[RFC PATCH 1/2] keys: Return user session keyring on lookup

sashiko-bot at kernel.org sashiko-bot at kernel.org
Thu Sep 24 06:01:43 UTC 2026


> A process without a session keyring looking up KEY_SPEC_SESSION_KEYRING
> without KEY_LOOKUP_CREATE mutates the credentials. This causes struct creds
> instances shared with other subsystems to become stale.
> 
> Address this by returning the resolved user session keyring directly
> without installing it into credentials.
> 
> Suggested-by: Jann Horn <jannh at google.com>
> Signed-off-by: Jarkko Sakkinen <jarkko at kernel.org>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260924055521.1981957-1-jarkko@kernel.org?part=1




More information about the Linux-security-module-archive mailing list