Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1618464
| From | Mimi Zohar <zohar@linux.vnet.ibm.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set |
| Date | 2017-04-07 05:50 +0200 |
| Message-ID | <ttt4m-1IG-3@gated-at.bofh.it> (permalink) |
| References | <tsZzj-7hF-5@gated-at.bofh.it> <tsZJ0-7kG-7@gated-at.bofh.it> <ttsrD-1tz-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Fri, 2017-04-07 at 11:05 +0800, Dave Young wrote: > On 04/05/17 at 09:15pm, David Howells wrote: > > From: Chun-Yi Lee <joeyli.kernel@gmail.com> > > > > When KEXEC_VERIFY_SIG is not enabled, kernel should not loads image > > through kexec_file systemcall if securelevel has been set. > > > > This code was showed in Matthew's patch but not in git: > > https://lkml.org/lkml/2015/3/13/778 > > > > Cc: Matthew Garrett <mjg59@srcf.ucam.org> > > Signed-off-by: Chun-Yi Lee <jlee@suse.com> > > Signed-off-by: David Howells <dhowells@redhat.com> > > cc: kexec@lists.infradead.org > > --- > > > > kernel/kexec_file.c | 6 ++++++ > > 1 file changed, 6 insertions(+) > > > > diff --git a/kernel/kexec_file.c b/kernel/kexec_file.c > > index b118735fea9d..f6937eecd1eb 100644 > > --- a/kernel/kexec_file.c > > +++ b/kernel/kexec_file.c > > @@ -268,6 +268,12 @@ SYSCALL_DEFINE5(kexec_file_load, int, kernel_fd, int, initrd_fd, > > if (!capable(CAP_SYS_BOOT) || kexec_load_disabled) > > return -EPERM; > > > > + /* Don't permit images to be loaded into trusted kernels if we're not > > + * going to verify the signature on them > > + */ > > + if (!IS_ENABLED(CONFIG_KEXEC_VERIFY_SIG) && kernel_is_locked_down()) > > + return -EPERM; > > + > > IMA can be used to verify file signatures too, based on the LSM hooks in kernel_read_file_from_fd(). CONFIG_KEXEC_VERIFY_SIG should not be required. Mimi > /* Make sure we have a legal set of flags */ > > if (flags != (flags & KEXEC_FILE_FLAGS)) > > return -EINVAL; > > > > > > _______________________________________________ > > kexec mailing list > > kexec@lists.infradead.org > > http://lists.infradead.org/mailman/listinfo/kexec > > Acked-by: Dave Young <dyoung@redhat.com> > > Thanks > Dave > -- > To unsubscribe from this list: send the line "unsubscribe linux-security-module" in > the body of a message to majordomo@vger.kernel.org > More majordomo info at http://vger.kernel.org/majordomo-info.html >
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 00/24] Kernel lockdown David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
[PATCH 24/24] Lock down module params that specify hardware parameters (eg. ioport) David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
[PATCH 03/24] efi: Lock down the kernel if booted in secure boot mode David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
[PATCH 20/24] bpf: Restrict kernel image access functions when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
Re: [PATCH 20/24] bpf: Restrict kernel image access functions when the kernel is locked down Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2017-04-06 14:30 +0200
Re: [PATCH 20/24] bpf: Restrict kernel image access functions when the kernel is locked down Ard Biesheuvel <ard.biesheuvel@linaro.org> - 2017-04-06 14:50 +0200
[PATCH 12/24] PCI: Lock down BAR access when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
[PATCH 15/24] asus-wmi: Restrict debugfs interface when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
Re: [PATCH 15/24] asus-wmi: Restrict debugfs interface when the kernel is locked down Andy Shevchenko <andy.shevchenko@gmail.com> - 2017-04-07 12:30 +0200
Re: [PATCH 15/24] asus-wmi: Restrict debugfs interface when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-07 15:00 +0200
Re: [PATCH 15/24] asus-wmi: Restrict debugfs interface when the kernel is locked down Andy Shevchenko <andy.shevchenko@gmail.com> - 2017-04-09 13:20 +0200
Re: [PATCH 15/24] asus-wmi: Restrict debugfs interface when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-10 15:20 +0200
[PATCH 02/24] Add the ability to lock down access to the running kernel image David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
[PATCH 07/24] kexec: Disable at runtime if the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
Re: [PATCH 07/24] kexec: Disable at runtime if the kernel is locked down Dave Young <dyoung@redhat.com> - 2017-04-07 05:10 +0200
[PATCH 08/24] Copy secure_boot flag in boot params across kexec reboot David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
[PATCH 06/24] Add a sysrq option to exit secure boot mode David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
[PATCH 10/24] hibernate: Disable when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
[PATCH 14/24] x86: Restrict MSR access when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:30 +0200
[PATCH 04/24] Enforce module signatures if the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:30 +0200
[PATCH 11/24] uswsusp: Disable when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:30 +0200
Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down "Rafael J. Wysocki" <rafael@kernel.org> - 2017-04-06 01:40 +0200
Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down Oliver Neukum <oneukum@suse.com> - 2017-04-06 08:50 +0200
Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-06 11:30 +0200
Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down "Rafael J. Wysocki" <rafael@kernel.org> - 2017-04-06 22:20 +0200
Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down Jiri Kosina <jikos@kernel.org> - 2017-04-06 22:30 +0200
Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down poma <pomidorabelisima@gmail.com> - 2017-04-08 05:30 +0200
Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down "Rafael J. Wysocki" <rafael@kernel.org> - 2017-04-06 22:20 +0200
Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-06 09:00 +0200
Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down "Rafael J. Wysocki" <rafael@kernel.org> - 2017-04-06 22:20 +0200
[PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set David Howells <dhowells@redhat.com> - 2017-04-05 22:30 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Dave Young <dyoung@redhat.com> - 2017-04-07 05:10 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-04-07 05:50 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Dave Young <dyoung@redhat.com> - 2017-04-07 08:20 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set David Howells <dhowells@redhat.com> - 2017-04-07 09:10 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Dave Young <dyoung@redhat.com> - 2017-04-07 09:50 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-04-07 10:30 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Dave Young <dyoung@redhat.com> - 2017-04-07 10:50 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-04-07 09:50 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Dave Young <dyoung@redhat.com> - 2017-04-07 10:10 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set David Howells <dhowells@redhat.com> - 2017-04-07 09:20 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-04-07 09:50 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set David Howells <dhowells@redhat.com> - 2017-04-07 11:20 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-04-07 14:40 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set David Howells <dhowells@redhat.com> - 2017-04-10 15:30 +0200
Re: [PATCH 00/24] Kernel lockdown "Austin S. Hemmelgarn" <ahferroin7@gmail.com> - 2017-04-07 18:10 +0200
Re: [PATCH 00/24] Kernel lockdown Justin Forbes <jmforbes@linuxtx.org> - 2017-04-07 18:40 +0200
csiph-web