From patchwork Fri Sep 22 16:59:01 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Kees Cook X-Patchwork-Id: 143626 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:a05:612c:172:b0:3f2:4152:657d with SMTP id h50csp5825333vqi; Fri, 22 Sep 2023 12:42:31 -0700 (PDT) X-Google-Smtp-Source: AGHT+IEB+p4yy/VBG4/Uyq4ZVMUwNffhtGNiN9dlx7pAIvSk57ffhIGaHTKgkD/nVETzMQY/COHV X-Received: by 2002:a05:6830:1d2:b0:6bf:21d3:2de5 with SMTP id r18-20020a05683001d200b006bf21d32de5mr678072ota.17.1695411750930; Fri, 22 Sep 2023 12:42:30 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1695411750; cv=none; d=google.com; s=arc-20160816; b=XAoBl8uFc/UI9AAWxOSxrZe8grkmiCMxDtcDRxdgmPn7QhP2P9RkGxULP9BArWjtaJ KXsA5/ilqsHRbve3t9F7li/RHDuHSZOXcZaePt20adLJ89L9d/XBAdFXe5TP45EQMDC0 yK4PkWOn1hpSdHdJRi0lYZ/U3H/t2xsQyPfN+lKZhmuw7PDhLCblL51h/5pfk5u1JsS1 SZTaMrB8735tttdZWvXUssTWxr36FlfrdwC68mJriQVtY3TM0XFpUwBUUNJnptt83QGF 8nE6GO9Y6LSp1deS49mYTwwC5JaV/lIw8KykPqJp0n0cL8z31i9Dp2a4L5rlyGiJMV7e uHyA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-disposition:mime-version:message-id :subject:cc:to:from:date:dkim-signature; bh=ZgApR4QKR0jTTIWGbZED9KyQ8+ob7E8gjbpmfglkOS4=; fh=s+AzyW1cR5UyFtbqbMzs/l2LyFDBrc2AepE8GOrHbas=; b=n4QX+RgRB1YH5nzJOA5oBWdIXp5HvDKNyEV0Xv0wTZL9MmuSx6Z69MFMxSfGiNpMOD UxN6UrIIxuKdoeUNUmX58SLti2wlUedjAMJvQtsV4WxPVpZU6IBc6bfKWdQZYTbAKQHh PvfeAq0VkKZ144ZIpAcBYVRKKnuCpJ/x5R+qnI5o1JwQfzhj1weKyrwQli2Ny0AzE5Ge sBhRzXI5PEd538n3xx/am5LsKSIrAS5Q2ErmV/H9SVhoGsKFbW9XsIwXdnhSMyR1Yd+b /j9D4glR7W/wCRpzOKgVS89K7cFaUFECyq0aMrrTRWHL0b9vXi4zYl36QC67Tc+js57c fPyQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=By1U7SEW; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.32 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Received: from agentk.vger.email (agentk.vger.email. [23.128.96.32]) by mx.google.com with ESMTPS id i62-20020a638741000000b0056c2892bfb9si1428557pge.644.2023.09.22.12.42.30 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 22 Sep 2023 12:42:30 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.32 as permitted sender) client-ip=23.128.96.32; Authentication-Results: mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b=By1U7SEW; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.32 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Received: from out1.vger.email (depot.vger.email [IPv6:2620:137:e000::3:0]) by agentk.vger.email (Postfix) with ESMTP id B1F1B823C120; Fri, 22 Sep 2023 09:59:19 -0700 (PDT) X-Virus-Status: Clean X-Virus-Scanned: clamav-milter 0.103.10 at agentk.vger.email Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231713AbjIVQ7L (ORCPT + 28 others); Fri, 22 Sep 2023 12:59:11 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:56142 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229538AbjIVQ7J (ORCPT ); Fri, 22 Sep 2023 12:59:09 -0400 Received: from mail-pl1-x634.google.com (mail-pl1-x634.google.com [IPv6:2607:f8b0:4864:20::634]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 6A330122 for ; Fri, 22 Sep 2023 09:59:03 -0700 (PDT) Received: by mail-pl1-x634.google.com with SMTP id d9443c01a7336-1c0c6d4d650so21177315ad.0 for ; Fri, 22 Sep 2023 09:59:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; t=1695401943; x=1696006743; darn=vger.kernel.org; h=content-disposition:mime-version:message-id:subject:cc:to:from:date :from:to:cc:subject:date:message-id:reply-to; bh=ZgApR4QKR0jTTIWGbZED9KyQ8+ob7E8gjbpmfglkOS4=; b=By1U7SEWbR+JttBpZqs5RCKlg3WBennOyEICh29yud2CTEiewcdgSdWagQ9HSw7wX1 cEKcjGvJnxcT16oU1kK+1j4wVzbMkzLtROj3ZKO3QI6IZ5dCfW9MNNzwIYjR/YX+xNm5 MUHn0MQFKuE08BNWY/K6wW+3S8IIPN5hL33uQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1695401943; x=1696006743; h=content-disposition:mime-version:message-id:subject:cc:to:from:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=ZgApR4QKR0jTTIWGbZED9KyQ8+ob7E8gjbpmfglkOS4=; b=X9vaagQf5I21pMzYMVv8iDwtddvhmQDGMcsnDsaoD/Tr+GSDeervDfkHc27pS80bvA SBzmW7tVCYbHMRwmGqRWwY9pvAG+Gmh0HN/Z3Q4QDuUqJ3jiH8HyiiTX+RBh4DU9KvOs 6GOI+L6Cn8+APCBt/pENrVRybjIhjv8QwJ5IDFqC1jJN8Bfom8o0UaqAjTK5vZjks71K nVitAOvxGXFGxbFyeUG2jwg84rcmEdrDTi8yjjb8SmptHkVx7oyPKHEHHJphAfNk9JUL J/ptt5G/2HN6o5R7lJ2/n3dDpINMkFoZADo5o4XTGawDmH9Y5cddoDs7fvRLW2u+c4UV o+Mg== X-Gm-Message-State: AOJu0YxyAbxQwrVukuWfoCTg/toF+4lJXfeUUOJ4PXTNfIqKAko+Dur5 /8jeRG7HaPNjq/q+fK6FnNMEyumWU6DNwBsRuIo= X-Received: by 2002:a17:903:2442:b0:1c4:375c:110a with SMTP id l2-20020a170903244200b001c4375c110amr27448pls.19.1695401942810; Fri, 22 Sep 2023 09:59:02 -0700 (PDT) Received: from www.outflux.net (198-0-35-241-static.hfc.comcastbusiness.net. [198.0.35.241]) by smtp.gmail.com with ESMTPSA id j5-20020a170902da8500b001c57aac6e5esm3728308plx.23.2023.09.22.09.59.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 22 Sep 2023 09:59:02 -0700 (PDT) Date: Fri, 22 Sep 2023 09:59:01 -0700 From: Kees Cook To: Linus Torvalds Cc: linux-kernel@vger.kernel.org, Alexey Dobriyan , Kees Cook Subject: [GIT PULL] hardening fixes for v6.6-rc3 Message-ID: <202309220957.927ADC0586@keescook> MIME-Version: 1.0 Content-Disposition: inline X-Spam-Status: No, score=-0.9 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,HEADER_FROM_DIFFERENT_DOMAINS, MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on agentk.vger.email Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org X-Greylist: Sender passed SPF test, not delayed by milter-greylist-4.6.4 (agentk.vger.email [0.0.0.0]); Fri, 22 Sep 2023 09:59:19 -0700 (PDT) X-getmail-retrieved-from-mailbox: INBOX X-GMAIL-THRID: 1777768072108755017 X-GMAIL-MSGID: 1777768072108755017 Hi Linus, Please pull these hardening fixes for v6.6-rc3. These have been in -next for a week now. Thanks! -Kees The following changes since commit 5f536ac6a5a7b67351e4e5ae4f9e1e57d31268e6: LoadPin: Annotate struct dm_verity_loadpin_trusted_root_digest with __counted_by (2023-08-25 16:07:30 -0700) are available in the Git repository at: https://git.kernel.org/pub/scm/linux/kernel/git/kees/linux.git tags/hardening-v6.6-rc3 for you to fetch changes up to 32a4ec211d4164e667d9d0b807fadf02053cd2e9: uapi: stddef.h: Fix __DECLARE_FLEX_ARRAY for C++ (2023-09-13 20:09:49 -0700) ---------------------------------------------------------------- hardening fixes for v6.6-rc3 - Fix UAPI stddef.h to avoid C++-ism (Alexey Dobriyan) - Fix harmless UAPI stddef.h header guard endif (Alexey Dobriyan) ---------------------------------------------------------------- Alexey Dobriyan (2): uapi: stddef.h: Fix header guard location uapi: stddef.h: Fix __DECLARE_FLEX_ARRAY for C++ include/uapi/linux/stddef.h | 7 +++++++ 1 file changed, 7 insertions(+)