Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1389707
| Path | csiph.com!aioe.org!bofh.it!news.nic.it!robomod |
|---|---|
| From | Rusty Russell <rusty@rustcorp.com.au> |
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH 1/3] module: Invalidate signatures on force-loaded modules |
| Date | Thu, 28 Apr 2016 02:30:02 +0200 |
| Message-ID | <rsI0a-289-3@gated-at.bofh.it> (permalink) |
| References | <rraMV-7Jc-1@gated-at.bofh.it> <rraMW-7Jc-13@gated-at.bofh.it> <rshW1-5I2-1@gated-at.bofh.it> <rsip3-6eQ-9@gated-at.bofh.it> |
| X-Original-To | Ben Hutchings <ben@decadent.org.uk> |
| User-Agent | Notmuch/0.21 (http://notmuchmail.org) Emacs/24.5.1 (x86_64-pc-linux-gnu) |
| MIME-Version | 1.0 |
| Content-Type | text/plain; charset=utf-8 |
| Content-Transfer-Encoding | 8BIT |
| Sender | robomod@news.nic.it |
| List-ID | <linux-kernel.vger.kernel.org> |
| X-Mailing-List | linux-kernel@vger.kernel.org |
| Approved | robomod@news.nic.it |
| Lines | 22 |
| Organization | linux.* mail to news gateway |
| X-Original-Cc | David Howells <dhowells@redhat.com>, David Woodhouse <dwmw2@infradead.org>, keyrings@vger.kernel.org, linux-kernel@vger.kernel.org |
| X-Original-Date | Thu, 28 Apr 2016 09:24:40 +0930 |
| X-Original-Message-ID | <87pota4ngf.fsf@rustcorp.com.au> |
| X-Original-References | <20160423184421.GL3348@decadent.org.uk> <20160423184501.GM3348@decadent.org.uk> <8760v464gr.fsf@rustcorp.com.au> <1461704447.5852.17.camel@decadent.org.uk> |
| X-Original-Sender | linux-kernel-owner@vger.kernel.org |
| Xref | csiph.com linux.kernel:1389707 |
Show key headers only | View raw
Ben Hutchings <ben@decadent.org.uk> writes: > On Tue, 2016-04-26 at 20:07 +0930, Rusty Russell wrote: >> Ben Hutchings <ben@decadent.org.uk> writes: >> > - if (info->len > markerlen && >> > + /* >> > + * Require flags == 0, as a module with version information >> > + * removed is no longer the module that was signed >> > + */ >> > + if (flags == 0 && >> This check is a bit lazy. We could have other flags in future, >> so this should really be !(flags & >> (MODULE_INIT_IGNORE_MODVERSIONS|MODULE_INIT_IGNORE_VERMAGIC) right? > > Yes we could, but I'd prefer this to fail-safe in case no-one thinks > about whether it should be updated then. Yeah, line ball. We could screw up either way, and I can't think of an reasonable new flag off the top of my head to give a concrete example. I've applied all three, thanks! Rusty.
Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread
[PATCH 0/3] Module signing and version info Ben Hutchings <ben@decadent.org.uk> - 2016-04-23 20:50 +0200
[PATCH 3/3] module: Disable MODULE_FORCE_LOAD when MODULE_SIG_FORCE is enabled Ben Hutchings <ben@decadent.org.uk> - 2016-04-23 20:50 +0200
[PATCH 2/3] Documentation/module-signing.txt: Note need for version info if reusing a key Ben Hutchings <ben@decadent.org.uk> - 2016-04-23 20:50 +0200
[PATCH 1/3] module: Invalidate signatures on force-loaded modules Ben Hutchings <ben@decadent.org.uk> - 2016-04-23 20:50 +0200
Re: [PATCH 1/3] module: Invalidate signatures on force-loaded modules Rusty Russell <rusty@rustcorp.com.au> - 2016-04-26 22:40 +0200
Re: [PATCH 1/3] module: Invalidate signatures on force-loaded modules Ben Hutchings <ben@decadent.org.uk> - 2016-04-26 23:10 +0200
Re: [PATCH 1/3] module: Invalidate signatures on force-loaded modules Rusty Russell <rusty@rustcorp.com.au> - 2016-04-28 02:30 +0200
csiph-web