From nobody Mon Sep 28 03:41:40 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E106835CB81; Thu, 27 Aug 2026 06:23:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787811840; cv=none; b=FLaMLvzp6d0DWJE/GNi4m7shD6+2tr12mZJxES5UF4TeRcsmS9JZa8vt7u0PWtHP+HnNqKQcIqxqsKs7EPhDTy0zLO3uqypuTQv2Cpd89igIR08SNPhs3OSRvzjs5ZDWzBgNwpWVgKjfntjsWmwFE/nlZwNI2sv/GYa6exnck0Y= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787811840; c=relaxed/simple; bh=jkag9wO124JNvB+E/xckAn+EMG//cCRvBT+B/DeP6fY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=TYJPEJJsNVh+R5wMHzAy+vGkINODL9stMgFg/s0jByjm3v8Rl+XkkBnwVmhDMRh34Vb23Bz92pI9MxQ9tGInFJRMdZzxDJJDPfVwDh2TklSTL1g62pT9jWa+qLvkW0YXgOShhIt0/cnh2ze576k4recJ3rN5VLbzEs2D/grSPnQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=ntK5gGGn; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="ntK5gGGn" Received: from pps.filterd (m0353729.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67R3VarM4139815; Thu, 27 Aug 2026 06:23:43 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=IL05qI0zF9+6tMvjp CrbdI1qk258KXsyIPDjSVuxBpk=; b=ntK5gGGnGsMaW9Rtw4TorTMaIyKWp1eBF 33tTmRUUt1AorET1z9WDZak8QtpsQzGgHS1xlXAMzd4WmoAYM7HCT6/YgVYFoWBN 0DIZo7v7VLuehPeIzOj2vEQqX2umztMKx0hzOGl9521iCQ6DjWCkAYMsOyJMrlKb WkoMp36DblIAsIJwQFtjh7w64lz0LvgzTOT6cwQ5DtGgCiK2BeytMTjNnQxWCk1A 8da5DvifreY9OJ+CL//KaXAj5SRlFVaXP0ffmP3thNpqpDuMAE8kcPjsv4rxIYzb xoVPxs1kuocyoz2gDYrPfDciTTkGMLQavVWPwp5xmLdy4fV9gSQEQ== Received: from ppma13.dal12v.mail.ibm.com (dd.9e.1632.ip4.static.sl-reverse.com [50.22.158.221]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4g73er3h60-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 27 Aug 2026 06:23:42 +0000 (GMT) Received: from pps.filterd (ppma13.dal12v.mail.ibm.com [127.0.0.1]) by ppma13.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67R6BF10013824; Thu, 27 Aug 2026 06:23:41 GMT Received: from smtprelay05.fra02v.mail.ibm.com ([9.218.2.225]) by ppma13.dal12v.mail.ibm.com (PPS) with ESMTPS id 4g7ragpawx-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 27 Aug 2026 06:23:41 +0000 (GMT) Received: from smtpav01.fra02v.mail.ibm.com (smtpav01.fra02v.mail.ibm.com [10.20.54.100]) by smtprelay05.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67R6Nb4D51053026 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Thu, 27 Aug 2026 06:23:37 GMT Received: from smtpav01.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 9FD342004B; Thu, 27 Aug 2026 06:23:37 +0000 (GMT) Received: from smtpav01.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 0B75220040; Thu, 27 Aug 2026 06:23:26 +0000 (GMT) Received: from li-fc74f8cc-3279-11b2-a85c-ef5828687581.ibm.com.com (unknown [9.76.202.253]) by smtpav01.fra02v.mail.ibm.com (Postfix) with ESMTP; Thu, 27 Aug 2026 06:23:25 +0000 (GMT) From: Srish Srinivasan To: linux-integrity@vger.kernel.org, keyrings@vger.kernel.org, linuxppc-dev@lists.ozlabs.org Cc: maddy@linux.ibm.com, mpe@ellerman.id.au, npiggin@gmail.com, christophe.leroy@csgroup.eu, James.Bottomley@HansenPartnership.com, jarkko@kernel.org, zohar@linux.ibm.com, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, nayna@linux.ibm.com, rnsastry@linux.ibm.com, ssrish@linux.ibm.com Subject: [PATCH 1/8] pseries/plpks: update PKS documentation and maintainer entry Date: Thu, 27 Aug 2026 11:53:01 +0530 Message-ID: <20260827062309.724808-2-ssrish@linux.ibm.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260827062309.724808-1-ssrish@linux.ibm.com> References: <20260827062309.724808-1-ssrish@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Reinject: loops=2 maxloops=12 X-Proofpoint-GUID: E5KGnUswwFo-46pFTKTVWSc5UDgwDV5r X-Proofpoint-ORIG-GUID: LbGZbk5F3iG2KsUicI5Szx52pvJNnEQC X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODI3MDA0OCBTYWx0ZWRfX+34rS6nAkAzr Hf1ppNN+ai/wFyCtqtPi/y01A/sK5QlJFbx2Di+6AjGZEKdB8XlCAtoWj7iYJ35Zk5o+Lji1TDD QsBMZc3ojSv5htLXww1y57LxW4nrgbF+JxCc+OFCdbmnqG8V2w5xOISS2XUTYtGWPPWC7SCZB47 mQDv37+z4l53QaVIm49oUWkLT5i5D6Wp7VLmbASF2tn1d54AxECy4P8aZmi7B/3Y7rOYeSMgSnJ LXyY7XiQ1LCh4ZEqBDsTwVNMo4Nm8EAFZEadeL1ABEUAGXgKE5GbUNx2QqhcM6tu7CMb6Q/o9Ij uUULtUpXnaca7uaNEQRgsPQCQMt2dKj8aiTUijqkV+vjuGjXDDCHv5ceHeeKkTUTh7ThoOiw3gk FRWpiGjc+TMJofzwrRD5HWQ8FvgJ7S4h+/Xu6zQYJgiqyXmim7fjRxzMULzbMnKs4QtcyDexyib Z02fPy8hzW69HB1aEhw== X-Authority-Analysis: v=2.4 cv=QsRuG1yd c=1 sm=1 tr=0 ts=6a8fd7ee cx=c_pps a=AfN7/Ok6k8XGzOShvHwTGQ==:117 a=AfN7/Ok6k8XGzOShvHwTGQ==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=uAbxVGIbfxUO_5tXvNgY:22 a=VnNF1IyMAAAA:8 a=VwQbUJbxAAAA:8 a=2YPxekF_mspUCEnIjzkA:9 X-Proofpoint-Spam-Info: AW1haW4tMjYwODI3MDA0OCBTYWx0ZWRfXzHaFJMhQwOuD Ao6BC1eI62J6ywaz4uT4m/rOmKZ6Ur6TUjuWtc7U13Y8McX6cCzOiBp6ekKna6/ylFJZcygSr4o itck6hLb/ZgN/saX3dRIIGY9vx8Wxic= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-27_02,2026-08-26_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 malwarescore=0 adultscore=0 suspectscore=0 priorityscore=1501 impostorscore=0 spamscore=0 lowpriorityscore=0 clxscore=1011 bulkscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608270048 Content-Type: text/plain; charset="utf-8" Wrap long PKS hcall return-value lines consistently and fix a typo in the H_PKS_UNWRAP_OBJECT description. Also update the MAINTAINERS entry from KEYS-TRUSTED-PLPKS to KEYS-TRUSTED-PKWM to reflect the PowerVM Key Wrapping Module naming. Fixes: 133aa79e211d ("pseries/plpks: add HCALLs for PowerVM Key Wrapping Mo= dule") Fixes: c99fcb0d735b ("keys/trusted_keys: establish PKWM as a trusted source= ") Signed-off-by: Srish Srinivasan --- Documentation/arch/powerpc/papr_hcalls.rst | 16 ++++++++-------- MAINTAINERS | 2 +- 2 files changed, 9 insertions(+), 9 deletions(-) diff --git a/Documentation/arch/powerpc/papr_hcalls.rst b/Documentation/arc= h/powerpc/papr_hcalls.rst index 14e39f095a1c..44c9c8b32ae3 100644 --- a/Documentation/arch/powerpc/papr_hcalls.rst +++ b/Documentation/arch/powerpc/papr_hcalls.rst @@ -305,8 +305,8 @@ like core instruction, core LLAT and nest. | Input: authorization, objectlabel, objectlabellen, policy, out, outlen | Out: *Hypervisor Generated Key, or None when the wrapping key policy is = set* | Return Value: *H_SUCCESS, H_Function, H_State, H_R_State, H_Parameter, H= _P2, - H_P3, H_P4, H_P5, H_P6, H_Authority, H_Nomem, H_Busy, H_Re= source, - H_Aborted* + H_P3, H_P4, H_P5, H_P6, H_Authority, H_Nomem, H_Busy, + H_Resource, H_Aborted* =20 H_PKS_GEN_KEY is used to have the hypervisor generate a new random key. This key is stored as an object in the Power LPAR Platform KeyStore with @@ -321,8 +321,8 @@ the user. Generation of wrapping keys is supported only= for a key size of | inlen, out, outlen, continue-token | Out: *continue-token, byte size of wrapped object, wrapped object* | Return Value: *H_SUCCESS, H_Function, H_State, H_R_State, H_Parameter, H= _P2, - H_P3, H_P4, H_P5, H_P6, H_P7, H_P8, H_P9, H_Authority, H_I= nvalid_Key, - H_NOT_FOUND, H_Busy, H_LongBusy, H_Aborted* + H_P3, H_P4, H_P5, H_P6, H_P7, H_P8, H_P9, H_Authority, + H_Invalid_Key, H_NOT_FOUND, H_Busy, H_LongBusy, H_Aborted* =20 H_PKS_WRAP_OBJECT is used to wrap an object using a wrapping key stored in= the Power LPAR Platform KeyStore and return the wrapped object to the caller. = The @@ -331,16 +331,16 @@ which must have been previously created with H_PKS_GE= N_KEY. The provided object is then encrypted with the wrapping key and additional metadata and the re= sult is returned to the caller. =20 - **H_PKS_UNWRAP_OBJECT** =20 | Input: authorization, objectwrapflags, in, inlen, out, outlen, continue-= token | Out: *continue-token, byte size of unwrapped object, unwrapped object* | Return Value: *H_SUCCESS, H_Function, H_State, H_R_State, H_Parameter, H= _P2, - H_P3, H_P4, H_P5, H_P6, H_P7, H_Authority, H_Unsupported, = H_Bad_Data, - H_NOT_FOUND, H_Invalid_Key, H_Busy, H_LongBusy, H_Aborted* + H_P3, H_P4, H_P5, H_P6, H_P7, H_Authority, H_Unsupported, + H_Bad_Data, H_NOT_FOUND, H_Invalid_Key, H_Busy, H_LongBusy, + H_Aborted* =20 -H_PKS_UNWRAP_OBJECT is used to unwrap an object that was previously warapp= ed with +H_PKS_UNWRAP_OBJECT is used to unwrap an object that was previously wrappe= d with H_PKS_WRAP_OBJECT. =20 References diff --git a/MAINTAINERS b/MAINTAINERS index 24ca91ce5d86..7d92526fbf64 100644 --- a/MAINTAINERS +++ b/MAINTAINERS @@ -14479,7 +14479,7 @@ S: Supported F: include/keys/trusted_dcp.h F: security/keys/trusted-keys/trusted_dcp.c =20 -KEYS-TRUSTED-PLPKS +KEYS-TRUSTED-PKWM M: Srish Srinivasan M: Nayna Jain L: linux-integrity@vger.kernel.org --=20 2.52.0 From nobody Mon Sep 28 03:41:40 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B91B94A23; Thu, 27 Aug 2026 06:24:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787811852; cv=none; b=PRARDS0xQdUJVKYH3021Wv807A1klSdjEdVGnTrIeZIXUOiUPqm5ZJP8KZkZHH7bWqPe8rr8UBz5RqDGkWcXG9mBPSCAZL25AmD+5jDPuRfQgGRFBlmY0PYiedyvXvQV8VOkoC/SwLCzuseM/9+6Q8B9VKN0b6xNsC9ztszpqt0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787811852; c=relaxed/simple; bh=UNQTBMM6a6QBetZm4ob/Bh0kqoQYQz//MRyROTO8tqA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=bm03OdZG6ICFhPbr6SgY00uYFwaD7jl/rV1mP8+mmq+r+Q85gxAuPTbJsWda15C8/VSqkrzpA9LR2bIeg/RZS4w7FmDHSWl8BaIeFQTA1KA6VLfqVDV6ThXNjnMr52CpIGps4pMPdIee6HmCuqgia/GzXKqdDFuC6BUs1ajEGHw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=o93Dkd0w; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="o93Dkd0w" Received: from pps.filterd (m0356516.