OSDN Git Service

evm: Don't deadlock if a crypto algorithm is unavailable
authorMatthew Garrett <mjg59@google.com>
Fri, 8 Jun 2018 21:57:42 +0000 (14:57 -0700)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 26 Sep 2018 06:36:37 +0000 (08:36 +0200)
commiteddbab1384841db30b270bc791ad623ad0cd5a38
tree45316853ff7c76f3cc9958dc9c865f566e3a9515
parent23bd97eaebc55d5eef9d3cd41e3bd6189a0e9dd6
evm: Don't deadlock if a crypto algorithm is unavailable

[ Upstream commit e2861fa71641c6414831d628a1f4f793b6562580 ]

When EVM attempts to appraise a file signed with a crypto algorithm the
kernel doesn't have support for, it will cause the kernel to trigger a
module load. If the EVM policy includes appraisal of kernel modules this
will in turn call back into EVM - since EVM is holding a lock until the
crypto initialisation is complete, this triggers a deadlock. Add a
CRYPTO_NOLOAD flag and skip module loading if it's set, and add that flag
in the EVM case in order to fail gracefully with an error message
instead of deadlocking.

Signed-off-by: Matthew Garrett <mjg59@google.com>
Acked-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Signed-off-by: Sasha Levin <alexander.levin@microsoft.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
crypto/api.c
include/linux/crypto.h
security/integrity/evm/evm_crypto.c