Re: security/keys: add CONFIG_KEYS_COMPAT to Kconfig

4 messages, 2 authors, 2017-06-05 · open the first message on its own page

Re: security/keys: add CONFIG_KEYS_COMPAT to Kconfig

From: Eric Biggers <hidden>
Date: 2017-03-29 19:20:08

On Thu,  9 Feb 2017 22:11:38 +0100, Bilal Amarni wrote:
CONFIG_KEYS_COMPAT is defined in arch-specific Kconfigs and is missing for
several 64-bit architectures : arm64, mips, parisc, tile.

At the moment and for those architectures, calling in 32-bit userspace the
keyctl syscall would return an ENOSYS error.

This patch moves the CONFIG_KEYS_COMPAT option to security/keys/Kconfig, to
make sure the compatibility wrapper is registered by default for any 64-bit
architecture as long as it is configured with CONFIG_COMPAT.
David, where can I find the git branch this patch was applied to?  I don't see
it anywhere in security-keys or linux-security.

I recently added KEYS_COMPAT to arm64 (5c2a625937ba); that should be reverted
after this patch.

Also, I'd like to submit a follow-on patch that removes KEYS_COMPAT and simply
uses COMPAT.

And the parisc architecture doesn't use compat_sys_keyctl() in its compat
syscall table, so that should be fixed too (though that's not a new bug).

- Eric
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Re: security/keys: add CONFIG_KEYS_COMPAT to Kconfig

From: Eric Biggers <hidden>
Date: 2017-06-03 02:44:04

On Wed, Mar 29, 2017 at 12:20:02PM -0700, Eric Biggers wrote:
On Thu,  9 Feb 2017 22:11:38 +0100, Bilal Amarni wrote:
quoted
CONFIG_KEYS_COMPAT is defined in arch-specific Kconfigs and is missing for
several 64-bit architectures : arm64, mips, parisc, tile.

At the moment and for those architectures, calling in 32-bit userspace the
keyctl syscall would return an ENOSYS error.

This patch moves the CONFIG_KEYS_COMPAT option to security/keys/Kconfig, to
make sure the compatibility wrapper is registered by default for any 64-bit
architecture as long as it is configured with CONFIG_COMPAT.
David, where can I find the git branch this patch was applied to?  I don't see
it anywhere in security-keys or linux-security.

I recently added KEYS_COMPAT to arm64 (5c2a625937ba); that should be reverted
after this patch.

Also, I'd like to submit a follow-on patch that removes KEYS_COMPAT and simply
uses COMPAT.

And the parisc architecture doesn't use compat_sys_keyctl() in its compat
syscall table, so that should be fixed too (though that's not a new bug).

- Eric
This patch is in the "keys-fixes" branch now, but it doesn't remove KEYS_COMPAT
from arch/arm64/Kconfig.  David, can you fix it?  Thanks!

Eric
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Re: security/keys: add CONFIG_KEYS_COMPAT to Kconfig

From: David Howells <dhowells@redhat.com>
Date: 2017-06-03 08:04:47

Eric Biggers [off-list ref] wrote:
This patch is in the "keys-fixes" branch now, but it doesn't remove KEYS_COMPAT
from arch/arm64/Kconfig.  David, can you fix it?  Thanks!
Done.  See below.

David
---
commit 90fe15899ffa2f7c6dd9a7c257c840cfbd523aad
Author: Bilal Amarni [off-list ref]
Date:   Fri Jun 2 14:29:19 2017 +0100

    security/keys: add CONFIG_KEYS_COMPAT to Kconfig
    
    CONFIG_KEYS_COMPAT is defined in arch-specific Kconfigs and is missing for
    several 64-bit architectures : mips, parisc, tile.
    
    At the moment and for those architectures, calling in 32-bit userspace the
    keyctl syscall would return an ENOSYS error.
    
    This patch moves the CONFIG_KEYS_COMPAT option to security/keys/Kconfig, to
    make sure the compatibility wrapper is registered by default for any 64-bit
    architecture as long as it is configured with CONFIG_COMPAT.
    
