From: Deven Bowers <deven.desai@linux.microsoft.com> To: agk@redhat.com, axboe@kernel.dk, snitzer@redhat.com, jmorris@namei.org, serge@hallyn.com, zohar@linux.ibm.com, viro@zeniv.linux.org.uk, paul@paul-moore.com, eparis@redhat.com, jannh@google.com, dm-devel@redhat.com, linux-integrity@vger.kernel.org, linux-security-module@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-block@vger.kernel.org, linux-audit@redhat.com Cc: tyhicks@linux.microsoft.com, linux-kernel@vger.kernel.org, corbet@lwn.net, sashal@kernel.org, jaskarankhurana@linux.microsoft.com, mdsakib@microsoft.com, nramas@linux.microsoft.com, pasha.tatashin@soleen.com Subject: [RFC PATCH v5 07/11] dm-verity: add bdev_setsecurity hook for dm-verity signature Date: Tue, 28 Jul 2020 14:36:07 -0700 [thread overview] Message-ID: <20200728213614.586312-8-deven.desai@linux.microsoft.com> (raw) In-Reply-To: <20200728213614.586312-1-deven.desai@linux.microsoft.com> Add a security hook call to set a security property of a block_device in dm-verity with the results of a verified, signed root-hash. Signed-off-by: Deven Bowers <deven.desai@linux.microsoft.com> --- drivers/md/dm-verity-verify-sig.c | 7 +++++++ include/linux/device-mapper.h | 2 ++ 2 files changed, 9 insertions(+) diff --git a/drivers/md/dm-verity-verify-sig.c b/drivers/md/dm-verity-verify-sig.c index 27dac8aa2e5a..242e2421d3c8 100644 --- a/drivers/md/dm-verity-verify-sig.c +++ b/drivers/md/dm-verity-verify-sig.c @@ -8,7 +8,10 @@ #include <linux/device-mapper.h> #include <linux/verification.h> #include <keys/user-type.h> +#include <linux/security.h> +#include <linux/list.h> #include <linux/module.h> +#include "dm-core.h" #include "dm-verity.h" #include "dm-verity-verify-sig.h" @@ -182,6 +185,10 @@ int verity_verify_root_hash(const struct dm_verity *v) goto cleanup; sig_target->passed = true; + + ret = security_bdev_setsecurity(dm_table_get_md(v->ti->table)->bdev, + DM_VERITY_SIGNATURE_SEC_NAME, + v->sig->sig, v->sig->sig_size); cleanup: kfree(root_hash); return ret; diff --git a/include/linux/device-mapper.h b/include/linux/device-mapper.h index 8750f2dc5613..02be0be21d38 100644 --- a/include/linux/device-mapper.h +++ b/include/linux/device-mapper.h @@ -624,4 +624,6 @@ static inline unsigned long to_bytes(sector_t n) return (n << SECTOR_SHIFT); } +#define DM_VERITY_SIGNATURE_SEC_NAME DM_NAME ".verity-sig" + #endif /* _LINUX_DEVICE_MAPPER_H */ -- 2.27.0
WARNING: multiple messages have this Message-ID (diff)
From: Deven Bowers <deven.desai@linux.microsoft.com> To: agk@redhat.com, axboe@kernel.dk, snitzer@redhat.com, jmorris@namei.org, serge@hallyn.com, zohar@linux.ibm.com, viro@zeniv.linux.org.uk, paul@paul-moore.com, eparis@redhat.com, jannh@google.com, dm-devel@redhat.com, linux-integrity@vger.kernel.org, linux-security-module@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-block@vger.kernel.org, linux-audit@redhat.com Cc: sashal@kernel.org, pasha.tatashin@soleen.com, mdsakib@microsoft.com, corbet@lwn.net, linux-kernel@vger.kernel.org, nramas@linux.microsoft.com, tyhicks@linux.microsoft.com, jaskarankhurana@linux.microsoft.com Subject: [RFC PATCH v5 07/11] dm-verity: add bdev_setsecurity hook for dm-verity signature Date: Tue, 28 Jul 2020 14:36:07 -0700 [thread overview] Message-ID: <20200728213614.586312-8-deven.desai@linux.microsoft.com> (raw) In-Reply-To: <20200728213614.586312-1-deven.desai@linux.microsoft.com> Add a security hook call to set a security property of a block_device in dm-verity with the results of a verified, signed root-hash. Signed-off-by: Deven Bowers <deven.desai@linux.microsoft.com> --- drivers/md/dm-verity-verify-sig.c | 7 +++++++ include/linux/device-mapper.h | 2 ++ 2 files changed, 9 insertions(+) diff --git a/drivers/md/dm-verity-verify-sig.c b/drivers/md/dm-verity-verify-sig.c index 27dac8aa2e5a..242e2421d3c8 100644 --- a/drivers/md/dm-verity-verify-sig.c +++ b/drivers/md/dm-verity-verify-sig.c @@ -8,7 +8,10 @@ #include <linux/device-mapper.h> #include <linux/verification.h> #include <keys/user-type.h> +#include <linux/security.h> +#include <linux/list.h> #include <linux/module.h> +#include "dm-core.h" #include "dm-verity.h" #include "dm-verity-verify-sig.h" @@ -182,6 +185,10 @@ int verity_verify_root_hash(const struct dm_verity *v) goto cleanup; sig_target->passed = true; + + ret = security_bdev_setsecurity(dm_table_get_md(v->ti->table)->bdev, + DM_VERITY_SIGNATURE_SEC_NAME, + v->sig->sig, v->sig->sig_size); cleanup: kfree(root_hash); return ret; diff --git a/include/linux/device-mapper.h b/include/linux/device-mapper.h index 8750f2dc5613..02be0be21d38 100644 --- a/include/linux/device-mapper.h +++ b/include/linux/device-mapper.h @@ -624,4 +624,6 @@ static inline unsigned long to_bytes(sector_t n) return (n << SECTOR_SHIFT); } +#define DM_VERITY_SIGNATURE_SEC_NAME DM_NAME ".verity-sig" + #endif /* _LINUX_DEVICE_MAPPER_H */ -- 2.27.0 -- Linux-audit mailing list Linux-audit@redhat.com https://www.redhat.com/mailman/listinfo/linux-audit
next prev parent reply other threads:[~2020-07-28 21:37 UTC|newest] Thread overview: 147+ messages / expand[flat|nested] mbox.gz Atom feed top 2020-07-28 21:36 [RFC PATCH v5 00/11] Integrity Policy Enforcement LSM (IPE) Deven Bowers 2020-07-28 21:36 ` Deven Bowers 2020-07-28 21:36 ` Deven Bowers 2020-07-28 21:36 ` [RFC PATCH v5 01/11] scripts: add ipe tooling to generate boot policy Deven Bowers 2020-07-28 21:36 ` Deven Bowers 2020-07-28 21:36 ` [RFC PATCH v5 02/11] security: add ipe lsm evaluation loop and audit system Deven Bowers 2020-07-28 21:36 ` Deven Bowers 2020-07-28 21:36 ` [RFC PATCH v5 03/11] security: add ipe lsm policy parser and policy loading Deven Bowers 2020-07-28 21:36 ` Deven Bowers 2020-07-28 21:36 ` Deven Bowers 2020-07-28 21:36 ` [RFC PATCH v5 04/11] ipe: add property for trust of boot volume Deven Bowers 2020-07-28 21:36 ` Deven Bowers 2020-07-28 21:36 ` [RFC PATCH v5 05/11] fs: add security blob and hooks for block_device Deven Bowers 2020-07-28 21:36 ` Deven Bowers 2020-07-28 22:22 ` Casey Schaufler 2020-07-28 22:22 ` Casey Schaufler 2020-07-28 22:40 ` Al Viro 2020-07-28 22:40 ` Al Viro 2020-07-28 23:55 ` Deven Bowers 2020-07-28 23:55 ` Deven Bowers 2020-07-28 21:36 ` [RFC PATCH v5 06/11] dm-verity: move signature check after tree validation Deven Bowers 2020-07-28 21:36 ` Deven Bowers 2020-07-28 21:50 ` Eric Biggers 2020-07-28 21:50 ` Eric Biggers 2020-07-28 23:55 ` Deven Bowers 2020-07-28 23:55 ` Deven Bowers 2020-07-28 21:36 ` Deven Bowers [this message] 2020-07-28 21:36 ` [RFC PATCH v5 07/11] dm-verity: add bdev_setsecurity hook for dm-verity signature Deven Bowers 2020-07-28 21:36 ` [RFC PATCH v5 08/11] ipe: add property for signed dmverity volumes Deven Bowers 2020-07-28 21:36 ` Deven Bowers 2020-07-28 21:36 ` [RFC PATCH v5 09/11] dm-verity: add bdev_setsecurity hook for root-hash Deven Bowers 2020-07-28 21:36 ` Deven Bowers 2020-07-28 21:36 ` [RFC PATCH v5 10/11] documentation: add ipe documentation Deven Bowers 2020-07-28 21:36 ` Deven Bowers 2020-07-28 21:36 ` [RFC PATCH v5 10/12] ipe: add property for dmverity roothash Deven Bowers 2020-07-28 21:36 ` Deven Bowers 2020-07-28 21:36 ` [RFC PATCH v5 11/11] cleanup: uapi/linux/audit.h Deven Bowers 2020-07-28 21:36 ` Deven Bowers 2020-07-28 21:36 ` [RFC PATCH v5 11/12] documentation: add ipe documentation Deven Bowers 2020-07-28 21:36 ` Deven Bowers 2020-07-28 21:36 ` [RFC PATCH v5 12/12] cleanup: uapi/linux/audit.h Deven Bowers 2020-07-28 21:36 ` Deven Bowers 2020-08-02 11:55 ` [RFC PATCH v5 00/11] Integrity Policy Enforcement LSM (IPE) Pavel Machek 2020-08-02 11:55 ` Pavel Machek 2020-08-02 14:03 ` Sasha Levin 2020-08-02 14:03 ` Sasha Levin 2020-08-02 14:31 ` Pavel Machek 2020-08-02 14:31 ` Pavel Machek 2020-08-02 16:43 ` [dm-devel] " James Bottomley 2020-08-02 16:43 ` James Bottomley 2020-08-04 16:07 ` Deven Bowers 2020-08-04 16:07 ` Deven Bowers 2020-08-04 16:07 ` [dm-devel] " Deven Bowers 2020-08-05 15:01 ` James Bottomley 2020-08-05 15:01 ` James Bottomley 2020-08-05 15:01 ` [dm-devel] " James Bottomley 2020-08-05 16:59 ` James Morris 2020-08-05 16:59 ` James Morris 2020-08-05 18:15 ` Mimi Zohar 2020-08-05 18:15 ` Mimi Zohar 2020-08-05 23:51 ` James Morris 2020-08-05 23:51 ` James Morris 2020-08-06 14:33 ` Mimi Zohar 2020-08-06 14:33 ` Mimi Zohar 2020-08-06 14:33 ` Mimi Zohar 2020-08-07 16:41 ` James Morris 2020-08-07 16:41 ` James Morris 2020-08-07 17:31 ` Mimi Zohar 2020-08-07 17:31 ` Mimi Zohar 2020-08-07 18:40 ` Mimi Zohar 2020-08-07 18:40 ` Mimi Zohar 2020-08-10 20:29 ` James Morris 2020-08-10 20:29 ` James Morris 2020-08-08 17:47 ` Chuck Lever 2020-08-08 17:47 ` Chuck Lever 2020-08-09 17:16 ` Mimi Zohar 2020-08-09 17:16 ` Mimi Zohar 2020-08-10 15:35 ` James Bottomley 2020-08-10 15:35 ` James Bottomley 2020-08-10 16:35 ` Mimi Zohar 2020-08-10 16:35 ` Mimi Zohar 2020-08-10 17:13 ` James Bottomley 2020-08-10 17:13 ` James Bottomley 2020-08-10 17:57 ` Mimi Zohar 2020-08-10 17:57 ` Mimi Zohar 2020-08-10 23:36 ` Chuck Lever 2020-08-10 23:36 ` Chuck Lever 2020-08-10 23:36 ` Chuck Lever 2020-08-11 5:43 ` James Bottomley 2020-08-11 5:43 ` James Bottomley 2020-08-11 5:43 ` James Bottomley 2020-08-11 14:48 ` Chuck Lever 2020-08-11 14:48 ` Chuck Lever 2020-08-11 14:48 ` Chuck Lever 2020-08-11 15:32 ` James Bottomley 2020-08-11 15:32 ` James Bottomley 2020-08-11 15:32 ` James Bottomley 2020-08-11 19:30 ` Pavel