From: Mikhail Ivanov <ivanov.mikhail1@huawei-partners.com>
To: Stephen Smalley <stephen.smalley.work@gmail.com>
Cc: "Mickaël Salaün" <mic@digikod.net>,
paul@paul-moore.com, selinux@vger.kernel.org,
omosnace@redhat.com, linux-security-module@vger.kernel.org,
netdev@vger.kernel.org, yusongping@huawei.com,
artem.kuzin@huawei.com, konstantin.meskhidze@huawei.com
Subject: Re: [PATCH] selinux: Read sk->sk_family once in selinux_socket_bind()
Date: Fri, 13 Dec 2024 19:40:07 +0300 [thread overview]
Message-ID: <fe8fe02f-db3b-a4a2-508f-dda8b434d44a@huawei-partners.com> (raw)
In-Reply-To: <CAEjxPJ737irXncrwoM3avg4L+U37QB2w+fjJZZYTjND5Z4_Nig@mail.gmail.com>
On 12/13/2024 6:46 PM, Stephen Smalley wrote:
> On Fri, Dec 13, 2024 at 5:57 AM Mikhail Ivanov
> <ivanov.mikhail1@huawei-partners.com> wrote:
>>
>> On 12/12/2024 8:50 PM, Mickaël Salaün wrote:
>>> This looks good be there are other places using sk->sk_family that
>>> should also be fixed.
>>
>> Thanks for checking this!
>>
>> For selinux this should be enough, I haven't found any other places
>> where sk->sk_family could be read from an IPv6 socket without locking.
>>
>> I also would like to prepare such fix for other LSMs (apparmor, smack,
>> tomoyo) (in separate patches).
>
> I'm wondering about the implications for SELinux beyond just
> sk->sk_family access, e.g. SELinux maps the (family, type, protocol)
> triple to a security class at socket creation time via
> socket_type_to_security_class() and caches the security class in the
> inode_security_struct and sk_security_struct for later use.
IPv6 and IPv4 TCP sockets are mapped to the same SECCLASS_TCP_SOCKET
security class. AFAICS there is no other places that can be affected by
the IPV6_ADDFORM transformation.
>
>>
>>>
>>> On Thu, Dec 12, 2024 at 06:20:00PM +0800, Mikhail Ivanov wrote:
>>>> selinux_socket_bind() is called without holding the socket lock.
>>>>
>>>> Use READ_ONCE() to safely read sk->sk_family for IPv6 socket in case
>>>> of lockless transformation to IPv4 socket via IPV6_ADDRFORM [1].
>>>>
>>>> [1] https://lore.kernel.org/all/20240202095404.183274-1-edumazet@google.com/
>>>>
>>>> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
>>>> Signed-off-by: Mikhail Ivanov <ivanov.mikhail1@huawei-partners.com>
>>>> ---
>>>> security/selinux/hooks.c | 4 +++-
>>>> 1 file changed, 3 insertions(+), 1 deletion(-)
>>>>
>>>> diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
>>>> index 5e5f3398f39d..b7adff2cf5f6 100644
>>>> --- a/security/selinux/hooks.c
>>>> +++ b/security/selinux/hooks.c
>>>> @@ -4715,8 +4715,10 @@ static int selinux_socket_bind(struct socket *sock, struct sockaddr *address, in
>>>> if (err)
>>>> goto out;
>>>>
>>>> + /* IPV6_ADDRFORM can change sk->sk_family under us. */
>>>> + family = READ_ONCE(sk->sk_family);
>>>> +
>>>> /* If PF_INET or PF_INET6, check name_bind permission for the port. */
>>>> - family = sk->sk_family;
>>>> if (family == PF_INET || family == PF_INET6) {
>>>> char *addrp;
>>>> struct common_audit_data ad;
>>>>
>>>> base-commit: 034294fbfdf0ded4f931f9503d2ca5bbf8b9aebd
>>>> --
>>>> 2.34.1
>>>>
>>>>
next prev parent reply other threads:[~2024-12-13 16:40 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-12-12 10:20 [PATCH] selinux: Read sk->sk_family once in selinux_socket_bind() Mikhail Ivanov
2024-12-12 17:50 ` Mickaël Salaün
2024-12-13 10:57 ` Mikhail Ivanov
2024-12-13 15:46 ` Stephen Smalley
2024-12-13 16:40 ` Mikhail Ivanov [this message]
2024-12-13 19:12 ` Stephen Smalley
2024-12-13 20:09 ` Paul Moore
2025-01-07 20:16 ` Stephen Smalley
2025-01-07 21:00 ` Paul Moore
2025-01-09 16:28 ` Mikhail Ivanov
2025-01-07 20:13 ` Stephen Smalley
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=fe8fe02f-db3b-a4a2-508f-dda8b434d44a@huawei-partners.com \
--to=ivanov.mikhail1@huawei-partners.com \
--cc=artem.kuzin@huawei.com \
--cc=konstantin.meskhidze@huawei.com \
--cc=linux-security-module@vger.kernel.org \
--cc=mic@digikod.net \
--cc=netdev@vger.kernel.org \
--cc=omosnace@redhat.com \
--cc=paul@paul-moore.com \
--cc=selinux@vger.kernel.org \
--cc=stephen.smalley.work@gmail.com \
--cc=yusongping@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.