Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1718791

Re: [PATCH net-next v7 05/10] landlock: Add LSM hooks related to filesystem

From Alexei Starovoitov <alexei.starovoitov@gmail.com>
Newsgroups linux.kernel
Subject Re: [PATCH net-next v7 05/10] landlock: Add LSM hooks related to filesystem
Date 2017-08-24 05:00 +0200
Message-ID <uhQxc-wP-5@gated-at.bofh.it> (permalink)
References <ugIBH-5t8-1@gated-at.bofh.it> <ugIBI-5t8-7@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Mon, Aug 21, 2017 at 02:09:28AM +0200, Mickaël Salaün wrote:
> Handle 33 filesystem-related LSM hooks for the Landlock filesystem
> event: LANDLOCK_SUBTYPE_EVENT_FS.
> 
> A Landlock event wrap LSM hooks for similar kernel object types (e.g.
> struct file, struct path...). Multiple LSM hooks can trigger the same
> Landlock event.
> 
> Landlock handle nine coarse-grained actions: read, write, execute, new,
> get, remove, ioctl, lock and fcntl. Each of them abstract LSM hook
> access control in a way that can be extended in the future.
> 
> The Landlock LSM hook registration is done after other LSM to only run
> actions from user-space, via eBPF programs, if the access was granted by
> major (privileged) LSMs.
> 
> Signed-off-by: Mickaël Salaün <mic@digikod.net>

...

> +/* WRAP_ARG_SB */
> +#define WRAP_ARG_SB_TYPE	WRAP_TYPE_FS
> +#define WRAP_ARG_SB_DEC(arg)					\
> +	EXPAND_C(WRAP_TYPE_FS) wrap_##arg =			\
> +	{ .type = BPF_HANDLE_FS_TYPE_DENTRY, .dentry = arg->s_root };
> +#define WRAP_ARG_SB_VAL(arg)	((uintptr_t)&wrap_##arg)
> +#define WRAP_ARG_SB_OK(arg)	(arg && arg->s_root)
...

> +HOOK_NEW_FS(sb_remount, 2,
> +	struct super_block *, sb,
> +	void *, data,
> +	WRAP_ARG_SB, sb,
> +	WRAP_ARG_RAW, LANDLOCK_ACTION_FS_WRITE
> +);

this looks wrong. casting super_block to dentry?

> +/* a directory inode contains only one dentry */
> +HOOK_NEW_FS(inode_create, 3,
> +	struct inode *, dir,
> +	struct dentry *, dentry,
> +	umode_t, mode,
> +	WRAP_ARG_INODE, dir,
> +	WRAP_ARG_RAW, LANDLOCK_ACTION_FS_WRITE
> +);

more general question: why you're not wrapping all useful
arguments? Like in the above dentry can be acted upon
by the landlock rule and it's readily available...

The limitation of only 2 args looks odd.
Is it a hard limitation ? how hard to extend?

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH net-next v7 00/10] Landlock LSM: Toward unprivileged sandboxing Mickaël Salaün <mic@digikod.net> - 2017-08-21 02:20 +0200
  [PATCH net-next v7 04/10] bpf: Define handle_fs and add a new helper bpf_handle_fs_get_mode() Mickaël Salaün <mic@digikod.net> - 2017-08-21 02:20 +0200
  [PATCH net-next v7 07/10] landlock: Add ptrace restrictions Mickaël Salaün <mic@digikod.net> - 2017-08-21 02:20 +0200
  [PATCH net-next v7 01/10] selftest: Enhance kselftest_harness.h with a step mechanism Mickaël Salaün <mic@digikod.net> - 2017-08-21 02:20 +0200
    Re: [PATCH net-next v7 01/10] selftest: Enhance kselftest_harness.h  with a step mechanism Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2017-08-24 04:40 +0200
      Re: [PATCH net-next v7 01/10] selftest: Enhance kselftest_harness.h  with a step mechanism Mickaël Salaün <mic@digikod.net> - 2017-08-25 10:10 +0200
  [PATCH net-next v7 09/10] bpf,landlock: Add tests for Landlock Mickaël Salaün <mic@digikod.net> - 2017-08-21 02:20 +0200
  [PATCH net-next v7 08/10] bpf: Add a Landlock sandbox example Mickaël Salaün <mic@digikod.net> - 2017-08-21 02:20 +0200
    Re: [PATCH net-next v7 08/10] bpf: Add a Landlock sandbox example Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2017-08-24 05:00 +0200
      Re: [PATCH net-next v7 08/10] bpf: Add a Landlock sandbox example Mickaël Salaün <mic@digikod.net> - 2017-08-25 10:20 +0200
  [PATCH net-next v7 05/10] landlock: Add LSM hooks related to filesystem Mickaël Salaün <mic@digikod.net> - 2017-08-21 02:20 +0200
    Re: [PATCH net-next v7 05/10] landlock: Add LSM hooks related to  filesystem Mickaël Salaün <mic@digikod.net> - 2017-08-23 00:10 +0200
    Re: [PATCH net-next v7 05/10] landlock: Add LSM hooks related to  filesystem Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2017-08-24 05:00 +0200
      Re: [PATCH net-next v7 05/10] landlock: Add LSM hooks related to  filesystem Mickaël Salaün <mic@digikod.net> - 2017-08-25 10:20 +0200
  [PATCH net-next v7 03/10] bpf,landlock: Define an eBPF program type for a Landlock rule Mickaël Salaün <mic@digikod.net> - 2017-08-21 02:20 +0200
    Re: [PATCH net-next v7 03/10] bpf,landlock: Define an eBPF program  type for a Landlock rule Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2017-08-24 04:40 +0200
      Re: [PATCH net-next v7 03/10] bpf,landlock: Define an eBPF program  type for a Landlock rule Mickaël Salaün <mic@digikod.net> - 2017-08-25 10:10 +0200
  [PATCH net-next v7 06/10] seccomp,landlock: Handle Landlock events per process hierarchy Mickaël Salaün <mic@digikod.net> - 2017-08-21 02:20 +0200
  [PATCH net-next v7 10/10] landlock: Add user and kernel documentation for Landlock Mickaël Salaün <mic@digikod.net> - 2017-08-21 02:20 +0200
  [PATCH net-next v7 02/10] bpf: Add eBPF program subtype and is_valid_subtype() verifier Mickaël Salaün <mic@digikod.net> - 2017-08-21 02:20 +0200
    Re: [PATCH net-next v7 02/10] bpf: Add eBPF program subtype and  is_valid_subtype() verifier Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2017-08-23 04:50 +0200
      Re: [PATCH net-next v7 02/10] bpf: Add eBPF program subtype and  is_valid_subtype() verifier Mickaël Salaün <mic@digikod.net> - 2017-08-23 09:50 +0200
        Re: [PATCH net-next v7 02/10] bpf: Add eBPF program subtype and  is_valid_subtype() verifier Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2017-08-24 03:30 +0200

csiph-web