Path: csiph.com!weretis.net!feeder8.news.weretis.net!srl.newsdeef.eu!news.corradoroberto.it!gothmog.csi.it!bofh.it!news.nic.it!robomod From: Cliff Kilby Newsgroups: linux.debian.bugs.dist,linux.debian.kernel Subject: Bug#1114737: Acknowledgement (linux-image-6.12.43+deb13-amd64: CONFIG_TRUSTED_KEYS is not set) Date: Tue, 09 Sep 2025 19:40:01 +0200 Message-ID: References: X-Mailbox-Line: From debian-bugs-dist-request@lists.debian.org Tue Sep 9 17:33:10 2025 Old-Return-Path: X-Spam-Flag: NO X-Spam-Score: -0.795 Reply-To: Cliff Kilby , 1114737@bugs.debian.org Resent-To: debian-bugs-dist@lists.debian.org Resent-Cc: debian-kernel@lists.debian.org X-Debian-Pr-Message: followup 1114737 X-Debian-Pr-Package: src:linux X-Debian-Pr-Source: linux X-Gm-Message-State: AOJu0YxUkJbVPrVbuvtXpAEdxAoUiaomO9sa8OQvNV/903+a8brv+BI7 GV9B2HY8HZuVQItSfEitF5GeF8PvmOBlkbypVpLK/7M2wc39LGrZ/4slgjtu3pSicPkR3YUh6Pi UPMH2+iA02YE3Sfu1DYHP+YjHZQL978PSL5KSjEA= X-Gm-Gg: ASbGncvU4cu182eRrFSIr+Gpfi99lSbYkq6pr1C8/BBuRsoMt1QP8BJpDQP9lqtAQOc ns1qvuEHyDKBSE/4IiY9g2UAoZg8J236CkmGqrwpYFprBx46U7Y329cBnJ24KJ1QyWO0KSJJ1qe IWf3Zsf+ZrzoUx3RYxMdgV9Ghmr6tPybtES+nBTFE1Dm//HOLuqDj3yExrsK2sxzGlu6a0GEhsc I2gj9250k5expVOfJI= X-Google-SMTP-Source: AGHT+IE02otB2LHc7ID2tuqgIfz3Dly4DQu8lUWWq0mB4HkvD8ojY2mWloCFAKBRgnz4+W1LngEhqC/lAlvqywmq4io= X-Received: by 2002:a05:6902:2a4a:b0:e96:edb1:83e1 with SMTP id 3f1490d57ef6-e9f68b96b2dmr10199666276.30.1757439114365; Tue, 09 Sep 2025 10:31:54 -0700 (PDT) MIME-Version: 1.0 X-Gm-Features: AS18NWDURiNg0XMjGgZ7O9IC6rnhaq7sXKtA9fQZQbpHns6E0qJxbjSejqLHxec Content-Type: multipart/alternative; boundary="00000000000020505e063e61aece" X-Debian-Message: from BTS X-Mailing-List: archive/latest/1924047 List-ID: List-URL: Approved: robomod@news.nic.it Lines: 97 Organization: linux.* mail to news gateway Sender: robomod@news.nic.it X-Original-Date: Tue, 9 Sep 2025 17:31:43 +0000 X-Original-Message-ID: X-Original-References: Xref: csiph.com linux.debian.bugs.dist:1260697 linux.debian.kernel:89149 --00000000000020505e063e61aece Content-Type: text/plain; charset="UTF-8" There does appear to be a complication for this change. keyctl can add trusted, but not read encrypted keys # keyctl add encrypted evm-key "new trusted:kmk-trusted 32" @u # keyctl pipe `keyctl search @u encrypted evm-key` keyctl_read_alloc: Operation not supported # keyctl search @u encrypted evm-key 58969095 The key exists but cannot be read. This appears to be due to https://bugzilla.kernel.org/show_bug.cgi?id=202577 If trusted is a module, and encrypted is builtin, encrypted cannot open a trusted key because the masterkey_trusted.o types are not exported out of the encrypted-keys namespace? (mind you, I am not a kernel developer, and this c is ... waaaaay out of my league.) In summary: CONFIG_TRUSTED_KEYS=n && CONFIG_ENCRYPTED_KEYS=y == keyctl add trusted fails. CONFIG_TRUSTED_KEYS=m && CONFIG_ENCRYPTED_KEYS=y == keyctl read encrypted from a trusted key fails. In order to have both, both have to be modules (to export the types), or both have to be builtin (to use the shared type lookups?). CONFIG_TRUSTED_KEYS=y I built the kernel again with the change above and : # uname -a Linux debian 6.12.43 #28 SMP PREEMPT_DYNAMIC Tue Sep 9 12:57:21 EDT 2025 x86_64 GNU/Linux # dmesg | grep -P '(trusted|encrypted)' [ 1.779375] Initialise system trusted keyrings [ 4.969001] Key type trusted registered [ 5.001211] Key type encrypted registered [ 24.235628] trusted_key: encrypted_key: master key parameter '' is invalid # keyctl search @u trusted kmk-trusted 625450296 # keyctl add encrypted evm-key "new trusted:kmk-trusted 32" @u 234222391 # keyctl link @u @s # keyctl pipe `keyctl search @u encrypted evm-key` default trusted:kmk-trusted 32 <> Success. Given my original goal was to follow the instructions as provided, I change my request to reconfigure the kernel build to CONFIG_TRUSTED_KEYS=y to fix the keyctl for both trusted and encrypted types. --00000000000020505e063e61aece Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
Th= ere does appear to be a complication for this change. keyctl can add truste= d, but not read encrypted keys
# keyctl add encrypted evm-key= "new trusted:kmk-trusted 32" @u
# keyctl pipe `keyctl = search @u encrypted evm-key`
keyctl_read_alloc: Operation not supported<= /div>
# keyctl search @u encrypted evm-key
58969095
The ke= y exists but cannot be read. This appears to be due to https://bugz= illa.kernel.org/show_bug.cgi?id=3D202577

