From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753100AbeFASTQ (ORCPT ); Fri, 1 Jun 2018 14:19:16 -0400 Received: from mx2.suse.de ([195.135.220.15]:35335 "EHLO mx2.suse.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751584AbeFASTP (ORCPT ); Fri, 1 Jun 2018 14:19:15 -0400 Date: Fri, 1 Jun 2018 20:19:13 +0200 From: "Luis R. Rodriguez" To: Mimi Zohar Cc: linux-integrity@vger.kernel.org, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, David Howells , "Luis R . Rodriguez" , Eric Biederman , kexec@lists.infradead.org, Andres Rodriguez , Greg Kroah-Hartman , Ard Biesheuvel , Kees Cook Subject: Re: [PATCH v4 4/8] firmware: add call to LSM hook before firmware sysfs fallback Message-ID: <20180601181913.GN4511@wotan.suse.de> References: <1527616920-5415-1-git-send-email-zohar@linux.vnet.ibm.com> <1527616920-5415-5-git-send-email-zohar@linux.vnet.ibm.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <1527616920-5415-5-git-send-email-zohar@linux.vnet.ibm.com> User-Agent: Mutt/1.6.0 (2016-04-01) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Tue, May 29, 2018 at 02:01:56PM -0400, Mimi Zohar wrote: > Add an LSM hook prior to allowing firmware sysfs fallback loading. Acked-by: Luis R. Rodriguez > Signed-off-by: Mimi Zohar > Cc: Luis R. Rodriguez > Cc: David Howells > Cc: Kees Cook > > Changelog v4: > - call new LSM security_kernel_arg hook > > Changelog v2: > - call security_kernel_read_blob() > - rename the READING_FIRMWARE_FALLBACK kernel_read_file_id enumeration to > READING_FIRMWARE_FALLBACK_SYSFS. > --- > drivers/base/firmware_loader/fallback.c | 7 +++++++ > 1 file changed, 7 insertions(+) > > diff --git a/drivers/base/firmware_loader/fallback.c b/drivers/base/firmware_loader/fallback.c > index 358354148dec..2443bda81631 100644 > --- a/drivers/base/firmware_loader/fallback.c > +++ b/drivers/base/firmware_loader/fallback.c > @@ -651,6 +651,8 @@ static bool fw_force_sysfs_fallback(unsigned int opt_flags) > > static bool fw_run_sysfs_fallback(unsigned int opt_flags) > { > + int ret; > + > if (fw_fallback_config.ignore_sysfs_fallback) { > pr_info_once("Ignoring firmware sysfs fallback due to sysctl knob\n"); > return false; > @@ -659,6 +661,11 @@ static bool fw_run_sysfs_fallback(unsigned int opt_flags) > if ((opt_flags & FW_OPT_NOFALLBACK)) > return false; > > + /* Also permit LSMs and IMA to fail firmware sysfs fallback */ > + ret = security_kernel_load_data(LOADING_FIRMWARE); > + if (ret < 0) > + return ret; > + > return fw_force_sysfs_fallback(opt_flags); > } > > -- > 2.7.5 > > -- Do not panic From mboxrd@z Thu Jan 1 00:00:00 1970 From: mcgrof@kernel.org (Luis R. Rodriguez) Date: Fri, 1 Jun 2018 20:19:13 +0200 Subject: [PATCH v4 4/8] firmware: add call to LSM hook before firmware sysfs fallback In-Reply-To: <1527616920-5415-5-git-send-email-zohar@linux.vnet.ibm.com> References: <1527616920-5415-1-git-send-email-zohar@linux.vnet.ibm.com> <1527616920-5415-5-git-send-email-zohar@linux.vnet.ibm.com> Message-ID: <20180601181913.GN4511@wotan.suse.de> To: linux-security-module@vger.kernel.org List-Id: linux-security-module.vger.kernel.org On Tue, May 29, 2018 at 02:01:56PM -0400, Mimi Zohar wrote: > Add an LSM hook prior to allowing firmware sysfs fallback loading. Acked-by: Luis R. Rodriguez > Signed-off-by: Mimi Zohar > Cc: Luis R. Rodriguez > Cc: David Howells > Cc: Kees Cook > > Changelog v4: > - call new LSM security_kernel_arg hook > > Changelog v2: > - call security_kernel_read_blob() > - rename the READING_FIRMWARE_FALLBACK kernel_read_file_id enumeration to > READING_FIRMWARE_FALLBACK_SYSFS. > --- > drivers/base/firmware_loader/fallback.c | 7 +++++++ > 1 file changed, 7 insertions(+) > > diff --git a/drivers/base/firmware_loader/fallback.c