* [PATCH v3] common: dom0less-bindings: introduce XSM labels
@ 2026-10-02 10:25 Sergiy Kibrik
[not found] ` <f24de507-2aac-4619-83f8-37e66f93cfb9@apertussolutions.com>
2026-10-05 14:20 ` Alejandro Vallejo
0 siblings, 2 replies; 3+ messages in thread
From: Sergiy Kibrik @ 2026-10-02 10:25 UTC (permalink / raw)
To: xen-devel@lists.xenproject.org
Cc: Sergiy Kibrik, Stefano Stabellini, Julien Grall, Bertrand Marquis,
Volodymyr Babchuk, Daniel P. Smith, Andrew Cooper, Michal Orzel,
Jan Beulich
Add "seclabel" property to be able to specify security label for a domain
when XSM Flask is enabled, similar to xl configuration files.
Currently guest domain can't be created by Xen in dom0less configuration when
Flask is enabled, as domain is assigned "system_u:system_r:unlabeled_t" label
by default, which Flask denies to create according to current policy.
Because code from outside of flask can't directly execute its internal API
a new routine flask_context_to_sid() introduced as part of XSM API exposed
to rest of Xen, which is a direct wrapper for security_context_to_sid().
Signed-off-by: Sergiy Kibrik <Sergiy_Kibrik@epam.com>
CC: Daniel P. Smith <dpsmith@apertussolutions.com>
CC: Andrew Cooper <andrew.cooper3@citrix.com>
CC: Michal Orzel <michal.orzel@amd.com>
CC: Jan Beulich <jbeulich@suse.com>
---
changes in v3:
- panic if `seclabel` property found but FLASK is disabled
changes in v2:
- add & use flask_context_to_sid() wrapper
---
docs/misc/arm/device-tree/booting.txt | 7 +++++++
xen/common/device-tree/dom0less-bindings.c | 13 +++++++++++++
xen/include/xsm/xsm.h | 3 +++
xen/xsm/flask/hooks.c | 5 +++++
4 files changed, 28 insertions(+)
diff --git a/docs/misc/arm/device-tree/booting.txt b/docs/misc/arm/device-tree/booting.txt
index bcb06bc796..d04455b744 100644
--- a/docs/misc/arm/device-tree/booting.txt
+++ b/docs/misc/arm/device-tree/booting.txt
@@ -345,6 +345,11 @@ with the following properties:
not passed. This configuration requires static allocation (xen,static-mem)
and direct mapping (direct-map).
+- seclabel
+
+ A string property specifying an XSM security label to this domain. Domains
+ will be classified “unlabeled” if this property not specified.
+
Under the "xen,domain" compatible node, one or more sub-nodes are present
for the DomU kernel and ramdisk.
@@ -422,6 +427,7 @@ chosen {
memory = <0 131072>;
cpus = <2>;
vpl011;
+ seclabel = "system_u:system_r:domU_t";
vcpu0 {
compatible = "xen,vcpu";
@@ -453,6 +459,7 @@ chosen {
#size-cells = <0x1>;
memory = <0 65536>;
cpus = <1>;
+ seclabel = "system_u:system_r:domU_t";
module@0x4c000000 {
compatible = "multiboot,kernel", "multiboot,module";
diff --git a/xen/common/device-tree/dom0less-bindings.c b/xen/common/device-tree/dom0less-bindings.c
index 41d72d0d58..01d5cc1bc9 100644
--- a/xen/common/device-tree/dom0less-bindings.c
+++ b/xen/common/device-tree/dom0less-bindings.c
@@ -11,6 +11,8 @@
#include <public/bootfdt.h>
#include <public/domctl.h>
+#include <xsm/xsm.h>
+
int __init parse_dom0less_node(struct dt_device_node *node,
struct boot_domain *bd)
{
@@ -21,6 +23,7 @@ int __init parse_dom0less_node(struct dt_device_node *node,
bool has_dtb = false;
bool iommu = false;
const char *dom0less_iommu = NULL;
+ const char *xsm_seclabel = NULL;
if ( !dt_device_is_compatible(node, "xen,domain") )
return -ENOENT;
@@ -141,5 +144,15 @@ int __init parse_dom0less_node(struct dt_device_node *node,
panic("'llc-colors' found, but LLC coloring is disabled\n");
#endif
+ if ( !dt_property_read_string(node, "seclabel", &xsm_seclabel) )
+ {
+ if ( !IS_ENABLED(CONFIG_XSM_FLASK) )
+ panic("'seclabel' found, but FLASK is disabled\n");
+ else if ( flask_context_to_sid(xsm_seclabel, strlen(xsm_seclabel),
+ &d_cfg->ssidref) )
