mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Stephan Mueller <smueller@chronox.de>
To: "'Herbert Xu" <herbert@gondor.apana.org.au>
Cc: linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: [PATCH v2 01/20] crypto: prevent helper ciphers from being used
Date: Fri, 27 Mar 2015 23:49:58 +0100	[thread overview]
Message-ID: <2386905.FFHjDQ6mFB@tachyon.chronox.de> (raw)
In-Reply-To: <1746748.uPZFXamDiM@tachyon.chronox.de>

Several hardware related cipher implementations are implemented as
follows: a "helper" cipher implementation is registered with the
kernel crypto API.

Such helper ciphers are never intended to be called by normal users. In
some cases, calling them via the normal crypto API may even cause
failures including kernel crashes. In a normal case, the "wrapping"
ciphers that use the helpers ensure that these helpers are invoked
such that they cannot cause any calamity.

Considering the AF_ALG user space interface, unprivileged users can
call all ciphers registered with the crypto API, including these
helper ciphers that are not intended to be called directly. That
means, with AF_ALG user space may invoke these helper ciphers
and may cause undefined states or side effects.

To avoid any potential side effects with such helpers, the patch
prevents the helpers to be called directly. A new cipher type
flag is added: CRYPTO_ALG_INTERNAL. This flag shall be used
to mark helper ciphers. These ciphers can only be used if the
caller invoke the cipher with CRYPTO_ALG_INTERNAL in the type and
mask field.

Signed-off-by: Stephan Mueller <smueller@chronox.de>
---
 crypto/api.c           | 6 ++++++
 include/linux/crypto.h | 6 ++++++
 2 files changed, 12 insertions(+)

diff --git a/crypto/api.c b/crypto/api.c
index 2a81e98..e45d37a 100644
--- a/crypto/api.c
+++ b/crypto/api.c
@@ -257,6 +257,12 @@ struct crypto_alg *crypto_alg_mod_lookup(const char *name, u32 type, u32 mask)
 		mask |= CRYPTO_ALG_TESTED;
 	}
 
+	/*
+	 * If the internal flag is set for a cipher, require a caller to
+	 * to invoke the cipher with the internal flag to use that cipher.
+	 */
+	mask |= CRYPTO_ALG_INTERNAL;
+
 	larval = crypto_larval_lookup(name, type, mask);
 	if (IS_ERR(larval) || !crypto_is_larval(larval))
 		return larval;
diff --git a/include/linux/crypto.h b/include/linux/crypto.h
index fb5ef16..10df5d2 100644
--- a/include/linux/crypto.h
+++ b/include/linux/crypto.h
@@ -95,6 +95,12 @@
 #define CRYPTO_ALG_KERN_DRIVER_ONLY	0x00001000
 
 /*
+ * Mark a cipher as a service implementation only usable by another
+ * cipher and never by a normal user of the kernel crypto API
+ */
+#define CRYPTO_ALG_INTERNAL		0x00002000
+
+/*
  * Transform masks and values (for crt_flags).
  */
 #define CRYPTO_TFM_REQ_MASK		0x000fff00
-- 
2.1.0



  reply	other threads:[~2015-03-27 23:06 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-03-27 22:49 [PATCH v2 00/20] crypto: restrict usage of helper ciphers Stephan Mueller
2015-03-27 22:49 ` Stephan Mueller [this message]
2015-03-27 22:50 ` [PATCH v2 02/20] crypto: testmgr to use CRYPTO_ALG_INTERNAL Stephan Mueller
2015-03-30 13:10   ` Herbert Xu
2015-03-30 19:31     ` Stephan Mueller
2015-03-27 22:51 ` [PATCH v2 03/20] crypto: cryptd to process CRYPTO_ALG_INTERNAL Stephan Mueller
2015-03-27 22:52 ` [PATCH v2 04/20] crypto: /proc/crypto: identify internal ciphers Stephan Mueller
2015-03-27 22:52 ` [PATCH v2 05/20] crypto: mark AES-NI helper ciphers Stephan Mueller
2015-03-27 22:53 ` [PATCH v2 06/20] crypto: mark ghash clmulni " Stephan Mueller
2015-03-27 22:54 ` [PATCH v2 07/20] crypto: mark GHASH ARMv8 vmull.p64 " Stephan Mueller
2015-03-27 22:54 ` [PATCH v2 08/20] crypto: mark AES-NI Camellia " Stephan Mueller
2015-03-27 22:55 ` [PATCH v2 09/20] crypto: mark CAST5 " Stephan Mueller
2015-03-27 22:55 ` [PATCH v2 10/20] crypto: mark AVX Camellia " Stephan Mueller
2015-03-27 22:56 ` [PATCH v2 11/20] crypto: mark CAST6 " Stephan Mueller
2015-03-27 22:56 ` [PATCH v2 12/20] crypto: mark Serpent AVX2 " Stephan Mueller
2015-03-27 22:57 ` [PATCH v2 13/20] crypto: mark Serpent AVX " Stephan Mueller
2015-03-27 22:57 ` [PATCH v2 14/20] crypto: mark Serpent SSE2 " Stephan Mueller
2015-03-27 22:58 ` [PATCH v2 15/20] crypto: mark Twofish AVX " Stephan Mueller
2015-03-27 22:59 ` [PATCH v2 16/20] crypto: mark NEON bit sliced AES " Stephan Mueller
2015-03-27 23:00 ` [PATCH v2 17/20] crypto: mark ARMv8 " Stephan Mueller
2015-03-27 23:00 ` [PATCH v2 18/20] crypto: mark 64 bit " Stephan Mueller
2015-03-27 23:01 ` [PATCH v2 19/20] crypto: mcryptd to process CRYPTO_ALG_INTERNAL Stephan Mueller
2015-03-27 23:02 ` [PATCH v2 20/20] crypto: mark Multi buffer SHA1 helper cipher Stephan Mueller

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2386905.FFHjDQ6mFB@tachyon.chronox.de \
    --to=smueller@chronox.de \
    --cc=herbert@gondor.apana.org.au \
    --cc=linux-crypto@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®