Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1503877

Re: [RFC v3 06/22] landlock: Add LSM hooks

From Thomas Graf <tgraf@suug.ch>
Newsgroups linux.kernel
Subject Re: [RFC v3 06/22] landlock: Add LSM hooks
Date 2016-10-19 17:20 +0200
Message-ID <su0OS-308-53@gated-at.bofh.it> (permalink)
References <shcNP-6gS-15@gated-at.bofh.it> <shcXv-6ki-13@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On 09/14/16 at 09:23am, Mickaël Salaün wrote:
> diff --git a/include/linux/bpf.h b/include/linux/bpf.h
> index 9aa01d9d3d80..36c3e482239c 100644
> --- a/include/linux/bpf.h
> +++ b/include/linux/bpf.h
> @@ -85,6 +85,8 @@ enum bpf_arg_type {
>  
>  	ARG_PTR_TO_CTX,		/* pointer to context */
>  	ARG_ANYTHING,		/* any (initialized) argument is ok */
> +
> +	ARG_PTR_TO_STRUCT_FILE,		/* pointer to struct file */

This should go into patch 7 I guess?

> +void __init landlock_add_hooks(void)
> +{
> +	pr_info("landlock: Becoming ready for sandboxing\n");
> +	security_add_hooks(landlock_hooks, ARRAY_SIZE(landlock_hooks));
> +}

Can we add the hooks when we load the first BPF program for a hook? That
would also allow to not make this conditional on a new config option
which all all distros have to enable anyway.

I would really like to see this patch split into the LSM part which
allows running BPF progs at LSM and your specific sandboxing use case
which requires the new BPF helpers, new reg type, etc.

Back to linux.kernel | Previous | NextNext in thread | Find similar | Unroll thread


Thread

Re: [RFC v3 06/22] landlock: Add LSM hooks Thomas Graf <tgraf@suug.ch> - 2016-10-19 17:20 +0200
  Re: [RFC v3 06/22] landlock: Add LSM hooks Mickaël Salaün <mic@digikod.net> - 2016-10-20 00:50 +0200

csiph-web