mirror of
https://github.com/torvalds/linux.git
synced 2026-09-23 13:14:02 +02:00
The discard-block check in dm_integrity_rw_tag() treats a stored tag
of all 0xf6 bytes (DISCARD_FILLER) as proof a block was discarded and
skips HMAC verification. allow_discards is only accepted in
dm-integrity's standalone mode. An attacker with raw write access to
the backing device, but without the integrity key, can stamp any block
with an all-0xf6 tag and have it served as authentic.
Add a new "allow_discards_keyed" target argument that marks discarded
blocks with a keyed checksum of (salt || sector) instead, computed by
integrity_discard_checksum().
Fixes:
|
||
|---|---|---|
| .. | ||
| cache-policies.rst | ||
| cache.rst | ||
| delay.rst | ||
| dm-clone.rst | ||
| dm-crypt.rst | ||
| dm-dust.rst | ||
| dm-ebs.rst | ||
| dm-flakey.rst | ||
| dm-ima.rst | ||
| dm-init.rst | ||
| dm-inlinecrypt.rst | ||
| dm-integrity.rst | ||
| dm-io.rst | ||
| dm-log.rst | ||
| dm-pcache.rst | ||
| dm-queue-length.rst | ||
| dm-raid.rst | ||
| dm-service-time.rst | ||
| dm-uevent.rst | ||
| dm-zoned.rst | ||
| era.rst | ||
| index.rst | ||
| kcopyd.rst | ||
| linear.rst | ||
| log-writes.rst | ||
| persistent-data.rst | ||
| snapshot.rst | ||
| statistics.rst | ||
| striped.rst | ||
| switch.rst | ||
| thin-provisioning.rst | ||
| unstriped.rst | ||
| vdo-design.rst | ||
| vdo.rst | ||
| verity.rst | ||
| writecache.rst | ||
| zero.rst | ||