+ panic("Invalid security context for domain: %s\n",
+ xsm_seclabel);
+ }
+
return arch_parse_dom0less_node(node, bd);
}
diff --git a/xen/include/xsm/xsm.h b/xen/include/xsm/xsm.h
index 9809e005e0..73d058a8b2 100644
--- a/xen/include/xsm/xsm.h
+++ b/xen/include/xsm/xsm.h
@@ -261,4 +261,7 @@ static inline bool has_xsm_magic(paddr_t start)
#endif /* CONFIG_XSM */
+int flask_context_to_sid(const char *scontext,
+ uint32_t scontext_len, uint32_t *sid);
+
#endif /* __XSM_H */
diff --git a/xen/xsm/flask/hooks.c b/xen/xsm/flask/hooks.c
index d65ba0aeae..0b44a2a3d9 100644
--- a/xen/xsm/flask/hooks.c
+++ b/xen/xsm/flask/hooks.c
@@ -2016,6 +2016,11 @@ const struct xsm_ops *__init flask_init(
return &flask_ops;
}
+int flask_context_to_sid(const char *scontext, uint32_t scontext_len, uint32_t *sid)
+{
+ return security_context_to_sid(scontext, scontext_len, sid);
+}
+
/*
* Local variables:
* mode: C
--
2.43.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH v3] common: dom0less-bindings: introduce XSM labels
[not found] ` <f24de507-2aac-4619-83f8-37e66f93cfb9@apertussolutions.com>
@ 2026-10-05 11:18 ` Orzel, Michal
0 siblings, 0 replies; 3+ messages in thread
From: Orzel, Michal @ 2026-10-05 11:18 UTC (permalink / raw)
To: Daniel P. Smith, Sergiy Kibrik, xen-devel@lists.xenproject.org
Cc: Stefano Stabellini, Julien Grall, Bertrand Marquis,
Volodymyr Babchuk, Andrew Cooper, Jan Beulich
On 03-Oct-26 23:34, Daniel P. Smith wrote:
> On 10/2/26 6:25 AM, Sergiy Kibrik wrote:
>> Add "seclabel" property to be able to specify security label for a domain
>> when XSM Flask is enabled, similar to xl configuration files.
>>
>> Currently guest domain can't be created by Xen in dom0less configuration when
>> Flask is enabled, as domain is assigned "system_u:system_r:unlabeled_t" label
>> by default, which Flask denies to create according to current policy.
>>
>> Because code from outside of flask can't directly execute its internal API
>> a new routine flask_context_to_sid() introduced as part of XSM API exposed
>> to rest of Xen, which is a direct wrapper for security_context_to_sid().
>>
>> Signed-off-by: Sergiy Kibrik <Sergiy_Kibrik@epam.com>
>> CC: Daniel P. Smith <dpsmith@apertussolutions.com>
>> CC: Andrew Cooper <andrew.cooper3@citrix.com>
>> CC: Michal Orzel <michal.orzel@amd.com>
>> CC: Jan Beulich <jbeulich@suse.com>
>> ---
>> changes in v3:
>> - panic if `seclabel` property found but FLASK is disabled
>> changes in v2:
>> - add & use flask_context_to_sid() wrapper
>> ---
>
> <snip/>
>
>> diff --git a/xen/common/device-tree/dom0less-bindings.c b/xen/common/device-tree/dom0less-bindings.c
>> index 41d72d0d58..01d5cc1bc9 100644
>> --- a/xen/common/device-tree/dom0less-bindings.c
>> +++ b/xen/common/device-tree/dom0less-bindings.c
>> @@ -11,6 +11,8 @@
>> #include <public/bootfdt.h>
>> #include <public/domctl.h>
>>
>> +#include <xsm/xsm.h>
>> +
>> int __init parse_dom0less_node(struct dt_device_node *node,
>> struct boot_domain *bd)
>> {
>> @@ -21,6 +23,7 @@ int __init parse_dom0less_node(struct dt_device_node *node,
>> bool has_dtb = false;
>> bool iommu = false;
>> const char *dom0less_iommu = NULL;
>> + const char *xsm_seclabel = NULL;
>>
>> if ( !dt_device_is_compatible(node, "xen,domain") )
>> return -ENOENT;
>> @@ -141,5 +144,15 @@ int __init parse_dom0less_node(struct dt_device_node *node,
>> panic("'llc-colors' found, but LLC coloring is disabled\n");
>> #endif
>>
>> + if ( !dt_property_read_string(node, "seclabel", &xsm_seclabel) )
>> + {
>> + if ( !IS_ENABLED(CONFIG_XSM_FLASK) )
>> + panic("'seclabel' found, but FLASK is disabled\n");
>
> Ultimately it's up to you, but I'm not sure you really will want to
> panic here. I personally would warn it was set but ignored because FLASK
> is not enabled.
