<feed xmlns='http://www.w3.org/2005/Atom'>
<title>kernel.git/kernel/bpf/bpf_lsm.c, branch linux-rolling-stable</title>
<subtitle>Hosts the 0x221E linux distro kernel.
</subtitle>
<id>https://git.0xinfinity.dev/distro/kernel.git/atom?h=linux-rolling-stable</id>
<link rel='self' href='https://git.0xinfinity.dev/distro/kernel.git/atom?h=linux-rolling-stable'/>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/'/>
<updated>2025-11-28T23:18:28Z</updated>
<entry>
<title>bpf: Disable file_alloc_security hook</title>
<updated>2025-11-28T23:18:28Z</updated>
<author>
<name>Amery Hung</name>
</author>
<published>2025-11-26T20:29:26Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=b4bf1d23dc1da236c92a9d9be68cc63358d1f750'/>
<id>urn:sha1:b4bf1d23dc1da236c92a9d9be68cc63358d1f750</id>
<content type='text'>
A use-after-free bug may be triggered by calling bpf_inode_storage_get()
in a BPF LSM program hooked to file_alloc_security. Disable the hook to
prevent this from happening.

The cause of the bug is shown in the trace below. In alloc_file(), a
file struct is first allocated through kmem_cache_alloc(). Then,
file_alloc_security hook is invoked. Since the zero initialization or
assignment of f-&gt;f_inode happen after this LSM hook, a BPF program may
get a dangeld inode pointer by walking the file struct.

  alloc_file()
  -&gt; alloc_empty_file()
     -&gt; f = kmem_cache_alloc()
     -&gt; init_file()
        -&gt; security_file_alloc() // f-&gt;f_inode not init-ed yet!
     -&gt; f-&gt;f_inode = NULL;
  -&gt; file_init_path()
     -&gt; f-&gt;f_inode = path-&gt;dentry-&gt;d_inode

Reported-by: Kaiyan Mei &lt;M202472210@hust.edu.cn&gt;
Reported-by: Yinhao Hu &lt;dddddd@hust.edu.cn&gt;
Reported-by: Dongliang Mu &lt;dzm91@hust.edu.cn&gt;
Closes: https://lore.kernel.org/bpf/1d2d1968.47cd3.19ab9528e94.Coremail.kaiyanm@hust.edu.cn/
Signed-off-by: Amery Hung &lt;ameryhung@gmail.com&gt;
Link: https://lore.kernel.org/r/20251126202927.2584874-1-ameryhung@gmail.com
Signed-off-by: Alexei Starovoitov &lt;ast@kernel.org&gt;
</content>
</entry>
<entry>
<title>bpf: lsm: Add two more sleepable hooks</title>
<updated>2025-02-14T03:35:31Z</updated>
<author>
<name>Song Liu</name>
</author>
<published>2025-01-30T21:35:47Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=7587d735b150bc593c812615bbd232980418eea3'/>
<id>urn:sha1:7587d735b150bc593c812615bbd232980418eea3</id>
<content type='text'>
Add bpf_lsm_inode_removexattr and bpf_lsm_inode_post_removexattr to list
sleepable_lsm_hooks. These two hooks are always called from sleepable
context.

Signed-off-by: Song Liu &lt;song@kernel.org&gt;
Reviewed-by: Matt Bobrowski &lt;mattbobrowski@google.com&gt;
Link: https://lore.kernel.org/r/20250130213549.3353349-4-song@kernel.org
Signed-off-by: Alexei Starovoitov &lt;ast@kernel.org&gt;
</content>
</entry>
<entry>
<title>bpf, lsm: Remove getlsmprop hooks BTF IDs</title>
<updated>2024-11-25T22:14:17Z</updated>
<author>
<name>Thomas Weißschuh</name>
</author>
<published>2024-11-25T19:53:07Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=8618f5ffba4d381610f6bb4c472a6148c2bfde96'/>
<id>urn:sha1:8618f5ffba4d381610f6bb4c472a6148c2bfde96</id>
<content type='text'>
These hooks are not useful for BPF LSM currently.
Furthermore a recent renaming introduced build warnings:

  BTFIDS  vmlinux
WARN: resolve_btfids: unresolved symbol bpf_lsm_task_getsecid_obj
WARN: resolve_btfids: unresolved symbol bpf_lsm_current_getsecid_subj