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67R3W8g41716516; Thu, 27 Aug 2026 06:23:55 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=fQoVl+C7ic20wFH9z MPu6rlMjpEI6FGSpNV3Fp23enI=; b=o93Dkd0wygQ/vdvc9gveJ0XcTAEc+zzVP V9GSCNTBQRUhSSiVcQai4M5Wmh0G8QyeellhhlhfKiWFG0YxwMy7NEWqeoreEPp6 QUsQrtTmq/STGbKFJ9wimSg3XPNHRrzWafGcunMybXsk1NY767K9b25wMzT31gbM QF0JopH6JIDtLm448fT93BNy9BqPZYyvfuaIaK2st3ilVqnHAhrRtgvS4u7etDVI +4M8iJQQ6Vrt7I8gGy3nTn7sV1lDUZwbfz0ud6MyC29MfbZwa71bwmoDDbuaw5Bg wQo3W33UkEWbM/ampFi+p0Adh0OfPrc9egX3XZb+FZD8t2M257HwQ== Received: from ppma23.wdc07v.mail.ibm.com (5d.69.3da9.ip4.static.sl-reverse.com [169.61.105.93]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4g716j3ner-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 27 Aug 2026 06:23:55 +0000 (GMT) Received: from pps.filterd (ppma23.wdc07v.mail.ibm.com [127.0.0.1]) by ppma23.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67R6BIpP032039; Thu, 27 Aug 2026 06:23:54 GMT Received: from smtprelay04.fra02v.mail.ibm.com ([9.218.2.228]) by ppma23.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4g7qkhedqe-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 27 Aug 2026 06:23:54 +0000 (GMT) Received: from smtpav01.fra02v.mail.ibm.com (smtpav01.fra02v.mail.ibm.com [10.20.54.100]) by smtprelay04.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67R6NolG30933564 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Thu, 27 Aug 2026 06:23:50 GMT Received: from smtpav01.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 4E36A20043; Thu, 27 Aug 2026 06:23:50 +0000 (GMT) Received: from smtpav01.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id CB9A020040; Thu, 27 Aug 2026 06:23:38 +0000 (GMT) Received: from li-fc74f8cc-3279-11b2-a85c-ef5828687581.ibm.com.com (unknown [9.76.202.253]) by smtpav01.fra02v.mail.ibm.com (Postfix) with ESMTP; Thu, 27 Aug 2026 06:23:38 +0000 (GMT) From: Srish Srinivasan To: linux-integrity@vger.kernel.org, keyrings@vger.kernel.org, linuxppc-dev@lists.ozlabs.org Cc: maddy@linux.ibm.com, mpe@ellerman.id.au, npiggin@gmail.com, christophe.leroy@csgroup.eu, James.Bottomley@HansenPartnership.com, jarkko@kernel.org, zohar@linux.ibm.com, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, nayna@linux.ibm.com, rnsastry@linux.ibm.com, ssrish@linux.ibm.com Subject: [PATCH 2/8] pseries/plpks: fix error handling in plpks_read_var() Date: Thu, 27 Aug 2026 11:53:02 +0530 Message-ID: <20260827062309.724808-3-ssrish@linux.ibm.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260827062309.724808-1-ssrish@linux.ibm.com> References: <20260827062309.724808-1-ssrish@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Reinject: loops=2 maxloops=12 X-Proofpoint-Spam-Info: AW1haW4tMjYwODI3MDA0OCBTYWx0ZWRfXxi8KTWZeoPgA /+QFjhToOCvAPKV5K/4jQ/QPXXYTjGgpg71fpzhIkpwCKTCLyyGoYjYzTFwl0mcooaJq2fR1hg4 I7vEE1JordkWRp6Ka3/6hv8hP6EoxsE= X-Proofpoint-GUID: 1f6GFyNTOWhnaMUBssfemC4Dp3oSCBh- X-Proofpoint-ORIG-GUID: yqtAB48qtqi5bYMVejs1M5ll1Kb3qjyx X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODI3MDA0OCBTYWx0ZWRfX1ab0m/hNCXjA 1XrIzEaYLV/AVQqhulmcfYxbDEepZaSLsBAorWrGB4C7otEWh/23s9GWgFHNUo85hQR1JKxaied LGcUvMkQA2j9nwuD4SUcOju+3vnn1TNbBbzVwXEOpGdMVddYFNjywaUWrMw1A2w7Y10kWzKwzsW xVH1jkeuFwnEWhYTzP3eCbLlZMu7m/6ZnmT/ij29mI74AUrkaxQE+6vLipHxG9HFR8ygXgrnDib r0lz7fhRhPlWBCMegaJZxbDdtJ23Csw/Z1Y0pdSmeA14o/JsmtyLpv28KwNrbcuqMqMAD3a8PDI g6GKH26cFfYJ8jhyv6rbtXCAyw7vrR9Ww525+iDcspswDdz4DbWogj2YGfbmKUR3N+m+YTL3Nqn 9zb+k/Wg39snVoD0BC19hLynDfl+MvS5b14bI8SjNus+OlAnM26Sxn+hITKkog8OoIiAiUN9UYM ILoi7xwtlwxAZtcIQKQ== X-Authority-Analysis: v=2.4 cv=H7brBeYi c=1 sm=1 tr=0 ts=6a8fd7fb cx=c_pps a=3Bg1Hr4SwmMryq2xdFQyZA==:117 a=3Bg1Hr4SwmMryq2xdFQyZA==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=Y2IxJ9c9Rs8Kov3niI8_:22 a=VnNF1IyMAAAA:8 a=oL9t_hqQ2ej-tATgvj4A:9 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-27_02,2026-08-26_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 suspectscore=0 malwarescore=0 lowpriorityscore=0 impostorscore=0 spamscore=0 bulkscore=0 adultscore=0 priorityscore=1501 clxscore=1015 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608270048 Content-Type: text/plain; charset="utf-8" When a plpks variable is initialized without a policy and used to read an object with the 'wrapping key' policy set, the hypervisor returns H_AUTHORITY along with the object's policy. However, plpks_read_var() at present treats this the same as any other H_AUTHORITY failure and returns an error without propagating the policy information to the caller. Distinguish this case from other H_AUTHORITY failures and only propagate policy information when it is returned alongside H_AUTHORITY by the hypervisor. Remove the explicit assignment of rc to zero in the case of H_SUCCESS as it is redundant. Also return -EPERM instead of -EINVAL when the 'wrapping key' policy bit is set by the caller, better reflecting the access restriction being enforced. Fixes: 2454a7af0f2a ("powerpc/pseries: define driver for Platform KeyStore") Fixes: 133aa79e211d ("pseries/plpks: add HCALLs for PowerVM Key Wrapping Mo= dule") Signed-off-by: Srish Srinivasan --- arch/powerpc/platforms/pseries/plpks.c | 13 ++++++------- 1 file changed, 6 insertions(+), 7 deletions(-) diff --git a/arch/powerpc/platforms/pseries/plpks.c b/arch/powerpc/platform= s/pseries/plpks.c index 23e4e2a922fc..7bd5c149dd09 100644 --- a/arch/powerpc/platforms/pseries/plpks.c +++ b/arch/powerpc/platforms/pseries/plpks.c @@ -826,7 +826,7 @@ static int plpks_read_var(u8 consumer, struct plpks_var= *var) return -EINVAL; =20 if (var->policy & PLPKS_WRAPPINGKEY) - return -EINVAL; + return -EPERM; =20 auth =3D construct_auth(consumer); if (IS_ERR(auth)) @@ -856,22 +856,21 @@ static int plpks_read_var(u8 consumer, struct plpks_v= ar *var) virt_to_phys(var->name), var->namelen, virt_to_phys(output), maxobjsize); =20 - if (rc !=3D H_SUCCESS) { rc =3D pseries_status_to_err(rc); - goto out_free_output; + if (rc !=3D -EPERM || !retbuf[1]) + goto out_free_output; + goto out_copy_policy; } =20 if (!var->data || var->datalen > retbuf[0]) var->datalen =3D retbuf[0]; =20 - var->policy =3D retbuf[1]; - if (var->data) memcpy(var->data, output, var->datalen); =20 - rc =3D 0; - +out_copy_policy: + var->policy =3D retbuf[1]; out_free_output: kfree(output); out_free_label: --=20 2.52.0 From nobody Mon Sep 28 03:41:40 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6C83A4A23; Thu, 27 Aug 2026 06:24:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787811863; cv=none; b=ukUqHGk8ElcHaCYK3AqSHmEWwSlvClHx1RpEwy5jcSo9vR8KMgU/E/Wee6uQTP2Is21eNGAY58gz2lSFQOHpbIt2AXR7Hp4fvWUJ7ryFdTSB5c9mgRINtO5FHhozN0UynpPnXtA6MfZpdtHQWIauEa8fVi5sN/6bM2FGXyigucM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787811863; c=relaxed/simple; bh=lTa4mgB5brMBY0wAGVoE6J60rIaur/dIbKYrOPNcUxs=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=GjolBlBphV7hSgvxFCh+sxG7nFAlBpfGY0gdMOvBSNp85NwOyODOKe6IoQ89+FS1Qx8Nt/VhEW1aG09e7S18ReOfsnKQMUmREYEQgPz/NbdtYVSqd0MG0Njo1aCdpzn94rpv7b8hnwxPM8T8EabX1U8eI3Kn+3ysBTnc0d3a3z8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=eTFA0Z5U; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="eTFA0Z5U" Received: from pps.filterd (m0353729.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67R3VdpT4139849; Thu, 27 Aug 2026 06:24:09 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=1La7cD0eYNIXwOype e2b6JhRgxYPQoqE00wTeUx+ofI=; b=eTFA0Z5UQzksliIfEp+vRHQW6okgKXSy6 x9UMo67tjKsprLtRDYBMqQGRVO02LWyxvMfBHjzrIzff6VnUMWjK4GKFbjdePz5N oBGMCqYWLyeeSAR3dRY0mWRJLUwhJ2y2JumrkLke1rf0eZiQyNJtiRRbTR4D8EDr mS/hPgORqsOna3Ebvh6gALIxdSdc4iD6xPWbzT9NkXG4a6/5mHoiOR5rScNQb4eU TSmxpSkjydbsVQ9QHbEDrGM3ofFH3j2OFk4okWgB0uTKNGjJUGpDIOVoIf3usbZ7 Q4jJuQvxsdVWH0yQPLD8H6NoF/5Z2E1sFNNZehGLSXLPxkBqYrsWw== Received: from ppma12.dal12v.mail.ibm.com (dc.9e.1632.ip4.static.sl-reverse.com [50.22.158.220]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4g73er3h7k-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 27 Aug 2026 06:24:08 +0000 (GMT) Received: from pps.filterd (ppma12.dal12v.mail.ibm.com [127.0.0.1]) by ppma12.