I explicitly requested this in v2 to match the user/Xen contract we want on Arm
(we want to panic on unsatisfied user requests to prevent silent degradation of
functionality).
~Michal
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH v3] common: dom0less-bindings: introduce XSM labels
2026-10-02 10:25 [PATCH v3] common: dom0less-bindings: introduce XSM labels Sergiy Kibrik
[not found] ` <f24de507-2aac-4619-83f8-37e66f93cfb9@apertussolutions.com>
@ 2026-10-05 14:20 ` Alejandro Vallejo
1 sibling, 0 replies; 3+ messages in thread
From: Alejandro Vallejo @ 2026-10-05 14:20 UTC (permalink / raw)
To: Sergiy Kibrik, xen-devel@lists.xenproject.org
Cc: Stefano Stabellini, Julien Grall, Bertrand Marquis,
Volodymyr Babchuk, Daniel P. Smith, Andrew Cooper, Michal Orzel,
Jan Beulich
On Fri Oct 2, 2026 at 12:25 PM CEST, Sergiy Kibrik wrote:
> Add "seclabel" property to be able to specify security label for a domain
> when XSM Flask is enabled, similar to xl configuration files.
>
> Currently guest domain can't be created by Xen in dom0less configuration when
> Flask is enabled, as domain is assigned "system_u:system_r:unlabeled_t" label
> by default, which Flask denies to create according to current policy.
>
> Because code from outside of flask can't directly execute its internal API
> a new routine flask_context_to_sid() introduced as part of XSM API exposed
> to rest of Xen, which is a direct wrapper for security_context_to_sid().
>
> Signed-off-by: Sergiy Kibrik <Sergiy_Kibrik@epam.com>
> CC: Daniel P. Smith <dpsmith@apertussolutions.com>
> CC: Andrew Cooper <andrew.cooper3@citrix.com>
> CC: Michal Orzel <michal.orzel@amd.com>
> CC: Jan Beulich <jbeulich@suse.com>
> ---
> changes in v3:
> - panic if `seclabel` property found but FLASK is disabled
> changes in v2:
> - add & use flask_context_to_sid() wrapper
> ---
> docs/misc/arm/device-tree/booting.txt | 7 +++++++
> xen/common/device-tree/dom0less-bindings.c | 13 +++++++++++++
> xen/include/xsm/xsm.h | 3 +++
> xen/xsm/flask/hooks.c | 5 +++++
> 4 files changed, 28 insertions(+)
>
> diff --git a/docs/misc/arm/device-tree/booting.txt b/docs/misc/arm/device-tree/booting.txt
> index bcb06bc796..d04455b744 100644
> --- a/docs/misc/arm/device-tree/booting.txt
> +++ b/docs/misc/arm/device-tree/booting.txt
> @@ -345,6 +345,11 @@ with the following properties:
> not passed. This configuration requires static allocation (xen,static-mem)
> and direct mapping (direct-map).
>
> +- seclabel
> +
> + A string property specifying an XSM security label to this domain. Domains
> + will be classified “unlabeled” if this property not specified.
This paragraph assumes FLASK=y, but many configurations of Xen do not ship it.
Perhaps it would be prudent to state what happens (kaboom) when you load
a DTB with this prop on a FLASK=n hypervisor.
