Received: by 10.192.165.148 with SMTP id m20csp4955521imm; Tue, 1 May 2018 06:50:43 -0700 (PDT) X-Google-Smtp-Source: AB8JxZrl6aa33OfHwtbytFdo660wBkplkASM6ocfoWLV+0yhNYINaQ/vgKQjxgBhLVkR3zdezsjw X-Received: by 2002:a17:902:8ec4:: with SMTP id x4-v6mr16105349plo.370.1525182643350; Tue, 01 May 2018 06:50:43 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1525182643; cv=none; d=google.com; s=arc-20160816; b=C/YiV6ePhEQkK2ntYhK8AYvXS08bLlhtVirf3T/zj2y84KKLxqteD+qOENoSt1pYLs u/+F4t8dY8zy0xq+A/lFNUES3C27NMODCMI0JPMw864Eq6yg1ur4idejLFTGG1ZUgd5z PZOkPG/41bijX/dhvBxvx66YwwgjqkCXcOdexfYgixQciC5cj7onR0avv6k8+b2TsmEA aAy8s4UyqU2xFX9U8Aj79eiephCRU+kPJBEsUj9mgkej04NyCesoF+Cgws2zgHmVFdcj RuROr3nDViVEXbocdPp8mBOhWOVz2ESwTFlQAFzSP+L/4tpoG/1nENPwoHTNL4WrxNKO iQiA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:message-id:references:in-reply-to:date :subject:cc:to:from:arc-authentication-results; bh=lpHYwwLBitUPgnIz4fr2mx2nwJ2HFbRv46HII5hZz8A=; b=J5PoI3e8Q8L0ak0PH20YVS27BA5+ueQNy4GwpEeL1o2XGTyHJpRwbw7of2I9s2n9LT UmsTv3Hgu8By3cPlY1mv8Xl+WV6CCfF9KZGh7HEBO9e1ybGuU7CWhAUol8icMPyfOKpI 7xjsvFGd7dQXsK4S2gEb8PuxrgIFXzoz2dlm55YNRoZ9XOLRirOjn+K1W8ZJdWNbVJC5 2oPEW+nWoexHhKULEGR3S7a8Titv962RYAgR6dvUIn9ZwViCvD5fUVWX/VSXVzBPdKxL qceGji9JFipIlAQtTb5M+Tevm3mZslGgGzWWaEMiCQWsnRvlAtc2AEy8ktIEjMk/cfxC 0Avg== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=ibm.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id s16-v6si7829001pgv.596.2018.05.01.06.50.29; Tue, 01 May 2018 06:50:43 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=ibm.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1755590AbeEANso (ORCPT + 99 others); Tue, 1 May 2018 09:48:44 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]:40238 "EHLO mx0a-001b2d01.pphosted.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1755487AbeEANsl (ORCPT ); Tue, 1 May 2018 09:48:41 -0400 Received: from pps.filterd (m0098419.ppops.net [127.0.0.1]) by mx0b-001b2d01.pphosted.com (8.16.0.22/8.16.0.22) with SMTP id w41Djj4a058658 for ; Tue, 1 May 2018 09:48:40 -0400 Received: from e06smtp11.uk.ibm.com (e06smtp11.uk.ibm.com [195.75.94.107]) by mx0b-001b2d01.pphosted.com with ESMTP id 2hpp3k7615-1 (version=TLSv1.2 cipher=AES256-GCM-SHA384 bits=256 verify=NOT) for ; Tue, 01 May 2018 09:48:39 -0400 Received: from localhost by e06smtp11.uk.ibm.com with IBM ESMTP SMTP Gateway: Authorized Use Only! Violators will be prosecuted for from ; Tue, 1 May 2018 14:48:37 +0100 Received: from b06cxnps4076.portsmouth.uk.ibm.com (9.149.109.198) by e06smtp11.uk.ibm.com (192.168.101.141) with IBM ESMTP SMTP Gateway: Authorized Use Only! Violators will be prosecuted; Tue, 1 May 2018 14:48:35 +0100 Received: from d06av24.portsmouth.uk.ibm.com (mk.ibm.com [9.149.105.60]) by b06cxnps4076.portsmouth.uk.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id w41DmYDW5767578; Tue, 1 May 2018 13:48:34 GMT Received: from d06av24.portsmouth.uk.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id D8C2E4203F; Tue, 1 May 2018 14:39:47 +0100 (BST) Received: from d06av24.portsmouth.uk.