Lines Matching refs:keyring
76 static int keyring_instantiate(struct key *keyring,
78 static void keyring_revoke(struct key *keyring);
79 static void keyring_destroy(struct key *keyring);
80 static void keyring_describe(const struct key *keyring, struct seq_file *m);
81 static long keyring_read(const struct key *keyring,
107 static void keyring_publish_name(struct key *keyring) in keyring_publish_name() argument
111 if (keyring->description && in keyring_publish_name()
112 keyring->description[0] && in keyring_publish_name()
113 keyring->description[0] != '.') { in keyring_publish_name()
115 list_add_tail(&keyring->name_link, &ns->keyring_name_list); in keyring_publish_name()
140 static int keyring_instantiate(struct key *keyring, in keyring_instantiate() argument
143 assoc_array_init(&keyring->keys); in keyring_instantiate()
145 keyring_publish_name(keyring); in keyring_instantiate()
412 static void keyring_destroy(struct key *keyring) in keyring_destroy() argument
414 if (keyring->description) { in keyring_destroy()
417 if (keyring->name_link.next != NULL && in keyring_destroy()
418 !list_empty(&keyring->name_link)) in keyring_destroy()
419 list_del(&keyring->name_link); in keyring_destroy()
424 if (keyring->restrict_link) { in keyring_destroy()
425 struct key_restriction *keyres = keyring->restrict_link; in keyring_destroy()
431 assoc_array_destroy(&keyring->keys, &keyring_assoc_array_ops); in keyring_destroy()
437 static void keyring_describe(const struct key *keyring, struct seq_file *m) in keyring_describe() argument
439 if (keyring->description) in keyring_describe()
440 seq_puts(m, keyring->description); in keyring_describe()
444 if (key_is_positive(keyring)) { in keyring_describe()
445 if (keyring->keys.nr_leaves_on_tree != 0) in keyring_describe()
446 seq_printf(m, ": %lu", keyring->keys.nr_leaves_on_tree); in keyring_describe()
485 static long keyring_read(const struct key *keyring, in keyring_read() argument
491 kenter("{%d},,%zu", key_serial(keyring), buflen); in keyring_read()
501 ret = assoc_array_iterate(&keyring->keys, in keyring_read()
510 ret = keyring->keys.nr_leaves_on_tree * sizeof(key_serial_t); in keyring_read()
527 struct key *keyring; in keyring_alloc() local
530 keyring = key_alloc(&key_type_keyring, description, in keyring_alloc()
532 if (!IS_ERR(keyring)) { in keyring_alloc()
533 ret = key_instantiate_and_link(keyring, NULL, 0, dest, NULL); in keyring_alloc()
535 key_put(keyring); in keyring_alloc()
536 keyring = ERR_PTR(ret); in keyring_alloc()
540 return keyring; in keyring_alloc()
558 int restrict_link_reject(struct key *keyring, in restrict_link_reject() argument
650 static int search_keyring(struct key *keyring, struct keyring_search_context *ctx) in search_keyring() argument
655 object = assoc_array_find(&keyring->keys, in search_keyring()
660 return assoc_array_iterate(&keyring->keys, ctx->iterator, ctx); in search_keyring()
667 static bool search_nested_keyrings(struct key *keyring, in search_nested_keyrings() argument
671 struct key *keyring; in search_nested_keyrings() member
683 keyring->serial, in search_nested_keyrings()
698 keyring_compare_object(keyring, &ctx->index_key)) { in search_nested_keyrings()
700 switch (ctx->iterator(keyring_key_to_ptr(keyring), ctx)) { in search_nested_keyrings()
714 kdebug("descend to %d", keyring->serial); in search_nested_keyrings()
715 if (keyring->flags & ((1 << KEY_FLAG_INVALIDATED) | in search_nested_keyrings()
722 if (search_keyring(keyring, ctx)) in search_nested_keyrings()
736 ptr = READ_ONCE(keyring->keys.root); in search_nested_keyrings()
802 stack[sp].keyring = keyring; in search_nested_keyrings()
808 keyring = key; in search_nested_keyrings()
849 keyring = stack[sp].keyring; in search_nested_keyrings()