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67R6BKS2000516; Thu, 27 Aug 2026 06:24:07 GMT Received: from smtprelay04.fra02v.mail.ibm.com ([9.218.2.228]) by ppma12.dal12v.mail.ibm.com (PPS) with ESMTPS id 4g7p3qeq23-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 27 Aug 2026 06:24:07 +0000 (GMT) Received: from smtpav01.fra02v.mail.ibm.com (smtpav01.fra02v.mail.ibm.com [10.20.54.100]) by smtprelay04.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67R6O4KP12059012 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Thu, 27 Aug 2026 06:24:04 GMT Received: from smtpav01.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id F25992004E; Thu, 27 Aug 2026 06:24:03 +0000 (GMT) Received: from smtpav01.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 9486020040; Thu, 27 Aug 2026 06:23:51 +0000 (GMT) Received: from li-fc74f8cc-3279-11b2-a85c-ef5828687581.ibm.com.com (unknown [9.76.202.253]) by smtpav01.fra02v.mail.ibm.com (Postfix) with ESMTP; Thu, 27 Aug 2026 06:23:50 +0000 (GMT) From: Srish Srinivasan To: linux-integrity@vger.kernel.org, keyrings@vger.kernel.org, linuxppc-dev@lists.ozlabs.org Cc: maddy@linux.ibm.com, mpe@ellerman.id.au, npiggin@gmail.com, christophe.leroy@csgroup.eu, James.Bottomley@HansenPartnership.com, jarkko@kernel.org, zohar@linux.ibm.com, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, nayna@linux.ibm.com, rnsastry@linux.ibm.com, ssrish@linux.ibm.com Subject: [PATCH 3/8] pseries/plpks: improve type consistency and parameter validation Date: Thu, 27 Aug 2026 11:53:03 +0530 Message-ID: <20260827062309.724808-4-ssrish@linux.ibm.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260827062309.724808-1-ssrish@linux.ibm.com> References: <20260827062309.724808-1-ssrish@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Reinject: loops=2 maxloops=12 X-Proofpoint-GUID: iiicmCC5pDUR9BOlYozzW-dnzi95fTbk X-Proofpoint-ORIG-GUID: cBB_1eG88gbzUY5EK5MQV0pNEoR6zCfH X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODI3MDA0OCBTYWx0ZWRfXyj0OBP2d6dmR Mvpc0p7VmD+jgDV4SOFaSocg5n0mM+2hFvSUUnp8x1qjs/PjX5F4i1+osIgaDFfl3ugDamxbYfn i5hoKQNKjZkJpVeQ5FWiLP+G0KOCXdKD1e9gvS3hazYv1OlMLR6veZlk9YUq1BlplF6rA8Qgt0i ahyZnAWg4yypQNfcAXhAata837Nt+9ibJwqp3s/LIWCO57ACMbIbc6W2Ma0Lk2B2tAeZ4VU2Jpj MtJcmT01aJrrZznvDC+plpD60Q9Ds0u5m9YNxDCBDiy5ZoqKCiJ2IG4wsDyUchKhUj7Wfys2bqV Bkzg93rxLW8rr4Oxx4b+rOomWm4HxvNYSJpEJBI/C9HzP8wCV/RCFB8P+eu4xcPrP5W6vAEf+gw 9f44azRv2qD11RjzJGDGpKpzCcnbIljSAPDmY85TaX3K5T63SqPDj4v5o+5eYYq1TnvY6r3LI/x OEu0JqaYpxKxIAgHClA== X-Authority-Analysis: v=2.4 cv=QsRuG1yd c=1 sm=1 tr=0 ts=6a8fd809 cx=c_pps a=bLidbwmWQ0KltjZqbj+ezA==:117 a=bLidbwmWQ0KltjZqbj+ezA==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=uAbxVGIbfxUO_5tXvNgY:22 a=VnNF1IyMAAAA:8 a=lkDOvFPUoNuE0DTt1acA:9 X-Proofpoint-Spam-Info: AW1haW4tMjYwODI3MDA0OCBTYWx0ZWRfX6sd2acnUrM64 Xh1vESIbDRzHKd4bK9DBNLF7DH4jK7ZTGRrEElN7S9m2c4P3dGnl2Iijl7VbckQR9IGum2gPrjT 2e/yvakiVJlLCvJuGMhiKqjPn3N3vDU= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-27_02,2026-08-26_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 malwarescore=0 adultscore=0 suspectscore=0 priorityscore=1501 impostorscore=0 spamscore=0 lowpriorityscore=0 clxscore=1015 bulkscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608270048 Content-Type: text/plain; charset="utf-8" Update plpks_wrap_object() and plpks_unwrap_object() to use u64 length parameters, matching the underlying hcall data types for consistency. Update the PKWM consumer, where these interfaces are used, accordingly. Add explicit casts when copying values from hcall return buffers into narrower data types. This makes the intended conversion clear and avoids implicit truncation in PLPKS hcall result handling. Also validate input pointers in plpks_signed_update_var() and plpks_read_var() before dereferencing them, addressing missing validation when reading and updating PLPKS objects. Fixes: 133aa79e211d ("pseries/plpks: add HCALLs for PowerVM Key Wrapping Mo= dule") Fixes: 2454a7af0f2a ("powerpc/pseries: define driver for Platform KeyStore") Fixes: 899d9b8fee66 ("powerpc/pseries: Implement signed update for PLPKS ob= jects") Fixes: c99fcb0d735b ("keys/trusted_keys: establish PKWM as a trusted source= ") Signed-off-by: Srish Srinivasan --- arch/powerpc/include/asm/plpks.h | 8 ++++---- arch/powerpc/platforms/pseries/plpks.c | 22 ++++++++++++++-------- security/keys/trusted-keys/trusted_pkwm.c | 4 ++-- 3 files changed, 20 insertions(+), 14 deletions(-) diff --git a/arch/powerpc/include/asm/plpks.h b/arch/powerpc/include/asm/pl= pks.h index e87f90e40d4e..8b2ffb27db5a 100644 --- a/arch/powerpc/include/asm/plpks.h +++ b/arch/powerpc/include/asm/plpks.h @@ -118,11 +118,11 @@ bool plpks_wrapping_is_supported(void); =20 int plpks_gen_wrapping_key(void); =20 -int plpks_wrap_object(u8 **input_buf, u32 input_len, u16 wrap_flags, - u8 **output_buf, u32 *output_len); +int plpks_wrap_object(u8 **input_buf, u64 input_len, u16 wrap_flags, + u8 **output_buf, u64 *output_len); =20 -int plpks_unwrap_object(u8 **input_buf, u32 input_len, - u8 **output_buf, u32 *output_len); +int plpks_unwrap_object(u8 **input_buf, u64 input_len, + u8 **output_buf, u64 *output_len); #else // CONFIG_PSERIES_PLPKS static inline bool plpks_is_available(void) { return false; } static inline u16 plpks_get_passwordlen(void) { BUILD_BUG(); } diff --git a/arch/powerpc/platforms/pseries/plpks.c b/arch/powerpc/platform= s/pseries/plpks.c index 7bd5c149dd09..45278c5a45c1 100644 --- a/arch/powerpc/platforms/pseries/plpks.c +++ b/arch/powerpc/platforms/pseries/plpks.c @@ -576,7 +576,7 @@ static int plpks_confirm_object_flushed(struct label *l= abel, virt_to_phys(auth), virt_to_phys(label), label->size); =20 - status =3D retbuf[0]; + status =3D (u8)retbuf[0]; if (rc) { timed_out =3D false; if (rc =3D=3D H_NOT_FOUND && status =3D=3D 1) @@ -637,6 +637,9 @@ int plpks_signed_update_var(struct plpks_var *var, u64 = flags) u64 continuetoken =3D 0; u64 timeout =3D 0; =20 + if (!var) + return -EINVAL; + if (!var->data || var->datalen <=3D 0 || var->namelen > PLPKS_MAX_NAME_SI= ZE) return -EINVAL; =20 @@ -822,6 +825,9 @@ static int plpks_read_var(u8 consumer, struct plpks_var= *var) u8 *output; int rc; =20 + if (!var) + return -EINVAL; + if (var->namelen > PLPKS_MAX_NAME_SIZE) return -EINVAL; =20 @@ -863,14 +869,14 @@ static int plpks_read_var(u8 consumer, struct plpks_v= ar *var) goto out_copy_policy; } =20 - if (!var->data || var->datalen > retbuf[0]) - var->datalen =3D retbuf[0]; + if (!var->data || var->datalen > (u16)retbuf[0]) + var->datalen =3D (u16)retbuf[0]; =20 if (var->data) memcpy(var->data, output, var->datalen); =20 out_copy_policy: - var->policy =3D retbuf[1]; + var->policy =3D (u32)retbuf[1]; out_free_output: kfree(output); out_free_label: @@ -1015,8 +1021,8 @@ EXPORT_SYMBOL_GPL(plpks_gen_wrapping_key); * * Returns: On success 0 is returned, a negative errno if not. */ -int plpks_wrap_object(u8 **input_buf, u32 input_len, u16 wrap_flags, - u8 **output_buf, u32 *output_len) +int plpks_wrap_object(u8 **input_buf, u64 input_len, u16 wrap_flags, + u8 **output_buf, u64 *output_len) { unsigned long retbuf[PLPAR_HCALL9_BUFSIZE] =3D { 0 }; struct plpks_auth *auth; @@ -1134,8 +1140,8 @@ EXPORT_SYMBOL_GPL(plpks_wrap_object); * * Returns: On success 0 is returned, a negative errno if not. */ -int plpks_unwrap_object(u8 **input_buf, u32 input_len, u8 **output_buf, - u32 *output_len) +int plpks_unwrap_object(u8 **input_buf, u64 input_len, u8 **output_buf, + u64 *output_len) { unsigned long retbuf[PLPAR_HCALL9_BUFSIZE] =3D { 0 }; struct plpks_auth *auth; diff --git a/security/keys/trusted-keys/trusted_pkwm.c b/security/keys/trus= ted-keys/trusted_pkwm.c index bf42c6679245..b6b5697426a8 100644 --- a/security/keys/trusted-keys/trusted_pkwm.c +++ b/security/keys/trusted-keys/trusted_pkwm.c @@ -83,7 +83,7 @@ static int trusted_pkwm_seal(struct trusted_key_payload *= p, char *datablob) struct trusted_key_options *options =3D NULL; struct trusted_pkwm_options *pkwm =3D NULL; u8 *input_buf, *output_buf; - u32 output_len, input_len; + u64 output_len, input_len; int rc; =20 options =3D trusted_options_alloc(); @@ -130,7 +130,7 @@ static int trusted_pkwm_seal(struct trusted_key_payload= *p, char *datablob) static int trusted_pkwm_unseal(struct trusted_key_payload *p, char *databl= ob) { u8 *input_buf, *output_buf; - u32 input_len, output_len; + u64 input_len, output_len; int rc; =20 input_len =3D p->blob_len; --=20 2.52.0 From nobody Mon Sep 28 03:41:40 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A97453630AD; Thu, 