From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f197.google.com (mail-pf1-f197.google.com [209.85.210.197]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1669B2EEE6C for ; Thu, 13 Aug 2026 00:26:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.197 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786580809; cv=none; b=qVHX3D1UQhbjSucA0krlDaMF0AiqkSmxcUoEwvislInGHbWUm8tXx44AIIM1mo7lnug7IvbDaMO90W34/MUGXAaX5I9QNjB/upPrFKMepm2AKRB0/PB1u7Kg/l6u3LaX6tDRDBD3NZ++oq3AzTCCszvqoQoR7kanETJNJN1PtE4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786580809; c=relaxed/simple; bh=5se711kePA411xaoz5RodsO+PLdGel9RlS6q8G/sC4I=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=bFkuQFW6m8fBH6Fvt82mpeQNoLph/w0aU1rAuVoAe9q1I22KEL8JgmBlchOx3VBmUbccJTqcRiAE9ktapC4Lcb/83BfJz3COEmWFW/ZdhDbmNcnObKAdvSizk5OKnCkPmPF1gw0vWOgTgNbGpZkgYj2j3h3PeQ4UgyBytDwKx5c= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--tweek.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=PLPeZ39k; arc=none smtp.client-ip=209.85.210.197 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--tweek.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="PLPeZ39k" Received: by mail-pf1-f197.google.com with SMTP id d2e1a72fcca58-84f7002f9afso1561901b3a.3 for ; Wed, 12 Aug 2026 17:26:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1786580807; x=1787185607; darn=vger.kernel.org; h=content-transfer-encoding:content-type:cc:to:from:subject :message-id:references:mime-version:in-reply-to:date:from:to:cc :subject:date:message-id:reply-to:content-type; bh=Qkjz+h+zNCGoWltKJetL2Y2JT1Z7HAkSp1FmTaM3CtU=; b=PLPeZ39kIdPQ9wekhs0NzjRWi0g5wU9Prl+htO8xBcFkU3JCSA1SE+liU26MJMGsE5 ByhTiXnyRWgD59RcAct4IrEAjcZoPU7NR2PqLOLU8tlCk4OOIG/1EBit6OoqTy1GFSFm H2OcpN+BH4NmrPKnvdV88+SKddhxHQkku6jYjGkny99+NX2knla7Q0mmxyARdUr6oBM6 E7jWGqVo7QBmfMo3FBp+I8LOM8XjJG3eIN8tFwTNCc1CD95G1GYCIEbsxN0gzpF3kS20 9ippzqsPZ2zOFqmAs8+5bVijVypsJbv8Vhx7af4d049+yxa3orpHGPpG0zuUakufFLSD CHng== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786580807; x=1787185607; h=content-transfer-encoding:content-type:cc:to:from:subject :message-id:references:mime-version:in-reply-to:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Qkjz+h+zNCGoWltKJetL2Y2JT1Z7HAkSp1FmTaM3CtU=; b=EFHQpmBHgT88ptCg1RaayJQbyigfQWExLlXJeuatb0JdErQQXmCn0Vj3DcIvAo37L4 DixsgNqR5aa7YJ1sYFjqyVR1dxiaue7TT3v8z1Brgg80j1aiXxQCTpmGl3AyB1SDLuKS WbwW8dbwSW9Wugd8a/pG2CY+0ZdZh1Uqz0J92UVxSN/yYbtjjdIUx1ecjRQp5MMH0c6I dkNQISpltKqYWTzR73KjpRMXr0D5HZH/mXeEfS6zR8zvjUUExzlBt1V72yEir16u+cZk VXODLU3TEW2e1lw8cX9piGDKSblsBa0fo2yo/zkFGTH1AdHzlG4u2g97i3qsPJFpE719 CKkw== X-Forwarded-Encrypted: i=1; AHgh+RoaauDwJg5QGD4tAdmD7CpHtW8TpPjdbter2CZyNFe3FZPT1mUG9xMe1J5DNWNqAhwlpq0=@vger.kernel.org X-Gm-Message-State: AOJu0Yzmqe63wJ0YgiUoo5lBmt44aIrQZxrlDUHk9N2kfVFhjYvmhX+0 k+sXxOXIvzvgxqFcFtKKilGCPXSUudWV7o6PFF0YjYMHYDa1ZgAAiRUI/lf57xuejYiMQ7jCOr+ LXA== X-Received: from pfx22.prod.google.com ([2002:a05:6a00:a456:b0:84b:50b5:d431]) (user=tweek job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:44cb:b0:848:4080:afe8 with SMTP id d2e1a72fcca58-84fc751547fmr1831794b3a.22.1786580807349; Wed, 12 Aug 2026 17:26:47 -0700 (PDT) Date: Thu, 13 Aug 2026 10:26:16 +1000 In-Reply-To: <20260813002618.3755631-1-tweek@google.com> Precedence: bulk X-Mailing-List: bpf@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260813002618.3755631-1-tweek@google.com> X-Mailer: git-send-email 2.55.0.691.gc56d675ccc-goog Message-ID: <20260813002618.3755631-4-tweek@google.com> Subject: [PATCH bpf-next 3/5] selinux: use kernel sid in security_bpf_* From: "=?UTF-8?q?Thi=C3=A9baud=20Weksteen?=" To: Paul Moore , Stephen Smalley , Alexei Starovoitov , Daniel Borkmann , Andrii Nakryiko , Jeffrey Vander Stoep Cc: "=?UTF-8?q?Thi=C3=A9baud=20Weksteen?=" , Ondrej Mosnacek , Eric Suen , Blaise Boscaccy , Sid Nayyar , Neill Kapron , Eric Biggers , Greg Kroah-Hartman , KP Singh , bpf@vger.kernel.org, selinux@vger.kernel.org, linux-kernel@vger.kernel.org Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable The security_bpf hooks provides a boolean to indicate if the call is coming from within the kernel or not. If true, use the kernel SID instead of relying on the current process SID. For the token-aware functions, the kernel sid is used to decide on the access, but the caller remains owner of the object (program or map). Signed-off-by: Thi=C3=A9baud Weksteen --- security/selinux/hooks.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c index f197cf476190..e7c5993f6954 100644 --- a/security/selinux/hooks.c +++ b/security/selinux/hooks.c @@ -7181,7 +7181,7 @@ static int selinux_ib_alloc_security(void *ib_sec) static int selinux_bpf(int cmd, union bpf_attr *attr, unsigned int size, bool kernel) { - u32 sid =3D current_sid(); + u32 sid =3D kernel ? SECINITSID_KERNEL : current_sid(); int ret; =20 if (selinux_policycap_bpf_token_perms()) @@ -7296,7 +7296,7 @@ static int selinux_bpf_map_create(struct bpf_map *map= , union bpf_attr *attr, bpfsec->sid =3D current_sid(); =20 if (!token) - ssid =3D bpfsec->sid; + ssid =3D kernel ? SECINITSID_KERNEL : bpfsec->sid; else ssid =3D selinux_bpffs_creator_sid(attr->map_token_fd); =20 @@ -7314,7 +7314,7 @@ static int selinux_bpf_prog_load(struct bpf_prog *pro= g, union bpf_attr *attr, bpfsec->sid =3D current_sid(); =20 if (!token) - ssid =3D bpfsec->sid; + ssid =3D kernel ? SECINITSID_KERNEL : bpfsec->sid; else ssid =3D selinux_bpffs_creator_sid(attr->prog_token_fd); =20 --=20 2.55.0.691.gc56d675ccc-goog