[PATCH v3 2/2] keys: Serialize ownership transfers with key accounting
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Sun Sep 27 16:33:53 UTC 2026
> Protecting individual accesses to key->user does not make ownership
> transfers atomic with accounting updates. keyctl_chown_key() holds
> key->sem, but instantiation is serialized by key_construction_mutex and
> need not hold that semaphore. KEY_LOOKUP_PARTIAL also permits chown of
> an uninstantiated key.
>
> The instantiated-key count can therefore be charged to the wrong owner:
>
> instantiate keyctl_chown_key()
> lock key_user_lock
> increment old->nikeys
> unlock key_user_lock
> observe KEY_IS_UNINSTANTIATED
> skip the nikeys transfer
> replace key->user
> [ ... ]
> key_user_lock, and release it on the quota-overrun path.
>
> Fixes: 5801649d8b83 ("[PATCH] keys: let keyctl_chown() change a key's owner")
> Cc: stable at vger.kernel.org
> Signed-off-by: Chengfeng Ye <nicoyip.dev at gmail.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260927162528.943886-1-nicoyip.dev@gmail.com?part=2
More information about the Linux-security-module-archive
mailing list