Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1656681 > unrolled thread

Re: security/keys: add CONFIG_KEYS_COMPAT to Kconfig

Started byEric Biggers <ebiggers3@gmail.com>
First post2017-06-03 04:50 +0200
Last post2017-06-05 05:40 +0200
Articles 3 — 2 participants

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: security/keys: add CONFIG_KEYS_COMPAT to Kconfig Eric Biggers <ebiggers3@gmail.com> - 2017-06-03 04:50 +0200
    Re: security/keys: add CONFIG_KEYS_COMPAT to Kconfig David Howells <dhowells@redhat.com> - 2017-06-03 10:10 +0200
      Re: security/keys: add CONFIG_KEYS_COMPAT to Kconfig Eric Biggers <ebiggers3@gmail.com> - 2017-06-05 05:40 +0200

#1656681 — Re: security/keys: add CONFIG_KEYS_COMPAT to Kconfig

FromEric Biggers <ebiggers3@gmail.com>
Date2017-06-03 04:50 +0200
SubjectRe: security/keys: add CONFIG_KEYS_COMPAT to Kconfig
Message-ID<tO7ix-1dp-1@gated-at.bofh.it>
On Wed, Mar 29, 2017 at 12:20:02PM -0700, Eric Biggers wrote:
> On Thu,  9 Feb 2017 22:11:38 +0100, Bilal Amarni wrote:
> > CONFIG_KEYS_COMPAT is defined in arch-specific Kconfigs and is missing for
> > several 64-bit architectures : arm64, mips, parisc, tile.
> > 
> > At the moment and for those architectures, calling in 32-bit userspace the
> > keyctl syscall would return an ENOSYS error.
> > 
> > This patch moves the CONFIG_KEYS_COMPAT option to security/keys/Kconfig, to
> > make sure the compatibility wrapper is registered by default for any 64-bit
> > architecture as long as it is configured with CONFIG_COMPAT.
> 
> David, where can I find the git branch this patch was applied to?  I don't see
> it anywhere in security-keys or linux-security.
> 
> I recently added KEYS_COMPAT to arm64 (5c2a625937ba); that should be reverted
> after this patch.
> 
> Also, I'd like to submit a follow-on patch that removes KEYS_COMPAT and simply
> uses COMPAT.
> 
> And the parisc architecture doesn't use compat_sys_keyctl() in its compat
> syscall table, so that should be fixed too (though that's not a new bug).
> 
> - Eric

This patch is in the "keys-fixes" branch now, but it doesn't remove KEYS_COMPAT
from arch/arm64/Kconfig.  David, can you fix it?  Thanks!

Eric

[toc] | [next] | [standalone]


#1656753

FromDavid Howells <dhowells@redhat.com>
Date2017-06-03 10:10 +0200
Message-ID<tOcid-4wc-5@gated-at.bofh.it>
In reply to#1656681
Eric Biggers <ebiggers3@gmail.com> wrote:

> This patch is in the "keys-fixes" branch now, but it doesn't remove KEYS_COMPAT
> from arch/arm64/Kconfig.  David, can you fix it?  Thanks!

Done.  See below.

David
---
commit 90fe15899ffa2f7c6dd9a7c257c840cfbd523aad
Author: Bilal Amarni <bilal.amarni@gmail.com>
Date:   Fri Jun 2 14:29:19 2017 +0100

    security/keys: add CONFIG_KEYS_COMPAT to Kconfig
    
    CONFIG_KEYS_COMPAT is defined in arch-specific Kconfigs and is missing for
    several 64-bit architectures : mips, parisc, tile.
    
    At the moment and for those architectures, calling in 32-bit userspace the
    keyctl syscall would return an ENOSYS error.
    
    This patch moves the CONFIG_KEYS_COMPAT option to security/keys/Kconfig, to
    make sure the compatibility wrapper is registered by default for any 64-bit
    architecture as long as it is configured with CONFIG_COMPAT.
    
