All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH v1 0/2] XSM labels support in dom0less
@ 2026-08-27  9:38 Sergiy Kibrik
  2026-08-27  9:38 ` [PATCH v1 1/2] flask: add const qualifier to security_context_to_sid() Sergiy Kibrik
  2026-08-27  9:38 ` [PATCH v1 2/2] common: dom0less-bindings: introduce XSM labels Sergiy Kibrik
  0 siblings, 2 replies; 10+ messages in thread
From: Sergiy Kibrik @ 2026-08-27  9:38 UTC (permalink / raw)
  To: xen-devel@lists.xenproject.org
  Cc: Sergiy Kibrik, Daniel P. Smith, Stefano Stabellini, Julien Grall,
	Bertrand Marquis, Michal Orzel, Volodymyr Babchuk

Currently FLASK can't really be enforced for domains being brought up in
dom0less mode, as security contexts are not assigned for domains in this
configuration. Thus domains are left with default SECINITSID_UNLABELED SID
which policy forbids to create:

    (XEN) [    0.637379] avc:  denied  { create } for current=d[IDLE] scontext=system_u:system_r:xenboot_t tcontext=system_u:system_r:unlabeled_t tclass=domain

This series extends dom0less bindings with ability to provide human-readable
security context in domain's DTS configuration, replicating a toolstack
approach and naming.

 -Sergiy

Sergiy Kibrik (2):
  flask: add const qualifier to security_context_to_sid()
  common: dom0less-bindings: introduce XSM labels

 docs/misc/arm/device-tree/booting.txt      |  8 ++++++++
 xen/common/device-tree/Makefile            |  2 ++
 xen/common/device-tree/dom0less-bindings.c | 11 +++++++++++
 xen/xsm/flask/include/security.h           |  2 +-
 xen/xsm/flask/ss/services.c                |  2 +-
 5 files changed, 23 insertions(+), 2 deletions(-)

-- 
2.43.0

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2026-09-04 10:02 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-27  9:38 [PATCH v1 0/2] XSM labels support in dom0less Sergiy Kibrik
2026-08-27  9:38 ` [PATCH v1 1/2] flask: add const qualifier to security_context_to_sid() Sergiy Kibrik
2026-08-27 18:08   ` Daniel P. Smith
2026-08-28  6:40   ` Jan Beulich
2026-08-31 10:01     ` Sergiy Kibrik
2026-09-01  6:34       ` Jan Beulich
2026-08-27  9:38 ` [PATCH v1 2/2] common: dom0less-bindings: introduce XSM labels Sergiy Kibrik
2026-08-27 18:09   ` Daniel P. Smith
2026-08-31 10:19   ` Andrew Cooper
2026-09-04 10:01     ` Sergiy Kibrik

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.