852 kdebug("ascend to %d [%d]", keyring->serial, slot); in search_nested_keyrings()
861 keyring->last_used_at = ctx->now; in search_nested_keyrings()
863 stack[--sp].keyring->last_used_at = ctx->now; in search_nested_keyrings()
906 struct key *keyring; in keyring_search_rcu() local
913 keyring = key_ref_to_ptr(keyring_ref); in keyring_search_rcu()
914 key_check(keyring); in keyring_search_rcu()
916 if (keyring->type != &key_type_keyring) in keyring_search_rcu()
926 if (search_nested_keyrings(keyring, ctx)) in keyring_search_rcu()
941 key_ref_t keyring_search(key_ref_t keyring, in keyring_search() argument
968 key = keyring_search_rcu(keyring, &ctx); in keyring_search()
1028 struct key *keyring; in keyring_restrict() local
1033 keyring = key_ref_to_ptr(keyring_ref); in keyring_restrict()
1034 key_check(keyring); in keyring_restrict()
1036 if (keyring->type != &key_type_keyring) in keyring_restrict()
1060 down_write(&keyring->sem); in keyring_restrict()
1063 if (keyring->restrict_link) in keyring_restrict()
1065 else if (keyring_detect_restriction_cycle(keyring, restrict_link)) in keyring_restrict()
1068 keyring->restrict_link = restrict_link; in keyring_restrict()
1071 up_write(&keyring->sem); in keyring_restrict()
1103 struct key *keyring, *key; in find_key_to_update() local
1106 keyring = key_ref_to_ptr(keyring_ref); in find_key_to_update()
1109 keyring->serial, index_key->type->name, index_key->description); in find_key_to_update()
1111 object = assoc_array_find(&keyring->keys, &keyring_assoc_array_ops, in find_key_to_update()
1146 struct key *keyring; in find_keyring_by_name() local
1156 list_for_each_entry(keyring, &ns->keyring_name_list, name_link) { in find_keyring_by_name()
1157 if (!kuid_has_mapping(ns, keyring->user->uid)) in find_keyring_by_name()
1160 if (test_bit(KEY_FLAG_REVOKED, &keyring->flags)) in find_keyring_by_name()
1163 if (strcmp(keyring->description, name) != 0) in find_keyring_by_name()
1168 &keyring->flags)) in find_keyring_by_name()
1171 if (key_permission(make_key_ref(keyring, 0), in find_keyring_by_name()
1179 if (!refcount_inc_not_zero(&keyring->usage)) in find_keyring_by_name()
1181 keyring->last_used_at = ktime_get_real_seconds(); in find_keyring_by_name()
1185 keyring = ERR_PTR(-ENOKEY); in find_keyring_by_name()
1188 return keyring; in find_keyring_by_name()
1238 int __key_link_lock(struct key *keyring, in __key_link_lock() argument
1240 __acquires(&keyring->sem) in __key_link_lock()
1243 if (keyring->type != &key_type_keyring) in __key_link_lock()
1246 down_write(&keyring->sem); in __key_link_lock()
1294 int __key_link_begin(struct key *keyring, in __key_link_begin() argument
1302 keyring->serial, index_key->type->name, index_key->description); in __key_link_begin()
1310 if (test_bit(KEY_FLAG_REVOKED, &keyring->flags)) in __key_link_begin()
1316 edit = assoc_array_insert(&keyring->keys, in __key_link_begin()
1329 ret = key_payload_reserve(keyring, in __key_link_begin()
1330 keyring->datalen + KEYQUOTA_LINK_BYTES); in __key_link_begin()
1352 int __key_link_check_live_key(struct key *keyring, struct key *key) in __key_link_check_live_key() argument
1357 return keyring_detect_cycle(keyring, key); in __key_link_check_live_key()
1382 void __key_link_end(struct key *keyring, in __key_link_end() argument
1385 __releases(&keyring->sem) in __key_link_end()
1389 kenter("%d,%s,", keyring->serial, index_key->type->name); in __key_link_end()
1393 key_payload_reserve(keyring, in __key_link_end()
1394 keyring->datalen - KEYQUOTA_LINK_BYTES); in __key_link_end()
1398 up_write(&keyring->sem); in __key_link_end()
1407 static int __key_link_check_restriction(struct key *keyring, struct key *key) in __key_link_check_restriction() argument
1409 if (!keyring->restrict_link || !keyring->restrict_link->check) in __key_link_check_restriction()
