signing.c 3.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125
  1. // SPDX-License-Identifier: GPL-2.0-or-later
  2. /* Module signature checker
  3. *
  4. * Copyright (C) 2012 Red Hat, Inc. All Rights Reserved.
  5. * Written by David Howells (dhowells@redhat.com)
  6. */
  7. #include <linux/kernel.h>
  8. #include <linux/errno.h>
  9. #include <linux/module.h>
  10. #include <linux/module_signature.h>
  11. #include <linux/string.h>
  12. #include <linux/verification.h>
  13. #include <linux/security.h>
  14. #include <crypto/public_key.h>
  15. #include <uapi/linux/module.h>
  16. #include "internal.h"
  17. #undef MODULE_PARAM_PREFIX
  18. #define MODULE_PARAM_PREFIX "module."
  19. static bool sig_enforce = IS_ENABLED(CONFIG_MODULE_SIG_FORCE);
  20. module_param(sig_enforce, bool_enable_only, 0644);
  21. /*
  22. * Export sig_enforce kernel cmdline parameter to allow other subsystems rely
  23. * on that instead of directly to CONFIG_MODULE_SIG_FORCE config.
  24. */
  25. bool is_module_sig_enforced(void)
  26. {
  27. return sig_enforce;
  28. }
  29. EXPORT_SYMBOL(is_module_sig_enforced);
  30. void set_module_sig_enforced(void)
  31. {
  32. sig_enforce = true;
  33. }
  34. /*
  35. * Verify the signature on a module.
  36. */
  37. int mod_verify_sig(const void *mod, struct load_info *info)
  38. {
  39. struct module_signature ms;
  40. size_t sig_len, modlen = info->len;
  41. int ret;
  42. pr_devel("==>%s(,%zu)\n", __func__, modlen);
  43. if (modlen <= sizeof(ms))
  44. return -EBADMSG;
  45. memcpy(&ms, mod + (modlen - sizeof(ms)), sizeof(ms));
  46. ret = mod_check_sig(&ms, modlen, "module");
  47. if (ret)
  48. return ret;
  49. sig_len = be32_to_cpu(ms.sig_len);
  50. modlen -= sig_len + sizeof(ms);
  51. info->len = modlen;
  52. return verify_pkcs7_signature(mod, modlen, mod + modlen, sig_len,
  53. VERIFY_USE_SECONDARY_KEYRING,
  54. VERIFYING_MODULE_SIGNATURE,
  55. NULL, NULL);
  56. }
  57. int module_sig_check(struct load_info *info, int flags)
  58. {
  59. int err = -ENODATA;
  60. const unsigned long markerlen = sizeof(MODULE_SIG_STRING) - 1;
  61. const char *reason;
  62. const void *mod = info->hdr;
  63. bool mangled_module = flags & (MODULE_INIT_IGNORE_MODVERSIONS |
  64. MODULE_INIT_IGNORE_VERMAGIC);
  65. /*
  66. * Do not allow mangled modules as a module with version information
  67. * removed is no longer the module that was signed.
  68. */
  69. if (!mangled_module &&
  70. info->len > markerlen &&
  71. memcmp(mod + info->len - markerlen, MODULE_SIG_STRING, markerlen) == 0) {
  72. /* We truncate the module to discard the signature */
  73. info->len -= markerlen;
  74. err = mod_verify_sig(mod, info);
  75. if (!err) {
  76. info->sig_ok = true;
  77. return 0;
  78. }
  79. }
  80. /*
  81. * We don't permit modules to be loaded into the trusted kernels
  82. * without a valid signature on them, but if we're not enforcing,
  83. * certain errors are non-fatal.
  84. */
  85. switch (err) {
  86. case -ENODATA:
  87. reason = "unsigned module";
  88. break;
  89. case -ENOPKG:
  90. reason = "module with unsupported crypto";
  91. break;
  92. case -ENOKEY:
  93. reason = "module with unavailable key";
  94. break;
  95. default:
  96. /*
  97. * All other errors are fatal, including lack of memory,
  98. * unparseable signatures, and signature check failures --
  99. * even if signatures aren't required.
  100. */
  101. return err;
  102. }
  103. if (is_module_sig_enforced()) {
  104. pr_notice("Loading of %s is rejected\n", reason);
  105. return -EKEYREJECTED;
  106. }
  107. return security_locked_down(LOCKDOWN_MODULE_SIGNATURE);
  108. }