mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: David Howells <dhowells@redhat.com>
To: torvalds@osdl.org, akpm@linux-foundation.org,
	trond.myklebust@fys.uio.no, chuck.lever@oracle.com
Cc: nfsv4@linux-nfs.org, linux-kernel@vger.kernel.org,
	linux-fsdevel@vger.kernel.org, selinux@tycho.nsa.gov,
	linux-security-module@vger.kernel.org, dhowells@redhat.com
Subject: [PATCH 04/45] KEYS: Allow clients to set key perms in key_create_or_update() [ver #35]
Date: Fri, 28 Mar 2008 14:30:31 +0000	[thread overview]
Message-ID: <20080328143031.3483.6520.stgit@warthog.procyon.org.uk> (raw)
In-Reply-To: <20080328143010.3483.99079.stgit@warthog.procyon.org.uk>

From: Arun Raghavan <arunsr@cse.iitk.ac.in>

The key_create_or_update() function provided by the keyring code has a default
set of permissions that are always applied to the key when created. This might
not be desirable to all clients.

Here's a patch that adds a "perm" parameter to the function to address this,
which can be set to KEY_PERM_UNDEF to revert to the current behaviour.

Signed-off-by: Arun Raghavan <arunsr@cse.iitk.ac.in>
Acked-by: David Howells <dhowells@redhat.com>
---

 include/linux/key.h    |    3 +++
 security/keys/key.c    |   18 ++++++++++--------
 security/keys/keyctl.c |    3 ++-
 3 files changed, 15 insertions(+), 9 deletions(-)


diff --git a/include/linux/key.h b/include/linux/key.h
index 163f864..8b0bd33 100644
--- a/include/linux/key.h
+++ b/include/linux/key.h
@@ -67,6 +67,8 @@ struct key;
 #define KEY_OTH_SETATTR	0x00000020
 #define KEY_OTH_ALL	0x0000003f
 
+#define KEY_PERM_UNDEF	0xffffffff
+
 struct seq_file;
 struct user_struct;
 struct signal_struct;
@@ -232,6 +234,7 @@ extern key_ref_t key_create_or_update(key_ref_t keyring,
 				      const char *description,
 				      const void *payload,
 				      size_t plen,
+				      key_perm_t perm,
 				      unsigned long flags);
 
 extern int key_update(key_ref_t key,
diff --git a/security/keys/key.c b/security/keys/key.c
index 654d23b..d98c619 100644
--- a/security/keys/key.c
+++ b/security/keys/key.c
@@ -757,11 +757,11 @@ key_ref_t key_create_or_update(key_ref_t keyring_ref,
 			       const char *description,
 			       const void *payload,
 			       size_t plen,
+			       key_perm_t perm,
 			       unsigned long flags)
 {
 	struct key_type *ktype;
 	struct key *keyring, *key = NULL;
-	key_perm_t perm;
 	key_ref_t key_ref;
 	int ret;
 
@@ -806,15 +806,17 @@ key_ref_t key_create_or_update(key_ref_t keyring_ref,
 			goto found_matching_key;
 	}
 
-	/* decide on the permissions we want */
-	perm = KEY_POS_VIEW | KEY_POS_SEARCH | KEY_POS_LINK | KEY_POS_SETATTR;
-	perm |= KEY_USR_VIEW | KEY_USR_SEARCH | KEY_USR_LINK | KEY_USR_SETATTR;
+	/* if the client doesn't provide, decide on the permissions we want */
+	if (perm == KEY_PERM_UNDEF) {
+		perm = KEY_POS_VIEW | KEY_POS_SEARCH | KEY_POS_LINK | KEY_POS_SETATTR;
+		perm |= KEY_USR_VIEW | KEY_USR_SEARCH | KEY_USR_LINK | KEY_USR_SETATTR;
 
-	if (ktype->read)
-		perm |= KEY_POS_READ | KEY_USR_READ;
+		if (ktype->read)
+			perm |= KEY_POS_READ | KEY_USR_READ;
 
-	if (ktype == &key_type_keyring || ktype->update)
-		perm |= KEY_USR_WRITE;
+		if (ktype == &key_type_keyring || ktype->update)
+			perm |= KEY_USR_WRITE;
+	}
 
 	/* allocate a new key */
 	key = key_alloc(ktype, description, current->fsuid, current->fsgid,
diff --git a/security/keys/keyctl.c b/security/keys/keyctl.c
index 1698bf9..5f0d85b 100644
--- a/security/keys/keyctl.c
+++ b/security/keys/keyctl.c
@@ -111,7 +111,8 @@ asmlinkage long sys_add_key(const char __user *_type,
 	/* create or update the requested key and add it to the target
 	 * keyring */
 	key_ref = key_create_or_update(keyring_ref, type, description,
-				       payload, plen, KEY_ALLOC_IN_QUOTA);
+				       payload, plen, KEY_PERM_UNDEF,
+				       KEY_ALLOC_IN_QUOTA);
 	if (!IS_ERR(key_ref)) {
 		ret = key_ref_to_ptr(key_ref)->serial;
 		key_ref_put(key_ref);


  parent reply	other threads:[~2008-03-28 14:36 UTC|newest]

Thread overview: 47+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-03-28 14:30 [PATCH 00/45] Permit filesystem local caching " David Howells
2008-03-28 14:30 ` [PATCH 01/45] KEYS: Increase the payload size when instantiating a key " David Howells
2008-03-28 14:30 ` [PATCH 02/45] KEYS: Check starting keyring as part of search " David Howells
2008-03-28 14:30 ` [PATCH 03/45] KEYS: Allow the callout data to be passed as a blob rather than a string " David Howells
2008-03-28 14:30 ` David Howells [this message]
2008-03-28 14:30 ` [PATCH 05/45] KEYS: Don't generate user and user session keyrings unless they're accessed " David Howells
2008-03-28 14:30 ` [PATCH 06/45] KEYS: Make the keyring quotas controllable through /proc/sys " David Howells
2008-04-01 15:29   ` Berthold Cogel
2008-03-28 14:30 ` [PATCH 07/45] KEYS: Make key_serial() a function if CONFIG_KEYS=y " David Howells
2008-03-28 14:30 ` [PATCH 08/45] KEYS: Add keyctl function to get a security label " David Howells
2008-03-28 14:30 ` [PATCH 09/45] Security: Change current->fs[ug]id to current_fs[ug]id() " David Howells
2008-03-28 14:31 ` [PATCH 10/45] Security: Separate task security context from task_struct " David Howells
2008-03-28 14:31 ` [PATCH 11/45] Security: De-embed task security record from task and use refcounting " David Howells
2008-03-28 14:31 ` [PATCH 12/45] Security: Add a kernel_service object class to SELinux " David Howells
2008-03-28 14:31 ` [PATCH 13/45] Security: Allow kernel services to override LSM settings for task actions " David Howells
2008-03-28 14:31 ` [PATCH 14/45] Security: Make NFSD work with detached security " David Howells
2008-03-28 14:31 ` [PATCH 15/45] FS-Cache: Release page->private after failed readahead " David Howells
2008-03-28 14:31 ` [PATCH 16/45] FS-Cache: Recruit a couple of page flags for cache management " David Howells
2008-03-28 14:31 ` [PATCH 17/45] FS-Cache: Provide an add_wait_queue_tail() function " David Howells
2008-03-28 14:31 ` [PATCH 18/45] FS-Cache: Generic filesystem caching facility " David Howells
2008-03-28 14:31 ` [PATCH 19/45] Add missing consts to xattr function arguments " David Howells
2008-03-28 14:31 ` [PATCH 20/45] CacheFiles: Add missing copy_page export for ia64 " David Howells
2008-03-28 14:31 ` [PATCH 21/45] CacheFiles: Be consistent about the use of mapping vs file->f_mapping in Ext3 " David Howells
2008-03-28 14:32 ` [PATCH 22/45] CacheFiles: Add a hook to write a single page of data to an inode " David Howells
2008-03-28 14:32 ` [PATCH 23/45] CacheFiles: Permit the page lock state to be monitored " David Howells
2008-03-28 14:32 ` [PATCH 24/45] CacheFiles: Export things for CacheFiles " David Howells
2008-03-28 14:32 ` [PATCH 25/45] CacheFiles: A cache that backs onto a mounted filesystem " David Howells
2008-03-28 14:32 ` [PATCH 26/45] AFS: Add a MAINTAINERS record for AFS " David Howells
2008-03-28 14:32 ` [PATCH 27/45] AFS: prevent double cell registration " David Howells
2008-03-28 14:32 ` [PATCH 28/45] FS-Cache: Make kAFS use FS-Cache " David Howells
2008-03-28 14:32 ` [PATCH 29/45] NFS: Add comment banners to some NFS functions " David Howells
2008-03-28 14:32 ` [PATCH 30/45] NFS: Add FS-Cache option bit and debug bit " David Howells
2008-03-28 14:32 ` [PATCH 31/45] NFS: Permit local filesystem caching to be enabled for NFS " David Howells
2008-03-28 14:32 ` [PATCH 32/45] NFS: Register NFS for caching and retrieve the top-level index " David Howells
2008-03-28 14:33 ` [PATCH 33/45] NFS: Define and create server-level objects " David Howells
2008-03-28 14:33 ` [PATCH 34/45] NFS: Define and create superblock-level " David Howells
2008-03-28 14:33 ` [PATCH 35/45] NFS: Define and create inode-level cache " David Howells
2008-03-28 14:33 ` [PATCH 36/45] NFS: Use local disk inode cache " David Howells
2008-03-28 14:33 ` [PATCH 37/45] NFS: Invalidate FsCache page flags when cache removed " David Howells
2008-03-28 14:33 ` [PATCH 38/45] NFS: Add some new I/O counters for FS-Cache doing things for NFS " David Howells
2008-03-28 14:33 ` [PATCH 39/45] NFS: FS-Cache page management " David Howells
2008-03-28 14:33 ` [PATCH 40/45] NFS: Add read context retention for FS-Cache to call back with " David Howells
2008-03-28 14:33 ` [PATCH 41/45] NFS: nfs_readpage_async() needs to be accessible as a fallback for local caching " David Howells
2008-03-28 14:33 ` [PATCH 42/45] NFS: Read pages from FS-Cache into an NFS inode " David Howells
2008-03-28 14:33 ` [PATCH 43/45] NFS: Store pages from an NFS inode into a local cache " David Howells
2008-03-28 14:33 ` [PATCH 44/45] NFS: Display local caching state " David Howells
2008-03-28 14:34 ` [PATCH 45/45] NFS: Add mount options to enable local caching on NFS " David Howells

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20080328143031.3483.6520.stgit@warthog.procyon.org.uk \
    --to=dhowells@redhat.com \
    --cc=akpm@linux-foundation.org \
    --cc=chuck.lever@oracle.com \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=nfsv4@linux-nfs.org \
    --cc=selinux@tycho.nsa.gov \
    --cc=torvalds@osdl.org \
    --cc=trond.myklebust@fys.uio.no \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®