If trusted is a module, and encrypted is built= in, encrypted cannot open a trusted key because the masterkey_trusted.o typ= es are not exported out of the encrypted-keys namespace?
(mind yo= u, I am not a kernel developer, and this c is ... waaaaay out of my league.= )
In summary:
CONFIG_TRUSTED_KEYS=3Dn && CONFIG_ENCRY= PTED_KEYS=3Dy =3D=3D keyctl add trusted fails.
CONFIG_TRUSTED_KEY= S=3Dm && CONFIG_ENCRYPTED_KEYS=3Dy =3D=3D keyctl read encrypted fro= m a trusted key fails.
In order to have both, both have to be mod= ules (to export the types), or both have to be builtin (to use the shared t= ype lookups?).

CONFIG_TRUSTED_KEYS= =3Dy

I built the kernel again with the = change above and :
# uname -a
Linux debian 6.12.43 #28 SMP PREEMPT_= DYNAMIC Tue Sep =C2=A09 12:57:21 EDT 2025 x86_64 GNU/Linux
# dmesg | grep -P '(trusted|encrypted)'
[ =C2=A0 =C2=A01.7= 79375] Initialise system trusted keyrings
[ =C2=A0 =C2=A04.969001] Key t= ype trusted registered
[ =C2=A0 =C2=A05.001211] Key type encrypted regis= tered
[ =C2=A0 24.235628] trusted_key: encrypted_key: master key paramet= er '' is invalid

# keyctl search @u trusted kmk-trusted
625450= 296
# keyctl add encrypted evm-key "new trusted:kmk-trusted = 32" @u
234222391
# keyctl link @u @s
# keyctl p= ipe `keyctl search @u encrypted evm-key`
default trusted:kmk-trusted 32 = <<REDACTED KEY MATERIAL>>

Success.=

Given my original goal was to follow the inst= ructions as provided, I change my request to reconfigure the kernel build t= o CONFIG_TRUSTED_KEYS=3Dy to fix the keyctl for both trusted and encrypted = types.


--00000000000020505e063e61aece--