Add DM_VERITY_VERIFY_ROOTHASH_SIG_FORCE Kconfig option. When enabled, dm-verity always requires a valid root hash signature: require_signatures defaults to true and can no longer be cleared on the command line. When disabled, the existing require_signatures module parameter controls enforcement.
Signed-off-by: Ayoub Zaki <[email protected]> --- Documentation/admin-guide/device-mapper/verity.rst | 5 +++++ drivers/md/Kconfig | 14 ++++++++++++++ drivers/md/dm-verity-verify-sig.c | 4 ++-- 3 files changed, 21 insertions(+), 2 deletions(-) diff --git a/Documentation/admin-guide/device-mapper/verity.rst b/Documentation/admin-guide/device-mapper/verity.rst index eb9475d7e196..bb48c001aeac 100644 --- a/Documentation/admin-guide/device-mapper/verity.rst +++ b/Documentation/admin-guide/device-mapper/verity.rst @@ -163,6 +163,11 @@ root_hash_sig_key_desc <key_description> also gain new certificates at run time if they are signed by a certificate already in the secondary trusted keyring. + Whether a signature is required for every dm-verity device is controlled by + the dm_verity.require_signatures parameter which defaults to off. Setting + DM_VERITY_VERIFY_ROOTHASH_SIG_FORCE makes it default to on in which case it + can no longer be turned off. + try_verify_in_tasklet If verity hashes are in cache and the IO size does not exceed the limit, verify data blocks in bottom half instead of workqueue. This option can diff --git a/drivers/md/Kconfig b/drivers/md/Kconfig index df27c7d066d2..59098d1f4534 100644 --- a/drivers/md/Kconfig +++ b/drivers/md/Kconfig @@ -610,6 +610,20 @@ config DM_VERITY_VERIFY_ROOTHASH_SIG_PLATFORM_KEYRING If unsure, say N. +config DM_VERITY_VERIFY_ROOTHASH_SIG_FORCE + bool "Require dm-verity root hash signature verification" + depends on DM_VERITY_VERIFY_ROOTHASH_SIG + help + Reject dm-verity devices that are created without a valid root hash + signature. Without this, whether a signature is required is decided + at boot time by the dm_verity.require_signatures parameter which + defaults to off. + + Enabling this makes that parameter default to on and it can then no + longer be turned off. + + If unsure, say N. + config DM_VERITY_FEC bool "Verity forward error correction support" depends on DM_VERITY diff --git a/drivers/md/dm-verity-verify-sig.c b/drivers/md/dm-verity-verify-sig.c index b2b55c41e2cb..aadcf5e4a47c 100644 --- a/drivers/md/dm-verity-verify-sig.c +++ b/drivers/md/dm-verity-verify-sig.c @@ -21,8 +21,8 @@ static bool dm_verity_keyring_unsealed __ro_after_init; module_param_named(keyring_unsealed, dm_verity_keyring_unsealed, bool, 0444); MODULE_PARM_DESC(keyring_unsealed, "Leave the dm-verity keyring unsealed"); -static bool require_signatures; -module_param(require_signatures, bool, 0444); +static bool require_signatures = IS_ENABLED(CONFIG_DM_VERITY_VERIFY_ROOTHASH_SIG_FORCE); +module_param(require_signatures, bool_enable_only, 0444); MODULE_PARM_DESC(require_signatures, "Verify the roothash of dm-verity hash tree"); base-commit: df2908090cda368b01ff43709f51890076c56157 -- 2.43.0

