From nobody Mon Jun 9 23:48:02 2025 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4bGTBX11h5z5ygw1; Mon, 09 Jun 2025 23:48:04 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R11" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4bGTBW0Ndvz3DrX; Mon, 09 Jun 2025 23:48:03 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1749512883; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=b1zDFRTtYEIWpzoPBuf2cNwnmppgHLhz6Bh4GkLGqsY=; b=ZwYby4188RxJnmc6MdNB2O7Xy135sR1ejdJlKxcKZwhWgBiHOV3PotkCJYUydSQqqw7K/F ySazQK66kzmv74oVqr0KkO0GBQFGwCqcykZDv8QFSpktI+bAEROX661OcxKFjGtFn2FQMO 4nn7WNlP/19LdSLAUcWniUPaz/wDYYt9bgMYhKUQmIVRnxUBGXY2AluCBQHBAwaMp96FIL 4V9+uUqxgG55bfTS247XA3Epbv3LyB2HwAe+CK442VR7edIvQt1utUuU4cF9dkjdqI4iTI 9wz8BdYdEIuFqBXc4LWXTrI3Fy4vUrzots/EJCZ4T/vCL39ZL+OaaU4jF5yRJQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1749512883; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=b1zDFRTtYEIWpzoPBuf2cNwnmppgHLhz6Bh4GkLGqsY=; b=qrTTxFUZkku/CXSSe7Mm3vKdVZX3UHMg6T1QrEHyUYzwVCpBdeJ+u5/6rmsNSVP2NCSkBq 0U8OckU5TRtaLUsNTeOkWUrtRU/qbYUPqxMFrgOXYfKUomlRVlyHRpWyoIvIA/yDzd4QVh YiZQ/OuzLOz06oUOo5AZg+C3ubRbb3Tlu3VPvqSqMmyPCn6vG9mk8WPJX0qjW0CfxOWfIF iXjYvuJMK4bZZkLAP/PG8FjVdb73J7z50x6hUh8WibFSKWoeiTZSCpZM9BdE3rPYiyLUhL RBZigcOEDLt/rvXE3QIXUn+LlGZQFSCzA/1it4AfpX8L7RAwhMovbl3yu6484w== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1749512883; a=rsa-sha256; cv=none; b=jnqLtr9AUBaKp25CLqi0uFpvLgyoVh5uJ9bNQ9eYdoh1jAU4/V8ZFUEhB8Pfy8fXlBPOqg YcMJZ20eb+f5V9Gh6+tHEYBm2wRUFHHe8mHJet0Ol6Za9i1KXf9tmY4fdIkQR5WsxJyOr2 MhLQKdsOlCpKkOm9Y70ME5IgS3yahfKCPeYMq2vGGlXTstDoUDhMFTogU3yh2a5PKbXYl/ sawrWz+0A4CSYCqHJOSN1Gt4RrAPmUPd9mUE540ENZOW37l6E7tCjLe/opOILkJAXEkOWY m/YX5bNGAMpexNjqUFTuX48nUCCPJ8lT0HUetUAxlmZ47MMQn2SFohv8s4Kamw== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4bGTBV752Nz2NL; Mon, 09 Jun 2025 23:48:02 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.18.1/8.18.1) with ESMTP id 559Nm2e1088794; Mon, 9 Jun 2025 23:48:02 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.18.1/8.18.1/Submit) id 559Nm2Ma088791; Mon, 9 Jun 2025 23:48:02 GMT (envelope-from git) Date: Mon, 9 Jun 2025 23:48:02 GMT Message-Id: <202506092348.559Nm2Ma088791@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Konstantin Belousov Subject: git: e17485c2bdc1 - main - inpcb: provide policy cr_canexport_ktlskeys() and the privilege PRIV_NETINET_KTLSKEYS List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kib X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: e17485c2bdc164a73c72aa73006025a31983e20b Auto-Submitted: auto-generated The branch main has been updated by kib: URL: https://cgit.FreeBSD.org/src/commit/?id=e17485c2bdc164a73c72aa73006025a31983e20b commit e17485c2bdc164a73c72aa73006025a31983e20b Author: Konstantin Belousov AuthorDate: 2025-06-07 13:49:11 +0000 Commit: Konstantin Belousov CommitDate: 2025-06-09 23:47:13 +0000 inpcb: provide policy cr_canexport_ktlskeys() and the privilege PRIV_NETINET_KTLSKEYS The policy defines the visibility of the ktls session keys to a thread. Reviewed by: markj Sponsored by: NVidia networking Differential revision: https://reviews.freebsd.org/D50653 --- sys/netinet/in_prot.c | 14 ++++++++++++++ sys/netinet/in_systm.h | 2 ++ sys/sys/priv.h | 1 + 3 files changed, 17 insertions(+) diff --git a/sys/netinet/in_prot.c b/sys/netinet/in_prot.c index 204f4f60456e..d81f24d6c040 100644 --- a/sys/netinet/in_prot.c +++ b/sys/netinet/in_prot.c @@ -38,6 +38,7 @@ #include #include #include +#include #include #include #include @@ -72,3 +73,16 @@ cr_canseeinpcb(struct ucred *cred, struct inpcb *inp) return (0); } + +bool +cr_canexport_ktlskeys(struct thread *td, struct inpcb *inp) +{ + int error; + + if (cr_canseeinpcb(td->td_ucred, inp) == 0 && + cr_xids_subset(td->td_ucred, inp->inp_cred)) + return (true); + error = priv_check(td, PRIV_NETINET_KTLSKEYS); + return (error == 0); + +} diff --git a/sys/netinet/in_systm.h b/sys/netinet/in_systm.h index 2f057b962d79..e2f553ec461c 100644 --- a/sys/netinet/in_systm.h +++ b/sys/netinet/in_systm.h @@ -58,8 +58,10 @@ typedef u_int32_t n_time; /* ms since 00:00 UTC, byte rev */ #ifdef _KERNEL struct inpcb; struct ucred; +struct thread; int cr_canseeinpcb(struct ucred *cred, struct inpcb *inp); +bool cr_canexport_ktlskeys(struct thread *td, struct inpcb *inp); uint32_t iptime(void); #endif diff --git a/sys/sys/priv.h b/sys/sys/priv.h index 9a1886454d86..1f73877ab450 100644 --- a/sys/sys/priv.h +++ b/sys/sys/priv.h @@ -406,6 +406,7 @@ #define PRIV_NETINET_SETHDROPTS 505 /* Set certain IPv4/6 header options. */ #define PRIV_NETINET_BINDANY 506 /* Allow bind to any address. */ #define PRIV_NETINET_HASHKEY 507 /* Get and set hash keys for IPv4/6. */ +#define PRIV_NETINET_KTLSKEYS 508 /* Read ktls session keys. */ /* * Placeholders for IPX/SPX privileges, not supported any more.