Link: https://lore.kernel.org/lkml/20241123-bpf_lsm_task_getsecid_obj-v1-1-0d0f94649e05@weissschuh.net/
Fixes: 37f670aacd48 ("lsm: use lsm_prop in security_current_getsecid")
Signed-off-by: Thomas Weißschuh &lt;linux@weissschuh.net&gt;
Link: https://lore.kernel.org/r/20241125-bpf_lsm_task_getsecid_obj-v2-1-c8395bde84e0@weissschuh.net
Signed-off-by: Alexei Starovoitov &lt;ast@kernel.org&gt;
</content>
</entry>
<entry>
<title>bpf, lsm: Remove bpf_lsm_key_free hook</title>
<updated>2024-10-08T19:52:40Z</updated>
<author>
<name>Thomas Weißschuh</name>
</author>
<published>2024-10-05T00:06:28Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=b24d7f0da6ef5a23456a301eaf51b170f961d4ae'/>
<id>urn:sha1:b24d7f0da6ef5a23456a301eaf51b170f961d4ae</id>
<content type='text'>
The key_free LSM hook has been removed.
Remove the corresponding BPF hook.

Avoid warnings during the build:
  BTFIDS  vmlinux
WARN: resolve_btfids: unresolved symbol bpf_lsm_key_free

Fixes: 5f8d28f6d7d5 ("lsm: infrastructure management of the key security blob")
Signed-off-by: Thomas Weißschuh &lt;linux@weissschuh.net&gt;
Signed-off-by: Andrii Nakryiko &lt;andrii@kernel.org&gt;
Acked-by: Song Liu &lt;song@kernel.org&gt;
Acked-by: Jiri Olsa &lt;jolsa@kernel.org&gt;
Link: https://lore.kernel.org/bpf/20241005-lsm-key_free-v1-1-42ea801dbd63@weissschuh.net
</content>
</entry>
<entry>
<title>bpf, lsm: Add check for BPF LSM return value</title>
<updated>2024-07-29T20:09:22Z</updated>
<author>
<name>Xu Kuohai</name>
</author>
<published>2024-07-19T11:00:52Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=5d99e198be279045e6ecefe220f5c52f8ce9bfd5'/>
<id>urn:sha1:5d99e198be279045e6ecefe220f5c52f8ce9bfd5</id>
<content type='text'>
A bpf prog returning a positive number attached to file_alloc_security
hook makes kernel panic.

This happens because file system can not filter out the positive number
returned by the LSM prog using IS_ERR, and misinterprets this positive
number as a file pointer.

Given that hook file_alloc_security never returned positive number
before the introduction of BPF LSM, and other BPF LSM hooks may
encounter similar issues, this patch adds LSM return value check
in verifier, to ensure no unexpected value is returned.

Fixes: 520b7aa00d8c ("bpf: lsm: Initialize the BPF LSM hooks")
Reported-by: Xin Liu &lt;liuxin350@huawei.com&gt;
Signed-off-by: Xu Kuohai &lt;xukuohai@huawei.com&gt;
Acked-by: Eduard Zingerman &lt;eddyz87@gmail.com&gt;
Link: https://lore.kernel.org/r/20240719110059.797546-3-xukuohai@huaweicloud.com
Signed-off-by: Alexei Starovoitov &lt;ast@kernel.org&gt;
Signed-off-by: Andrii Nakryiko &lt;andrii@kernel.org&gt;
</content>
</entry>
<entry>
<title>bpf, lsm: Add disabled BPF LSM hook list</title>
<updated>2024-07-29T20:09:18Z</updated>
<author>
<name>Xu Kuohai</name>
</author>
<published>2024-07-19T11:00:51Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=21c7063f6d08ab9afa088584939791bee0c177e5'/>
<id>urn:sha1:21c7063f6d08ab9afa088584939791bee0c177e5</id>
<content type='text'>
Add a disabled hooks list for BPF LSM. progs being attached to the
listed hooks will be rejected by the verifier.

Suggested-by: KP Singh &lt;kpsingh@kernel.org&gt;
Signed-off-by: Xu Kuohai &lt;xukuohai@huawei.com&gt;
Link: https://lore.kernel.org/r/20240719110059.797546-2-xukuohai@huaweicloud.com
Signed-off-by: Alexei Starovoitov &lt;ast@kernel.org&gt;
Signed-off-by: Andrii Nakryiko &lt;andrii@kernel.org&gt;
</content>
</entry>
<entry>
<title>bpf: Add security_file_post_open() LSM hook to sleepable_lsm_hooks</title>
<updated>2024-06-21T17:55:57Z</updated>
<author>
<name>Matt Bobrowski</name>
</author>
<published>2024-06-18T19:29:22Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=6ddf3a9abd9fdfdd63d8c906fc1393f7950c23f4'/>
<id>urn:sha1:6ddf3a9abd9fdfdd63d8c906fc1393f7950c23f4</id>
<content type='text'>
The new generic LSM hook security_file_post_open() was recently added
to the LSM framework in commit 8f46ff5767b0b ("security: Introduce
file_post_open hook"). Let's proactively add this generic LSM hook to
the sleepable_lsm_hooks BTF ID set, because I can't see there being
any strong reasons not to, and it's only a matter of time before
someone else comes around and asks for it to be there.

security_file_post_open() is inherently sleepable as it's purposely
situated in the kernel that allows LSMs to directly read out the
contents of the backing file if need be. Additionally, it's called
directly after security_file_open(), and that LSM hook in itself
already exists in the sleepable_lsm_hooks BTF ID set.

Signed-off-by: Matt Bobrowski &lt;mattbobrowski@google.com&gt;
Signed-off-by: Daniel Borkmann &lt;daniel@iogearbox.net&gt;
Link: https://lore.kernel.org/bpf/20240618192923.379852-1-mattbobrowski@google.com
</content>
</entry>
<entry>
<title>bpf: Minor clean-up to sleepable_lsm_hooks BTF set</title>
<updated>2024-02-01T17:37:45Z</updated>
<author>
<name>Matt Bobrowski</name>
</author>
<published>2024-02-01T10:43:40Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=1581e5118e485e82cfb5d04d636a79aaefb6f266'/>
<id>urn:sha1:1581e5118e485e82cfb5d04d636a79aaefb6f266</id>
<content type='text'>
There's already one main CONFIG_SECURITY_NETWORK ifdef block within
the sleepable_lsm_hooks BTF set. Consolidate this duplicated ifdef
block as there's no need for it and all things guarded by it should
remain in one place in this specific context.

Signed-off-by: Matt Bobrowski &lt;mattbobrowski@google.com&gt;
Signed-off-by: Daniel Borkmann &lt;daniel@iogearbox.net&gt;
Link: https://lore.kernel.org/bpf/Zbt1smz43GDMbVU3@google.com
</content>
</entry>
<entry>
<title>bpf,lsm: Add BPF token LSM hooks</title>
<updated>2024-01-25T00:21:01Z</updated>
<author>
<name>Andrii Nakryiko</name>
</author>
<published>2024-01-24T02:21:08Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=f568a3d49af9aed813a184353592efe29b0e3d16'/>
<id>urn:sha1:f568a3d49af9aed813a184353592efe29b0e3d16</id>
<content type='text'>
Wire up bpf_token_create and bpf_token_free LSM hooks, which allow to
allocate LSM security blob (we add `void *security` field to struct
bpf_token for that), but also control who can instantiate BPF token.
This follows existing pattern for BPF map and BPF prog.

Also add security_bpf_token_allow_cmd() and security_bpf_token_capable()
LSM hooks that allow LSM implementation to control and negate (if
necessary) BPF token's delegation of a specific bpf_cmd and capability,
respectively.

Signed-off-by: Andrii Nakryiko &lt;andrii@kernel.org&gt;
Signed-off-by: Alexei Starovoitov &lt;ast@kernel.org&gt;
Acked-by: Paul Moore &lt;paul@paul-moore.com&gt;
Link: https://lore.kernel.org/bpf/20240124022127.2379740-12-andrii@kernel.org
</content>
</entry>
<entry>
<title>bpf,lsm: Refactor bpf_map_alloc/bpf_map_free LSM hooks</title>
<updated>2024-01-25T00:21:01Z</updated>
<author>
<name>Andrii Nakryiko</name>
</author>
<published>2024-01-24T02:21:07Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=a2431c7eabcf9bd5a1e7a1f7ecded40fdda4a8c5'/>
<id>urn:sha1:a2431c7eabcf9bd5a1e7a1f7ecded40fdda4a8c5</id>
<content type='text'>
Similarly to bpf_prog_alloc LSM hook, rename and extend bpf_map_alloc
hook into bpf_map_create, taking not just struct bpf_map, but also
bpf_attr and bpf_token, to give a fuller context to LSMs.

Unlike bpf_prog_alloc, there is no need to move the hook around, as it
currently is firing right before allocating BPF map ID and FD, which
seems to be a sweet spot.

But like bpf_prog_alloc/bpf_prog_free combo, make sure that bpf_map_free
LSM hook is called even if bpf_map_create hook returned error, as if few
LSMs are combined together it could be that one LSM successfully
allocated security blob for its needs, while subsequent LSM rejected BPF
map creation. The former LSM would still need to free up LSM blob, so we
need to ensure security_bpf_map_free() is called regardless of the
outcome.

Signed-off-by: Andrii Nakryiko &lt;andrii@kernel.org&gt;
Signed-off-by: Alexei Starovoitov &lt;ast@kernel.org&gt;
Acked-by: Paul Moore &lt;paul@paul-moore.com&gt;
Link: https://lore.kernel.org/bpf/20240124022127.2379740-11-andrii@kernel.org
</content>
</entry>
</feed>