27 Aug 2026 06:24:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787811878; cv=none; b=hIWFvdmVLUUVNy72F0LZZX3Nbno00RNLgWj1yJU4uf2CWjBqZXPpdg/u5b6z1PXQbeyowmos0WhcqBfsCFJYnNH7Fj3dOgB8S0Yvi+bbb83+uKEMHLcc1vUpBTAscdVJoplMoYo0ZCcQD3gBWvuFRcduHqB1FPxxySNAfy0GNpY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787811878; c=relaxed/simple; bh=uNWf7wq9t1ywDzK6n70DLtcjQtPFNWfjzVSf07SHSmQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=EVF8o96BlZL9ldmQWdDolb5bB1PtcfNlKE4cyxznxROVB2Tj5wOwiB6cxNg0NK0oHop/Yp9yhh3pwHqK5x/HyULroaJz4NoSCmc7Hfg7ebKE+AP72mVAgnH6ztgjm1lE1jLGvU57LbG0x1va44GpqY6N4/0JAkRmv1AfKwlPcFo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=FEpsraUs; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="FEpsraUs" Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67R3Veof1823853; Thu, 27 Aug 2026 06:24:21 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=frp7duogNzNycmdIw xcJ+of17iEXKSGWdWO2svAK0g8=; b=FEpsraUsKUCpKC+1ff/AMkt7WoX/w/qFw sVlxElMFfHRV6qA3ZSpcmUKkw1NX3fhK3h3EPn7UkQYY6KO8C9WCQQie6/N1rfyb YF0EZMzamWi/VNRkzqoYSLqmgFVN/XSA2aMUTpIwonRnZ+2fjtxpIVoClAzTPs/K zC4JhQLI/01xJwTd3YnZIcWuevUbNpa8ahcOgD1b3Dddbyr2xGzK5HsIcsza5iif q+39xZSKfIJN6DZ87B2P7hQYlLEyDJGFdK2WJunqzNaOdQAdA9A/IzssGae64VQN +wC0YtvyP97NX5NNeQ+wI50CDrGovCrznuiHjSzInXD9JOrvcv2rA== Received: from ppma23.wdc07v.mail.ibm.com (5d.69.3da9.ip4.static.sl-reverse.com [169.61.105.93]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4g73g53mxv-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 27 Aug 2026 06:24:20 +0000 (GMT) Received: from pps.filterd (ppma23.wdc07v.mail.ibm.com [127.0.0.1]) by ppma23.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67R6BNYK032069; Thu, 27 Aug 2026 06:24:19 GMT Received: from smtprelay03.fra02v.mail.ibm.com ([9.218.2.224]) by ppma23.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4g7qkhedsa-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 27 Aug 2026 06:24:19 +0000 (GMT) Received: from smtpav01.fra02v.mail.ibm.com (smtpav01.fra02v.mail.ibm.com [10.20.54.100]) by smtprelay03.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67R6OFfc42074430 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Thu, 27 Aug 2026 06:24:15 GMT Received: from smtpav01.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id B67AD20043; Thu, 27 Aug 2026 06:24:15 +0000 (GMT) Received: from smtpav01.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 3479220040; Thu, 27 Aug 2026 06:24:05 +0000 (GMT) Received: from li-fc74f8cc-3279-11b2-a85c-ef5828687581.ibm.com.com (unknown [9.76.202.253]) by smtpav01.fra02v.mail.ibm.com (Postfix) with ESMTP; Thu, 27 Aug 2026 06:24:04 +0000 (GMT) From: Srish Srinivasan To: linux-integrity@vger.kernel.org, keyrings@vger.kernel.org, linuxppc-dev@lists.ozlabs.org Cc: maddy@linux.ibm.com, mpe@ellerman.id.au, npiggin@gmail.com, christophe.leroy@csgroup.eu, James.Bottomley@HansenPartnership.com, jarkko@kernel.org, zohar@linux.ibm.com, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, nayna@linux.ibm.com, rnsastry@linux.ibm.com, ssrish@linux.ibm.com Subject: [PATCH 4/8] pseries/plpks: rename the default wrapping key macro Date: Thu, 27 Aug 2026 11:53:04 +0530 Message-ID: <20260827062309.724808-5-ssrish@linux.ibm.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260827062309.724808-1-ssrish@linux.ibm.com> References: <20260827062309.724808-1-ssrish@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Reinject: loops=2 maxloops=12 X-Proofpoint-ORIG-GUID: eqf0fvjd09CrlrOV8uEVmZjn3iEbWov3 X-Proofpoint-Spam-Info: AW1haW4tMjYwODI3MDA0OCBTYWx0ZWRfX+Dk+4MOGguXT GabBh6cj3Al/QbSQ1En8v4GvpBze7wE0O019hT8gVNwbiGTS21JMwQmDjbnT76VfdwPhLeOaTac BezQ23Zm1V/BM3etInaAGlNEkuiCXu4= X-Proofpoint-GUID: -NLidSNWeEX8s94wb9J7NnslxfpolDZA X-Authority-Analysis: v=2.4 cv=JZyMa0KV c=1 sm=1 tr=0 ts=6a8fd815 cx=c_pps a=3Bg1Hr4SwmMryq2xdFQyZA==:117 a=3Bg1Hr4SwmMryq2xdFQyZA==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VnNF1IyMAAAA:8 a=ZsBnnucTmTjdUaLPtLYA:9 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODI3MDA0OCBTYWx0ZWRfX1nAuE9xCBME8 JU/FNbbT82yN5yVu+Lh4VPsBalIdtxCwthCErB5imE99AgQE9jEpWjueVIZP8DtvOtHHPB1tssO mL8tJgSItqTuF5RATGoZ/SmfHV35QnIr8WA8rXH8Fq6HMkZXvNdew+cUDkIOQOBtQYQ9vFmNfJH nrDtXwsTri5JoKdWq8nHu2bR5eD5czghMEHFdqpI0URsFDmO6fwZ9292C3kGZsjeq7VBGMKcaCu hGzq5Jic2NurdZDU0rIhvyuBLEUDOYPz1xDMqOK26WDgknR4omtBP4KbbzHtr03xfosEZGX5VGG bYLOYKAXBSgkZuxEqWrRTGml4jesTms5o33srfpjkr7NT3i6G5BheAvfBXuP9RyPcd0Aca+nMs6 xSmYDHraZkbP2BOekkZ9wWq1/PFelJh3h0lFhh0pvnbp/rrvudbSSC0dRne0fmf9LPZVJa/Wz/n 3bBgoyRrILC2PLlGquw== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-27_02,2026-08-26_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 clxscore=1015 adultscore=0 priorityscore=1501 impostorscore=0 malwarescore=0 bulkscore=0 lowpriorityscore=0 suspectscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608270048 Content-Type: text/plain; charset="utf-8" Rename PLPKS_WRAPKEY_NAME to PLPKS_DEFAULT_WRAPKEY_LABEL to clarify that the macro represents the default wrapping key label used by PKWM. Signed-off-by: Srish Srinivasan --- arch/powerpc/platforms/pseries/plpks.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/arch/powerpc/platforms/pseries/plpks.c b/arch/powerpc/platform= s/pseries/plpks.c index 45278c5a45c1..b553f7b130b6 100644 --- a/arch/powerpc/platforms/pseries/plpks.c +++ b/arch/powerpc/platforms/pseries/plpks.c @@ -10,7 +10,7 @@ #define pr_fmt(fmt) "plpks: " fmt =20 #define PLPKS_WRAPKEY_COMPONENT "PLPKSWR" -#define PLPKS_WRAPKEY_NAME "default-wrapping-key" +#define PLPKS_DEFAULT_WRAPKEY_LABEL "default-wrapping-key" =20 /* * To 4K align the {input, output} buffers to the {UN}WRAP H_CALLs @@ -938,7 +938,7 @@ int plpks_gen_wrapping_key(void) struct label *label; int rc =3D 0, pseries_status =3D 0; struct plpks_var var =3D { - .name =3D PLPKS_WRAPKEY_NAME, + .name =3D PLPKS_DEFAULT_WRAPKEY_LABEL, .namelen =3D strlen(var.name), .policy =3D PLPKS_WRAPPINGKEY, .os =3D PLPKS_VAR_LINUX, @@ -1033,7 +1033,7 @@ int plpks_wrap_object(u8 **input_buf, u64 input_len, = u16 wrap_flags, bool sb_audit_or_enforce_bit =3D wrap_flags & BIT(0); bool sb_enforce_bit =3D wrap_flags & BIT(1); struct plpks_var var =3D { - .name =3D PLPKS_WRAPKEY_NAME, + .name =3D PLPKS_DEFAULT_WRAPKEY_LABEL, .namelen =3D strlen(var.name), .os =3D PLPKS_VAR_LINUX, .component =3D PLPKS_WRAPKEY_COMPONENT --=20 2.52.0 From nobody Mon Sep 28 03:41:40 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DF2CE35C69F; Thu, 27 Aug 2026 06:24:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787811890; cv=none; b=hbhnHjZWDdxlkyW13TdLI7pkde4V26hqqAHqjNEzRG8WJqvd24FeUjTp+FTIOwB/GVQSdzAagqsnU5w5d9buVxYGBWXtyc74M0hQGEnQYMtH2PePxj7lGbnonJd1Ulv/ER68u6/L5C1jhae9t93y2A4E8W94Tk+fL2Y/6UYoF5w= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787811890; c=relaxed/simple; bh=9L8rmOpeSKap62LUW4zSsvE84i9y85+ze77IM79wJeI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Lzb600MVuPpFNxLi7tqwmuyngZcOFll/6dnjAnVYsU8Q5YH3cRGSF+fJAiGAAHsn/0KqfqqI2huhRXfE8rX517rdxUvlwZ6jo0b0L4I2dDHbDnfDwMx9CPXS5wI08RkxLGOqTvN64T20nzgGNbHLEIXOiV6wsSo++cis2oPfKS4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=HKqd375+; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="HKqd375+" Received: from pps.filterd (m0356516.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67R3Vklw1715331; Thu, 27 Aug 2026 06:24:34 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=k/H8sfpIq20rBYe8K YZJHelmYkcLEhaFVHitAkdt8LM=; b=HKqd375+Af/1Qhi87QWJRSBMhCh144MkZ OBYfJsMkB3i359tZcBoQMgdr+0FHMbun44wkhctBVhgv2d1t3z31wg096hKiLNB4 z6DEeT7r7wDnmo6QM5vYG5I6UUq+gOy08EjqIKga+pdzSpI/DEVNjjLIzscmhDdl L6Sotr7GIIsGEzNEfDe/xxcEuIku/Piw18YUwq34+4CkXEB2lbib4GaYUacOOyxr tTljqW0dnfbFoR/knQbuw7lngDZOuYZ80NKssuF9Tz7El1qrMh15wuKejgW6Q/dN 80gAH5KVVQ2uZ3hShSIjRAtDvDSU8Syp9i3I1xtRtbbDwuk8M3dbQ== Received: from ppma13.dal12v.mail.ibm.com (dd.9e.1632.ip4.static.sl-reverse.com [50.22.158.221]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4g716j3nhd-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 27 Aug 2026 06:24:33 +0000 (GMT) Received: from pps.filterd (ppma13.dal12v.mail.ibm.com [127.0.0.1]) by ppma13.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67R6BF1I013824; Thu, 27 Aug 2026 06:24:32 GMT Received: from smtprelay02.fra02v.mail.ibm.com ([9.218.2.226]) by ppma13.dal12v.mail.ibm.com (PPS) with ESMTPS id 4g7ragpb1x-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 27 Aug 2026 06:24:32 +0000 (GMT) Received: from smtpav01.fra02v.mail.ibm.com (smtpav01.fra02v.mail.ibm.com [10.20.54.100]) by smtprelay02.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67R6OSXL38928702 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Thu, 27 Aug 2026 06:24:28 GMT Received: from smtpav01.