Skip to content

keyring: use KeyctlSearch - #132

Merged
Foxboron merged 2 commits into
Foxboron:masterfrom
Kranzes:keyring-keyctl-search
Aug 2, 2026
Merged

Foxboron merged 2 commits into
Foxboron:masterfrom
Kranzes:keyring-keyctl-search

Conversation

@Kranzes

@Kranzes Kranzes commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

Kranzes added 2 commits July 18, 2026 00:05
ReadKey and RemoveKey passed non-NULL callout info to request_key(2),
which asks the kernel to instantiate missing keys by spawning
/sbin/request-key from the host root filesystem. The agent only looks
up keys it added itself, so the upcall can never succeed; all it does
is make the error for a missing key depend on the host:

- /sbin/request-key present (keyutils installed): the helper runs and
  fails, the key is negatively instantiated, and the caller gets ENOKEY
- /sbin/request-key absent (e.g. NixOS): the usermode helper fails to
  exec and the caller gets ENOENT

This is why the keyring tests expecting ENOKEY pass on some machines
and fail with ENOENT on others, as reported in
NixOS/nixpkgs#394097.

request_key(2) also only searches the calling process's thread,
process and session keyrings; its destination keyring argument is only
used to link the found key into. Searching k.ringid worked only
because the agent joins that keyring as its session keyring.

keyctl(KEYCTL_SEARCH) searches the requested keyring directly, never
upcalls, and uniformly returns ENOKEY for a missing key, which is what
the tests already expect.
With KEYCTL_SEARCH a missing key is always reported as ENOKEY,
regardless of whether /sbin/request-key exists on the host, so the
ENOENT workaround from Foxboron#94 is dead code. Its warning was also
misleading: keyring caching never needed the keyutils helpers; only
the errno for a cache miss depended on them.
@Foxboron

Copy link
Copy Markdown
Owner

This makes sense, thanks!

@Foxboron
Foxboron merged commit 5f8786b into Foxboron:master Aug 2, 2026
5 checks passed
@Foxboron

Foxboron commented Aug 2, 2026

Copy link
Copy Markdown
Owner

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants