Re: [PATCH bpf-next 00/11] BPF keyring and signed loader ML-DSA support

Paul Moore <[email protected]>
Newsgroups org.kernel.vger.keyrings,org.kernel.vger.bpf
Message-ID <CAHC9VhQb9-zR-W5acwACe=bH0VvmwPEAyGvsJNG5VyVxEVhtJg@mail.gmail.com>
On Fri, Aug 21, 2026 at 5:41 PM Daniel Borkmann <[email protected]> wrote:
>
> Add a dedicated BPF keyring which is integrated for BPF signing. It
> is modelled after the dm-verity keyring which was added in commit
> 033724b ("dm-verity: add dm-verity keyring") and which can eventually
> be used also via systemd through the same enrollment method as in
> dm-verity's case. It is selected with a new well-known keyring_id
> VERIFY_USE_BPF_KEYRING and gives an operator a place to enroll a
> BPF-only signing key at boot, specifically scoped to signed BPF
> program loading. Next, to demonstrate that BPF signing is algorithm
> agnostic, we add a few small tooling changes to support ML-DSA and
> integrate everything into BPF selftest for BPF CI to ensure nothing
> breaks with future changes. For more details, see individual commits.
>
> Daniel Borkmann (11):
>   bpf: Add a bpf keyring for program signature validation
>   bpf: Refuse caller-supplied keyrings when the bpf one is active
>   bpf: Raise the bound on a program's signature size
>   bpftool: Support ML-DSA program signing
>   selftests/bpf: Add a test for the sealed bpf keyring
>   selftests/bpf: Rebuild signed lskels when signing key changes
>   selftests/bpf: Rename the verify_sig_setup.sh setup into setup-rsa
>   selftests/bpf: Add an end-to-end ML-DSA signed loader test
>   selftests/bpf: Allow appending to guest kernel cmdline in vmtest.sh
>   selftests/bpf: Add tests for bpf keyring in signed loader
>   Documentation/bpf: Document the bpf keyring and improve examples
>
>  .../admin-guide/kernel-parameters.txt         |  15 +
>  Documentation/bpf/signing.rst                 | 274 +++++++--
>  include/linux/bpf.h                           |  13 +
>  include/linux/verification.h                  |  10 +
>  kernel/bpf/Makefile                           |   3 +
>  kernel/bpf/keys.c                             |  72 +++
>  kernel/bpf/verifier.c                         |  42 +-
>  tools/bpf/bpftool/main.h                      |   2 +-
>  tools/bpf/bpftool/sign.c                      |  22 +-
>  tools/testing/selftests/bpf/Makefile          |   2 +-
>  tools/testing/selftests/bpf/config            |   1 +
>  .../selftests/bpf/prog_tests/signed_loader.c  | 518 +++++++++++++++++-
>  .../bpf/prog_tests/verify_pkcs7_sig.c         |   4 +-
>  .../testing/selftests/bpf/verify_sig_setup.sh |  63 ++-
>  tools/testing/selftests/bpf/vmtest.sh         |  16 +-
>  15 files changed, 974 insertions(+), 83 deletions(-)
>  create mode 100644 kernel/bpf/keys.c

CC'ing the keyring folks for obvious reasons.  A lore link to the full
thread can be found below:

https://lore.kernel.org/all/[email protected]

-- 
paul-moore.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.