[PATCH] keys: set persistent keyring timeout before destination linking

Karl Mehltretter kmehltretter at gmail.com
Tue Sep 1 16:16:12 UTC 2026


On Tue, Sep 01, 2026 at 04:30:27PM +0100, Jarkko Sakkinen wrote:
> > Tested with QEMU 10.2.1 TCG. The reproducer set
> > /proc/sys/kernel/keys/persistent_keyring_expiry to 60 seconds, restricted
> > the destination with KEYCTL_RESTRICT_KEYRING, and then called
> > KEYCTL_GET_PERSISTENT. No LSM policy was loaded.
> > 
> >                       syscall result  /proc/keys expiry
> >   i386 baseline       -EPERM          perm
> >   i386 patched        -EPERM          1m
> >   x86_64 patched      -EPERM          1m
> > 
> > Full kernel builds completed for i386 and ARM926, and for x86_64 with
> > CONFIG_PROVE_LOCKING=y. The x86_64 reproducer completed without lockdep
> > reports, warnings, or bugs.
> 
> Please describe this in the commit message and delete most of
> the text it has. This is the motivation part.

Got it, thanks. I'll shorten commit message.

I also found a narrow race if linking is delayed past expiry and GC runs.
It is unlikely in practice, but reproducible with an injected delay, so
I'll address it in v2.

Thanks,
Karl



More information about the Linux-security-module-archive mailing list