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id CFACF20043; Thu, 27 Aug 2026 06:24:28 +0000 (GMT) Received: from smtpav01.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 267EC20040; Thu, 27 Aug 2026 06:24:17 +0000 (GMT) Received: from li-fc74f8cc-3279-11b2-a85c-ef5828687581.ibm.com.com (unknown [9.76.202.253]) by smtpav01.fra02v.mail.ibm.com (Postfix) with ESMTP; Thu, 27 Aug 2026 06:24:16 +0000 (GMT) From: Srish Srinivasan To: linux-integrity@vger.kernel.org, keyrings@vger.kernel.org, linuxppc-dev@lists.ozlabs.org Cc: maddy@linux.ibm.com, mpe@ellerman.id.au, npiggin@gmail.com, christophe.leroy@csgroup.eu, James.Bottomley@HansenPartnership.com, jarkko@kernel.org, zohar@linux.ibm.com, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, nayna@linux.ibm.com, rnsastry@linux.ibm.com, ssrish@linux.ibm.com Subject: [PATCH 5/8] pseries/plpks: hide wrapping_features when unsupported Date: Thu, 27 Aug 2026 11:53:05 +0530 Message-ID: <20260827062309.724808-6-ssrish@linux.ibm.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260827062309.724808-1-ssrish@linux.ibm.com> References: <20260827062309.724808-1-ssrish@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Reinject: loops=2 maxloops=12 X-Proofpoint-Spam-Info: AW1haW4tMjYwODI3MDA0OCBTYWx0ZWRfX0uOi/RcrTijL oC9eUoQjvfJAb4snONYEY8uTbNDw/y4HWYQ0nDDaW4MCUP31iojddeNVsxxDpwCUVfCVQlvY05L doty31Y6svRmmq4QaW/3mkLKzd/PEAM= X-Proofpoint-GUID: 0sJKQR3k2h17EYTSSyCOZ1QNbnfu--X- X-Proofpoint-ORIG-GUID: 999WyhPe0QqdHMdlrRsZ6ViMpxpevS2a X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODI3MDA0OCBTYWx0ZWRfXxpIKykJreSHs vNDWI0znHlcu0OsyomSVBVCr4VI4BYlxEH66gXoHZlUMiBf1SnLkrih7oJq039RxYLmdOmyqU8F JGZhIxHj8D3kJ1ZR8N77a9nbjaTD2NPEfbWYTvdLDMh3VejG0zEQryBU2WmItPTL9Jad2MqrNem DdyRBEQPp8h3WmGRu2JzohV4HMrw7CYpwhhztEgoduWL3z1TE0gCH2dA5jbbVUKBqoC0bl9P73A 1LLtUyf8p0KO0o0uUWb9mPFbfrVoklPwVpO4iqrqfkb0yoeKVVET8VfRkV6ce/uz0KzATY7fXFN CTH9ycYxDyjcoGyJThAzHb/vUfYYct4SCZEhsbL+jo80kGG8WxHqyM3jz+F+w1Qf8zLa8Ve1CRo aFGlX7JIt6ASqAzTEWS9pPnRCJrXfFKJ8LY6KvdXKfY6ySIHBSBH1NCv090lmDCQAzwM0952Ysb 6/QNPHxQs6PjpA2o/AA== X-Authority-Analysis: v=2.4 cv=H7brBeYi c=1 sm=1 tr=0 ts=6a8fd822 cx=c_pps a=AfN7/Ok6k8XGzOShvHwTGQ==:117 a=AfN7/Ok6k8XGzOShvHwTGQ==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=Y2IxJ9c9Rs8Kov3niI8_:22 a=VnNF1IyMAAAA:8 a=Lnrgi2ogIeW2OlIaXxgA:9 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-27_02,2026-08-26_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 suspectscore=0 malwarescore=0 lowpriorityscore=0 impostorscore=0 spamscore=0 bulkscore=0 adultscore=0 priorityscore=1501 clxscore=1015 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608270048 Content-Type: text/plain; charset="utf-8" The PLPKS wrapping features config is only valid on systems that support the "Key Wrapping" feature. Currently the config is always exposed, even when the feature is unavailable. Add is_visible attribute_group callback to suppress the wrapping features sysfs attribute when the "Key Wrapping" feature is not supported. Declare the attribute group static const, as it is not modified after initialization. Fixes: 447eb1d5ef00 ("pseries/plpks: expose PowerVM wrapping features via t= he sysfs") Signed-off-by: Srish Srinivasan --- arch/powerpc/platforms/pseries/plpks-sysfs.c | 20 +++++++++++++++----- 1 file changed, 15 insertions(+), 5 deletions(-) diff --git a/arch/powerpc/platforms/pseries/plpks-sysfs.c b/arch/powerpc/pl= atforms/pseries/plpks-sysfs.c index c2ebcbb41ae3..f2436229f323 100644 --- a/arch/powerpc/platforms/pseries/plpks-sysfs.c +++ b/arch/powerpc/platforms/pseries/plpks-sysfs.c @@ -45,6 +45,16 @@ static const struct attribute *config_attrs[] =3D { =20 static struct kobject *plpks_kobj, *plpks_config_kobj; =20 +static umode_t plpks_config_attr_is_visible(struct kobject *kobj, + struct attribute *attr, int n) +{ + if (attr =3D=3D &attr_wrapping_features.attr && + !plpks_wrapping_is_supported()) + return 0; + + return attr->mode; +} + int plpks_config_create_softlink(struct kobject *from) { if (!plpks_config_kobj) @@ -52,13 +62,13 @@ int plpks_config_create_softlink(struct kobject *from) return sysfs_create_link(from, plpks_config_kobj, "config"); } =20 +static const struct attribute_group config_group =3D { + .attrs =3D (struct attribute **)config_attrs, + .is_visible =3D plpks_config_attr_is_visible, +}; + static __init int plpks_sysfs_config(struct kobject *kobj) { - struct attribute_group config_group =3D { - .name =3D NULL, - .attrs =3D (struct attribute **)config_attrs, - }; - return sysfs_create_group(kobj, &config_group); } =20 --=20 2.52.0 From nobody Mon Sep 28 03:41:40 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C93ED30F543; Thu, 27 Aug 2026 06:25:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787811906; cv=none; b=GxSTpEQAStxt5IECxz0aGSmUBhq551rk9Am7kf8ur/F4LjKZ1D+vuCbPhaN/y9PCLvzL6tXDdxIsdiZtY6Vc518lmxAy81oLgkdDn2UeQJ3JsrBiZOjf1q+kSRjkal4coOoAVfpNQR8jFhy5EOtetBwbf5iZG0UsrEgTQ51cvMw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787811906; c=relaxed/simple; bh=iDq6EJzuqrlglgAd9Bk6wZouBfXyePw+4QFSIQrKDtw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=NGagmfLX97BL4seSgMwPokX2r2CnkRxfEyaJJa09nqfK6WEJXWxJJ2MR8pdGE0jYMWP155V7NZzsAbQghC9KxiNKkp6EK0+5wLsKo4eXphOF+tduqfvbsuu6d6D9byszG6J7UDG5+qcr94+UQ7MtQybwCdraFabDt2Co9OdzTAQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=P8UreXTp; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="P8UreXTp" Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67R3VYPj1823501; Thu, 27 Aug 2026 06:24:51 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=y7mIKa8SMqewT9qKn kzb55opk81UwrGOYbwGVmOwq3w=; b=P8UreXTpcZgn2ZYpFPwxzgaKT8irAqDH4 qCJjHx7xK478pvBaDvl0z5NS+ZJZlMOgPI6zhNDCUaVBqd3rin12uWI9WjRoB55w 7UIpIXDCSC4NZAPQI3eDoCNO9fUZGYKC1SeV/4tIHYv1BgDl2ssscQDcEatTL19Q BWr17Jc///+PE4qEhRaqzbvk1d8eNJWe+Nd1lNEM3bGGhZsue9m5hNBOC5B4vJUl hX/n+9Cxa64cod9Gmyt/HOOz0Jgb07vTfEHYayItaknVlGixzgdYQZ4jLIPHa76b TiAzpUm1Z8Cm0NLUn387bDlG842bLts9rTgD8yF40R9anY/00f0YA== Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4g73g53n0y-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 27 Aug 2026 06:24:50 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67R6BLjG025475; Thu, 27 Aug 2026 06:24:49 GMT Received: from smtprelay07.fra02v.mail.ibm.com ([9.218.2.229]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4g7q3k6fqk-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 27 Aug 2026 06:24:49 +0000 (GMT) Received: from smtpav01.fra02v.mail.ibm.com (smtpav01.fra02v.mail.ibm.com [10.20.54.100]) by smtprelay07.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67R6Ojfi28508506 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Thu, 27 Aug 2026 06:24:45 GMT Received: from smtpav01.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 3317320043; Thu, 27 Aug 2026 06:24:45 +0000 (GMT) Received: from smtpav01.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 2F2EB20040; Thu, 27 Aug 2026 06:24:30 +0000 (GMT) Received: from li-fc74f8cc-3279-11b2-a85c-ef5828687581.ibm.com.com (unknown [9.76.202.253]) by smtpav01.fra02v.mail.ibm.com (Postfix) with ESMTP; Thu, 27 Aug 2026 06:24:29 +0000 (GMT) From: Srish Srinivasan To: linux-integrity@vger.kernel.org, keyrings@vger.kernel.org, linuxppc-dev@lists.ozlabs.org Cc: maddy@linux.ibm.com, mpe@ellerman.id.au, npiggin@gmail.com, christophe.leroy@csgroup.eu, James.Bottomley@HansenPartnership.com, jarkko@kernel.org, zohar@linux.ibm.com, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, nayna@linux.ibm.com, rnsastry@linux.ibm.com, ssrish@linux.ibm.com Subject: [PATCH 6/8] pseries/plpks: add HCALLs for PKWM wrapping key life cycle management Date: Thu, 27 Aug 2026 11:53:06 +0530 Message-ID: <20260827062309.724808-7-ssrish@linux.ibm.