From: Milan Broz <gmazyland@gmail.com>
To: Eric Biggers <ebiggers@kernel.org>
Cc: Mikulas Patocka <mpatocka@redhat.com>,
Lorenz Kofler <lorenz@sigma-star.at>,
Mike Snitzer <snitzer@kernel.org>,
Benjamin Marzinski <bmarzins@redhat.com>,
Alasdair Kergon <agk@redhat.com>,
dm-devel@lists.linux.dev, linux-kernel@vger.kernel.org,
upstream+dm@sigma-star.at, David Howells <dhowells@redhat.com>,
Jarkko Sakkinen <jarkko@kernel.org>,
keyrings@vger.kernel.org
Subject: Re: [RFC PATCH 1/1] dm-integrity: support keys in the kernel keyring
Date: Mon, 5 Oct 2026 08:20:14 +0200 [thread overview]
Message-ID: <ff601118-7ef4-4ece-94a3-9671e78fa3c8@gmail.com> (raw)
In-Reply-To: <20261004172934.GC1906@quark>
On 10/4/26 7:29 PM, Eric Biggers wrote:
> On Sun, Oct 04, 2026 at 09:44:57AM +0200, Milan Broz wrote:
>> On 10/2/26 10:14 PM, Eric Biggers wrote:
>> ...
>>> From what I understand, the point of the keyring support in
>>> dm-{crypt,inlinecrypt,integrity} is:
>>>
>>> - To support "trusted" keys. But that is not what was actually
>>> implemented in dm-inlinecrypt.
>>>
>>> - To avoid having the key be readable with STATUSTYPE_TABLE. But that
>>> is not what was actually implemented in dm-inlinecrypt. Keyrings are
>>> also unnecesary to solve that problem.
>>
>> There is more to that
>>
>> - to avoid key cached in dm-crypt (or other target)
>> (dmsetup must be able to retrieve mapping table in the form directly
>> reusable for recreating DM mapping, so raw key must be available)
>
> It's of course still there anyway, so that the data can be encrypted or
> decrypted. crypt_config::cipher_tfm for dm-crypt, inlinecrypt_ctx::key
> for dm-inlinecrypt, or dm_integrity_c::internal_shash for dm-integrity.
Raw key is then not part of internal dm-crypt structures, that was the point.
Crypto API needs key, obviously. I did not check recent dm-inline crypt, though.
>> - to avoid inclusion of key in DM ioctl calls (mapping table again)
>
> Unless the "trusted" key type is being used it just makes the raw key be
> passed to the kernel using a different syscall: add_key() instead of
> ioctl(). It doesn't seem fundamentally different.
Technically, yes. Just the key is now sent through ioctl that (should)
be designed for it, not in DM-ioctls that are used extensively for all other
parameters.
We had to add wiping of all buffers there exactly for this reason.
And I think the split is better also for tracing calls etc.
And while all these subsystems are not perfect, they are compatible for many
years. IMO this is very important. We are not in Google monorepo environment
where anything can be changed anytime as you know all users.
Milan
prev parent reply other threads:[~2026-10-05 6:20 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 6:27 [RFC PATCH 0/1] " Lorenz Kofler
2026-09-28 6:27 ` [RFC PATCH 1/1] " Lorenz Kofler
2026-09-30 15:00 ` Mikulas Patocka
2026-10-02 9:12 ` Lorenz Kofler
2026-10-02 11:48 ` Mikulas Patocka
2026-10-02 20:14 ` Eric Biggers
2026-10-02 21:09 ` Mikulas Patocka
2026-10-04 7:44 ` Milan Broz
2026-10-04 17:29 ` Eric Biggers
2026-10-05 6:20 ` Milan Broz [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ff601118-7ef4-4ece-94a3-9671e78fa3c8@gmail.com \
--to=gmazyland@gmail.com \
--cc=agk@redhat.com \
--cc=bmarzins@redhat.com \
--cc=dhowells@redhat.com \
--cc=dm-devel@lists.linux.dev \
--cc=ebiggers@kernel.org \
--cc=jarkko@kernel.org \
--cc=keyrings@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=lorenz@sigma-star.at \
--cc=mpatocka@redhat.com \
--cc=snitzer@kernel.org \
--cc=upstream+dm@sigma-star.at \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®