BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Justin Suess" <utilityemal77@gmail.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next 10/13] bpf: Add the bpf_landlock_restrict_binprm kfunc
Date: Fri, 31 Jul 2026 02:46:37 +0000	[thread overview]
Message-ID: <20260731024637.9D4E81F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260731022047.189137-11-utilityemal77@gmail.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] Multiple calls to bpf_landlock_restrict_binprm() do not compose; a later call replaces a previously staged restriction instead of intersecting it, violating BPF LSM composition principles.
- [Medium] bpf_landlock_kfunc_filter incorrectly restricts the release kfunc bpf_landlock_put_ruleset to only the two bprm sleepable hooks, violating the stated design and preventing valid reference cleanup in other LSM hooks.
--

--- Patch [10]: [PATCH bpf-next 10/13] bpf: Add the bpf_landlock_restrict_binprm kfunc ---
commit fe3f43b90a0bd65c9f7f90c67126bdf361901840
Author: Justin Suess <utilityemal77@gmail.com>

bpf: Add the bpf_landlock_restrict_binprm kfunc

This commit adds the bpf_landlock_restrict_binprm kfunc to enforce Landlock
rulesets on execution credentials. The restriction is staged and committed at
the execution's point of no return. It also limits the enforcement to specific
LSM hooks.

> diff --git a/kernel/bpf/bpf_lsm.c b/kernel/bpf/bpf_lsm.c
> index 9ff1c35fcd6e5..67aa902f12570 100644
> --- a/kernel/bpf/bpf_lsm.c
> +++ b/kernel/bpf/bpf_lsm.c

[ ... ]

> @@ -535,6 +535,42 @@ __bpf_kfunc void bpf_landlock_put_ruleset(struct bpf_landlock_ruleset *ruleset)
>  	security_policy_kptr_put(LSM_ID_LANDLOCK, &policy);
>  }
>  
> +/**
> + * bpf_landlock_restrict_binprm - Enforce a Landlock ruleset on exec
> + *                                credentials
> + * @bprm: execution context providing the prepared credentials to
> + *        restrict
> + * @ruleset: Landlock ruleset to enforce
> + * @flags: landlock_restrict_self(2) flags, except
> + *         %LANDLOCK_RESTRICT_SELF_TSYNC
> + *
> + * Restrict the credentials prepared in @bprm with @ruleset, so that
> + * the executed task starts confined by it, following the same domain
> + * composition rules as landlock_restrict_self(2).  The restriction is
> + * staged and only committed at the execution's point of no return: an
> + * execution that fails before that point is unaffected, and a later
> + * call on the same execution replaces a previously staged
> + * restriction.  @ruleset is only borrowed: the caller keeps its
> + * reference.
> + *
> + * The landlock_restrict_self(2) flags apply with their usual
> + * semantics.  Only %LANDLOCK_RESTRICT_SELF_TSYNC is rejected, as it
> + * targets the calling threads rather than the execution.
> + *
> + * Return: 0 on success, -EOPNOTSUPP if the Landlock LSM is not
> + * enabled, -EINVAL if @flags contains an unsupported flag, other
> + * negative values on failure as for landlock_restrict_self(2).
> + */
> +__bpf_kfunc int bpf_landlock_restrict_binprm(struct linux_binprm *bprm,
> +					     struct bpf_landlock_ruleset *ruleset,
> +					     u32 flags)
> +{
> +	union lsm_policy_kptr policy = { .landlock.ruleset = ruleset };
> +
> +	return security_bprm_enforce_policy_kptr(LSM_ID_LANDLOCK, bprm,
> +						 &policy, flags);

[Severity: High]
Does replacing instead of intersecting the ruleset break the BPF LSM
composition principles?

If multiple BPF LSM programs are attached to the same hook, a later call to
bpf_landlock_restrict_binprm() replaces a previously staged restriction
rather than layering or intersecting it.

This allows a subsequent program to completely bypass and discard the security
policy enforced by an earlier program.