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 4176042042; Tue, 1 May 2018 14:39:46 +0100 (BST) Received: from localhost.ibm.com (unknown [9.80.105.194]) by d06av24.portsmouth.uk.ibm.com (Postfix) with ESMTP; Tue, 1 May 2018 14:39:45 +0100 (BST) From: Mimi Zohar To: linux-integrity@vger.kernel.org Cc: Hans de Goede , Ard Biesheuvel , Peter Jones , Mimi Zohar , linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, David Howells , "Luis R . Rodriguez" , "Luis R . Rodriguez" , Kees Cook , Matthew Garrett Subject: [PATCH 1/6] firmware: permit LSMs and IMA to fail firmware sysfs fallback loading Date: Tue, 1 May 2018 09:48:18 -0400 X-Mailer: git-send-email 2.7.5 In-Reply-To: <1525182503-13849-1-git-send-email-zohar@linux.vnet.ibm.com> References: <1525182503-13849-1-git-send-email-zohar@linux.vnet.ibm.com> X-TM-AS-GCONF: 00 x-cbid: 18050113-0040-0000-0000-00000453CC13 X-IBM-AV-DETECTION: SAVI=unused REMOTE=unused XFE=unused x-cbparentid: 18050113-0041-0000-0000-000020F7E72F Message-Id: <1525182503-13849-2-git-send-email-zohar@linux.vnet.ibm.com> X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:,, definitions=2018-05-01_07:,, signatures=0 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 malwarescore=0 suspectscore=1 phishscore=0 bulkscore=0 spamscore=0 clxscore=1015 lowpriorityscore=0 impostorscore=0 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1709140000 definitions=main-1805010138 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Add an LSM hook prior to allowing firmware sysfs fallback loading. Signed-off-by: Mimi Zohar Cc: Luis R. Rodriguez Cc: David Howells Cc: Kees Cook Cc: Matthew Garrett --- drivers/base/firmware_loader/fallback.c | 7 +++++++ include/linux/fs.h | 1 + 2 files changed, 8 insertions(+) diff --git a/drivers/base/firmware_loader/fallback.c b/drivers/base/firmware_loader/fallback.c index 31b5015b59fe..23d2af30474e 100644 --- a/drivers/base/firmware_loader/fallback.c +++ b/drivers/base/firmware_loader/fallback.c @@ -651,6 +651,8 @@ static bool fw_force_sysfs_fallback(unsigned int opt_flags) static bool fw_run_sysfs_fallback(unsigned int opt_flags) { + int ret; + if (fw_fallback_config.ignore_sysfs_fallback) { pr_info_once("Ignoring firmware sysfs fallback due to sysctl knob\n"); return false; @@ -659,6 +661,11 @@ static bool fw_run_sysfs_fallback(unsigned int opt_flags) if ((opt_flags & FW_OPT_NOFALLBACK)) return false; + /* Also permit LSMs and IMA to fail firmware sysfs fallback */ + ret = security_kernel_read_file(NULL, READING_FIRMWARE_FALLBACK); + if (ret < 0) + return ret; + return fw_force_sysfs_fallback(opt_flags); } diff --git a/include/linux/fs.h b/include/linux/fs.h index 760d8da1b6c7..dc16a73c3d38 100644 --- a/include/linux/fs.h +++ b/include/linux/fs.h @@ -2810,6 +2810,7 @@ extern int do_pipe_flags(int *, int); id(UNKNOWN, unknown) \ id(FIRMWARE, firmware) \ id(FIRMWARE_PREALLOC_BUFFER, firmware) \ + id(FIRMWARE_FALLBACK, firmware) \ id(MODULE, kernel-module) \ id(KEXEC_IMAGE, kexec-image) \ id(KEXEC_INITRAMFS, kexec-initramfs) \ -- 2.7.5