From: Matthew Garrett <matthewg@nvidia.com>
To: mjg59@srcf.ucam.org
Cc: keyrings@vger.kernel.org, James.Bottomley@HansenPartnership.com,
linux-integrity@vger.kernel.org, rafael@kernel.org,
linux-pm@vger.kernel.org, linux-efi@vger.kernel.org,
Matthew Garrett <matthewg@nvidia.com>
Subject: [PATCH 17/17] PM: hibernate: Allow hibernation under lockdown with signed images
Date: Thu, 8 Oct 2026 06:20:33 -0700 [thread overview]
Message-ID: <20261008132532.1155166-18-matthewg@nvidia.com> (raw)
In-Reply-To: <20261008132532.1155166-1-matthewg@nvidia.com>
Hibernation is unavailable when the kernel is locked down, as an image
could be modified to alter the running kernel when it is restored. With
CONFIG_HIBERNATION_TPM_SIGNATURE, only images signed with a key that the
kernel created are restored, so this no longer applies.
Allow hibernation under lockdown when images are signed. Images are not
encrypted, though, and contain all of kernel memory, which would then be
readable from the swap device or through /dev/snapshot. Add a
LOCKDOWN_HIBERNATION_IMAGE reason at the confidentiality level, so that
hibernation remains unavailable when the kernel is locked down for
confidentiality.
Signed-off-by: Matthew Garrett <matthewg@nvidia.com>
---
include/linux/security.h | 1 +
kernel/power/Kconfig | 5 +++++
kernel/power/hibernate.c | 18 +++++++++++++-----
security/security.c | 1 +
4 files changed, 20 insertions(+), 5 deletions(-)
diff --git a/include/linux/security.h b/include/linux/security.h
index 153e9043058f..6b4dfe80501b 100644
--- a/include/linux/security.h
+++ b/include/linux/security.h
@@ -155,6 +155,7 @@ enum lockdown_reason {
LOCKDOWN_TRACEFS,
LOCKDOWN_XMON_RW,
LOCKDOWN_XFRM_SECRET,
+ LOCKDOWN_HIBERNATION_IMAGE,
LOCKDOWN_CONFIDENTIALITY_MAX,
};
diff --git a/kernel/power/Kconfig b/kernel/power/Kconfig
index 2eb6af9226f7..639dc124c17d 100644
--- a/kernel/power/Kconfig
+++ b/kernel/power/Kconfig
@@ -132,6 +132,11 @@ config HIBERNATION_TPM_SIGNATURE
ExitBootServices() is called. If these requirements are not met,
hibernation is unavailable.
+ As only signed images are restored, hibernation remains available
+ when the kernel is locked down for integrity. Images are not
+ encrypted, so it is unavailable when the kernel is locked down for
+ confidentiality.
+
If unsure, say N.
config TPM_HIBERNATE_INSECURE
diff --git a/kernel/power/hibernate.c b/kernel/power/hibernate.c
index 256790aeca86..7bbef9c3ae1c 100644
--- a/kernel/power/hibernate.c
+++ b/kernel/power/hibernate.c
@@ -108,11 +108,19 @@ bool hibernation_in_progress(void)
bool hibernation_available(void)
{
- return nohibernate == 0 &&
- !security_locked_down(LOCKDOWN_HIBERNATION) &&
- !secretmem_active() && !cxl_mem_active() &&
- (!IS_ENABLED(CONFIG_HIBERNATION_TPM_SIGNATURE) ||
- hibernate_tpm_available());
+ if (nohibernate || secretmem_active() || cxl_mem_active())
+ return false;
+
+ /*
+ * Only images signed by the kernel are restored, so hibernation does
+ * not undermine the integrity of a locked down kernel. Images are
+ * not encrypted, though, so they would expose kernel memory.
+ */
+ if (IS_ENABLED(CONFIG_HIBERNATION_TPM_SIGNATURE))
+ return hibernate_tpm_available() &&
+ !security_locked_down(LOCKDOWN_HIBERNATION_IMAGE);
+
+ return !security_locked_down(LOCKDOWN_HIBERNATION);
}
/**
diff --git a/security/security.c b/security/security.c
index 2ee276ab15c5..5d91ca69bbf1 100644
--- a/security/security.c
+++ b/security/security.c
@@ -71,6 +71,7 @@ const char *const lockdown_reasons[LOCKDOWN_CONFIDENTIALITY_MAX + 1] = {
[LOCKDOWN_TRACEFS] = "use of tracefs",
[LOCKDOWN_XMON_RW] = "xmon read and write access",
[LOCKDOWN_XFRM_SECRET] = "xfrm SA secret",
+ [LOCKDOWN_HIBERNATION_IMAGE] = "hibernation with signed images",
[LOCKDOWN_CONFIDENTIALITY_MAX] = "confidentiality",
};
--
2.43.0
next prev parent reply other threads:[~2026-10-08 13:26 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 13:20 [RFC] Make hibernation work with lockdown Matthew Garrett
2026-10-08 13:20 ` [PATCH 01/17] tpm: Define a kernel-owned TPM NV index that can't be modified by userland Matthew Garrett
2026-10-08 13:41 ` Matthew Garrett
2026-10-08 16:24 ` Jarkko Sakkinen
2026-10-08 16:23 ` Jarkko Sakkinen
2026-10-09 8:33 ` Matthew Garrett
2026-10-08 17:06 ` Ilias Apalodimas
2026-10-08 13:20 ` [PATCH 02/17] efi: Add a mechanism to modify TPM state depending on kernel security features Matthew Garrett
2026-10-08 16:38 ` Jarkko Sakkinen
2026-10-08 13:20 ` [PATCH 03/17] tpm: Allow tpm2_start_auth_session() to start an audit session Matthew Garrett
2026-10-08 13:20 ` [PATCH 04/17] tpm: Log commands executed in " Matthew Garrett
2026-10-08 13:20 ` [PATCH 05/17] tpm: Add a kernel attestation key and signed audit digest retrieval Matthew Garrett
2026-10-08 16:45 ` James Bottomley
2026-10-09 8:29 ` Matthew Garrett
2026-10-08 13:20 ` [PATCH 06/17] tpm: Use TPM2_NV_ReadPublic to read NV index names Matthew Garrett
2026-10-08 13:20 ` [PATCH 07/17] tpm: Add in-kernel support for reading NV indices Matthew Garrett
2026-10-08 13:20 ` [PATCH 08/17] tpm: Add NV define, undefine and write helpers Matthew Garrett
2026-10-08 13:20 ` [PATCH 09/17] tpm: Provision the kernel NV index at registration Matthew Garrett
2026-10-08 13:20 ` [PATCH 10/17] tpm: Move the bounds-checked response reader to a header Matthew Garrett
2026-10-08 13:20 ` [PATCH 11/17] tpm: Add kernel signing key creation with audited provenance Matthew Garrett
2026-10-08 17:00 ` James Bottomley
2026-10-09 8:31 ` Matthew Garrett
2026-10-08 13:20 ` [PATCH 12/17] tpm: Add signing with the kernel signing key Matthew Garrett
2026-10-08 13:20 ` [PATCH 13/17] tpm: Add verification of kernel signing key provenance Matthew Garrett
2026-10-08 13:20 ` [PATCH 14/17] PM: hibernate: Add image digest and signature page infrastructure Matthew Garrett
2026-10-08 13:20 ` [PATCH 15/17] PM: hibernate: Sign and verify images with a kernel-generated TPM key Matthew Garrett
2026-10-08 13:20 ` [PATCH 16/17] PM: hibernate: Refuse to verify images with a virtual TPM Matthew Garrett
2026-10-08 13:20 ` Matthew Garrett [this message]
2026-10-08 16:53 ` [PATCH 17/17] PM: hibernate: Allow hibernation under lockdown with signed images Jarkko Sakkinen
2026-10-09 8:31 ` Matthew Garrett
2026-10-08 15:56 ` [RFC] Make hibernation work with lockdown Jarkko Sakkinen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008132532.1155166-18-matthewg@nvidia.com \
--to=matthewg@nvidia.com \
--cc=James.Bottomley@HansenPartnership.com \
--cc=keyrings@vger.kernel.org \
--cc=linux-efi@vger.kernel.org \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-pm@vger.kernel.org \
--cc=mjg59@srcf.ucam.org \
--cc=rafael@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox