Changes in 4.9.204 net/mlx4_en: fix mlx4 ethtool -N insertion net: rtnetlink: prevent underflows in do_setvfinfo() sfc: Only cancel the PPS workqueue if it exists net/mlx5e: Fix set vf link state error flow net/sched: act_pedit: fix WARN() in the traffic path gpio: max77620: Fixup debounce delays tools: gpio: Correctly add make dependencies for gpio_utils Revert "fs: ocfs2: fix possible null-pointer dereferences in ocfs2_xa_prepare_entry()" mm/ksm.c: don't WARN if page is still mapped in remove_stable_node() platform/x86: asus-nb-wmi: Support ALS on the Zenbook UX430UQ platform/x86: asus-wmi: Only Tell EC the OS will handle display hotkeys from asus_nb_wmi mwifiex: Fix NL80211_TX_POWER_LIMITED ALSA: isight: fix leak of reference to firewire unit in error path of .probe callback printk: fix integer overflow in setup_log_buf() gfs2: Fix marking bitmaps non-full synclink_gt(): fix compat_ioctl() powerpc: Fix signedness bug in update_flash_db() powerpc/eeh: Fix use of EEH_PE_KEEP on wrong field brcmsmac: AP mode: update beacon when TIM changes ath10k: allocate small size dma memory in ath10k_pci_diag_write_mem spi: sh-msiof: fix deferred probing mmc: mediatek: fix cannot receive new request when msdc_cmd_is_ready fail btrfs: handle error of get_old_root gsmi: Fix bug in append_to_eventlog sysfs handler misc: mic: fix a DMA pool free failure m68k: fix command-line parsing when passed from u-boot amiflop: clean up on errors during setup scsi: ips: fix missing break in switch KVM/x86: Fix invvpid and invept register operand size in 64-bit mode scsi: isci: Use proper enumerated type in atapi_d2h_reg_frame_handler scsi: isci: Change sci_controller_start_task's return type to sci_status scsi: iscsi_tcp: Explicitly cast param in iscsi_sw_tcp_host_get_param clk: mmp2: fix the clock id for sdh2_clk and sdh3_clk ASoC: tegra_sgtl5000: fix device_node refcounting scsi: dc395x: fix dma API usage in srb_done scsi: dc395x: fix DMA API usage in sg_update_list net: fix warning in af_unix net: ena: Fix Kconfig dependency on X86 xfs: fix use-after-free race in xfs_buf_rele kprobes, x86/ptrace.h: Make regs_get_kernel_stack_nth() not fault on bad stack ALSA: i2c/cs8427: Fix int to char conversion macintosh/windfarm_smu_sat: Fix debug output USB: misc: appledisplay: fix backlight update_status return code usbip: tools: fix atoi() on non-null terminated string SUNRPC: Fix a compile warning for cmpxchg64() sunrpc: safely reallow resvport min/max inversion atm: zatm: Fix empty body Clang warnings s390/perf: Return error when debug_register fails spi: omap2-mcspi: Set FIFO DMA trigger level to word length sparc: Fix parport build warnings. ceph: fix dentry leak in ceph_readdir_prepopulate rtc: s35390a: Change buf's type to u8 in s35390a_init f2fs: fix to spread clear_cold_data() mISDN: Fix type of switch control variable in ctrl_teimanager qlcnic: fix a return in qlcnic_dcb_get_capability() net: ethernet: ti: cpsw: unsync mcast entries while switch promisc mode mfd: arizona: Correct calling of runtime_put_sync mfd: mc13xxx-core: Fix PMIC shutdown when reading ADC values mfd: max8997: Enale irq-wakeup unconditionally selftests/ftrace: Fix to test kprobe $comm arg only if available thermal: rcar_thermal: Prevent hardware access during system suspend powerpc/process: Fix flush_all_to_thread for SPE sparc64: Rework xchg() definition to avoid warnings. fs/ocfs2/dlm/dlmdebug.c: fix a sleep-in-atomic-context bug in dlm_print_one_mle() mm/page-writeback.c: fix range_cyclic writeback vs writepages deadlock macsec: update operstate when lower device changes macsec: let the administrator set UP state even if lowerdev is down um: Make