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260827062309.724808-1-ssrish@linux.ibm.com> References: <20260827062309.724808-1-ssrish@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Reinject: loops=2 maxloops=12 X-Proofpoint-ORIG-GUID: AAB6je96kGilHTWyG76e6zvLcagZrVwv X-Proofpoint-Spam-Info: AW1haW4tMjYwODI3MDA0OCBTYWx0ZWRfX4RMNumew6K8Z mRwvxLx9Wr3BTBpP9sUaXLp6bKz25Te9OzFEK9eV1j4j6iBUIaFXu9XigZ2fp6ZPM4WG9zA0Ajt Mc54/RHVKysikghedSy1OfavnSCzv9Y= X-Proofpoint-GUID: itOrUxSkJf3GZULq1JA4hklpEoXwrihn X-Authority-Analysis: v=2.4 cv=JZyMa0KV c=1 sm=1 tr=0 ts=6a8fd833 cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VnNF1IyMAAAA:8 a=lWQKvBrNlG38MY5WF7oA:9 a=4Rbdz_3SWuTzBNBt:21 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODI3MDA0OCBTYWx0ZWRfX1wO/pDYEz8jO cKxAQOHEIn5+z8t+lN4/1VqEP2JVSSqTMOSTFD3xZ/X1M39tgfyooldXRJCLhhZnyKqmB2ELj/y I9oa6deGUo4ChcQB0Jj4yWdGNZ1tGVyl+Tey/v9BgbLP0cz49+7DY+740CLAnBhdZa4J8jzEdRF 7vbLa0tBzbe9OSpoIZpBnxyqynIl8i/5KBlnf8UCwqd7haERh8irKFo/hVmmDi6B3lZj7r7CdF1 p71bm/erkle1q143CUNnu1J/0X2U4JTK3/8M4s5jiuBGgIkoWO2wc8QyJeh5A7H2koYan7NZ8Dl u1bRaXLzxOGyhHM5iaQue+XbBlThuIdwxe7x4KIFmFX9NCL2qSZ4I/O5G4Gadr8E27ZZQGnXHtt hGqDMzqWKEZlLWoRUfsEoq+y2AJh21HT+P2/yyJIZndQvsV40WpdfxMEMNq7TMIRb/s/baCZzOy eGuiPGhHwtdTb79xC2Q== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-27_02,2026-08-26_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 clxscore=1015 adultscore=0 priorityscore=1501 impostorscore=0 malwarescore=0 bulkscore=0 lowpriorityscore=0 suspectscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608270048 Content-Type: text/plain; charset="utf-8" The PKWM trusted source uses a single wrapping key per LPAR, created only once during trust source initialization. All the wrap and unwrap requests are bound to this default wrapping key. Implement H_PKS_REVOKE_OBJECT, H_PKS_UNREVOKE_OBJECT, and H_PKS_GET_OBJECTLABELS HCALLs to enable support for revoking and unrevoking PKWM wrapping keys, and for retrieving wrapping key labels. The label retrieval operation (H_PKS_GET_OBJECTLABELS) applies to all wrapping keys including the default one, while the life cycle operations (H_PKS_REVOKE_OBJECT/H_PKS_UNREVOKE_OBJECT) apply only to user-created wrapping keys. Signed-off-by: Srish Srinivasan --- Documentation/arch/powerpc/papr_hcalls.rst | 33 ++ arch/powerpc/include/asm/hvcall.h | 5 +- arch/powerpc/include/asm/plpks.h | 15 + arch/powerpc/platforms/pseries/plpks.c | 475 ++++++++++++++++++++- 4 files changed, 524 insertions(+), 4 deletions(-) diff --git a/Documentation/arch/powerpc/papr_hcalls.rst b/Documentation/arc= h/powerpc/papr_hcalls.rst index 44c9c8b32ae3..3455b403a048 100644 --- a/Documentation/arch/powerpc/papr_hcalls.rst +++ b/Documentation/arch/powerpc/papr_hcalls.rst @@ -343,6 +343,39 @@ is returned to the caller. H_PKS_UNWRAP_OBJECT is used to unwrap an object that was previously wrappe= d with H_PKS_WRAP_OBJECT. =20 +**H_PKS_REVOKE_OBJECT** + +| Input: authorization, objectlabel, objectlabellen, flags +| Out: *object policy* +| Return Value: *H_Success, H_Function, H_State, H_Parameter, H_P2, H_P3, = H_P4, + H_Authority, H_Not_Found, H_Busy, H_Aborted* + +H_PKS_REVOKE_OBJECT is used to revoke an object in Platform Keystore. + + +**H_PKS_UNREVOKE_OBJECT** + +| Input: authorization, objectlabel, objectlabellen, flags +| Out: *object policy* +| Return Value: *H_Success, H_Function, H_State, H_Parameter, H_P2, H_P3, = H_P4, + H_Authority, H_Not_Found, H_Busy, H_Aborted* + +H_PKS_UNREVOKE_OBJECT is used to unrevoke an object that was previously re= voked +with H_PKS_REVOKE_OBJECT in Platform Keystore. + + +**H_PKS_GET_OBJECTLABELS** + +| Input: authorization, continueToken, out, outlen +| Out: *continue-token, number of object labels in the returned list, obje= ct + label list* +| Return Value: *H_Success, H_Function, H_State, H_Parameter, H_P2, H_P3, = H_P4, + H_Authority, H_Busy, H_Aborted, H_Continue* + +H_PKS_GET_OBJECTLABELS is used to retrieve a list of object labels owned b= y the +specified consumer. + + References =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D .. [1] "Power Architecture Platform Reference" diff --git a/arch/powerpc/include/asm/hvcall.h b/arch/powerpc/include/asm/h= vcall.h index dff90a7d7f70..4d4c2ce1dd87 100644 --- a/arch/powerpc/include/asm/hvcall.h +++ b/arch/powerpc/include/asm/hvcall.h @@ -340,6 +340,7 @@ #define H_PKS_GET_CONFIG 0x41C #define H_PKS_SET_PASSWORD 0x420 #define H_PKS_GEN_PASSWORD 0x424 +#define H_PKS_GET_OBJECTLABELS 0x428 #define H_PKS_WRITE_OBJECT 0x42C #define H_PKS_GEN_KEY 0x430 #define H_PKS_READ_OBJECT 0x434 @@ -362,7 +363,9 @@ #define H_GUEST_DELETE 0x488 #define H_PKS_WRAP_OBJECT 0x490 #define H_PKS_UNWRAP_OBJECT 0x494 -#define MAX_HCALL_OPCODE H_PKS_UNWRAP_OBJECT +#define H_PKS_REVOKE_OBJECT 0x4AC +#define H_PKS_UNREVOKE_OBJECT 0x4B0 +#define MAX_HCALL_OPCODE H_PKS_UNREVOKE_OBJECT =20 /* Scope args for H_SCM_UNBIND_ALL */ #define H_UNBIND_SCOPE_ALL (0x1) diff --git a/arch/powerpc/include/asm/plpks.h b/arch/powerpc/include/asm/pl= pks.h index 8b2ffb27db5a..c39d1f07017e 100644 --- a/arch/powerpc/include/asm/plpks.h +++ b/arch/powerpc/include/asm/plpks.h @@ -25,6 +25,7 @@ #define PLPKS_SIGNEDUPDATE PPC_BIT32(7) // Object can only be modified by = signed updates #define PLPKS_WRAPPINGKEY PPC_BIT32(8) // Object contains a wrapping key #define PLPKS_HVPROVISIONED PPC_BIT32(28) // Hypervisor has provisioned th= is object +#define PLPKS_REVOKED PPC_BIT32(30) // Object is revoked =20 // Signature algorithm flags from signed_update_algorithms #define PLPKS_ALG_RSA2048 PPC_BIT(0) @@ -123,6 +124,20 @@ int plpks_wrap_object(u8 **input_buf, u64 input_len, u= 16 wrap_flags, =20 int plpks_unwrap_object(u8 **input_buf, u64 input_len, u8 **output_buf, u64 *output_len); + +int plpks_revoke_wrapping_key(struct plpks_var *var); + +int plpks_unrevoke_wrapping_key(struct plpks_var *var); + +int plpks_del_wrapping_key(struct plpks_var *var); + +int plpks_is_wrapping_key_revoked(struct plpks_var *var); + +int plpks_get_object_labels(u8 **output_buf, u64 *output_len, + char *comp_prefix); + +bool plpks_revoke_is_supported(void); + #else // CONFIG_PSERIES_PLPKS static inline bool plpks_is_available(void) { return false; } static inline u16 plpks_get_passwordlen(void) { BUILD_BUG(); } diff --git a/arch/powerpc/platforms/pseries/plpks.c b/arch/powerpc/platform= s/pseries/plpks.c index b553f7b130b6..48a86497eb2b 100644 --- a/arch/powerpc/platforms/pseries/plpks.c +++ b/arch/powerpc/platforms/pseries/plpks.c @@ -23,8 +23,17 @@ */ #define PLPKS_WRAPPING_BUF_DIFF 1024 =20 +/* + * Maximum length for the buffer to store the retrieved object labels + */ +#define PLPKS_OBJLABEL_BUF_MAX 2550 + +#define PLPKS_OBJLABEL_LEN_FIELD_SIZE 2 +#define PLPKS_OBJLABEL_PREFIX_LEN 8 + #define PLPKS_WRAP_INTERFACE_BIT 3 #define PLPKS_WRAPPING_KEY_LENGTH 32 +#define PLPKS_REVOKE_INTERFACE_BIT 4 =20 #define WRAPFLAG_BE_BIT_SET(be_bit) \ BIT_ULL(63 - (be_bit)) @@ -46,6 +55,7 @@ #include #include #include +#include #include #include #include @@ -67,6 +77,7 @@ static u32 maxlargeobjectsize; static u64 signedupdatealgorithms; static u64 wrappingfeatures; static bool wrapsupport; +static bool revokesupport; =20 struct plpks_auth { u8 version; @@ -146,6 +157,9 @@ static int pseries_status_to_err(int rc) case H_ABORTED: err =3D -EIO; break; + case H_CONTINUE: + err =3D -EAGAIN; + break; default: err =3D -EINVAL; } @@ -312,6 +326,7 @@ static int _plpks_get_config(void) signedupdatealgorithms =3D be64_to_cpu(config->signedupdatealgorithms); wrappingfeatures =3D be64_to_cpu(config->wrappingfeatures); wrapsupport =3D config->flags & PPC_BIT8(PLPKS_WRAP_INTERFACE_BIT); + revokesupport =3D config->flags & PPC_BIT8(PLPKS_REVOKE_INTERFACE_BIT); =20 // Validate that the numbers we get back match the requirements of the sp= ec if (maxpwsize < 32) { @@ -831,9 +846,6 @@ static int plpks_read_var(u8 consumer, struct plpks_var= *var) if (var->namelen > PLPKS_MAX_NAME_SIZE) return -EINVAL; =20 - if (var->policy & PLPKS_WRAPPINGKEY) - return -EPERM; - auth =3D construct_auth(consumer); if (IS_ERR(auth)) return PTR_ERR(auth); @@ -903,6 +915,23 @@ bool plpks_wrapping_is_supported(void) } EXPORT_SYMBOL_GPL(plpks_wrapping_is_supported); =20 +/** + * plpks_revoke_is_supported() - Get the H_PKS_REVOKE_OBJECT and + * H_PKS_UNREVOKE_OBJECT interfaces availability status for the LPAR. + * + * Successful execution of the H_PKS_GET_CONFIG HCALL during initialization + * sets bit 4 of the flags variable in the PLPKS config structure if the + * H_PKS_REVOKE_OBJECT and H_PKS_UNREVOKE_OBJECT interfaces are supported. + * + * Returns: true if the H_PKS_REVOKE_OBJECT and H_PKS_UNREVOKE_OBJECT inte= rfaces + * are supported, false if not. + */ +bool plpks_revoke_is_supported(void) +{ + return revokesupport; +} +EXPORT_SYMBOL_GPL(plpks_revoke_is_supported); + /** * plpks_gen_wrapping_key() - Generate a new random key with the 'wrapping= key' * policy set. @@ -1189,6 +1218,446 @@ int plpks_unwrap_object(u8 **input_buf, u64 input_l= en, u8 **output_buf, } EXPORT_SYMBOL_GPL(plpks_unwrap_object); =20 +/** + * plpks_revoke_wrapping_key() - Revoke a wrapping key stored in the PLPKS. + * @var: variable representing the wrapping key to be revoked + * + * The H_PKS_REVOKE_OBJECT HCALL revokes an object stored in the PLPKS. + * + * Possible reasons for the returned errno values: + * + * -ENXIO if PLPKS is not supported + * -EIO if PLPKS access is blocked due to the LPAR's state + * if PLPKS modification is blocked due to the LPAR's state + * if an error occurred while processing the request + * -EINVAL if invalid authorization parameter + * if invalid wrapping key label parameter + * if invalid wrapping key label length parameter + * if invalid or unsupported wrapping key revoking flags + * -EPERM if access is denied + * -ENOENT if the requested wrapping key was not found + * -EBUSY if unable to handle the request or long running operation + * initiated, retry later. + * + * Returns: On success 0 is returned, a negative errno if not. + */ +int plpks_revoke_wrapping_key(struct plpks_var *var) +{ + unsigned long retbuf[PLPAR_HCALL_BUFSIZE] =3D { 0 }; + struct plpks_auth *auth =3D NULL; + struct label *label; + u64 objrevokeflags =3D 0; + int rc =3D 0, pseries_status =3D 0; + + if (!var->name || !*var->name) { + pr_err("key label cannot be NULL/empty\n"); + rc =3D -EINVAL; + goto out; + } + + if (!strcmp((char *)var->name, PLPKS_DEFAULT_WRAPKEY_LABEL)) { + pr_warn("the default wrapping key must not be revoked!\n"); + rc =3D -EPERM; + goto out; + } + + auth =3D construct_auth(PLPKS_OS_OWNER); + if (IS_ERR(auth)) { + rc =3D PTR_ERR(auth); + goto out; + } + + label =3D construct_label(var->component, var->os, var->name, + var->namelen); + if (IS_ERR(label)) { + rc =3D PTR_ERR(label); + goto out; + } + + rc =3D plpar_hcall(H_PKS_REVOKE_OBJECT, retbuf, virt_to_phys(auth), + virt_to_phys(label), label->size, objrevokeflags); + + pseries_status =3D rc; + rc =3D pseries_status_to_err(rc); + + if (rc) { + pr_err("H_PKS_REVOKE_OBJECT failed. pseries_status=3D%d, rc=3D%d\n", + pseries_status, rc); + } + + if (!rc || (rc =3D=3D -EPERM && retbuf[0])) + var->policy =3D (u32)retbuf[0]; + + kfree(label); +out: + kfree(auth); + return rc; +} +EXPORT_SYMBOL_GPL(plpks_revoke_wrapping_key); + +/** + * plpks_unrevoke_wrapping_key() - Unrevoke a revoked wrapping key in the = PLPKS. + * @var: variable representing the revoked wrapping key to be unrevoked + * + * The H_PKS_UNREVOKE_OBJECT HCALL unrevokes a revoked object stored in the + * PLPKS. + * + * Possible reasons for the returned errno values: + * + * -ENXIO if PLPKS is not supported + * -EIO if PLPKS access is blocked due to the LPAR's state + * if PLPKS modification is blocked due to the LPAR's state + * if an error occurred while processing the request + * -EINVAL if invalid authorization parameter + * if invalid object label parameter + * if invalid object label length parameter + * if invalid or unsupported object revoking flags + * -EPERM if access is denied + * -ENOENT if the requested object was not found + * -EBUSY if unable to handle the request or long running operation + * initiated, retry later. + * + * Returns: On success 0 is returned, a negative errno if not. + */ +int plpks_unrevoke_wrapping_key(struct plpks_var *var) +{ + unsigned long retbuf[PLPAR_HCALL_BUFSIZE] =3D { 0 }; + struct plpks_auth *auth =3D NULL; + struct label *label; + u64 objrevokeflags =3D 0; + int rc =3D 0, pseries_status =3D 0; + + if (!var->name || !*var->name) { + pr_err("key label cannot be NULL/empty\n"); + rc =3D -EINVAL; + goto out; + } + + if (!strcmp((char *)var->name, PLPKS_DEFAULT_WRAPKEY_LABEL)) { + pr_warn("unrevoke on the default wrapping key is invalid\n"); + rc =3D -EINVAL; + goto out; + } + + auth =3D construct_auth(PLPKS_OS_OWNER); + if (IS_ERR(auth)) { + rc =3D PTR_ERR(auth); + goto out; + } + + label =3D construct_label(var->component, var->os, var->name, + var->namelen); + if (IS_ERR(label)) { + rc =3D PTR_ERR(label); + goto out; + } + + rc =3D plpar_hcall(H_PKS_UNREVOKE_OBJECT, retbuf, + virt_to_phys(auth), virt_to_phys(label), + label->size, objrevokeflags); + + pseries_status =3D rc; + rc =3D pseries_status_to_err(rc); + + if (rc) + pr_err("H_PKS_UNREVOKE_OBJECT failed. pseries_status=3D%d, rc=3D%d\n", + pseries_status, rc); + + if (!rc || (rc =3D=3D -EPERM && retbuf[0])) + var->policy =3D (u32)retbuf[0]; + + kfree(label); +out: + kfree(auth); + return rc; +} +EXPORT_SYMBOL_GPL(plpks_unrevoke_wrapping_key); + +/** + * plpks_is_wrapping_key_revoked() - Check if a given wrapping key has been + * revoked. + * @var: variable representing the wrapping key to be checked + * + * When the H_PKS_READ_OBJECT HCALL tries reads an object that exists but = when + * the policy is not met, it returns H_AUTHORITY along with the 4-byte obj= ect + * policy. This policy is inspected to determine if the object has been re= voked. + * + * Possible reasons for the returned errno values: + * + * -ENXIO if PLPKS is not supported + * -EIO if PLPKS access is blocked due to the LPAR's state + * if an error occurred while processing the request + * -EINVAL if invalid authorization parameter + * if invalid object label parameter + * if invalid object label len parameter + * if invalid output data parameter + * if invalid output data len parameter + * -EPERM if access is denied + * -ENOENT if the requested object was not found + * -EFBIG if the requested object couldn't be + * stored in the buffer provided + * -EBUSY if unable to handle the request + * + * Returns: 1 is returned if the wrapping key has been revoked. 0 is retur= ned if + * the wrapping key has not been revoked. Otherwise, a negative errno + * is returned. + */ +int plpks_is_wrapping_key_revoked(struct plpks_var *var) +{ + int rc; + + if (!var->name || !*var->name) { + pr_err("key label cannot be NULL/empty\n"); + rc =3D -EINVAL; + goto out; + } + + rc =3D plpks_read_var(PLPKS_OS_OWNER, var); + if (!rc) { + pr_err("unexpected successful read of wrapping key\n"); + rc =3D -EIO; + } else if (rc =3D=3D -EPERM) { + if (var->policy & PLPKS_WRAPPINGKEY) { + if (var->policy & PLPKS_REVOKED) + rc =3D 1; + else + rc =3D 0; + } + } + +out: + return rc; +} +EXPORT_SYMBOL_GPL(plpks_is_wrapping_key_revoked); + +/** + * plpks_del_wrapping_key() - Delete a wrapping key from the PLPKS. + * @var: variable representing the revoked wrapping key to be deleted + * + * The plpks_remove_var function removes the specified variable and its da= ta + * from the PLPKS by invoking the H_PKS_REMOVE_OBJECT HCALL. + * + * Possible reasons for the returned errno values: + * + * -ENXIO if PLPKS is not supported + * -EIO if PLPKS access is blocked due to the LPAR's state + * if PLPKS modification is blocked due to the LPAR's state + * if an error occurred while processing the request + * -EINVAL if invalid authorization parameter + * if invalid object label parameter + * if invalid object label len parameter + * -EPERM if access is denied + * -ENOENT if the requested object was not found + * -EBUSY if unable to handle the request + * + * Returns: On success 0 is returned, a negative errno if not. + */ +int plpks_del_wrapping_key(struct plpks_var *var) +{ + int rc; + struct plpks_var_name vname; + + if (!var->name || !*var->name) { + pr_err("key label cannot be NULL/empty\n"); + rc =3D -EINVAL; + goto out; + } + + if (!strcmp((char *)var->name, PLPKS_DEFAULT_WRAPKEY_LABEL)) { + pr_warn("the default wrapping key must not be deleted!\n"); + rc =3D -EPERM; + goto out; + } + + rc =3D plpks_is_wrapping_key_revoked(var); + if (rc =3D=3D 1) { + vname =3D (struct plpks_var_name) { + .name =3D var->name, + .namelen =3D var->namelen + }; + + rc =3D plpks_remove_var(PLPKS_WRAPKEY_COMPONENT, var->os, + vname); + if (rc) + pr_err("deletion of <%s> failed. rc=3D%d\n", + (char *)var->name, rc); + goto out; + } else if (!rc) { + pr_err("revoke <%s> before deletion\n", (char *)var->name); + rc =3D -EPERM; + goto out; + } else { + pr_err("revocation status check failed for <%s>. rc =3D %d\n", + (char *)var->name, rc); + } + +out: + return rc; +} +EXPORT_SYMBOL_GPL(plpks_del_wrapping_key); + +/** + * plpks_get_object_labels() - retrieve a list of object labels for the ob= jects + * stored in the PLPKS + * @output_buf: buffer to store the retrieved object labels + * @output_len: number of object labels retrieved + * @comp_prefix: component prefix string + * + * The H_PKS_GET_OBJECTLABELS HCALL retrieves a list of object labels for = the + * objects with the given component prefix stored in the PLPKS. + * + * Possible reasons for the returned errno values: + * + * -ENXIO if PLPKS is not supported + * -EIO if PLPKS access is blocked due to the LPAR's state + * if PLPKS modification is blocked due to the LPAR's state + * if an error occurred while processing the request + * -EINVAL if invalid authorization parameter + * if invalid output buffer parameter + * if invalid output buffer length parameter + * if invalid continue token parameter + * if the provided component prefix is NULL + * -EPERM if access is denied + * -EBUSY if unable to handle the request or long running operation + * initiated, retry later. + * + * Returns: On success 0 is returned, a negative errno if not. + */ +int plpks_get_object_labels(u8 **output_buf, u64 *output_len, + char *comp_prefix) +{ + unsigned long retbuf[PLPAR_HCALL_BUFSIZE] =3D { 0 }; + u8 *labels_buf =3D NULL; + u8 *tmp_buf =3D NULL; + struct plpks_auth *auth =3D NULL; + struct label_attr *metadata =3D NULL; + u16 label_len; + u64 labels_count; + u64 continuetoken =3D 0, output_buf_len =3D 0; + int rc =3D 0, pseries_status =3D 0; + size_t labels_buf_offset =3D 0, output_buf_offset =3D 0; + size_t obj_label_entry_size, i; + + *output_buf =3D NULL; + *output_len =3D 0; + + if (!comp_prefix) { + rc =3D -EINVAL; + goto out; + } + + auth =3D construct_auth(PLPKS_OS_OWNER); + if (IS_ERR(auth)) { + rc =3D PTR_ERR(auth); + goto out; + } + + do { + labels_buf =3D + kzalloc(roundup_pow_of_two(PLPKS_OBJLABEL_BUF_MAX), + GFP_KERNEL); + + if (!labels_buf) { + pr_err("labels_buf buffer allocation failed\n"); + rc =3D -ENOMEM; + goto out_free_output_buf; + } + + rc =3D plpar_hcall(H_PKS_GET_OBJECTLABELS, retbuf, + virt_to_phys(auth), continuetoken, + virt_to_phys(labels_buf), + roundup_pow_of_two(PLPKS_OBJLABEL_BUF_MAX)); + + pseries_status =3D rc; + rc =3D pseries_status_to_err(rc); + + if (rc && rc !