Received: by 2002:ad5:4acb:0:0:0:0:0 with SMTP id n11csp4300392imw; Tue, 12 Jul 2022 05:45:20 -0700 (PDT) X-Google-Smtp-Source: AGRyM1veB6zc/IuQkP+Sny1FEKPtt7dpTmxvAnLLSdpf0sPpPKYR3hzIPUSNIbPLRht75RWCu3J8 X-Received: by 2002:a17:90a:5e0b:b0:1f0:5565:ee6e with SMTP id w11-20020a17090a5e0b00b001f05565ee6emr4124706pjf.128.1657629920490; Tue, 12 Jul 2022 05:45:20 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1657629920; cv=none; d=google.com; s=arc-20160816; b=rcLTDKd9xGJ+QGB09fk9RsPaLs2lD69+sqCVd531nxpIbeD5IrrX+vQjd21xlDAyhm 6mYPgU+321aVAqUKK+uCC5Jj6xuaHHIUlG/6uHymwsZ8V0lC7l6CiP+6S1KRLcBcjbYS vmJNmuOtD3qdvsmkxMSFOAdP+0EyARBWigjEegYL4XC5zhMqmHDKvoLLLusxsv/ZKCBA XbxK/nNwxgKQCOJQT5Ko8CGMv4bsqBVId+XDcFMrLFxcNedOF6BeoX08sRcaqqXddKt1 3cgFwObSnoSjgztYtsBGUwM4MQTfP/RBQwKqIOmQ/Q+/Kx/F/2cdvJEPFr4J/44FeJF6 7YvQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :dkim-signature; bh=mahips1lu0ySaTvg9gVpfKQSOO+wb9pXCCegZia8ars=; b=F5XHsww+xqY1C29SGkIO2SVA2T5JKqR4Gyaaj8exa71b+NO9tN+w9IhAwI5NLzNiQM NRoKUHH4zdFeI8AesfOsgu2DtR6wFDXbhsZfody98KSO4GSselVdn6OfCgxvqirGcq1b SCtKy5qQsVnTjEWg5UMESdzkDY1EBxEK7pL1SEouzBfpZxT3fX7gOAnTaUtkFfELoz/s 9P3peA5an0fzYYNC4b6DPT6QOdPgtSfvAKFNcAFkDmThljiOKgpdt6q7rGeSH07IL++/ /CMkWfiIZVzEmMsAenzHR8OXoD0QD1v+lGO96PafjxEll2/MsvwvSYl9/Mn124xNFpGS EKVw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@redhat.com header.s=mimecast20190719 header.b=Kut4eyxR; spf=pass (google.com: domain of linux-nfs-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-nfs-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=redhat.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id j11-20020a63fc0b000000b0040da1209ed4si13704446pgi.775.2022.07.12.05.44.58; Tue, 12 Jul 2022 05:45:20 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-nfs-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@redhat.com header.s=mimecast20190719 header.b=Kut4eyxR; spf=pass (google.com: domain of linux-nfs-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-nfs-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=redhat.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232416AbiGLMf2 (ORCPT + 99 others); Tue, 12 Jul 2022 08:35:28 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:52350 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231893AbiGLMf1 (ORCPT ); Tue, 12 Jul 2022 08:35:27 -0400 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by lindbergh.monkeyblade.net (Postfix) with ESMTP id 5DD522E9F5 for ; Tue, 12 Jul 2022 05:35:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1657629325; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=mahips1lu0ySaTvg9gVpfKQSOO+wb9pXCCegZia8ars=; b=Kut4eyxRTjQp+T7Za8mcvc3DH8zlUt8yiw4etn2rFnCrwv6HHCbhZ074Ifnozwo2bxJXtJ mnn8aKGeNwMS0dc/9W6Q7kfE3zOvvpR+EFC571PGslL2k0wt72C2BTtbVXe5mCTkUQyZye lQIvjviwGXQnoNznzqa8X0obGvAF0Oo= Received: from mimecast-mx02.redhat.com (mimecast-mx02.redhat.com [66.187.233.88]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id us-mta-605-0S4qp9sdOfi3PS15Qd8Fig-1; Tue, 12 Jul 2022 08:35:22 -0400 X-MC-Unique: 0S4qp9sdOfi3PS15Qd8Fig-1 Received: from smtp.corp.redhat.com (int-mx08.intmail.prod.int.rdu2.redhat.com [10.11.54.8]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx02.redhat.com (Postfix) with ESMTPS id 1039918E0043; Tue, 12 Jul 2022 12:35:22 +0000 (UTC) Received: from bcodding.csb (unknown [10.22.48.8]) by smtp.corp.redhat.com (Postfix) with ESMTP id CDA06C28129; Tue, 12 Jul 2022 12:35:21 +0000 (UTC) Received: by bcodding.csb (Postfix, from userid 24008) id 59EB010C30E1; Tue, 12 Jul 2022 08:35:21 -0400 (EDT) From: Benjamin Coddington To: David Howells , linux-kernel@vger.kernel.org Cc: ebiederm@xmission.com, Ian Kent , Trond Myklebust , linux-nfs@vger.kernel.org, linux-fsdevel@vger.kernel.org