From: Jarkko Sakkinen <jarkko@kernel.org>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: David Howells <dhowells@redhat.com>,
Herbert Xu <herbert@gondor.apana.org.au>,
"David S. Miller" <davem@davemloft.net>,
keyrings@vger.kernel.org, linux-integrity@vger.kernel.org
Subject: [GIT PULL] KEYS changes for v7.3-rc7
Date: Tue, 6 Oct 2026 01:46:40 +0300 [thread overview]
Message-ID: <asQo0Kb0SF0vZcHa@kernel.org> (raw)
Hi,
I've started to take steps towards better quality PRs.
Br, Jarkko
The following changes since commit 7704c4c5bb127673b4f0ead839919db573559e38:
Merge tag 'i2c-fixes-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux (2026-10-04 09:38:11 -0700)
are available in the Git repository at:
git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd.git tags/keys-v7.3-rc7
for you to fetch changes up to dd3ea3fcba7c75493760cdbccd35f029597e8d5e:
KEYS: Fix add_key() race with keyring restriction (2026-10-04 21:09:32 +0300)
----------------------------------------------------------------
KEYS changes for v7.3-rc7
This pull request contains two critical bug fixes, which can be briefly
descibed as follows:
1. key_get_persistent() creates a new persisten keyring for UID if it does
not exist yet, and creates a link from it to the nominated keyring.
Function did not set timeout when linking failed, therefore preventing
GC. The bug was addressed by calling key_set_timeout() regardless of
key_link() result when the persistent keyring gets created by
key_get_persistent().
2. __key_create_or_update() made a copy of keyring->restrict_link before
holding keyring->sem, which can cause add_key() to be executed against
stale keyring restrictions. The bug was fixed by copying the value only
after keyring->sem was taken.
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
----------------------------------------------------------------
Karl Mehltretter (1):
keys: finalize persistent keyring timeout after link attempt
성병찬 (1):
KEYS: Fix add_key() race with keyring restriction
security/keys/key.c | 6 ++---
security/keys/persistent.c | 55 +++++++++++++++++++++++++++-------------------
2 files changed, 35 insertions(+), 26 deletions(-)
next reply other threads:[~2026-10-05 22:46 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-05 22:46 Jarkko Sakkinen [this message]
2026-10-06 3:03 ` [GIT PULL] KEYS changes for v7.3-rc7 Linus Torvalds
2026-10-06 6:33 ` Jarkko Sakkinen
2026-10-06 3:04 ` pr-tracker-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=asQo0Kb0SF0vZcHa@kernel.org \
--to=jarkko@kernel.org \
--cc=davem@davemloft.net \
--cc=dhowells@redhat.com \
--cc=herbert@gondor.apana.org.au \
--cc=keyrings@vger.kernel.org \
--cc=linux-integrity@vger.kernel.org \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.