Files
twx-linux/include/linux
Matthew Garrett eddbab1384 evm: Don't deadlock if a crypto algorithm is unavailable
[ Upstream commit e2861fa716 ]

When EVM attempts to appraise a file signed with a crypto algorithm the
kernel doesn't have support for, it will cause the kernel to trigger a
module load. If the EVM policy includes appraisal of kernel modules this
will in turn call back into EVM - since EVM is holding a lock until the
crypto initialisation is complete, this triggers a deadlock. Add a
CRYPTO_NOLOAD flag and skip module loading if it's set, and add that flag
in the EVM case in order to fail gracefully with an error message
instead of deadlocking.

Signed-off-by: Matthew Garrett <mjg59@google.com>
Acked-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Signed-off-by: Sasha Levin <alexander.levin@microsoft.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2018-09-26 08:36:37 +02:00
..
2017-10-08 10:26:06 +02:00
2018-04-24 09:34:18 +02:00
2017-06-14 15:06:00 +02:00
2018-02-28 10:18:33 +01:00
2017-07-15 12:16:11 +02:00
2017-05-14 14:00:22 +02:00
2017-07-12 15:01:02 +02:00
2017-08-06 18:59:43 -07:00
2018-04-24 09:34:12 +02:00
2017-08-24 17:12:19 -07:00
2018-09-09 20:01:20 +02:00
2017-08-24 17:12:21 -07:00
2017-08-30 10:21:40 +02:00
2017-04-21 09:31:21 +02:00
2017-12-25 14:23:37 +01:00