]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/commit
evm: Don't deadlock if a crypto algorithm is unavailable
authorMatthew Garrett <mjg59@google.com>
Fri, 8 Jun 2018 21:57:42 +0000 (14:57 -0700)
committerJuerg Haefliger <juergh@canonical.com>
Wed, 24 Jul 2019 01:49:09 +0000 (19:49 -0600)
commit42a729ed906e15629ded9d498222f2550b2e8f5b
treed53683e0e8912df9ec11692611851f0c8fc06fe1
parentc5b5f98c841842fa14caa60e9739654083e46270
evm: Don't deadlock if a crypto algorithm is unavailable

BugLink: https://bugs.launchpad.net/bugs/1836117
[ Upstream commit e2861fa71641c6414831d628a1f4f793b6562580 ]

When EVM attempts to appraise a file signed with a crypto algorithm the
kernel doesn't have support for, it will cause the kernel to trigger a
module load. If the EVM policy includes appraisal of kernel modules this
will in turn call back into EVM - since EVM is holding a lock until the
crypto initialisation is complete, this triggers a deadlock. Add a
CRYPTO_NOLOAD flag and skip module loading if it's set, and add that flag
in the EVM case in order to fail gracefully with an error message
instead of deadlocking.

Signed-off-by: Matthew Garrett <mjg59@google.com>
Acked-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Signed-off-by: Sasha Levin <alexander.levin@microsoft.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
Signed-off-by: Kleber Sacilotto de Souza <kleber.souza@canonical.com>
crypto/api.c
include/linux/crypto.h
security/integrity/evm/evm_crypto.c