Skip to content

feat(security): keep superkey and SELinux contexts out of logs and argv - #321

Merged
Admirepowered merged 1 commit into
bmax121:mainfrom
JavSaia:feat/credential-hardening
Oct 3, 2026
Merged

Admirepowered merged 1 commit into
bmax121:mainfrom
JavSaia:feat/credential-hardening

Conversation

@JavSaia

@JavSaia JavSaia commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

What

The superkey and the per-UID SELinux contexts are credentials, and several code paths exposed them.

Superkey handling

  • Authentication compares in constant time. The previous loop accumulated XOR differences and returned as soon as the lengths differed, which leaks the key length and the length of any matching prefix.

  • Rotating the key wipes the previous value with volatile stores, and the SHA256 context and digest buffer are wiped after hash verification.

  • SUPERCALL_SKEY_GET and the supercmd key get subcommand no longer return the plaintext key by default. A hardened build can define KP_HIDE_SUPERKEY to disable readback entirely; the default keeps the previous behaviour so existing managers keep working.

  • call_skey_set() copied the new key out of user space and then passed the original __user pointer to the rotation helper, which dereferenced it as a kernel pointer. It now uses the copied buffer and wipes it on every exit path.

kptools

  • New --skey-fd and --root-skey-fd options read the key from a file descriptor, so it does not appear in argv and therefore not in /proc/<pid>/cmdline or the shell history.

  • Image inspection (-l) redacts the superkey and the root-superkey verifier unless --show-secrets is passed explicitly.

  • Patching and key reset no longer print key material; the reset log states that the key changed without showing either value.

SELinux contexts

  • accctl, sucompat and the LKM su paths no longer log context strings at info level.
  • Contexts received from user space are length-checked before use.

Authorisation boundaries

An SU-allowlisted caller is not an administrator. SUPER_CALL arguments from such a caller are now restricted to a read-only set; module load/unload/control and key management require the superkey. SUPERCALL_SU_PROFILE is scoped to the caller's own UID.

supercmd wipes the credential argument as soon as authentication is done, and no longer echoes the SELinux context in its grant reply.

Build

base/setup.o, x86/setup.x86.o and kptools.o embed the version constants from version via #include; the Makefiles now list it as a prerequisite, so an incremental build cannot ship a stale version stamp. (This is how a 0.14 tree produced a kpimg reporting 0xd09 earlier.)

Tests

  • checks/test_secret.c — volatile erasure, constant-time comparison, fd secret input (including the oversized-input wipe path).
PASS: credential erasure, constant-time compare, fd secret input

Breaking changes

  • SU-allowlisted (non-admin) callers can no longer invoke KPM management or key-management supercalls without the superkey.
  • key get / SUPERCALL_SKEY_GET still work by default; only a KP_HIDE_SUPERKEY build disables them.

The superkey and per-UID SELinux contexts are credentials; several code
paths exposed them.

Superkey handling
- Authentication now compares in constant time.  The previous loop
  accumulated XOR differences and returned as soon as the length differed,
  which leaks the key length and the matching prefix.
- Rotating the key wipes the previous value with volatile stores, and the
  SHA256 context and digest buffer are wiped after hash verification.
- SUPERCALL_SKEY_GET and the supercmd "key get" subcommand no longer
  return the plaintext key by default.  A hardened build can define
  KP_HIDE_SUPERKEY to disable readback entirely; the default keeps the
  previous behaviour so existing managers keep working.
- call_skey_set() copied the key out of user space and then passed the
  original __user pointer to the rotation helper, which dereferenced it as
  a kernel pointer.  It now uses the copied buffer and wipes it on every
  exit path.

kptools
- New --skey-fd and --root-skey-fd options read the key from a file
  descriptor, so it does not appear in argv (and therefore not in
  /proc/<pid>/cmdline or the shell history).
- Image inspection (-l) redacts the superkey and the root-superkey
  verifier unless --show-secrets is passed explicitly.
- Patching and key reset no longer print key material; the reset log
  states that the key changed without showing either value.

SELinux contexts
- accctl, sucompat and the LKM su paths no longer log context strings at
  info level.
- Contexts received from user space are length-checked before use.

Authorisation boundaries
- An SU-allowlisted caller is not an administrator.  SUPER_CALL arguments
  from such a caller are now restricted to a read-only set
  (KP_HIDE... , SU_PROFILE for its own UID, and the version/hello calls);
  module load/unload/control and key management require the superkey.
- supercmd wipes the credential argument as soon as authentication is
  done, and no longer echoes the SELinux context in its grant reply.

Build
- base/setup.o, x86/setup.x86.o and kptools.o embed the version constants
  from version via #include; the Makefiles now list it as a prerequisite
  so an incremental build cannot ship a stale version stamp.
@Admirepowered
Admirepowered merged commit 53c43f3 into bmax121:main Oct 3, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants