feat(security): keep superkey and SELinux contexts out of logs and argv - #321
Merged
Merged
Conversation
The superkey and per-UID SELinux contexts are credentials; several code paths exposed them. Superkey handling - Authentication now compares in constant time. The previous loop accumulated XOR differences and returned as soon as the length differed, which leaks the key length and the matching prefix. - Rotating the key wipes the previous value with volatile stores, and the SHA256 context and digest buffer are wiped after hash verification. - SUPERCALL_SKEY_GET and the supercmd "key get" subcommand no longer return the plaintext key by default. A hardened build can define KP_HIDE_SUPERKEY to disable readback entirely; the default keeps the previous behaviour so existing managers keep working. - call_skey_set() copied the key out of user space and then passed the original __user pointer to the rotation helper, which dereferenced it as a kernel pointer. It now uses the copied buffer and wipes it on every exit path. kptools - New --skey-fd and --root-skey-fd options read the key from a file descriptor, so it does not appear in argv (and therefore not in /proc/<pid>/cmdline or the shell history). - Image inspection (-l) redacts the superkey and the root-superkey verifier unless --show-secrets is passed explicitly. - Patching and key reset no longer print key material; the reset log states that the key changed without showing either value. SELinux contexts - accctl, sucompat and the LKM su paths no longer log context strings at info level. - Contexts received from user space are length-checked before use. Authorisation boundaries - An SU-allowlisted caller is not an administrator. SUPER_CALL arguments from such a caller are now restricted to a read-only set (KP_HIDE... , SU_PROFILE for its own UID, and the version/hello calls); module load/unload/control and key management require the superkey. - supercmd wipes the credential argument as soon as authentication is done, and no longer echoes the SELinux context in its grant reply. Build - base/setup.o, x86/setup.x86.o and kptools.o embed the version constants from version via #include; the Makefiles now list it as a prerequisite so an incremental build cannot ship a stale version stamp.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The superkey and the per-UID SELinux contexts are credentials, and several code paths exposed them.
Superkey handling
Authentication compares in constant time. The previous loop accumulated XOR differences and returned as soon as the lengths differed, which leaks the key length and the length of any matching prefix.
Rotating the key wipes the previous value with volatile stores, and the SHA256 context and digest buffer are wiped after hash verification.
SUPERCALL_SKEY_GETand the supercmdkey getsubcommand no longer return the plaintext key by default. A hardened build can defineKP_HIDE_SUPERKEYto disable readback entirely; the default keeps the previous behaviour so existing managers keep working.call_skey_set()copied the new key out of user space and then passed the original__userpointer to the rotation helper, which dereferenced it as a kernel pointer. It now uses the copied buffer and wipes it on every exit path.kptools
New
--skey-fdand--root-skey-fdoptions read the key from a file descriptor, so it does not appear inargvand therefore not in/proc/<pid>/cmdlineor the shell history.Image inspection (
-l) redacts the superkey and the root-superkey verifier unless--show-secretsis passed explicitly.Patching and key reset no longer print key material; the reset log states that the key changed without showing either value.
SELinux contexts
accctl,sucompatand the LKM su paths no longer log context strings at info level.Authorisation boundaries
An SU-allowlisted caller is not an administrator.
SUPER_CALLarguments from such a caller are now restricted to a read-only set; module load/unload/control and key management require the superkey.SUPERCALL_SU_PROFILEis scoped to the caller's own UID.supercmdwipes the credential argument as soon as authentication is done, and no longer echoes the SELinux context in its grant reply.Build
base/setup.o,x86/setup.x86.oandkptools.oembed the version constants fromversionvia#include; the Makefiles now list it as a prerequisite, so an incremental build cannot ship a stale version stamp. (This is how a0.14tree produced akpimgreporting0xd09earlier.)Tests
checks/test_secret.c— volatile erasure, constant-time comparison, fd secret input (including the oversized-input wipe path).Breaking changes
key get/SUPERCALL_SKEY_GETstill work by default; only aKP_HIDE_SUPERKEYbuild disables them.