    [DH: Modified to remove arm64 compat enablement also as requested by Eric
     Biggers]
    
    Signed-off-by: Bilal Amarni <bilal.amarni@gmail.com>
    Signed-off-by: David Howells <dhowells@redhat.com>
    Reviewed-by: Arnd Bergmann <arnd@arndb.de>
    cc: Eric Biggers <ebiggers3@gmail.com>

diff --git a/arch/arm64/Kconfig b/arch/arm64/Kconfig
index 3dcd7ec69bca..b2024db225a9 100644
--- a/arch/arm64/Kconfig
+++ b/arch/arm64/Kconfig
@@ -1084,10 +1084,6 @@ config SYSVIPC_COMPAT
 	def_bool y
 	depends on COMPAT && SYSVIPC
 
-config KEYS_COMPAT
-	def_bool y
-	depends on COMPAT && KEYS
-
 endmenu
 
 menu "Power management options"
diff --git a/arch/powerpc/Kconfig b/arch/powerpc/Kconfig
index f7c8f9972f61..83d2e0f43c26 100644
--- a/arch/powerpc/Kconfig
+++ b/arch/powerpc/Kconfig
@@ -1215,11 +1215,6 @@ source "arch/powerpc/Kconfig.debug"
 
 source "security/Kconfig"
 
-config KEYS_COMPAT
-	bool
-	depends on COMPAT && KEYS
-	default y
-
 source "crypto/Kconfig"
 
 config PPC_LIB_RHEAP
diff --git a/arch/s390/Kconfig b/arch/s390/Kconfig
index e161fafb495b..6967addc6a89 100644
--- a/arch/s390/Kconfig
+++ b/arch/s390/Kconfig
@@ -363,9 +363,6 @@ config COMPAT
 config SYSVIPC_COMPAT
 	def_bool y if COMPAT && SYSVIPC
 
-config KEYS_COMPAT
-	def_bool y if COMPAT && KEYS
-
 config SMP
 	def_bool y
 	prompt "Symmetric multi-processing support"
diff --git a/arch/sparc/Kconfig b/arch/sparc/Kconfig
index 58243b0d21c0..5bb7a403af02 100644
--- a/arch/sparc/Kconfig
+++ b/arch/sparc/Kconfig
@@ -573,9 +573,6 @@ config SYSVIPC_COMPAT
 	depends on COMPAT && SYSVIPC
 	default y
 
-config KEYS_COMPAT
-	def_bool y if COMPAT && KEYS
-
 endmenu
 
 source "net/Kconfig"
diff --git a/arch/x86/Kconfig b/arch/x86/Kconfig
index 4ccfacc7232a..0efb4c9497bc 100644
--- a/arch/x86/Kconfig
+++ b/arch/x86/Kconfig
@@ -2776,10 +2776,6 @@ config COMPAT_FOR_U64_ALIGNMENT
 config SYSVIPC_COMPAT
 	def_bool y
 	depends on SYSVIPC
-
-config KEYS_COMPAT
-	def_bool y
-	depends on KEYS
 endif
 
 endmenu
diff --git a/security/keys/Kconfig b/security/keys/Kconfig
index 6fd95f76bfae..00b7431a8aeb 100644
--- a/security/keys/Kconfig
+++ b/security/keys/Kconfig
@@ -20,6 +20,10 @@ config KEYS
 
 	  If you are unsure as to whether this is required, answer N.
 
+config KEYS_COMPAT
+	def_bool y
+	depends on COMPAT && KEYS
+
 config PERSISTENT_KEYRINGS
 	bool "Enable register of persistent per-UID keyrings"
 	depends on KEYS

[toc] | [prev] | [next] | [standalone]


#1657236

FromEric Biggers <ebiggers3@gmail.com>
Date2017-06-05 05:40 +0200
Message-ID<tOR22-5Sy-1@gated-at.bofh.it>
In reply to#1656753
On Sat, Jun 03, 2017 at 09:04:42AM +0100, David Howells wrote:
> Eric Biggers <ebiggers3@gmail.com> wrote:
> 
> > This patch is in the "keys-fixes" branch now, but it doesn't remove KEYS_COMPAT
> > from arch/arm64/Kconfig.  David, can you fix it?  Thanks!
> 
> Done.  See below.
> 
> David
> ---

Looks good now, thanks.  (Except that as I mentioned before, I don't think we
need the KEYS_COMPAT option at all, but that can be another patch.)

Eric

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web