> +}
> +

[ ... ]

> @@ -566,7 +605,10 @@ BTF_ID_LIST_SINGLE(bpf_landlock_get_ruleset_ids, func,
>   * in the fd table of the task that set the ruleset up, so
>   * bpf_landlock_get_ruleset_from_fd() is exclusive to syscall
>   * programs, which run in that task's context; an LSM program runs in
> - * the context of the task it mediates.
> + * the context of the task it mediates.  Enforcement is exclusive to
> + * the sleepable bprm LSM hooks the policy operation is specified
> + * for, and the release kfunc is allowed wherever a reference can be
> + * held.
>   */
>  static int bpf_landlock_kfunc_filter(const struct bpf_prog *prog, u32 kfunc_id)
>  {
> @@ -575,6 +617,8 @@ static int bpf_landlock_kfunc_filter(const struct bpf_prog *prog, u32 kfunc_id)
>  
>  	switch (prog->type) {
>  	case BPF_PROG_TYPE_SYSCALL:
> +		if (kfunc_id == bpf_landlock_restrict_binprm_ids[0])
> +			return -EACCES;
>  		return 0;
>  	case BPF_PROG_TYPE_LSM:
>  		if (kfunc_id == bpf_landlock_get_ruleset_ids[0])

[Severity: Medium]
Does the bpf_landlock_kfunc_filter() logic inadvertently restrict the release
kfunc as well?

The updated comment states that the release kfunc (bpf_landlock_put_ruleset)
is allowed wherever a reference can be held.

However, in the BPF_PROG_TYPE_LSM case, the filter still applies this check
to all kfuncs (including the release kfunc) instead of isolating it to the
restriction kfunc:

	if (!btf_id_set_contains(&bpf_landlock_kfunc_hooks,
				 prog->aux->attach_btf_id))
		return -EACCES;

This prevents BPF LSM programs attached to non-bprm hooks from calling
bpf_landlock_put_ruleset() to release acquired ruleset references.

Should there be an exemption for the release kfunc here?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260731022047.189137-1-utilityemal77@gmail.com?part=10

  reply	other threads:[~2026-07-31  2:46 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-31  2:20 [PATCH bpf-next 00/13] BPF interface for applying Landlock rulesets Justin Suess
2026-07-31  2:20 ` [PATCH bpf-next 01/13] lsm: Add LSM hook security_policy_kptr_from_fd Justin Suess
2026-07-31  2:20 ` [PATCH bpf-next 02/13] lsm: Add LSM hook security_policy_kptr_put Justin Suess
2026-07-31  2:44   ` sashiko-bot
2026-07-31  2:20 ` [PATCH bpf-next 03/13] lsm: Add LSM hook security_bprm_enforce_policy_kptr Justin Suess
2026-07-31  2:20 ` [PATCH bpf-next 04/13] landlock: Expose the ruleset fd lookup to the rest of Landlock Justin Suess
2026-07-31  2:20 ` [PATCH bpf-next 05/13] landlock: Factor the credential restriction out of landlock_restrict_self() Justin Suess
2026-07-31  2:20 ` [PATCH bpf-next 06/13] landlock: Implement the LSM policy kptr hooks Justin Suess
2026-07-31  2:20 ` [PATCH bpf-next 07/13] bpf: Add the LSM policy kfunc infrastructure Justin Suess
2026-07-31  2:20 ` [PATCH bpf-next 08/13] bpf: Add the bpf_landlock_put_ruleset kfunc and ruleset destructor Justin Suess
2026-07-31  2:46   ` sashiko-bot
2026-07-31  2:20 ` [PATCH bpf-next 09/13] bpf: Add the bpf_landlock_get_ruleset_from_fd kfunc Justin Suess
2026-07-31  2:20 ` [PATCH bpf-next 10/13] bpf: Add the bpf_landlock_restrict_binprm kfunc Justin Suess
2026-07-31  2:46   ` sashiko-bot [this message]
2026-07-31  2:20 ` [PATCH bpf-next 11/13] selftests/bpf: Add tests for the Landlock policy kfuncs Justin Suess
2026-07-31  2:20 ` [PATCH bpf-next 12/13] landlock: Document the BPF kfunc interface Justin Suess
2026-07-31  2:45   ` sashiko-bot
2026-07-31  2:20 ` [PATCH bpf-next 13/13] lsm: Document the LSM policy kptr hooks Justin Suess

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260731024637.9D4E81F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=utilityemal77@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox