mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] KEYS: request_key() should return -ENOKEY if the constructed key is negative
@ 2010-08-06 15:08 David Howells
  0 siblings, 0 replies; only message in thread
From: David Howells @ 2010-08-06 15:08 UTC (permalink / raw)
  To: torvalds, akpm
  Cc: keyrings, linux-security-module, linux-kernel, David Howells

request_key() should return -ENOKEY if the key it constructs has been
negatively instantiated.

Without this, request_key() can return an unusable key to its caller, and if
the caller then does key_validate() that won't catch the problem.

Signed-off-by: David Howells <dhowells@redhat.com>
---

 security/keys/request_key.c |    2 ++
 1 files changed, 2 insertions(+), 0 deletions(-)

diff --git a/security/keys/request_key.c b/security/keys/request_key.c
index 0d26f68..0088dd8 100644
--- a/security/keys/request_key.c
+++ b/security/keys/request_key.c
@@ -537,6 +537,8 @@ int wait_for_key_construction(struct key *key, bool intr)
 			  intr ? TASK_INTERRUPTIBLE : TASK_UNINTERRUPTIBLE);
 	if (ret < 0)
 		return ret;
+	if (test_bit(KEY_FLAG_NEGATIVE, &key->flags))
+		return -ENOKEY;
 	return key_validate(key);
 }
 EXPORT_SYMBOL(wait_for_key_construction);


^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2010-08-06 15:09 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2010-08-06 15:08 [PATCH] KEYS: request_key() should return -ENOKEY if the constructed key is negative David Howells

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®