[PATCH v2 06/10] pseries/plpks: fix self-reference in plpks_var initializer

R Nageswara Sastry rnsastry at linux.ibm.com
Fri Sep 4 06:14:59 UTC 2026


On 31.08.2026 4:47 PM, Srish Srinivasan wrote:
> In plpks_gen_wrapping_key() and plpks_wrap_object(), strlen(var.name) is
> used to initialize var.namelen within the same struct initializer. This
> references a member of var before initialization of var is complete.
>
> Use the compile-time length of PLPKS_DEFAULT_WRAPKEY_LABEL instead.
>
> Reported-by: R Nageswara Sastry <rnsastry at linux.ibm.com>
> Fixes: 133aa79e211d ("pseries/plpks: add HCALLs for PowerVM Key Wrapping Module")
> Cc: stable at vger.kernel.org
> Signed-off-by: Srish Srinivasan <ssrish at linux.ibm.com>
Tested-by: R Nageswara Sastry <rnsastry at linux.ibm.com>

Tested on ppc64le PowerVM LPARs on firmware with wrap/unwrap support,
with and without Secure Boot enabled.

Verified that PKWM initialisation and trusted key seal/unseal work
correctly with the compile-time label length fix in place.
> ---
>   arch/powerpc/platforms/pseries/plpks.c | 4 ++--
>   1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/arch/powerpc/platforms/pseries/plpks.c b/arch/powerpc/platforms/pseries/plpks.c
> index b553f7b130b6..d582c786ccad 100644
> --- a/arch/powerpc/platforms/pseries/plpks.c
> +++ b/arch/powerpc/platforms/pseries/plpks.c
> @@ -939,7 +939,7 @@ int plpks_gen_wrapping_key(void)
>   	int rc = 0, pseries_status = 0;
>   	struct plpks_var var = {
>   		.name = PLPKS_DEFAULT_WRAPKEY_LABEL,
> -		.namelen = strlen(var.name),
> +		.namelen = sizeof(PLPKS_DEFAULT_WRAPKEY_LABEL) - 1,
>   		.policy = PLPKS_WRAPPINGKEY,
>   		.os = PLPKS_VAR_LINUX,
>   		.component = PLPKS_WRAPKEY_COMPONENT
> @@ -1034,7 +1034,7 @@ int plpks_wrap_object(u8 **input_buf, u64 input_len, u16 wrap_flags,
>   	bool sb_enforce_bit = wrap_flags & BIT(1);
>   	struct plpks_var var = {
>   		.name = PLPKS_DEFAULT_WRAPKEY_LABEL,
> -		.namelen = strlen(var.name),
> +		.namelen = sizeof(PLPKS_DEFAULT_WRAPKEY_LABEL) - 1,
>   		.os = PLPKS_VAR_LINUX,
>   		.component = PLPKS_WRAPKEY_COMPONENT
>   	};

-- 
Thanks and Regards
R.Nageswara Sastry




More information about the Linux-security-module-archive mailing list