line/tty semantics use true write IRQ linux/bitmap.h: handle constant zero-size bitmaps correctly linux/bitmap.h: fix type of nbits in bitmap_shift_right() hfsplus: fix BUG on bnode parent update hfs: fix BUG on bnode parent update hfsplus: prevent btree data loss on ENOSPC hfs: prevent btree data loss on ENOSPC hfsplus: fix return value of hfsplus_get_block() hfs: fix return value of hfs_get_block() hfsplus: update timestamps on truncate() hfs: update timestamp on truncate() fs/hfs/extent.c: fix array out of bounds read of array extent mm/memory_hotplug: make add_memory() take the device_hotplug_lock igb: shorten maximum PHC timecounter update interval ntb_netdev: fix sleep time mismatch ntb: intel: fix return value for ndev_vec_mask() arm64: makefile fix build of .i file in external module case ocfs2: don't put and assigning null to bh allocated outside ocfs2: fix clusters leak in ocfs2_defrag_extent() net: do not abort bulk send on BQL status sched/fair: Don't increase sd->balance_interval on newidle balance audit: print empty EXECVE args wlcore: Fix the return value in case of error in 'wlcore_vendor_cmd_smart_config_start()' rtl8xxxu: Fix missing break in switch brcmsmac: never log "tid x is not agg'able" by default wireless: airo: potential buffer overflow in sprintf() rtlwifi: rtl8192de: Fix misleading REG_MCUFWDL information scsi: mpt3sas: Fix Sync cache command failure during driver unload scsi: mpt3sas: Fix driver modifying persistent data in Manufacturing page11 scsi: megaraid_sas: Fix msleep granularity scsi: lpfc: fcoe: Fix link down issue after 1000+ link bounces dlm: fix invalid free dlm: don't leak kernel pointer to userspace ACPICA: Use %d for signed int print formatting instead of %u net: bcmgenet: return correct value 'ret' from bcmgenet_power_down sock: Reset dst when changing sk_mark via setsockopt pinctrl: qcom: spmi-gpio: fix gpio-hog related boot issues pinctrl: lpc18xx: Use define directive for PIN_CONFIG_GPIO_PIN_INT pinctrl: zynq: Use define directive for PIN_CONFIG_IO_STANDARD PCI: keystone: Use quirk to limit MRRS for K2G spi: omap2-mcspi: Fix DMA and FIFO event trigger size mismatch mm/memory_hotplug: Do not unlock when fails to take the device_hotplug_lock Bluetooth: Fix invalid-free in bcsp_close() KVM: MMU: Do not treat ZONE_DEVICE pages as being reserved ath9k_hw: fix uninitialized variable data dm: use blk_set_queue_dying() in __dm_destroy() arm64: fix for bad_mode() handler to always result in panic cpufreq: Skip cpufreq resume if it's not suspended ocfs2: remove ocfs2_is_o2cb_active() ARM: 8904/1: skip nomap memblocks while finding the lowmem/highmem boundary ARC: perf: Accommodate big-endian CPU x86/insn: Fix awk regexp warnings x86/speculation: Fix incorrect MDS/TAA mitigation status x86/speculation: Fix redundant MDS mitigation message nfc: port100: handle command failure cleanly l2tp: don't use l2tp_tunnel_find() in l2tp_ip and l2tp_ip6 media: vivid: Set vid_cap_streaming and vid_out_streaming to true media: vivid: Fix wrong locking that causes race conditions on streaming stop media: usbvision: Fix races among open, close, and disconnect cpufreq: Add NULL checks to show() and store() methods of cpufreq media: uvcvideo: Fix error path in control parsing failure media: b2c2-flexcop-usb: add sanity checking media: cxusb: detect cxusb_ctrl_msg error in query media: imon: invalid dereference in imon_touch_event virtio_console: reset on out of memory virtio_console: don't tie bufs to a vq virtio_console: allocate inbufs in add_port() only if it is needed virtio_ring: fix return code on DMA mapping fails virtio_console: fix uninitialized variable use virtio_console: drop custom control queue cleanup virtio_console: move removal code usbip: tools: fix fd leakage in the function of read_attr_usbip_status usb-serial: cp201x: support Mark-10 digital force gauge USB: chaoskey: fix error case of a timeout appledisplay: fix error handling in the scheduled work USB: serial: mos7840: add USB ID to support Moxa UPort 2210 USB: serial: mos7720: fix remote wakeup USB: serial: mos7840: fix remote wakeup USB: serial: option: add support for DW5821e with eSIM support USB: serial: option: add support for Foxconn T77W968 LTE modules staging: comedi: usbduxfast: usbduxfast_ai_cmdtest rounding error powerpc/64s: support nospectre_v2 cmdline option powerpc/book3s64: Fix link stack flush on context switch KVM: PPC: Book3S HV: Flush link stack on guest exit to host kernel Linux 4.9.204 Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
231 lines
6.6 KiB
C
231 lines
6.6 KiB
C
/*
|
|
* linux/net/sunrpc/gss_krb5_seal.c
|
|
*
|
|
* Adapted from MIT Kerberos 5-1.2.1 lib/gssapi/krb5/k5seal.c
|
|
*
|
|
* Copyright (c) 2000-2008 The Regents of the University of Michigan.
|
|
* All rights reserved.
|
|
*
|
|
* Andy Adamson <andros@umich.edu>
|
|
* J. Bruce Fields <bfields@umich.edu>
|
|
*/
|
|
|
|
/*
|
|
* Copyright 1993 by OpenVision Technologies, Inc.
|
|
*
|
|
* Permission to use, copy, modify, distribute, and sell this software
|
|
* and its documentation for any purpose is hereby granted without fee,
|
|
* provided that the above copyright notice appears in all copies and
|
|
* that both that copyright notice and this permission notice appear in
|
|
* supporting documentation, and that the name of OpenVision not be used
|
|
* in advertising or publicity pertaining to distribution of the software
|
|
* without specific, written prior permission. OpenVision makes no
|
|
* representations about the suitability of this software for any
|
|
* purpose. It is provided "as is" without express or implied warranty.
|
|
*
|
|
* OPENVISION DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE,
|
|
* INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS, IN NO
|
|
* EVENT SHALL OPENVISION BE LIABLE FOR ANY SPECIAL, INDIRECT OR
|
|
* CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF
|
|
* USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
|
* OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
|
* PERFORMANCE OF THIS SOFTWARE.
|
|
*/
|
|
|
|
/*
|
|
* Copyright (C) 1998 by the FundsXpress, INC.
|
|
*
|
|
* All rights reserved.
|
|
*
|
|
* Export of this software from the United States of America may require
|
|
* a specific license from the United States Government. It is the
|
|
* responsibility of any person or organization contemplating export to
|
|
* obtain such a license before exporting.
|
|
*
|
|
* WITHIN THAT CONSTRAINT, permission to use, copy, modify, and
|
|
* distribute this software and its documentation for any purpose and
|
|
* without fee is hereby granted, provided that the above copyright
|
|
* notice appear in all copies and that both that copyright notice and
|
|
* this permission notice appear in supporting documentation, and that
|
|
* the name of FundsXpress. not be used in advertising or publicity pertaining
|
|
* to distribution of the software without specific, written prior
|
|
* permission. FundsXpress makes no representations about the suitability of
|
|
* this software for any purpose. It is provided "as is" without express
|
|
* or implied warranty.
|
|
*
|
|
* THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR
|
|
* IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED
|
|
* WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE.
