From: "Daniel P. Smith" <dpsmith@apertussolutions.com>
To: Sergiy Kibrik <Sergiy_Kibrik@epam.com>,
"xen-devel@lists.xenproject.org" <xen-devel@lists.xenproject.org>
Cc: Stefano Stabellini <sstabellini@kernel.org>,
Julien Grall <julien@xen.org>,
Bertrand Marquis <bertrand.marquis@arm.com>,
Michal Orzel <michal.orzel@amd.com>,
Volodymyr Babchuk <Volodymyr_Babchuk@epam.com>
Subject: Re: [PATCH v1 2/2] common: dom0less-bindings: introduce XSM labels
Date: Thu, 27 Aug 2026 14:09:54 -0400 [thread overview]
Message-ID: <35391c92-c01d-43d5-b89a-7eb086a292a5@apertussolutions.com> (raw)
In-Reply-To: <e97ab666be0d667dc823c3d881ac9ed76267a7a5.1787821757.git.Sergiy_Kibrik@epam.com>
On 8/27/26 5:38 AM, Sergiy Kibrik wrote:
> Add "seclabel" property to be able to specify security label for a domain
> when XSM Flask is enabled, similar to xl configuration files.
>
> Currently guest domain can't be created by Xen in dom0less configuration when
> Flask is enabled, as domain is assigned "system_u:system_r:unlabeled_t" label
> by default, which Flask denies to create according to current policy.
>
> Signed-off-by: Sergiy Kibrik <Sergiy_Kibrik@epam.com>
> ---
> docs/misc/arm/device-tree/booting.txt | 8 ++++++++
> xen/common/device-tree/Makefile | 2 ++
> xen/common/device-tree/dom0less-bindings.c | 11 +++++++++++
> 3 files changed, 21 insertions(+)
>
> diff --git a/docs/misc/arm/device-tree/booting.txt b/docs/misc/arm/device-tree/booting.txt
> index bcb06bc796..fcc7be0ffb 100644
> --- a/docs/misc/arm/device-tree/booting.txt
> +++ b/docs/misc/arm/device-tree/booting.txt
> @@ -345,6 +345,12 @@ with the following properties:
> not passed. This configuration requires static allocation (xen,static-mem)
> and direct mapping (direct-map).
>
> +- seclabel
> +
> + A string property specifying an XSM security label to this domain. Effective
> + only when FLASK is enabled. Domains will be classified “unlabeled” if
> + this property not specified.
> +
> Under the "xen,domain" compatible node, one or more sub-nodes are present
> for the DomU kernel and ramdisk.
>
> @@ -422,6 +428,7 @@ chosen {
> memory = <0 131072>;
> cpus = <2>;
> vpl011;
> + seclabel = "system_u:system_r:domU_t";
>
> vcpu0 {
> compatible = "xen,vcpu";
> @@ -453,6 +460,7 @@ chosen {
> #size-cells = <0x1>;
> memory = <0 65536>;
> cpus = <1>;
> + seclabel = "system_u:system_r:domU_t";
>
> module@0x4c000000 {
> compatible = "multiboot,kernel", "multiboot,module";
> diff --git a/xen/common/device-tree/Makefile b/xen/common/device-tree/Makefile
> index 9036e455d6..e4de292533 100644
> --- a/xen/common/device-tree/Makefile
> +++ b/xen/common/device-tree/Makefile
> @@ -11,3 +11,5 @@ obj-$(CONFIG_DOMAIN_BUILD_HELPERS) += kernel.o
> obj-$(CONFIG_STATIC_EVTCHN) += static-evtchn.init.o
> obj-$(CONFIG_STATIC_MEMORY) += static-memory.init.o
> obj-$(CONFIG_STATIC_SHM) += static-shmem.init.o
> +
> +CFLAGS-y += -I$(srctree)/xsm/flask/include
> diff --git a/xen/common/device-tree/dom0less-bindings.c b/xen/common/device-tree/dom0less-bindings.c
> index 41d72d0d58..bffd2ec65d 100644
> --- a/xen/common/device-tree/dom0less-bindings.c
> +++ b/xen/common/device-tree/dom0less-bindings.c
> @@ -11,6 +11,8 @@
> #include <public/bootfdt.h>
> #include <public/domctl.h>
>
> +#include <security.h>
> +
> int __init parse_dom0less_node(struct dt_device_node *node,
> struct boot_domain *bd)
> {
> @@ -21,6 +23,7 @@ int __init parse_dom0less_node(struct dt_device_node *node,
> bool has_dtb = false;
> bool iommu = false;
> const char *dom0less_iommu = NULL;
> + const char *xsm_seclabel = NULL;
>
> if ( !dt_device_is_compatible(node, "xen,domain") )
> return -ENOENT;
> @@ -141,5 +144,13 @@ int __init parse_dom0less_node(struct dt_device_node *node,
> panic("'llc-colors' found, but LLC coloring is disabled\n");
> #endif
>
> + if ( IS_ENABLED(CONFIG_XSM_FLASK) &&
> + !dt_property_read_string(node, "seclabel", &xsm_seclabel) )
> + {
> + if ( security_context_to_sid(xsm_seclabel, strlen(xsm_seclabel),
> + &d_cfg->ssidref) )
> + panic("Invalid security context for domain: %s\n", xsm_seclabel);
> + }
> +
> return arch_parse_dom0less_node(node, bd);
> }
Acked-by: Daniel P. Smith <dpsmith@apertussolutions.com>
next prev parent reply other threads:[~2026-08-27 18:10 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-27 9:38 [PATCH v1 0/2] XSM labels support in dom0less Sergiy Kibrik
2026-08-27 9:38 ` [PATCH v1 1/2] flask: add const qualifier to security_context_to_sid() Sergiy Kibrik
2026-08-27 18:08 ` Daniel P. Smith
2026-08-28 6:40 ` Jan Beulich
2026-08-31 10:01 ` Sergiy Kibrik
2026-09-01 6:34 ` Jan Beulich
2026-08-27 9:38 ` [PATCH v1 2/2] common: dom0less-bindings: introduce XSM labels Sergiy Kibrik
2026-08-27 18:09 ` Daniel P. Smith [this message]
2026-08-31 10:19 ` Andrew Cooper
2026-09-04 10:01 ` Sergiy Kibrik
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=35391c92-c01d-43d5-b89a-7eb086a292a5@apertussolutions.com \
--to=dpsmith@apertussolutions.com \
--cc=Sergiy_Kibrik@epam.com \
--cc=Volodymyr_Babchuk@epam.com \
--cc=bertrand.marquis@arm.com \
--cc=julien@xen.org \
--cc=michal.orzel@amd.com \
--cc=sstabellini@kernel.org \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.