Type multipart/alternative; boundary="00000000000020505e063e61aece"
X-Debian-Message from BTS
X-Mailing-List <debian-bugs-dist@lists.debian.org> archive/latest/1924047
List-ID <debian-bugs-dist.lists.debian.org>
List-URL <https://lists.debian.org/debian-bugs-dist/>
Approved robomod@news.nic.it
Lines 97
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Date Tue, 9 Sep 2025 17:31:43 +0000
X-Original-Message-ID <CAEvRzv2g+BHTOL8VAyeTXJSqc+=E5yq_om_d+Dp9t6YJ9TCUdA@mail.gmail.com>
X-Original-References <CAEvRzv3p=RbctHXaGwh1N3BzZDy66H6vz0zDsdpwmhCH7=P4ow@mail.gmail.com> <handler.1114737.B.17573734492674569.ack@bugs.debian.org> <CAEvRzv0r8j6=UgNEXUQD1rEO_XmX2xXiNQYgnwjGE7=SAS4zQw@mail.gmail.com> <CAEvRzv3p=RbctHXaGwh1N3BzZDy66H6vz0zDsdpwmhCH7=P4ow@mail.gmail.com> <CAEvRzv0r8j6=UgNEXUQD1rEO_XmX2xXiNQYgnwjGE7=SAS4zQw@mail.gmail.com>
Xref csiph.com linux.debian.bugs.dist:1260697 linux.debian.kernel:89149

Cross-posted to 2 groups.

Show key headers only | View raw


[Multipart message — attachments visible in raw view] - view raw

There does appear to be a complication for this change. keyctl can add
trusted, but not read encrypted keys
# keyctl add encrypted evm-key "new trusted:kmk-trusted 32" @u
# keyctl pipe `keyctl search @u encrypted evm-key`
keyctl_read_alloc: Operation not supported
# keyctl search @u encrypted evm-key
58969095
The key exists but cannot be read. This appears to be due to
https://bugzilla.kernel.org/show_bug.cgi?id=202577

If trusted is a module, and encrypted is builtin, encrypted cannot open a
trusted key because the masterkey_trusted.o types are not exported out of
the encrypted-keys namespace?
(mind you, I am not a kernel developer, and this c is ... waaaaay out of my
league.)
In summary:
CONFIG_TRUSTED_KEYS=n && CONFIG_ENCRYPTED_KEYS=y == keyctl add trusted
fails.
CONFIG_TRUSTED_KEYS=m && CONFIG_ENCRYPTED_KEYS=y == keyctl read encrypted
from a trusted key fails.
In order to have both, both have to be modules (to export the types), or
both have to be builtin (to use the shared type lookups?).

CONFIG_TRUSTED_KEYS=y

I built the kernel again with the change above and :
# uname -a
Linux debian 6.12.43 #28 SMP PREEMPT_DYNAMIC Tue Sep  9 12:57:21 EDT 2025
x86_64 GNU/Linux
# dmesg | grep -P '(trusted|encrypted)'
[    1.779375] Initialise system trusted keyrings
[    4.969001] Key type trusted registered
[    5.001211] Key type encrypted registered
[   24.235628] trusted_key: encrypted_key: master key parameter '' is
invalid

# keyctl search @u trusted kmk-trusted
625450296
# keyctl add encrypted evm-key "new trusted:kmk-trusted 32" @u
234222391
# keyctl link @u @s
# keyctl pipe `keyctl search @u encrypted evm-key`
default trusted:kmk-trusted 32 <<REDACTED KEY MATERIAL>>

Success.

Given my original goal was to follow the instructions as provided, I change
my request to reconfigure the kernel build to CONFIG_TRUSTED_KEYS=y to fix
the keyctl for both trusted and encrypted types.

Back to linux.debian.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

Bug#1114737: linux-image-6.12.43+deb13-amd64: CONFIG_TRUSTED_KEYS is not set Cliff Kilby <cliffjkilby@gmail.com> - 2025-09-09 01:20 +0200
  Bug#1114737: Acknowledgement (linux-image-6.12.43+deb13-amd64: CONFIG_TRUSTED_KEYS is not set) Cliff Kilby <cliffjkilby@gmail.com> - 2025-09-09 16:10 +0200
    Bug#1114737: Acknowledgement (linux-image-6.12.43+deb13-amd64: CONFIG_TRUSTED_KEYS is not set) Cliff Kilby <cliffjkilby@gmail.com> - 2025-09-09 19:40 +0200

csiph-web