=3D -EAGAIN) { + pr_err("H_PKS_GET_OBJECTLABELS failed. pseries_status=3D%d rc=3D%d\n", + pseries_status, rc); + goto out_free_labels_buf; + } else { + /* + * Setting an incorrect countinuetoken upon + * receiving H_CONTINUE would result in H_P2. Since + * the continuetoken is being set to the expected + * value from the previous call, H_P2 must not be + * returned. + */ + continuetoken =3D retbuf[1]; + + labels_count =3D retbuf[0]; + if (!labels_count) { + kfree(labels_buf); + labels_buf =3D NULL; + goto out; + } + + /* + * Filter out object labels that don't have the provided + * component prefix. + */ + + output_buf_len +=3D + roundup_pow_of_two(PLPKS_OBJLABEL_BUF_MAX); + + tmp_buf =3D krealloc(*output_buf, output_buf_len, + GFP_KERNEL); + + if (!tmp_buf) { + pr_err("output buffer re-allocation failed\n"); + rc =3D -ENOMEM; + goto out_free_labels_buf; + } + + *output_buf =3D tmp_buf; + + for (i =3D 0; i < labels_count; ++i) { + label_len =3D + get_unaligned_be16(labels_buf + + labels_buf_offset); + + obj_label_entry_size =3D + PLPKS_OBJLABEL_LEN_FIELD_SIZE + + label_len; + + metadata =3D + (struct label_attr *)(labels_buf + + labels_buf_offset + + PLPKS_OBJLABEL_LEN_FIELD_SIZE); + + if (!memcmp(metadata->prefix, comp_prefix, + PLPKS_OBJLABEL_PREFIX_LEN)) { + memcpy(*output_buf + output_buf_offset, + labels_buf + labels_buf_offset, + obj_label_entry_size); + + output_buf_offset +=3D + obj_label_entry_size; + (*output_len) +=3D 1; + } + labels_buf_offset +=3D obj_label_entry_size; + } + kfree(labels_buf); + labels_buf =3D NULL; + labels_buf_offset =3D 0; + } + } while (rc =3D=3D -EAGAIN); + + goto out; + +out_free_labels_buf: + kfree(labels_buf); + labels_buf =3D NULL; +out_free_output_buf: + kfree(*output_buf); + *output_buf =3D NULL; + *output_len =3D 0; +out: + kfree(auth); + return rc; +} +EXPORT_SYMBOL_GPL(plpks_get_object_labels); + /** * plpks_read_os_var() - Fetch the data for the specified variable that is= owned * by the OS consumer. --=20 2.52.0 From nobody Mon Sep 28 03:41:40 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B47C2360EF9; Thu, 27 Aug 2026 06:25:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787811923; cv=none; b=b6J5jlRSVtuofgRWg/qnhn/ZBz2lpIfCaaGESEW7JbChah79EhqFUqA7GZdsgS+VXjNL3kFSMEvru2QkWN4t+wqBX6CxE3nXj5dnzKFQ+BStJNCruLFZQ3yHaOV0BKCSS+6u23XLdj/Zhs6mCd1yondnF+UyuLecU3r23x2owTs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787811923; c=relaxed/simple; bh=xe0/+a1IF5UnoeyTpE2rn8DxgA3cBPT5bYE3cOGm9ek=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Uv1lZ3yjH7Fmeil5kmA4a+NDS7kWOS/ueVXl0AaSJFVdDPIu12pUrBa4xxA09fNIWFiOTQdJOlCqeWV9wYOemUocwNOwUFKGPNraiOgXaHjssjA6oXWjIGRFB2rXJG38CdcipmvwqS7Yr/gVHQBDAbktJYZHdhdXGrZYC1szii4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=ZRUYqTSO; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="ZRUYqTSO" Received: from pps.filterd (m0356516.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67R3VbFw1715137; Thu, 27 Aug 2026 06:25:06 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=P7jt09uy+SzM6EQWv nOTQdzajCQSCCY23H7YjteKRK4=; b=ZRUYqTSOQhIPFhAYvuqtmCEw2ZZcA06uf 5LCjR4cQPgBc4zyk5A9CUHfRlB8koVhsif4+hMIaGupSYWlItYmvV8wQchsNYa+q pfaqDO505ca18oWJwP8pll98ADa5WOanVs3W2ob0neok8T8Fsg1mSDCcE99gz98T SkHL+8WCH2j4cGzYTjW9Qc97gp2dNDTyi6OP752ZzWV7g3H2V9AqvGOMu4rqOXAP xvcdIrJr1EOcdmwCw2hyOFOEAm6ce+howS95C7vRUWsV8aNJB9/QnFLxf96a+/BC Lpe/E8XnnU/qPY+bFZAtD0pYWLx658nRzh7T1XWVutCsJ5Mv6x83Q== Received: from ppma13.dal12v.mail.ibm.com (dd.9e.1632.ip4.static.sl-reverse.com [50.22.158.221]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4g716j3nkq-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 27 Aug 2026 06:25:05 +0000 (GMT) Received: from pps.filterd (ppma13.dal12v.mail.ibm.com [127.0.0.1]) by ppma13.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67R6BFDC013821; Thu, 27 Aug 2026 06:25:04 GMT Received: from smtprelay04.fra02v.mail.ibm.com ([9.218.2.228]) by ppma13.dal12v.mail.ibm.com (PPS) with ESMTPS id 4g7ragpb42-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 27 Aug 2026 06:25:04 +0000 (GMT) Received: from smtpav01.fra02v.mail.ibm.com (smtpav01.fra02v.mail.ibm.com [10.20.54.100]) by smtprelay04.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67R6P09N27919094 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Thu, 27 Aug 2026 06:25:00 GMT Received: from smtpav01.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 7A6EC20043; Thu, 27 Aug 2026 06:25:00 +0000 (GMT) Received: from smtpav01.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 6437B20040; Thu, 27 Aug 2026 06:24:46 +0000 (GMT) Received: from li-fc74f8cc-3279-11b2-a85c-ef5828687581.ibm.com.com (unknown [9.76.202.253]) by smtpav01.fra02v.mail.ibm.com (Postfix) with ESMTP; Thu, 27 Aug 2026 06:24:45 +0000 (GMT) From: Srish Srinivasan To: linux-integrity@vger.kernel.org, keyrings@vger.kernel.org, linuxppc-dev@lists.ozlabs.org Cc: maddy@linux.ibm.com, mpe@ellerman.id.au, npiggin@gmail.com, christophe.leroy@csgroup.eu, James.Bottomley@HansenPartnership.com, jarkko@kernel.org, zohar@linux.ibm.com, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, nayna@linux.ibm.com, rnsastry@linux.ibm.com, ssrish@linux.ibm.com Subject: [PATCH 7/8] keys/trusted_keys: enable PKWM wrapping key selection by label Date: Thu, 27 Aug 2026 11:53:07 +0530 Message-ID: <20260827062309.724808-8-ssrish@linux.ibm.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260827062309.724808-1-ssrish@linux.ibm.com> References: <20260827062309.724808-1-ssrish@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Reinject: loops=2 maxloops=12 X-Proofpoint-Spam-Info: AW1haW4tMjYwODI3MDA0OCBTYWx0ZWRfX/TJPWNRllthQ l5azOL8AVmriQWP03DwgEowStbupK0nx/28U7Gnt13m1zIXoF/0ddSYzjLTPScQ8D4jbr7JIeLR hEURWo0pQPZuVkHPixQFqIBv7NhsgZI= X-Proofpoint-GUID: tW9eTvKSRAK08msxmIMGfRaIq3v4GE6h X-Proofpoint-ORIG-GUID: aNx6s4h9Tg5Fo92Cm2jC3aVqjQquUt42 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODI3MDA0OCBTYWx0ZWRfX09SQtdMU9oiD PvFpv9NnJ2LJffpwGBQDqTono8c/7txfX4UIBnmvi+GVbnRsDBFlDxZxbghRaMfhlAzLsYVZn5N 97KDrpT0yjgaJRM6JNHiUod99rjCAtnULi9vmRYH3WI8i/89EqsWqJDVJx/cZ4JZzi/winP5Drk k8a5lkY+8oo183qUltPxHNbevHEuBWg+ZWwQiUy095nVJQQLDuyoLPq6YxdmMVWByUvLPu9SDLO 3hZQshtujVqByFYPcoNacQen1Tmmt9dF4Bs4GhCDhHrMlgCi2/7Ns+zAadCeumrl8XlTx8Yumqr PbdR4ZmFh4fMQZrhfU5DZDTr4hjaqtyGJrMxBM3KP/nQcvvOHVMgBS3MR7bKlJQP4pmVt5O0Ud0 kRksqs5bcdRwEFEQQLx4qu3XoinhO8c8t1fYL8bi1ZVCWYGZCihAHlXA3fwsVVeGZBbWZ77Z7+Y MU+KAnyTmTLh8T0CMyg== X-Authority-Analysis: v=2.4 cv=H7brBeYi c=1 sm=1 tr=0 ts=6a8fd841 cx=c_pps a=AfN7/Ok6k8XGzOShvHwTGQ==:117 a=AfN7/Ok6k8XGzOShvHwTGQ==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=Y2IxJ9c9Rs8Kov3niI8_:22 a=VnNF1IyMAAAA:8 a=_1a9KapSLEuvdD3BKzMA:9 a=f3zRgoRf0S4GXb-2:21 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-27_02,2026-08-26_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 suspectscore=0 malwarescore=0 lowpriorityscore=0 impostorscore=0 spamscore=0 bulkscore=0 adultscore=0 priorityscore=1501 clxscore=1015 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608270048 Content-Type: text/plain; charset="utf-8" The PKWM trusted source currently uses the default wrapping key for all seal and unseal operations. However, PKWM supports multiple wrapping keys, enabling better isolation between trusted keys. Allow users to provide an active wrapping key of their choice created through sysfs when sealing trusted keys through a new wrapping_key=3D