Subject: [PATCH 1/2] KEYS: Add key_type keyagent Date: Tue, 12 Jul 2022 08:35:20 -0400 Message-Id: <65d37935ce8cc978430f93b831482e9455b9186d.1657624639.git.bcodding@redhat.com> In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Scanned-By: MIMEDefang 2.85 on 10.11.54.8 X-Spam-Status: No, score=-3.4 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_LOW, SPF_HELO_NONE,SPF_NONE,T_SCC_BODY_TEXT_LINE autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-nfs@vger.kernel.org Define and register a new key_type called keyagent. When instantiated, keyagent keys take a reference on the struct pid of the current task, and store a number between SIGRTMIN and SIGRTMAX. In a later patch, we'll use that number to send a realtime signal to the keyagent task in order to answer request-key callouts for other key types. Signed-off-by: Benjamin Coddington --- security/keys/Kconfig | 9 +++++ security/keys/Makefile | 1 + security/keys/keyagent.c | 73 ++++++++++++++++++++++++++++++++++++++++ 3 files changed, 83 insertions(+) create mode 100644 security/keys/keyagent.c diff --git a/security/keys/Kconfig b/security/keys/Kconfig index abb03a1b2a5c..f31a0f94ca88 100644 --- a/security/keys/Kconfig +++ b/security/keys/Kconfig @@ -112,6 +112,15 @@ config USER_DECRYPTED_DATA If you are unsure as to whether this is required, answer N. +config KEYAGENT + bool "KEYAGENT" + depends on KEYS + help + This option allows persistent userland processes to answer + request-key callouts. + + If you are unsure as to whether this is required, answer N. + config KEY_DH_OPERATIONS bool "Diffie-Hellman operations on retained keys" depends on KEYS diff --git a/security/keys/Makefile b/security/keys/Makefile index 5f40807f05b3..c753f8f79c38 100644 --- a/security/keys/Makefile +++ b/security/keys/Makefile @@ -23,6 +23,7 @@ obj-$(CONFIG_SYSCTL) += sysctl.o obj-$(CONFIG_PERSISTENT_KEYRINGS) += persistent.o obj-$(CONFIG_KEY_DH_OPERATIONS) += dh.o obj-$(CONFIG_ASYMMETRIC_KEY_TYPE) += keyctl_pkey.o +obj-$(CONFIG_KEYAGENT) += keyagent.o # # Key types diff --git a/security/keys/keyagent.c b/security/keys/keyagent.c new file mode 100644 index 000000000000..87ebfe00c710 --- /dev/null +++ b/security/keys/keyagent.c @@ -0,0 +1,73 @@ +// SPDX-License-Identifier: GPL-2.0-or-later +/* Key Agent handling + * + * Copyright (C) 2022 Red Hat Inc. All Rights Reserved. + * Written by Benjamin Coddington (bcodding@redhat.com) + */ + +#include +#include +#include +#include + +#include + +/* + * Keyagent key payload. + */ +struct keyagent { + struct pid *pid; + int sig; +}; + +/* + * Instantiate takes a reference to the current task's struct pid + * and the requested realtime signal number. + */ +static int +keyagent_instantiate(struct key *key, struct key_preparsed_payload *prep) +{ + struct keyagent *ka; + __be16 sig = *(__be16 *)prep->data; + + /* Only real-time signals numbers allowed */ + if (sig < SIGRTMIN || sig > SIGRTMAX) + return -EINVAL; + + ka = kzalloc(sizeof(struct keyagent), GFP_KERNEL); + if (!ka) + return -ENOMEM; + + ka->pid = get_task_pid(current, PIDTYPE_PID); + ka->sig = sig; + key->payload.data[0] = ka; + + return 0; +} + +static void keyagent_destroy(struct key *key) +{ + struct keyagent *ka = key->payload.data[0]; + + put_pid(ka->pid); + kfree(ka); +} + +/* + * keyagent keys represent userland processes waiting on signals from the + * kernel to respond to request-key callouts + */ +struct key_type key_type_keyagent = { + .name = "keyagent", + .instantiate = keyagent_instantiate, + .def_datalen = sizeof(struct keyagent), + .destroy = keyagent_destroy, + .describe = user_describe, +}; + +static int __init keyagent_init(void) +{ + return register_key_type(&key_type_keyagent); +} + +late_initcall(keyagent_init); -- 2.31.1