Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1618496

Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set

From Dave Young <dyoung@redhat.com>
Newsgroups linux.kernel
Subject Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set
Date 2017-04-07 08:20 +0200
Message-ID <ttvpv-3pt-7@gated-at.bofh.it> (permalink)
References <tsZzj-7hF-5@gated-at.bofh.it> <tsZJ0-7kG-7@gated-at.bofh.it> <ttsrD-1tz-1@gated-at.bofh.it> <ttt4m-1IG-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On 04/06/17 at 11:49pm, Mimi Zohar wrote:
> On Fri, 2017-04-07 at 11:05 +0800, Dave Young wrote:
> > On 04/05/17 at 09:15pm, David Howells wrote:
> > > From: Chun-Yi Lee <joeyli.kernel@gmail.com>
> > > 
> > > When KEXEC_VERIFY_SIG is not enabled, kernel should not loads image
> > > through kexec_file systemcall if securelevel has been set.
> > > 
> > > This code was showed in Matthew's patch but not in git:
> > > https://lkml.org/lkml/2015/3/13/778
> > > 
> > > Cc: Matthew Garrett <mjg59@srcf.ucam.org>
> > > Signed-off-by: Chun-Yi Lee <jlee@suse.com>
> > > Signed-off-by: David Howells <dhowells@redhat.com>
> > > cc: kexec@lists.infradead.org
> > > ---
> > > 
> > >  kernel/kexec_file.c |    6 ++++++
> > >  1 file changed, 6 insertions(+)
> > > 
> > > diff --git a/kernel/kexec_file.c b/kernel/kexec_file.c
> > > index b118735fea9d..f6937eecd1eb 100644
> > > --- a/kernel/kexec_file.c
> > > +++ b/kernel/kexec_file.c
> > > @@ -268,6 +268,12 @@ SYSCALL_DEFINE5(kexec_file_load, int, kernel_fd, int, initrd_fd,
> > >  	if (!capable(CAP_SYS_BOOT) || kexec_load_disabled)
> > >  		return -EPERM;
> > >  
> > > +	/* Don't permit images to be loaded into trusted kernels if we're not
> > > +	 * going to verify the signature on them
> > > +	 */
> > > +	if (!IS_ENABLED(CONFIG_KEXEC_VERIFY_SIG) && kernel_is_locked_down())
> > > +		return -EPERM;
> > > +
> > >  
> 
> IMA can be used to verify file signatures too, based on the LSM hooks
> in  kernel_read_file_from_fd().  CONFIG_KEXEC_VERIFY_SIG should not be
> required.

Mimi, I remember we talked somthing before about the two signature 
verification. One can change IMA policy in initramfs userspace,
also there are kernel cmdline param to disable IMA, so it can break the
lockdown? Suppose kexec boot with ima disabled cmdline param and then
kexec reboot again..

> 
> Mimi
> 
> 
> > 	/* Make sure we have a legal set of flags */
> > >  	if (flags != (flags & KEXEC_FILE_FLAGS))
> > >  		return -EINVAL;
> > > 
> > > 
> > > _______________________________________________
> > > kexec mailing list
> > > kexec@lists.infradead.org
> > > http://lists.infradead.org/mailman/listinfo/kexec
> > 
> > Acked-by: Dave Young <dyoung@redhat.com>
> > 
> > Thanks
> > Dave
> > --
> > To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
> > the body of a message to majordomo@vger.kernel.org
> > More majordomo info at  http://vger.kernel.org/majordomo-info.html
> > 
> 

