sys-kernel/pf-sources: add 6.19_p4

Add upstream patch for "ima: verify the previous kernel's IMA buffer lies in
 addressable RAM"

Signed-off-by: Ivan S. Titov <iohann.s.titov@gmail.com>
Closes: https://github.com/gentoo/gentoo/pull/45864
Signed-off-by: Joonas Niilola <juippis@gentoo.org>
This commit is contained in:
Ivan S. Titov
2026-03-24 17:10:20 +01:00
committed by Joonas Niilola
parent 3453804afb
commit 496aa213b3
3 changed files with 187 additions and 0 deletions

View File

@@ -4,6 +4,9 @@ DIST genpatches-6.18-10.base.tar.xz 595340 BLAKE2B 0c83bfd6474e5e0e2a5c114466207
DIST genpatches-6.18-10.extras.tar.xz 4324 BLAKE2B b87a2631899b124e8ffbea47b2d1b57dc8b4a2e76bd5019128e456fbef507a854d1a9bd1fbe8597ac1940dac186082f4ed608da4e9dc6c6fec5750c4a0a412c8 SHA512 fbc639ddb801c70cb7067fad412ec92ad8e84226a752b035c79903751db6ad4b816d3dcf80624ffcc39c31d44d021f52e61969c59afc0ffc622d535c1aac95aa
DIST genpatches-6.19-1.base.tar.xz 7328 BLAKE2B 06f4f9b8f996f8a4793343974e52625136a45173fd1849c8efb42e2097f758f6eb5416814ec28f76749e1a1ce9626929dd2c916f26d830b6e652fffaa2cc023e SHA512 3a2d76b55aaf826c09d068b0bd0d37bf22e8d0d9d50cda52519ed0a3b5f1fc88749360116cfeab4ca56266d759dbb690060ecc2a8ccececd91c3ead8cc42bd79
DIST genpatches-6.19-1.extras.tar.xz 4320 BLAKE2B 6da65211eefbbf2468be32bb09fdfcda0b2f5dfcfe9f90b252cb1f069db5f578d876afc68dd0a435a8b8c12823b29637985f90720da4ebb3c926e4e91848e815 SHA512 dd8e340d756eb238552cbe0cebc0726d7d64e782b013a37d427f0631fae2bce4607a62f88d1a2f8b669ec0cae91140d4ff66bc77c019798df40be959403aa7a5
DIST genpatches-6.19-8.base.tar.xz 750728 BLAKE2B 3199dccc32d65f209bf96b913db4eb135ac47632922f5970d41dfc9c2d37072329387673da85307d7b5cccfbf06a8ec590a11469598683e840495cfef1142100 SHA512 4c0bff2bcc7e89a9a0cc202e6a35e6f74c5936a5ee5326d78271a31c4bf88bf8f41379ffd3c26959c0840d3cbd1bd0753242d638926bb804ea95ab47cf074f72
DIST genpatches-6.19-8.extras.tar.xz 4320 BLAKE2B 6f2e26293c91b15622892468da1885a428962cfea653918348e2dcea521d7847f27b54264aa8a205fc8516ef409e36600b3f1ad4a47fbc7afeebad0bcd1ee802 SHA512 dcff32cb894fa05bce17e75cd68518d93e07a1da00b966af7b67b230cc1a881a1898f1442429b89391e988c43f16dcf5306cf3ffb588e8bd34de2cd36a8509a8
DIST linux-6.17-pf4.tar.gz 253598641 BLAKE2B 5a6774f02f1ea67e587cf1374c8e826bb2bf73ddaed3741d60f02ae2c84217ea845233b0ff01d2043b61cf360f1b5a289d329deb41cec804106a63e9296e7619 SHA512 4abf01fbedbc448b0714f175112e35c6e1d1ace89ce3a4ea93978fb3c7e138daa2710bd718255dd59ec90d9ada554179988ae2bd0ca9798798ee76ab3e24b454
DIST linux-6.18-pf6.tar.gz 254953102 BLAKE2B 2eb7606d9a28a70dec23853bb321b78642c0202e6e891ddb5601afec1938365906171cfb53507d7b24167f62e55850d75f0e1fb570589a9ad06831b1bea159dc SHA512 80dd56acaa51577dda10f56679897ab679306d0b9693ba71c44bf66cf4ee9f81cb039492e731c5a9628f2a5fb66b1511ab8d4650d0a9afd5be28bea158fe9ac6
DIST linux-6.19-pf1.tar.gz 257527291 BLAKE2B 6cbeeee14aa895e61e7e9e8861442f059f0e6ff91b8667b059d127ad9eea8ced29350124000f89cb7ec6aa55cdbb821899c7437293e99e2440eaa795901818f0 SHA512 5867fcda49f5608ddd18a778d86b9456a9d2e22636af6b7b71550de0b50be4a32dc9112c0ce84094b1957cec84b789ba9a242085f3dd19b4167a217b09dd7c35
DIST linux-6.19-pf4.tar.gz 257542784 BLAKE2B 054533729f42a6c434341f0c35421f1814999735c98c6c9eaa15da8713bce70c6f4001c9952346e8759b26bf81646bfa9648c3e99de74fc2db9fe3f1eaf744a2 SHA512 71e347092b0f7e176219e7727fabd56a82c254a3d34f0ea76979d009b7a56e5963ceca2a63485ec2b144bfdea1447852396e9b3c8ce6009a98f851f5178ac83e

View File

@@ -0,0 +1,89 @@
From 10d1c75ed4382a8e79874379caa2ead8952734f9 Mon Sep 17 00:00:00 2001
From: Harshit Mogalapalli <harshit.mogalapalli@oracle.com>
Date: Tue, 30 Dec 2025 22:16:07 -0800
Subject: [PATCH] ima: verify the previous kernel's IMA buffer lies in
addressable RAM
When the second-stage kernel is booted with a limiting command line (e.g.
"mem=<size>"), the IMA measurement buffer handed over from the previous
kernel may fall outside the addressable RAM of the new kernel. Accessing
such a buffer can fault during early restore.
Introduce a small generic helper, ima_validate_range(), which verifies
that a physical [start, end] range for the previous-kernel IMA buffer lies
within addressable memory:
- On x86, use pfn_range_is_mapped().
- On OF based architectures, use page_is_ram().
Signed-off-by: Harshit Mogalapalli <harshit.mogalapalli@oracle.com>
Reviewed-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
---
include/linux/ima.h | 1 +
security/integrity/ima/ima_kexec.c | 35 ++++++++++++++++++++++++++++++
2 files changed, 36 insertions(+)
diff --git a/include/linux/ima.h b/include/linux/ima.h
index 8e29cb4e6a01d..abf8923f8fc51 100644
--- a/include/linux/ima.h
+++ b/include/linux/ima.h
@@ -69,6 +69,7 @@ static inline int ima_measure_critical_data(const char *event_label,
#ifdef CONFIG_HAVE_IMA_KEXEC
int __init ima_free_kexec_buffer(void);
int __init ima_get_kexec_buffer(void **addr, size_t *size);
+int ima_validate_range(phys_addr_t phys, size_t size);
#endif
#ifdef CONFIG_IMA_SECURE_AND_OR_TRUSTED_BOOT
diff --git a/security/integrity/ima/ima_kexec.c b/security/integrity/ima/ima_kexec.c
index 5beb69edd12fd..36a34c54de58b 100644
--- a/security/integrity/ima/ima_kexec.c
+++ b/security/integrity/ima/ima_kexec.c
@@ -12,6 +12,8 @@
#include <linux/kexec.h>
#include <linux/of.h>
#include <linux/ima.h>
+#include <linux/mm.h>
+#include <linux/overflow.h>
#include <linux/reboot.h>
#include <asm/page.h>
#include "ima.h"
@@ -294,3 +296,36 @@ void __init ima_load_kexec_buffer(void)
pr_debug("Error restoring the measurement list: %d\n", rc);
}
}
+
+/*
+ * ima_validate_range - verify a physical buffer lies in addressable RAM
+ * @phys: physical start address of the buffer from previous kernel
+ * @size: size of the buffer
+ *
+ * On success return 0. On failure returns -EINVAL so callers can skip
+ * restoring.
+ */
+int ima_validate_range(phys_addr_t phys, size_t size)
+{
+ unsigned long start_pfn, end_pfn;
+ phys_addr_t end_phys;
+
+ if (check_add_overflow(phys, (phys_addr_t)size - 1, &end_phys))
+ return -EINVAL;
+
+ start_pfn = PHYS_PFN(phys);
+ end_pfn = PHYS_PFN(end_phys);
+
+#ifdef CONFIG_X86
+ if (!pfn_range_is_mapped(start_pfn, end_pfn))
+#else
+ if (!page_is_ram(start_pfn) || !page_is_ram(end_pfn))
+#endif
+ {
+ pr_warn("IMA: previous kernel measurement buffer %pa (size 0x%zx) lies outside available memory\n",
+ &phys, size);
+ return -EINVAL;
+ }
+
+ return 0;
+}
--
2.51.0

View File

@@ -0,0 +1,95 @@
# Copyright 1999-2026 Gentoo Authors
# Distributed under the terms of the GNU General Public License v2
EAPI=8
# Define what default functions to run.
ETYPE="sources"
# Use genpatches but don't include the 'experimental' use flag.
K_EXP_GENPATCHES_NOUSE="1"
# Genpatches version to use. -pf patch set already includes vanilla linux updates. Regularly "1"
# is the wanted value here, but the genpatches patch set can be bumped if it includes some
# important fixes. src_prepare() will handle deleting the updated vanilla linux patches.
# See https://archives.gentoo.org/gentoo-kernel/ (or subscribe to the list) to see all patches.
K_GENPATCHES_VER="8"
# -pf patch set already sets EXTRAVERSION to kernel Makefile.
K_NOSETEXTRAVERSION="1"
# pf-sources is not officially supported/covered by the Gentoo security team.
K_SECURITY_UNSUPPORTED="1"
# Define which parts to use from genpatches - experimental is already included in the -pf patch
# set.
K_WANT_GENPATCHES="base extras"
# Major kernel version, e.g. 5.14.
SHPV="${PV/_p*/}"
# Replace "_p" with "-pf", since using "-pf" is not allowed for an ebuild name by PMS.
PFPV="${PV/_p/-pf}"
inherit kernel-2 optfeature
detect_version
DESCRIPTION="Linux kernel fork that includes the pf-kernel patchset and Gentoo's genpatches"
HOMEPAGE="https://pfkernel.natalenko.name/
https://dev.gentoo.org/~alicef/genpatches/"
SRC_URI="https://codeberg.org/pf-kernel/linux/archive/v${PFPV}.tar.gz -> linux-${PFPV}.tar.gz
${GENPATCHES_URI}"
S="${WORKDIR}/linux-${PFPV}"
KEYWORDS="~amd64 ~ppc ~ppc64 ~x86"
K_EXTRAEINFO="For more info on pf-sources and details on how to report problems,
see: ${HOMEPAGE}."
pkg_setup() {
ewarn ""
ewarn "${PN} is *not* supported by the Gentoo Kernel Project in any way."
ewarn "If you need support, please contact the pf developers directly."
ewarn "Do *not* open bugs in Gentoo's bugzilla unless you have issues with"
ewarn "the ebuilds. Thank you."
ewarn ""
kernel-2_pkg_setup
}
src_unpack() {
# Since the Codeberg-hosted pf-sources include full kernel sources, we need to manually override
# the src_unpack phase because kernel-2_src_unpack() does a lot of unwanted magic here.
unpack ${A}
mv linux linux-${PFPV} || die "Failed to move source directory"
}
src_prepare() {
# When genpatches basic version is bumped, it also includes vanilla linux updates. Those are
# already in the -pf patch set, so need to remove the vanilla linux patches to avoid conflicts.
if [[ ${K_GENPATCHES_VER} -ne 1 ]]; then
find "${WORKDIR}"/ -type f -name '10*linux*patch' -delete ||
die "Failed to delete vanilla linux patches in src_prepare."
fi
# kernel-2_src_prepare doesn't apply PATCHES(). Chosen genpatches are also applied here.
eapply "${WORKDIR}"/*.patch
eapply "${FILESDIR}/ima_validate_range.patch"
default
}
pkg_postinst() {
# Fixes "wrongly" detected directory name, bgo#862534.
local KV_FULL="${PFPV}"
kernel-2_pkg_postinst
optfeature "userspace KSM helper" sys-process/uksmd
}
pkg_postrm() {
# Same here, bgo#862534.
local KV_FULL="${PFPV}"
kernel-2_pkg_postrm
}