Thread (7 messages) 7 messages, 2 authors, 29d ago

[PATCH 1/2] keys/trusted_keys: return immediately after TPM unseal failure

flat view
COLD29d

From: Srish Srinivasan <ssrish@linux.ibm.com>
Date: 2026-09-02 10:31:34
Also in: keyrings, linux-integrity, lkml
Subsystem: keys-trusted, keys/keyrings, security subsystem, the rest · Maintainers: James Bottomley, Jarkko Sakkinen, Mimi Zohar, David Howells, Paul Moore, James Morris, "Serge E. Hallyn", Linus Torvalds

Revision v6 of 4 in this series.

Revisions (4)
  1. v6 current
  2. v7 [diff vs current]
  3. v8 [diff vs current]
  4. v9 [diff vs current]
trusted_tpm_unseal() proceeds to pcrlock() when the TPM unseal operation
fails. If pcrlock() succeeds, its return value overwrites the unseal error,
causing key instantiation to succeed.

Return immediately when unseal fails to preserve the original error.

Fixes: 5d0682be3189 ("KEYS: trusted: Add generic trusted keys framework")
Cc: stable@vger.kernel.org
Signed-off-by: Srish Srinivasan <ssrish@linux.ibm.com>
---
 security/keys/trusted-keys/trusted_tpm1.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/security/keys/trusted-keys/trusted_tpm1.c b/security/keys/trusted-keys/trusted_tpm1.c
index bf0bf7f36970..1168ca235205 100644
--- a/security/keys/trusted-keys/trusted_tpm1.c
+++ b/security/keys/trusted-keys/trusted_tpm1.c
@@ -923,8 +923,10 @@ static int trusted_tpm_unseal(struct trusted_key_payload *p, char *datablob)
 		ret = tpm2_unseal_trusted(chip, p, options);
 	else
 		ret = key_unseal(p, options);
-	if (ret < 0)
+	if (ret < 0) {
 		pr_info("key_unseal failed (%d)\n", ret);
+		return ret;
+	}
 
 	if (options->pcrlock) {
 		ret = pcrlock(options->pcrlock);
-- 
2.53.0
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help