Machek 2020-08-11 19:30 ` Pavel Machek 2020-08-11 19:30 ` Pavel Machek 2020-08-12 14:45 ` Chuck Lever 2020-08-12 14:45 ` Chuck Lever 2020-08-12 14:45 ` Chuck Lever 2020-08-11 15:53 ` James Bottomley 2020-08-11 15:53 ` James Bottomley 2020-08-11 15:53 ` James Bottomley 2020-08-12 14:15 ` Chuck Lever 2020-08-12 14:15 ` Chuck Lever 2020-08-12 14:15 ` Chuck Lever 2020-08-12 15:51 ` James Bottomley 2020-08-12 15:51 ` James Bottomley 2020-08-12 15:51 ` James Bottomley 2020-08-13 14:42 ` Chuck Lever 2020-08-13 14:42 ` Chuck Lever 2020-08-13 14:42 ` Chuck Lever 2020-08-13 15:10 ` James Bottomley 2020-08-13 15:10 ` James Bottomley 2020-08-13 15:10 ` James Bottomley 2020-08-14 14:21 ` Chuck Lever 2020-08-14 14:21 ` Chuck Lever 2020-08-14 14:21 ` Chuck Lever 2020-08-11 18:28 ` James Bottomley 2020-08-11 18:28 ` James Bottomley 2020-08-11 18:28 ` James Bottomley 2020-08-12 13:56 ` Chuck Lever 2020-08-12 13:56 ` Chuck Lever 2020-08-12 13:56 ` Chuck Lever 2020-08-12 15:42 ` James Bottomley 2020-08-12 15:42 ` James Bottomley 2020-08-12 15:42 ` James Bottomley 2020-08-13 14:21 ` Chuck Lever 2020-08-13 14:21 ` Chuck Lever 2020-08-13 14:21 ` Chuck Lever 2020-08-13 14:42 ` James Bottomley 2020-08-13 14:42 ` James Bottomley 2020-08-13 14:42 ` James Bottomley 2020-08-13 14:56 ` Chuck Lever 2020-08-13 14:56 ` Chuck Lever 2020-08-13 14:56 ` Chuck Lever 2020-08-11 21:03 ` James Morris 2020-08-11 21:03 ` James Morris 2020-08-11 21:03 ` James Morris 2020-08-12 14:18 ` Chuck Lever 2020-08-12 14:18 ` Chuck Lever 2020-08-12 14:18 ` Chuck Lever 2020-08-12 17:07 ` Deven Bowers 2020-08-12 17:07 ` Deven Bowers
Reply instructions: You may reply publicly to this message via plain-text email using any one of the following methods: * Save the following mbox file, import it into your mail client, and reply-to-all from there: mbox Avoid top-posting and favor interleaved quoting: https://en.wikipedia.org/wiki/Posting_style#Interleaved_style * Reply using the --to, --cc, and --in-reply-to switches of git-send-email(1): git send-email \ --in-reply-to=20200728213614.586312-8-deven.desai@linux.microsoft.com \ --to=deven.desai@linux.microsoft.com \ --cc=agk@redhat.com \ --cc=axboe@kernel.dk \ --cc=corbet@lwn.net \ --cc=dm-devel@redhat.com \ --cc=eparis@redhat.com \ --cc=jannh@google.com \ --cc=jaskarankhurana@linux.microsoft.com \ --cc=jmorris@namei.org \ --cc=linux-audit@redhat.com \ --cc=linux-block@vger.kernel.org \ --cc=linux-fsdevel@vger.kernel.org \ --cc=linux-integrity@vger.kernel.org \ --cc=linux-kernel@vger.kernel.org \ --cc=linux-security-module@vger.kernel.org \ --cc=mdsakib@microsoft.com \ --cc=nramas@linux.microsoft.com \ --cc=pasha.tatashin@soleen.com \ --cc=paul@paul-moore.com \ --cc=sashal@kernel.org \ --cc=serge@hallyn.com \ --cc=snitzer@redhat.com \ --cc=tyhicks@linux.microsoft.com \ --cc=viro@zeniv.linux.org.uk \ --cc=zohar@linux.ibm.com \ /path/to/YOUR_REPLY https://kernel.org/pub/software/scm/git/docs/git-send-email.html * If your mail client supports setting the In-Reply-To header via mailto: links, try the mailto: linkBe sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.