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 00/24] Kernel lockdown David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
  [PATCH 24/24] Lock down module params that specify hardware  parameters (eg. ioport) David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
  [PATCH 03/24] efi: Lock down the kernel if booted in secure boot  mode David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
  [PATCH 20/24] bpf: Restrict kernel image access functions when the  kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
    Re: [PATCH 20/24] bpf: Restrict kernel image access functions when  the kernel is locked down Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2017-04-06 14:30 +0200
      Re: [PATCH 20/24] bpf: Restrict kernel image access functions when  the kernel is locked down Ard Biesheuvel <ard.biesheuvel@linaro.org> - 2017-04-06 14:50 +0200
  [PATCH 12/24] PCI: Lock down BAR access when the kernel is locked  down David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
  [PATCH 15/24] asus-wmi: Restrict debugfs interface when the kernel  is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
    Re: [PATCH 15/24] asus-wmi: Restrict debugfs interface when the  kernel is locked down Andy Shevchenko <andy.shevchenko@gmail.com> - 2017-04-07 12:30 +0200
      Re: [PATCH 15/24] asus-wmi: Restrict debugfs interface when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-07 15:00 +0200
        Re: [PATCH 15/24] asus-wmi: Restrict debugfs interface when the  kernel is locked down Andy Shevchenko <andy.shevchenko@gmail.com> - 2017-04-09 13:20 +0200
          Re: [PATCH 15/24] asus-wmi: Restrict debugfs interface when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-10 15:20 +0200
  [PATCH 02/24] Add the ability to lock down access to the running  kernel image David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
  [PATCH 07/24] kexec: Disable at runtime if the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
    Re: [PATCH 07/24] kexec: Disable at runtime if the kernel is locked  down Dave Young <dyoung@redhat.com> - 2017-04-07 05:10 +0200
  [PATCH 08/24] Copy secure_boot flag in boot params across kexec  reboot David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
  [PATCH 06/24] Add a sysrq option to exit secure boot mode David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
  [PATCH 10/24] hibernate: Disable when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
  [PATCH 14/24] x86: Restrict MSR access when the kernel is locked  down David Howells <dhowells@redhat.com> - 2017-04-05 22:30 +0200
  [PATCH 04/24] Enforce module signatures if the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:30 +0200
  [PATCH 11/24] uswsusp: Disable when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:30 +0200
    Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down "Rafael J. Wysocki" <rafael@kernel.org> - 2017-04-06 01:40 +0200
      Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down Oliver Neukum <oneukum@suse.com> - 2017-04-06 08:50 +0200
        Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-06 11:30 +0200
          Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down "Rafael J. Wysocki" <rafael@kernel.org> - 2017-04-06 22:20 +0200
            Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down Jiri Kosina <jikos@kernel.org> - 2017-04-06 22:30 +0200
              Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down poma <pomidorabelisima@gmail.com> - 2017-04-08 05:30 +0200
          Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down "Rafael J. Wysocki" <rafael@kernel.org> - 2017-04-06 22:20 +0200
      Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-06 09:00 +0200
        Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down "Rafael J. Wysocki" <rafael@kernel.org> - 2017-04-06 22:20 +0200
  [PATCH 09/24] kexec_file: Disable at runtime if securelevel has  been set David Howells <dhowells@redhat.com> - 2017-04-05 22:30 +0200
    Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has  been set Dave Young <dyoung@redhat.com> - 2017-04-07 05:10 +0200
      Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has  been set Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-04-07 05:50 +0200
        Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has  been set Dave Young <dyoung@redhat.com> - 2017-04-07 08:20 +0200
          Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set David Howells <dhowells@redhat.com> - 2017-04-07 09:10 +0200
            Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has  been set Dave Young <dyoung@redhat.com> - 2017-04-07 09:50 +0200
              Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has  been set Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-04-07 10:30 +0200
                Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has  been set Dave Young <dyoung@redhat.com> - 2017-04-07 10:50 +0200
          Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has  been set Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-04-07 09:50 +0200
            Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has  been set Dave Young <dyoung@redhat.com> - 2017-04-07 10:10 +0200
        Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set David Howells <dhowells@redhat.com> - 2017-04-07 09:20 +0200
          Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has  been set Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-04-07 09:50 +0200
            Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set David Howells <dhowells@redhat.com> - 2017-04-07 11:20 +0200
              Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has  been set Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-04-07 14:40 +0200
                Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set David Howells <dhowells@redhat.com> - 2017-04-10 15:30 +0200
  Re: [PATCH 00/24] Kernel lockdown "Austin S. Hemmelgarn" <ahferroin7@gmail.com> - 2017-04-07 18:10 +0200
    Re: [PATCH 00/24] Kernel lockdown Justin Forbes <jmforbes@linuxtx.org> - 2017-04-07 18:40 +0200

csiph-web