|
|
*/
|
|
|
|
#include <linux/types.h>
|
|
#include <linux/jiffies.h>
|
|
#include <linux/sunrpc/gss_krb5.h>
|
|
#include <linux/random.h>
|
|
#include <linux/crypto.h>
|
|
#include <linux/atomic.h>
|
|
|
|
#if IS_ENABLED(CONFIG_SUNRPC_DEBUG)
|
|
# define RPCDBG_FACILITY RPCDBG_AUTH
|
|
#endif
|
|
|
|
DEFINE_SPINLOCK(krb5_seq_lock);
|
|
|
|
static void *
|
|
setup_token(struct krb5_ctx *ctx, struct xdr_netobj *token)
|
|
{
|
|
u16 *ptr;
|
|
void *krb5_hdr;
|
|
int body_size = GSS_KRB5_TOK_HDR_LEN + ctx->gk5e->cksumlength;
|
|
|
|
token->len = g_token_size(&ctx->mech_used, body_size);
|
|
|
|
ptr = (u16 *)token->data;
|
|
g_make_token_header(&ctx->mech_used, body_size, (unsigned char **)&ptr);
|
|
|
|
/* ptr now at start of header described in rfc 1964, section 1.2.1: */
|
|
krb5_hdr = ptr;
|
|
*ptr++ = KG_TOK_MIC_MSG;
|
|
/*
|
|
* signalg is stored as if it were converted from LE to host endian, even
|
|
* though it's an opaque pair of bytes according to the RFC.
|
|
*/
|
|
*ptr++ = (__force u16)cpu_to_le16(ctx->gk5e->signalg);
|
|
*ptr++ = SEAL_ALG_NONE;
|
|
*ptr = 0xffff;
|
|
|
|
return krb5_hdr;
|
|
}
|
|
|
|
static void *
|
|
setup_token_v2(struct krb5_ctx *ctx, struct xdr_netobj *token)
|
|
{
|
|
u16 *ptr;
|
|
void *krb5_hdr;
|
|
u8 *p, flags = 0x00;
|
|
|
|
if ((ctx->flags & KRB5_CTX_FLAG_INITIATOR) == 0)
|
|
flags |= 0x01;
|
|
if (ctx->flags & KRB5_CTX_FLAG_ACCEPTOR_SUBKEY)
|
|
flags |= 0x04;
|
|
|
|
/* Per rfc 4121, sec 4.2.6.1, there is no header,
|
|
* just start the token */
|
|
krb5_hdr = ptr = (u16 *)token->data;
|
|
|
|
*ptr++ = KG2_TOK_MIC;
|
|
p = (u8 *)ptr;
|
|
*p++ = flags;
|
|
*p++ = 0xff;
|
|
ptr = (u16 *)p;
|
|
*ptr++ = 0xffff;
|
|
*ptr = 0xffff;
|
|
|
|
token->len = GSS_KRB5_TOK_HDR_LEN + ctx->gk5e->cksumlength;
|
|
return krb5_hdr;
|
|
}
|
|
|
|
static u32
|
|
gss_get_mic_v1(struct krb5_ctx *ctx, struct xdr_buf *text,
|
|
struct xdr_netobj *token)
|
|
{
|
|
char cksumdata[GSS_KRB5_MAX_CKSUM_LEN];
|
|
struct xdr_netobj md5cksum = {.len = sizeof(cksumdata),
|
|
.data = cksumdata};
|
|
void *ptr;
|
|
s32 now;
|
|
u32 seq_send;
|
|
u8 *cksumkey;
|
|
|
|
dprintk("RPC: %s\n", __func__);
|
|
BUG_ON(ctx == NULL);
|
|
|
|
now = get_seconds();
|
|
|
|
ptr = setup_token(ctx, token);
|
|
|
|
if (ctx->gk5e->keyed_cksum)
|
|
cksumkey = ctx->cksum;
