keyring: use KeyctlSearch - #132
Merged
Merged
Conversation
ReadKey and RemoveKey passed non-NULL callout info to request_key(2), which asks the kernel to instantiate missing keys by spawning /sbin/request-key from the host root filesystem. The agent only looks up keys it added itself, so the upcall can never succeed; all it does is make the error for a missing key depend on the host: - /sbin/request-key present (keyutils installed): the helper runs and fails, the key is negatively instantiated, and the caller gets ENOKEY - /sbin/request-key absent (e.g. NixOS): the usermode helper fails to exec and the caller gets ENOENT This is why the keyring tests expecting ENOKEY pass on some machines and fail with ENOENT on others, as reported in NixOS/nixpkgs#394097. request_key(2) also only searches the calling process's thread, process and session keyrings; its destination keyring argument is only used to link the found key into. Searching k.ringid worked only because the agent joins that keyring as its session keyring. keyctl(KEYCTL_SEARCH) searches the requested keyring directly, never upcalls, and uniformly returns ENOKEY for a missing key, which is what the tests already expect.
With KEYCTL_SEARCH a missing key is always reported as ENOKEY, regardless of whether /sbin/request-key exists on the host, so the ENOENT workaround from Foxboron#94 is dead code. Its warning was also misleading: keyring caching never needed the keyutils helpers; only the errno for a cache miss depended on them.
Owner
|
This makes sense, thanks! |
Owner
|
Thanks! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
keyring: use KEYCTL_SEARCH instead of request_key(2)
cmd/ssh-tpm-agent: drop ENOENT handling for cache misses