dm-integrity currently accepts keys only as hex strings in the table, so
keys that never leave the kernel, such as trusted keys, cannot be used.

This patch adds support for retrieving keys from the kernel keyring
using the same format as dm-crypt:

  :<key_size>:<key_type>:<key_description>

The keyring lookup code is copied from dm-crypt's
crypt_set_keyring_key() and its helpers. I would prefer to share this
code between dm-crypt and dm-integrity rather than duplicate it, but I
am not sure what the best way is. I see only two options:

1. static inline helpers in a drivers/md header, so dm-crypt and
   dm-integrity each compile their own copy
2. a small library module, similar to dm-bufio, so there is one copy
   that follows the value (y/m) of dm-crypt and dm-integrity

Putting the helpers into dm-mod does not work. The helpers use
key_type_encrypted and key_type_trusted, which can be modules. With
e.g., BLK_DEV_DM=y, DM_CRYPT=m and ENCRYPTED_KEYS=m, built-in dm-mod
would reference a module symbol, and vmlinux fails to link.

Please let me know which approach you would prefer, or if there is a
better way to share this code.

Lorenz Kofler (1):
  dm-integrity: support keys in the kernel keyring

 .../device-mapper/dm-integrity.rst            |  25 +++
 drivers/md/Kconfig                            |   2 +
 drivers/md/dm-integrity.c                     | 164 ++++++++++++++++++
 3 files changed, 191 insertions(+)


base-commit: f0100363d8c374bd8e9ea7c9ba02744f0b802ca4
-- 
2.55.0


Reply via email to