[RFC PATCH 1/2] keys: Return user session keyring on lookup
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Thu Sep 24 06:01:43 UTC 2026
> A process without a session keyring looking up KEY_SPEC_SESSION_KEYRING
> without KEY_LOOKUP_CREATE mutates the credentials. This causes struct creds
> instances shared with other subsystems to become stale.
>
> Address this by returning the resolved user session keyring directly
> without installing it into credentials.
>
> Suggested-by: Jann Horn <jannh at google.com>
> Signed-off-by: Jarkko Sakkinen <jarkko at kernel.org>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260924055521.1981957-1-jarkko@kernel.org?part=1
More information about the Linux-security-module-archive
mailing list