|
|
else
|
|
cksumkey = NULL;
|
|
|
|
if (make_checksum(ctx, ptr, 8, text, 0, cksumkey,
|
|
KG_USAGE_SIGN, &md5cksum))
|
|
return GSS_S_FAILURE;
|
|
|
|
memcpy(ptr + GSS_KRB5_TOK_HDR_LEN, md5cksum.data, md5cksum.len);
|
|
|
|
spin_lock(&krb5_seq_lock);
|
|
seq_send = ctx->seq_send++;
|
|
spin_unlock(&krb5_seq_lock);
|
|
|
|
if (krb5_make_seq_num(ctx, ctx->seq, ctx->initiate ? 0 : 0xff,
|
|
seq_send, ptr + GSS_KRB5_TOK_HDR_LEN, ptr + 8))
|
|
return GSS_S_FAILURE;
|
|
|
|
return (ctx->endtime < now) ? GSS_S_CONTEXT_EXPIRED : GSS_S_COMPLETE;
|
|
}
|
|
|
|
static u32
|
|
gss_get_mic_v2(struct krb5_ctx *ctx, struct xdr_buf *text,
|
|
struct xdr_netobj *token)
|
|
{
|
|
char cksumdata[GSS_KRB5_MAX_CKSUM_LEN];
|
|
struct xdr_netobj cksumobj = { .len = sizeof(cksumdata),
|
|
.data = cksumdata};
|
|
void *krb5_hdr;
|
|
s32 now;
|
|
u64 seq_send;
|
|
u8 *cksumkey;
|
|
unsigned int cksum_usage;
|
|
|
|
dprintk("RPC: %s\n", __func__);
|
|
|
|
krb5_hdr = setup_token_v2(ctx, token);
|
|
|
|
/* Set up the sequence number. Now 64-bits in clear
|
|
* text and w/o direction indicator */
|
|
spin_lock(&krb5_seq_lock);
|
|
seq_send = ctx->seq_send64++;
|
|
spin_unlock(&krb5_seq_lock);
|
|
*((__be64 *)(krb5_hdr + 8)) = cpu_to_be64(seq_send);
|
|
|
|
if (ctx->initiate) {
|
|
cksumkey = ctx->initiator_sign;
|
|
cksum_usage = KG_USAGE_INITIATOR_SIGN;
|
|
} else {
|
|
cksumkey = ctx->acceptor_sign;
|
|
cksum_usage = KG_USAGE_ACCEPTOR_SIGN;
|
|
}
|
|
|
|
if (make_checksum_v2(ctx, krb5_hdr, GSS_KRB5_TOK_HDR_LEN,
|
|
text, 0, cksumkey, cksum_usage, &cksumobj))
|
|
return GSS_S_FAILURE;
|
|
|
|
memcpy(krb5_hdr + GSS_KRB5_TOK_HDR_LEN, cksumobj.data, cksumobj.len);
|
|
|
|
now = get_seconds();
|
|
|
|
return (ctx->endtime < now) ? GSS_S_CONTEXT_EXPIRED : GSS_S_COMPLETE;
|
|
}
|
|
|
|
u32
|
|
gss_get_mic_kerberos(struct gss_ctx *gss_ctx, struct xdr_buf *text,
|
|
struct xdr_netobj *token)
|
|
{
|
|
struct krb5_ctx *ctx = gss_ctx->internal_ctx_id;
|
|
|
|
switch (ctx->enctype) {
|
|
default:
|
|
BUG();
|
|
case ENCTYPE_DES_CBC_RAW:
|
|
case ENCTYPE_DES3_CBC_RAW:
|
|
case ENCTYPE_ARCFOUR_HMAC:
|
|
return gss_get_mic_v1(ctx, text, token);
|
|
case ENCTYPE_AES128_CTS_HMAC_SHA1_96:
|
|
case ENCTYPE_AES256_CTS_HMAC_SHA1_96:
|
|
return gss_get_mic_v2(ctx, text, token);
|
|
}
|
|
}
|
|
|