mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] dm-verity: clear LSM integrity state on suspend
@ 2026-09-21 22:05 Fan Wu
  0 siblings, 0 replies; only message in thread
From: Fan Wu @ 2026-09-21 22:05 UTC (permalink / raw)
  To: dm-devel
  Cc: mpatocka, snitzer, agk, bmarzins, paul, linux-security-module,
	linux-kernel

dm-verity publishes its root hash and signature state to LSMs in
verity_preresume(). LSMs such as IPE store this information in the block
device's security blob and use it to authorize access to files.

The original LSM integration relied on DM_TARGET_IMMUTABLE to prevent
verity from being replaced by a different target type. However, DM allows
tables containing a DM_TARGET_WILDCARD target to replace immutable
targets. The block device can then retain the old integrity state even
though its data is no longer verified by dm-verity.

Clear the published root hash and signature state in verity_postsuspend()
so that the block device does not retain stale dm-verity attributes after
the verity target is replaced.

Fixes: a6af7bc3d72f ("dm-verity: expose root hash digest and signature data to LSMs")
Assisted-by: gpt-6-astra
Signed-off-by: Fan Wu <wufan@kernel.org>
---
 drivers/md/dm-verity-target.c | 39 ++++++++++++++++++++++++++++-------
 1 file changed, 32 insertions(+), 7 deletions(-)

diff --git a/drivers/md/dm-verity-target.c b/drivers/md/dm-verity-target.c
index cb105ccc47ec..6d589867623c 100644
--- a/drivers/md/dm-verity-target.c
+++ b/drivers/md/dm-verity-target.c
@@ -825,13 +825,6 @@ static int verity_map(struct dm_target *ti, struct bio *bio)
 	return DM_MAPIO_SUBMITTED;
 }
 
-static void verity_postsuspend(struct dm_target *ti)
-{
-	struct dm_verity *v = ti->private;
-	flush_workqueue(v->verify_wq);
-	dm_bufio_client_reset(v->bufio);
-}
-
 /*
  * Status: V (valid) or C (corruption found)
  */
@@ -1733,6 +1726,11 @@ static int verity_security_set_signature(struct block_device *bdev,
 					  v->sig_size);
 }
 
+static void verity_security_clear_signature(struct block_device *bdev)
+{
+	security_bdev_setintegrity(bdev, LSM_INT_DMVERITY_SIG_VALID, NULL, 0);
+}
+
 #else
 
 static inline int verity_security_set_signature(struct block_device *bdev,
@@ -1741,6 +1739,10 @@ static inline int verity_security_set_signature(struct block_device *bdev,
 	return 0;
 }
 
+static inline void verity_security_clear_signature(struct block_device *bdev)
+{
+}
+
 #endif /* CONFIG_DM_VERITY_VERIFY_ROOTHASH_SIG */
 
 /*
@@ -1779,8 +1781,31 @@ static int verity_preresume(struct dm_target *ti)
 	return r;
 }
 
+static void verity_security_clear_integrity(struct dm_target *ti)
+{
+	struct block_device *bdev = dm_disk(dm_table_get_md(ti->table))->part0;
+
+	security_bdev_setintegrity(bdev, LSM_INT_DMVERITY_ROOTHASH, NULL, 0);
+	verity_security_clear_signature(bdev);
+}
+
+#else
+
+static inline void verity_security_clear_integrity(struct dm_target *ti)
+{
+}
+
 #endif /* CONFIG_SECURITY */
 
+static void verity_postsuspend(struct dm_target *ti)
+{
+	struct dm_verity *v = ti->private;
+
+	flush_workqueue(v->verify_wq);
+	dm_bufio_client_reset(v->bufio);
+	verity_security_clear_integrity(ti);
+}
+
 static struct target_type verity_target = {
 	.name		= "verity",
 /* Note: the LSMs depend on the singleton and immutable features */

base-commit: 93f51579e7df248780214094418f205253383cc5
-- 
2.55.0


^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-21 22:05 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-21 22:05 [PATCH] dm-verity: clear LSM integrity state on suspend Fan Wu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®