Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1625735

Re: [PATCH net-next v6 10/11] bpf,landlock: Add tests for Landlock

Path csiph.com!aioe.org!bofh.it!news.nic.it!robomod
From Kees Cook <keescook@chromium.org>
Newsgroups linux.kernel
Subject Re: [PATCH net-next v6 10/11] bpf,landlock: Add tests for Landlock
Date Wed, 19 Apr 2017 02:00:02 +0200
Message-ID <txLcm-48r-1@gated-at.bofh.it> (permalink)
References <tq929-6KA-5@gated-at.bofh.it> <tq92a-6KA-21@gated-at.bofh.it> <txKzD-3PB-9@gated-at.bofh.it> <txLcm-48r-3@gated-at.bofh.it>
X-Original-To Mickaël Salaün <mic@digikod.net>
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc:content-transfer-encoding; bh=QXUnpBM9I8Zwl6UnNx3vkt+PYiit44sAh7nh/SiayCs=; b=hbGIVLoB95+DsAzxQJ5pHtTZVUeNsKTRA2H54CzFrgLiFgHTlxbGzP3OdW5S848a2i YYUYnvhDeVBFEUqzi2itQT/HCgGRBt1txdknjBN5W1ZKrm4f5lPQbMOEs43gcr7aPskQ nWuActrmjRpYIYG2LHpeg27BIKnoTwVNy4gkyGcuUuW671/ZaBsgtIETifoGcAsVYw7z vF3BqHzmyn8K9MVf2BEt6s46QoJbOPWgl8lLM1idXxFiTEcBr0ZLaZxPzgvIzO+Ytn0A XRGInrIlsYcQcc+gcGRy/FEQ6eXJbuWK8x2lGEcLM8DiVs1XXOho0J0Rt19tWwnKT0tf gcnQ==
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc:content-transfer-encoding; bh=QXUnpBM9I8Zwl6UnNx3vkt+PYiit44sAh7nh/SiayCs=; b=fx1zUfDsVT3/+pLQWB+LUUU5nT1ASaASsTv7qBjoD3gMCefkuQukC8IziG9aeMIBA7 +IM4VVHZXFyQQHX3+Tn+s+VrS04Qo8hhPmgti8EzKukJph/bQhGPsKC8ZdT/AwKRNdXe gC1yOh36k66AEjHD6ZlzFgZCIMeiZOqoFg+a8=
X-Google-Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc:content-transfer-encoding; bh=QXUnpBM9I8Zwl6UnNx3vkt+PYiit44sAh7nh/SiayCs=; b=grgT/WJmsevMzVksVtANjZGqQOOSXqK5v/UkDxwVdCJE5lm/hzFp3jMBJfF3U2EuzR 6M3BoWan/KUxlhAhkMjiBasnsK6Hy9vHX5FDfjjO5932i8WagTD/OtHBuCGbXQeF6gtr nIU3nqu2iYnU4tjnOsGAvRWWYSZQYBaJP4msGRYH4AdsvPNw+anj0xmUT9Ghq+1yG0Ow QcR6FgIAz6n7tGJPaYTSRjoNDdZds7P9qQ+8OPcbywNfhHpcbbejzkZKc0E1JoGl7cx8 uxFrwlUm+DTJMcaWnywVnoggHreSyRCUSu3iMLfAqeh8kkuWrBJc9pvYGZV1SlvsswU4 MAIA==
X-Gm-Message-State AN3rC/7OOx4vTz+ClAxzatRiH7iqjQQPSVnWzleFPzu02Mda/41RMS1l Vn0Ff7ezXLIPLUesskX4Q0TikGNouWpF
X-Received by 10.36.152.196 with SMTP id n187mr642560itd.28.1492559944219; Tue, 18 Apr 2017 16:59:04 -0700 (PDT)
MIME-Version 1.0
X-Google-Sender-Auth NbrWWmOWTDvhsrMsDz_a7Z5yELY
Content-Type text/plain; charset=UTF-8
Content-Transfer-Encoding quoted-printable
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 68
Organization linux.* mail to news gateway
X-Original-Cc LKML <linux-kernel@vger.kernel.org>, Alexei Starovoitov <ast@kernel.org>, Andy Lutomirski <luto@amacapital.net>, Arnaldo Carvalho de Melo <acme@kernel.org>, Casey Schaufler <casey@schaufler-ca.com>, Daniel Borkmann <daniel@iogearbox.net>, David Drysdale <drysdale@google.com>, "David S . Miller" <davem@davemloft.net>, "Eric W . Biederman" <ebiederm@xmission.com>, James Morris <james.l.morris@oracle.com>, Jann Horn <jann@thejh.net>, Jonathan Corbet <corbet@lwn.net>, Matthew Garrett <mjg59@srcf.ucam.org>, Michael Kerrisk <mtk.manpages@gmail.com>, Paul Moore <paul@paul-moore.com>, Sargun Dhillon <sargun@sargun.me>, "Serge E . Hallyn" <serge@hallyn.com>, Shuah Khan <shuah@kernel.org>, Tejun Heo <tj@kernel.org>, Thomas Graf <tgraf@suug.ch>, Will Drewry <wad@chromium.org>, "kernel-hardening@lists.openwall.com" <kernel-hardening@lists.openwall.com>, Linux API <linux-api@vger.kernel.org>, linux-security-module <linux-security-module@vger.kernel.org>, Network Development <netdev@vger.kernel.org>
X-Original-Date Tue, 18 Apr 2017 16:59:03 -0700
X-Original-Message-ID <CAGXu5jJp2Nt47EDL=wvqUuk4kTcExBqm1KbQtFOL_BTE+rybjQ@mail.gmail.com>
X-Original-References <20170328234650.19695-1-mic@digikod.net> <20170328234650.19695-11-mic@digikod.net> <CAGXu5j+-sFD5z2daPjvM0Q8vM=g9ZtwJ7-ZakqoUcjsiAD=+1A@mail.gmail.com> <f5291c43-100f-a06c-6c64-c718a02822df@digikod.net>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1625735

Show key headers only | View raw


On Tue, Apr 18, 2017 at 4:53 PM, Mickaël Salaün <mic@digikod.net> wrote:
> On 19/04/2017 01:16, Kees Cook wrote:
>> On Tue, Mar 28, 2017 at 4:46 PM, Mickaël Salaün <mic@digikod.net> wrote:
>>> --- /dev/null
>>> +++ b/tools/testing/selftests/landlock/Makefile
>>> @@ -0,0 +1,47 @@
>>> +LIBDIR := ../../../lib
>>> +BPFOBJ := $(LIBDIR)/bpf/bpf.o
>>> +LOADOBJ := ../../../../samples/bpf/bpf_load.o
>>
>> Is the selftest tarball creation tool okay with this? IIRC, it should
>> be fine since it'll be a built object already, but it's a random
>> thought I had while looking at this.
>
> Hum, I'll check since it's the same for BPF tests.

Okay, cool.

>>> +# asm/sysreg.h - inline assembly used by it is incompatible with llvm.
>>> +# But, there is no easy way to fix it, so just exclude it since it is
>>> +# useless for BPF samples.
>>> +$(obj)/%.o: $(src)/%.c
>>> +       $(CLANG) $(NOSTDINC_FLAGS) $(LINUXINCLUDE) $(EXTRA_CFLAGS) \
>>> +               -D__KERNEL__ -D__ASM_SYSREG_H -Wno-unused-value -Wno-pointer-sign \
>>> +               -Wno-compare-distinct-pointer-types \
>>> +               -Wno-gnu-variable-sized-type-not-at-end \
>>> +               -Wno-tautological-compare \
>>> +               -O2 -emit-llvm -c $< -o -| $(LLC) -march=bpf -filetype=obj -o $@
>>
>> Is clang required for the samples and the selftests? That needs to be
>> avoided... there needs to be a way to show people how to build a
>> landlock rule without requiring clang.
>
> I can rewrite this tests without requiring clang but it is already
> required for BPF tests…

So, I guess it's not a big deal for selftests (but it'd be nice, even
for BPF), but I think at least the samples/ should have examples on
how to do it "by hand", etc. Not everyone will build stuff with clang,
and it'd be good to make landlock as available as possible.

>>> +#define ASSERT_STEP(cond) \
>>> +       { \
>>> +               step--; \
>>> +               if (!(cond)) \
>>> +                       _exit(step); \
>>> +       }
>>
>> Can you explain this in more detail? I'm assuming there is a problem
>> with writing to the TH_LOG_STREAM fd or something?
>
> It's a trick to use the test framework without requiring to be allowed
> to write to an FD (i.e. log stream), but only to exit a code. I use this
> to test a Landlock rule which forbid access to any FS objects (including
> open FD). This could be used for seccomp too.

Okay. For seccomp, we just allow the fd. :P I'm not opposed to it; it
just makes some debugging harder without text details, etc.

-Kees

-- 
Kees Cook
Pixel Security

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Re: [PATCH net-next v6 10/11] bpf,landlock: Add tests for Landlock Kees Cook <keescook@chromium.org> - 2017-04-19 01:20 +0200
  Re: [PATCH net-next v6 10/11] bpf,landlock: Add tests for Landlock Kees Cook <keescook@chromium.org> - 2017-04-19 02:00 +0200
  Re: [PATCH net-next v6 10/11] bpf,landlock: Add tests for Landlock Mickaël Salaün <mic@digikod.net> - 2017-04-19 02:00 +0200

csiph-web