    [DH: Modified to remove arm64 compat enablement also as requested by Eric
     Biggers]
    
    Signed-off-by: Bilal Amarni [off-list ref]
    Signed-off-by: David Howells [off-list ref]
    Reviewed-by: Arnd Bergmann [off-list ref]
    cc: Eric Biggers [off-list ref]
diff --git a/arch/arm64/Kconfig b/arch/arm64/Kconfig
index 3dcd7ec69bca..b2024db225a9 100644
--- a/arch/arm64/Kconfig
+++ b/arch/arm64/Kconfig
@@ -1084,10 +1084,6 @@ config SYSVIPC_COMPAT
 	def_bool y
 	depends on COMPAT && SYSVIPC
 
-config KEYS_COMPAT
-	def_bool y
-	depends on COMPAT && KEYS
-
 endmenu
 
 menu "Power management options"
diff --git a/arch/powerpc/Kconfig b/arch/powerpc/Kconfig
index f7c8f9972f61..83d2e0f43c26 100644
--- a/arch/powerpc/Kconfig
+++ b/arch/powerpc/Kconfig
@@ -1215,11 +1215,6 @@ source "arch/powerpc/Kconfig.debug"
 
 source "security/Kconfig"
 
-config KEYS_COMPAT
-	bool
-	depends on COMPAT && KEYS
-	default y
-
 source "crypto/Kconfig"
 
 config PPC_LIB_RHEAP
diff --git a/arch/s390/Kconfig b/arch/s390/Kconfig
index e161fafb495b..6967addc6a89 100644
--- a/arch/s390/Kconfig
+++ b/arch/s390/Kconfig
@@ -363,9 +363,6 @@ config COMPAT
 config SYSVIPC_COMPAT
 	def_bool y if COMPAT && SYSVIPC
 
-config KEYS_COMPAT
-	def_bool y if COMPAT && KEYS
-
 config SMP
 	def_bool y
 	prompt "Symmetric multi-processing support"
diff --git a/arch/sparc/Kconfig b/arch/sparc/Kconfig
index 58243b0d21c0..5bb7a403af02 100644
--- a/arch/sparc/Kconfig
+++ b/arch/sparc/Kconfig
@@ -573,9 +573,6 @@ config SYSVIPC_COMPAT
 	depends on COMPAT && SYSVIPC
 	default y
 
-config KEYS_COMPAT
-	def_bool y if COMPAT && KEYS
-
 endmenu
 
 source "net/Kconfig"
diff --git a/arch/x86/Kconfig b/arch/x86/Kconfig
index 4ccfacc7232a..0efb4c9497bc 100644
--- a/arch/x86/Kconfig
+++ b/arch/x86/Kconfig
@@ -2776,10 +2776,6 @@ config COMPAT_FOR_U64_ALIGNMENT
 config SYSVIPC_COMPAT
 	def_bool y
 	depends on SYSVIPC
-
-config KEYS_COMPAT
-	def_bool y
-	depends on KEYS
 endif
 
 endmenu
diff --git a/security/keys/Kconfig b/security/keys/Kconfig
index 6fd95f76bfae..00b7431a8aeb 100644
--- a/security/keys/Kconfig
+++ b/security/keys/Kconfig
@@ -20,6 +20,10 @@ config KEYS
 
 	  If you are unsure as to whether this is required, answer N.
 
+config KEYS_COMPAT
+	def_bool y
+	depends on COMPAT && KEYS
+
 config PERSISTENT_KEYRINGS
 	bool "Enable register of persistent per-UID keyrings"
 	depends on KEYS
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Re: security/keys: add CONFIG_KEYS_COMPAT to Kconfig

From: Eric Biggers <hidden>
Date: 2017-06-05 03:34:23

On Sat, Jun 03, 2017 at 09:04:42AM +0100, David Howells wrote:
Eric Biggers [off-list ref] wrote:
quoted
This patch is in the "keys-fixes" branch now, but it doesn't remove KEYS_COMPAT
from arch/arm64/Kconfig.  David, can you fix it?  Thanks!
Done.  See below.

David
---
Looks good now, thanks.  (Except that as I mentioned before, I don't think we
need the KEYS_COMPAT option at all, but that can be another patch.)

Eric
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help