b/drivers/base/firmware_loader/fallback.c > index 358354148dec..2443bda81631 100644 > --- a/drivers/base/firmware_loader/fallback.c > +++ b/drivers/base/firmware_loader/fallback.c > @@ -651,6 +651,8 @@ static bool fw_force_sysfs_fallback(unsigned int opt_flags) > > static bool fw_run_sysfs_fallback(unsigned int opt_flags) > { > + int ret; > + > if (fw_fallback_config.ignore_sysfs_fallback) { > pr_info_once("Ignoring firmware sysfs fallback due to sysctl knob\n"); > return false; > @@ -659,6 +661,11 @@ static bool fw_run_sysfs_fallback(unsigned int opt_flags) > if ((opt_flags & FW_OPT_NOFALLBACK)) > return false; > > + /* Also permit LSMs and IMA to fail firmware sysfs fallback */ > + ret = security_kernel_load_data(LOADING_FIRMWARE); > + if (ret < 0) > + return ret; > + > return fw_force_sysfs_fallback(opt_flags); > } > > -- > 2.7.5 > > -- Do not panic -- To unsubscribe from this list: send the line "unsubscribe linux-security-module" in the body of a message to majordomo at vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html From mboxrd@z Thu Jan 1 00:00:00 1970 Return-path: Received: from mx2.suse.de ([195.135.220.15]) by bombadil.infradead.org with esmtps (Exim 4.90_1 #2 (Red Hat Linux)) id 1fOoe8-0007mo-S1 for kexec@lists.infradead.org; Fri, 01 Jun 2018 18:19:30 +0000 Date: Fri, 1 Jun 2018 20:19:13 +0200 From: "Luis R. Rodriguez" Subject: Re: [PATCH v4 4/8] firmware: add call to LSM hook before firmware sysfs fallback Message-ID: <20180601181913.GN4511@wotan.suse.de> References: <1527616920-5415-1-git-send-email-zohar@linux.vnet.ibm.com> <1527616920-5415-5-git-send-email-zohar@linux.vnet.ibm.com> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: <1527616920-5415-5-git-send-email-zohar@linux.vnet.ibm.com> List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "kexec" Errors-To: kexec-bounces+dwmw2=infradead.org@lists.infradead.org To: Mimi Zohar Cc: Kees Cook , Ard Biesheuvel , Greg Kroah-Hartman , kexec@lists.infradead.org, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, David Howells , "Luis R . Rodriguez" , Eric Biederman , linux-integrity@vger.kernel.org, Andres Rodriguez On Tue, May 29, 2018 at 02:01:56PM -0400, Mimi Zohar wrote: > Add an LSM hook prior to allowing firmware sysfs fallback loading. Acked-by: Luis R. Rodriguez > Signed-off-by: Mimi Zohar > Cc: Luis R. Rodriguez > Cc: David Howells > Cc: Kees Cook > > Changelog v4: > - call new LSM security_kernel_arg hook > > Changelog v2: > - call security_kernel_read_blob() > - rename the READING_FIRMWARE_FALLBACK kernel_read_file_id enumeration to > READING_FIRMWARE_FALLBACK_SYSFS. > --- > drivers/base/firmware_loader/fallback.c | 7 +++++++ > 1 file changed, 7 insertions(+) > > diff --git a/drivers/base/firmware_loader/fallback.c b/drivers/base/firmware_loader/fallback.c > index 358354148dec..2443bda81631 100644 > --- a/drivers/base/firmware_loader/fallback.c > +++ b/drivers/base/firmware_loader/fallback.c > @@ -651,6 +651,8 @@ static bool fw_force_sysfs_fallback(unsigned int opt_flags) > > static bool fw_run_sysfs_fallback(unsigned int opt_flags) > { > + int ret; > + > if (fw_fallback_config.ignore_sysfs_fallback) { > pr_info_once("Ignoring firmware sysfs fallback due to sysctl knob\n"); > return false; > @@ -659,6 +661,11 @@ static bool fw_run_sysfs_fallback(unsigned int opt_flags) > if ((opt_flags & FW_OPT_NOFALLBACK)) > return false; > > + /* Also permit LSMs and IMA to fail firmware sysfs fallback */ > + ret = security_kernel_load_data(LOADING_FIRMWARE); > + if (ret < 0) > + return ret; > + > return fw_force_sysfs_fallback(opt_flags); > } > > -- > 2.7.5 > > -- Do not panic _______________________________________________ kexec mailing list kexec@lists.infradead.org http://lists.infradead.org/mailman/listinfo/kexec