> +
> Under the "xen,domain" compatible node, one or more sub-nodes are present
> for the DomU kernel and ramdisk.
>
> @@ -422,6 +427,7 @@ chosen {
> memory = <0 131072>;
> cpus = <2>;
> vpl011;
> + seclabel = "system_u:system_r:domU_t";
>
> vcpu0 {
> compatible = "xen,vcpu";
> @@ -453,6 +459,7 @@ chosen {
> #size-cells = <0x1>;
> memory = <0 65536>;
> cpus = <1>;
> + seclabel = "system_u:system_r:domU_t";
>
> module@0x4c000000 {
> compatible = "multiboot,kernel", "multiboot,module";
> diff --git a/xen/common/device-tree/dom0less-bindings.c b/xen/common/device-tree/dom0less-bindings.c
> index 41d72d0d58..01d5cc1bc9 100644
> --- a/xen/common/device-tree/dom0less-bindings.c
> +++ b/xen/common/device-tree/dom0less-bindings.c
> @@ -11,6 +11,8 @@
> #include <public/bootfdt.h>
> #include <public/domctl.h>
>
> +#include <xsm/xsm.h>
> +
> int __init parse_dom0less_node(struct dt_device_node *node,
> struct boot_domain *bd)
> {
> @@ -21,6 +23,7 @@ int __init parse_dom0less_node(struct dt_device_node *node,
> bool has_dtb = false;
> bool iommu = false;
> const char *dom0less_iommu = NULL;
> + const char *xsm_seclabel = NULL;
>
> if ( !dt_device_is_compatible(node, "xen,domain") )
> return -ENOENT;
> @@ -141,5 +144,15 @@ int __init parse_dom0less_node(struct dt_device_node *node,
> panic("'llc-colors' found, but LLC coloring is disabled\n");
> #endif
>
> + if ( !dt_property_read_string(node, "seclabel", &xsm_seclabel) )
> + {
> + if ( !IS_ENABLED(CONFIG_XSM_FLASK) )
> + panic("'seclabel' found, but FLASK is disabled\n");
> + else if ( flask_context_to_sid(xsm_seclabel, strlen(xsm_seclabel),
nit: else if could be plain if
> + &d_cfg->ssidref) )
> + panic("Invalid security context for domain: %s\n",
> + xsm_seclabel);
bad indentation of the panic statement. At the proper 4 blanks from the
conditional branch, panic() fits in 80 lines. Fewer with s/Invalid/Bad/.
> + }
> +
> return arch_parse_dom0less_node(node, bd);
> }
> diff --git a/xen/include/xsm/xsm.h b/xen/include/xsm/xsm.h
> index 9809e005e0..73d058a8b2 100644
> --- a/xen/include/xsm/xsm.h
> +++ b/xen/include/xsm/xsm.h
> @@ -261,4 +261,7 @@ static inline bool has_xsm_magic(paddr_t start)
>
> #endif /* CONFIG_XSM */
>
> +int flask_context_to_sid(const char *scontext,
> + uint32_t scontext_len, uint32_t *sid);
nit: with s/context/ctxt/ this fits in a single line, otherwise...
> +
> #endif /* __XSM_H */
> diff --git a/xen/xsm/flask/hooks.c b/xen/xsm/flask/hooks.c
> index d65ba0aeae..0b44a2a3d9 100644
> --- a/xen/xsm/flask/hooks.c
> +++ b/xen/xsm/flask/hooks.c
> @@ -2016,6 +2016,11 @@ const struct xsm_ops *__init flask_init(
> return &flask_ops;
> }
>
> +int flask_context_to_sid(const char *scontext, uint32_t scontext_len, uint32_t *sid)
... this one needs to be split as it crosses the 80 columns boundary.
> +{
> + return security_context_to_sid(scontext, scontext_len, sid);
> +}
> +
> /*
> * Local variables:
> * mode: C
Cheers,
Alejandro
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-05 14:20 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-02 10:25 [PATCH v3] common: dom0less-bindings: introduce XSM labels Sergiy Kibrik
[not found] ` <f24de507-2aac-4619-83f8-37e66f93cfb9@apertussolutions.com>
2026-10-05 11:18 ` Orzel, Michal
2026-10-05 14:20 ` Alejandro Vallejo
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.