Received: by 2002:a05:7412:37c9:b0:e2:908c:2ebd with SMTP id jz9csp2856074rdb; Fri, 22 Sep 2023 10:06:31 -0700 (PDT) X-Google-Smtp-Source: AGHT+IEYmMrHopqdjeKC7Efo0npSE4jHmMFKPGyQ32SC6mSkFrT8LX5I+Fy+BZxCwOrH9hLqX2Wf X-Received: by 2002:a05:6358:3407:b0:139:4783:5140 with SMTP id h7-20020a056358340700b0013947835140mr221877rwd.16.1695402391273; Fri, 22 Sep 2023 10:06:31 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1695402391; cv=none; d=google.com; s=arc-20160816; b=TE5DG+Dm+xCFneAjY2MszMOYBpvggesInuNc8xRm5yNnMZAABWbDJeMWf7KY2GQJw6 xce1UB4pXIFs4L8GuyZ408smkvS4U4+L76D8GiFl+D+bkAuxQojtlynbaXzjpn3KKH5z ac3Kxs6Jbu+2ry489EGF67NL9MtVPxsJj9NaEWuqddzwKhTG8bS/3PYqARaorWDrjgns oWAkitQWCzGSA1yvX9+QRHuD4kGhjG0Nd/eEcNiUUJ3OHOtMqM3MFrDJzqvaEUhfjNn9 HuOQ3+vG4svV2Sm1wVQtXtk3hZcFVDEm+49rcec38jL+TGKPkwucIG/ErwriNYN3WzGO az0w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-disposition:mime-version:message-id :subject:cc:to:from:date:dkim-signature; bh=ZgApR4QKR0jTTIWGbZED9KyQ8+ob7E8gjbpmfglkOS4=; fh=s+AzyW1cR5UyFtbqbMzs/l2LyFDBrc2AepE8GOrHbas=; b=n4QX+RgRB1YH5nzJOA5oBWdIXp5HvDKNyEV0Xv0wTZL9MmuSx6Z69MFMxSfGiNpMOD UxN6UrIIxuKdoeUNUmX58SLti2wlUedjAMJvQtsV4WxPVpZU6IBc6bfKWdQZYTbAKQHh PvfeAq0VkKZ144ZIpAcBYVRKKnuCpJ/x5R+qnI5o1JwQfzhj1weKyrwQli2Ny0AzE5Ge sBhRzXI5PEd538n3xx/am5LsKSIrAS5Q2ErmV/H9SVhoGsKFbW9XsIwXdnhSMyR1Yd+b /j9D4glR7W/wCRpzOKgVS89K7cFaUFECyq0aMrrTRWHL0b9vXi4zYl36QC67Tc+js57c fPyQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=By1U7SEW; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::3:8 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Return-Path: Received: from fry.vger.email (fry.vger.email. [2620:137:e000::3:8]) by mx.google.com with ESMTPS id w64-20020a636243000000b00573ed0023e1si4223732pgb.333.2023.09.22.10.06.30 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 22 Sep 2023 10:06:31 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::3:8 as permitted sender) client-ip=2620:137:e000::3:8; Authentication-Results: mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=By1U7SEW; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::3:8 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Received: from out1.vger.email (depot.vger.email [IPv6:2620:137:e000::3:0]) by fry.vger.email (Postfix) with ESMTP id 523D783BB58B; Fri, 22 Sep 2023 09:59:10 -0700 (PDT) X-Virus-Status: Clean X-Virus-Scanned: clamav-milter 0.103.10 at fry.vger.email Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231247AbjIVQ7K (ORCPT + 99 others); Fri, 22 Sep 2023 12:59:10 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:56142 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229538AbjIVQ7J (ORCPT ); Fri, 22 Sep 2023 12:59:09 -0400 Received: from mail-pl1-x634.google.com (mail-pl1-x634.google.com [IPv6:2607:f8b0:4864:20::634]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 6A330122 for ; Fri, 22 Sep 2023 09:59:03 -0700 (PDT) Received: by mail-pl1-x634.google.com with SMTP id d9443c01a7336-1c0c6d4d650so21177315ad.0 for ; Fri, 22 Sep 2023 09:59:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; t=1695401943; x=1696006743; darn=vger.kernel.org; h=content-disposition:mime-version:message-id:subject:cc:to:from:date :from:to:cc:subject:date:message-id:reply-to; bh=ZgApR4QKR0jTTIWGbZED9KyQ8+ob7E8gjbpmfglkOS4=; b=By1U7SEWbR+JttBpZqs5RCKlg3WBennOyEICh29yud2CTEiewcdgSdWagQ9HSw7wX1 cEKcjGvJnxcT16oU1kK+1j4wVzbMkzLtROj3ZKO3QI6IZ5dCfW9MNNzwIYjR/YX+xNm5 MUHn0MQFKuE08BNWY/K6wW+3S8IIPN5hL33uQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1695401943; x=1696006743; h=content-disposition:mime-version:message-id:subject:cc:to:from:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=ZgApR4QKR0jTTIWGbZED9KyQ8+ob7E8gjbpmfglkOS4=; b=X9vaagQf5I21pMzYMVv8iDwtddvhmQDGMcsnDsaoD/Tr+GSDeervDfkHc27pS80bvA SBzmW7tVCYbHMRwmGqRWwY9pvAG+Gmh0HN/Z3Q4QDuUqJ3jiH8HyiiTX+RBh4DU9KvOs 6GOI+L6Cn8+APCBt/pENrVRybjIhjv8QwJ5IDFqC1jJN8Bfom8o0UaqAjTK5vZjks71K nVitAOvxGXFGxbFyeUG2jwg84rcmEdrDTi8yjjb8SmptHkVx7oyPKHEHHJphAfNk9JUL J/ptt5G/2HN6o5R7lJ2/n3dDpINMkFoZADo5o4XTGawDmH9Y5cddoDs7fvRLW2u+c4UV o+Mg== X-Gm-Message-State: AOJu0YxyAbxQwrVukuWfoCTg/toF+4lJXfeUUOJ4PXTNfIqKAko+Dur5 /8jeRG7HaPNjq/q+fK6FnNMEyumWU6DNwBsRuIo= X-Received: by 2002:a17:903:2442:b0:1c4:375c:110a with SMTP id l2-20020a170903244200b001c4375c110amr27448pls.19.1695401942810; Fri, 22 Sep 2023 09:59:02 -0700 (PDT) Received: from www.outflux.net (198-0-35-241-static.hfc.comcastbusiness.net. [198.0.35.241]) by smtp.gmail.com with ESMTPSA id j5-20020a170902da8500b001c57aac6e5esm3728308plx.23.2023.09.22.09.59.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 22 Sep 2023 09:59:02 -0700 (PDT) Date: Fri, 22 Sep 2023 09:59:01 -0700 From: Kees Cook To: Linus Torvalds Cc: linux-kernel@vger.kernel.org, Alexey Dobriyan , Kees Cook Subject: [GIT PULL] hardening fixes for v6.6-rc3 Message-ID: <202309220957.927ADC0586@keescook> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline X-Spam-Status: No, score=-0.9 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,HEADER_FROM_DIFFERENT_DOMAINS, MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on fry.vger.email Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org X-Greylist: Sender passed SPF test, not delayed by milter-greylist-4.6.4 (fry.vger.email [0.0.0.0]); Fri, 22 Sep 2023 09:59:10 -0700 (PDT) Hi Linus, Please pull these hardening fixes for v6.6-rc3. These have been in -next for a week now. Thanks! -Kees The following changes since commit 5f536ac6a5a7b67351e4e5ae4f9e1e57d31268e6: LoadPin: Annotate struct dm_verity_loadpin_trusted_root_digest with __counted_by (2023-08-25 16:07:30 -0700) are available in the Git repository at: https://git.kernel.org/pub/scm/linux/kernel/git/kees/linux.git tags/hardening-v6.6-rc3 for you to fetch changes up to 32a4ec211d4164e667d9d0b807fadf02053cd2e9: uapi: stddef.h: Fix __DECLARE_FLEX_ARRAY for C++ (2023-09-13 20:09:49 -0700) ---------------------------------------------------------------- hardening fixes for v6.6-rc3 - Fix UAPI stddef.h to avoid C++-ism (Alexey Dobriyan) - Fix harmless UAPI stddef.h header guard endif (Alexey Dobriyan) ---------------------------------------------------------------- Alexey Dobriyan (2): uapi: stddef.h: Fix header guard location uapi: stddef.h: Fix __DECLARE_FLEX_ARRAY for C++ include/uapi/linux/stddef.h | 7 +++++++ 1 file changed, 7 insertions(+) -- Kees Cook