All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jarkko Sakkinen <jarkko@kernel.org>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: David Howells <dhowells@redhat.com>,
	Herbert Xu <herbert@gondor.apana.org.au>,
	"David S. Miller" <davem@davemloft.net>,
	keyrings@vger.kernel.org, linux-integrity@vger.kernel.org
Subject: [GIT PULL] KEYS changes for v7.3-rc7
Date: Tue, 6 Oct 2026 01:46:40 +0300	[thread overview]
Message-ID: <asQo0Kb0SF0vZcHa@kernel.org> (raw)

Hi,

I've started to take steps towards better quality PRs. 

Br, Jarkko

The following changes since commit 7704c4c5bb127673b4f0ead839919db573559e38:

  Merge tag 'i2c-fixes-7.3-rc6' of git://git.kernel.org/pub/scm/linux/kernel/git/andi.shyti/linux (2026-10-04 09:38:11 -0700)

are available in the Git repository at:

  git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd.git tags/keys-v7.3-rc7

for you to fetch changes up to dd3ea3fcba7c75493760cdbccd35f029597e8d5e:

  KEYS: Fix add_key() race with keyring restriction (2026-10-04 21:09:32 +0300)

----------------------------------------------------------------
KEYS changes for v7.3-rc7

This pull request contains two critical bug fixes, which can be briefly
descibed as follows:

1. key_get_persistent() creates a new persisten keyring for UID  if it does
   not exist yet, and creates a link from it to the nominated keyring.
   Function did not set timeout when linking failed, therefore preventing
   GC. The bug was addressed by calling key_set_timeout() regardless of
   key_link() result when the persistent keyring gets created by
   key_get_persistent().
2. __key_create_or_update() made a copy of keyring->restrict_link before
   holding keyring->sem, which can cause add_key() to be executed against
   stale keyring restrictions. The bug was fixed by copying the value only
   after keyring->sem was taken.

Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>

----------------------------------------------------------------
Karl Mehltretter (1):
      keys: finalize persistent keyring timeout after link attempt

성병찬 (1):
      KEYS: Fix add_key() race with keyring restriction

 security/keys/key.c        |  6 ++---
 security/keys/persistent.c | 55 +++++++++++++++++++++++++++-------------------
 2 files changed, 35 insertions(+), 26 deletions(-)

             reply	other threads:[~2026-10-05 22:46 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-05 22:46 Jarkko Sakkinen [this message]
2026-10-06  3:03 ` [GIT PULL] KEYS changes for v7.3-rc7 Linus Torvalds
2026-10-06  6:33   ` Jarkko Sakkinen
2026-10-06  3:04 ` pr-tracker-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=asQo0Kb0SF0vZcHa@kernel.org \
    --to=jarkko@kernel.org \
    --cc=davem@davemloft.net \
    --cc=dhowells@redhat.com \
    --cc=herbert@gondor.apana.org.au \
    --cc=keyrings@vger.kernel.org \
    --cc=linux-integrity@vger.kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.