1411 return keyring->restrict_link->check(keyring, key->type, &key->payload, in __key_link_check_restriction()
1412 keyring->restrict_link->key); in __key_link_check_restriction()
1435 int key_link(struct key *keyring, struct key *key) in key_link() argument
1440 kenter("{%d,%d}", keyring->serial, refcount_read(&keyring->usage)); in key_link()
1442 key_check(keyring); in key_link()
1445 ret = __key_link_lock(keyring, &key->index_key); in key_link()
1449 ret = __key_link_begin(keyring, &key->index_key, &edit); in key_link()
1453 kdebug("begun {%d,%d}", keyring->serial, refcount_read(&keyring->usage)); in key_link()
1454 ret = __key_link_check_restriction(keyring, key); in key_link()
1456 ret = __key_link_check_live_key(keyring, key); in key_link()
1461 __key_link_end(keyring, &key->index_key, edit); in key_link()
1463 kleave(" = %d {%d,%d}", ret, keyring->serial, refcount_read(&keyring->usage)); in key_link()
1471 static int __key_unlink_lock(struct key *keyring) in __key_unlink_lock() argument
1472 __acquires(&keyring->sem) in __key_unlink_lock()
1474 if (keyring->type != &key_type_keyring) in __key_unlink_lock()
1477 down_write(&keyring->sem); in __key_unlink_lock()
1484 static int __key_unlink_begin(struct key *keyring, struct key *key, in __key_unlink_begin() argument
1491 edit = assoc_array_delete(&keyring->keys, &keyring_assoc_array_ops, in __key_unlink_begin()
1506 static void __key_unlink(struct key *keyring, struct key *key, in __key_unlink() argument
1511 key_payload_reserve(keyring, keyring->datalen - KEYQUOTA_LINK_BYTES); in __key_unlink()
1517 static void __key_unlink_end(struct key *keyring, in __key_unlink_end() argument
1520 __releases(&keyring->sem) in __key_unlink_end()
1524 up_write(&keyring->sem); in __key_unlink_end()
1544 int key_unlink(struct key *keyring, struct key *key) in key_unlink() argument
1549 key_check(keyring); in key_unlink()
1552 ret = __key_unlink_lock(keyring); in key_unlink()
1556 ret = __key_unlink_begin(keyring, key, &edit); in key_unlink()
1558 __key_unlink(keyring, key, &edit); in key_unlink()
1559 __key_unlink_end(keyring, key, edit); in key_unlink()
1646 int keyring_clear(struct key *keyring) in keyring_clear() argument
1651 if (keyring->type != &key_type_keyring) in keyring_clear()
1654 down_write(&keyring->sem); in keyring_clear()
1656 edit = assoc_array_clear(&keyring->keys, &keyring_assoc_array_ops); in keyring_clear()
1662 key_payload_reserve(keyring, 0); in keyring_clear()
1666 up_write(&keyring->sem); in keyring_clear()
1676 static void keyring_revoke(struct key *keyring) in keyring_revoke() argument
1680 edit = assoc_array_clear(&keyring->keys, &keyring_assoc_array_ops); in keyring_revoke()
1684 key_payload_reserve(keyring, 0); in keyring_revoke()
1714 void keyring_gc(struct key *keyring, time64_t limit) in keyring_gc() argument
1718 kenter("%x{%s}", keyring->serial, keyring->description ?: ""); in keyring_gc()
1720 if (keyring->flags & ((1 << KEY_FLAG_INVALIDATED) | in keyring_gc()
1726 result = assoc_array_iterate(&keyring->keys, in keyring_gc()
1737 down_write(&keyring->sem); in keyring_gc()
1738 assoc_array_gc(&keyring->keys, &keyring_assoc_array_ops, in keyring_gc()
1740 up_write(&keyring->sem); in keyring_gc()
1759 void keyring_restriction_gc(struct key *keyring, struct key_type *dead_type) in keyring_restriction_gc() argument
1763 kenter("%x{%s}", keyring->serial, keyring->description ?: ""); in keyring_restriction_gc()
1772 if (!dead_type || !keyring->restrict_link || in keyring_restriction_gc()
1773 keyring->restrict_link->keytype != dead_type) { in keyring_restriction_gc()
1779 down_write(&keyring->sem); in keyring_restriction_gc()
1781 keyres = keyring->restrict_link; in keyring_restriction_gc()
1789 up_write(&keyring->sem); in keyring_restriction_gc()