linux-fsdevel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH v2 bpf-next 0/4] bpf path iterator
@ 2025-06-03  6:59 Song Liu
  2025-06-03  6:59 ` [PATCH v2 bpf-next 1/4] namei: Introduce new helper function path_walk_parent() Song Liu
                   ` (3 more replies)
  0 siblings, 4 replies; 23+ messages in thread
From: Song Liu @ 2025-06-03  6:59 UTC (permalink / raw)
  To: bpf, linux-fsdevel, linux-kernel, linux-security-module
  Cc: kernel-team, andrii, eddyz87, ast, daniel, martin.lau, viro,
	brauner, jack, kpsingh, mattbobrowski, amir73il, repnop, jlayton,
	josef, mic, gnoack, m, Song Liu

In security use cases, it is common to apply rules to VFS subtrees.
However, filtering files in a subtree is not straightforward [1].

One solution to this problem is to start from a path and walk up the VFS
tree (towards the root). Among in-tree LSMs, Landlock uses this solution.

BPF LSM solutions, such like Tetragon [2], also use similar approaches.
However, due to lack of proper helper/kfunc support, BPF LSM solutions
usually do the path walk with probe read, which is racy.

This patchset introduce a reliable helper path_walk_parent, which walks
path to its VFS parent. The helper is use in Landlock.

A new BPF iterator, path iterator, is introduced to do the path walking.
The BPF path iterator uses the new path_walk_parent help to walk the VFS
tree.

Changes v1 => v2:
1. Rename path_parent => path_walk_parent.
2. Remove path_connected check in path_walk_parent.
3. Fix is_access_to_paths_allowed().
4. Remove mode for path iterator, add a flag instead.

v1: https://lore.kernel.org/bpf/20250528222623.1373000-1-song@kernel.org/


[1] https://lpc.events/event/18/contributions/1940/
[2] https://github.com/cilium/tetragon/

Song Liu (4):
  namei: Introduce new helper function path_walk_parent()
  landlock: Use path_walk_parent()
  bpf: Introduce path iterator
  selftests/bpf: Add tests for bpf path iterator

 fs/namei.c                                    |  52 +++++++
 include/linux/namei.h                         |   2 +
 kernel/bpf/Makefile                           |   1 +
 kernel/bpf/helpers.c                          |   3 +
 kernel/bpf/path_iter.c                        |  58 ++++++++
 kernel/bpf/verifier.c                         |   5 +
 security/landlock/fs.c                        |  31 ++--
 .../testing/selftests/bpf/bpf_experimental.h  |   6 +
 .../selftests/bpf/prog_tests/path_iter.c      |  12 ++
 tools/testing/selftests/bpf/progs/path_iter.c | 134 ++++++++++++++++++
 10 files changed, 283 insertions(+), 21 deletions(-)
 create mode 100644 kernel/bpf/path_iter.c
 create mode 100644 tools/testing/selftests/bpf/prog_tests/path_iter.c
 create mode 100644 tools/testing/selftests/bpf/progs/path_iter.c

--
2.47.1

^ permalink raw reply	[flat|nested] 23+ messages in thread

end of thread, other threads:[~2025-06-06 17:01 UTC | newest]

Thread overview: 23+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-06-03  6:59 [PATCH v2 bpf-next 0/4] bpf path iterator Song Liu
2025-06-03  6:59 ` [PATCH v2 bpf-next 1/4] namei: Introduce new helper function path_walk_parent() Song Liu
2025-06-06 11:10   ` Mickaël Salaün
2025-06-06 14:40   ` Al Viro
2025-06-06 17:01     ` Song Liu
2025-06-03  6:59 ` [PATCH v2 bpf-next 2/4] landlock: Use path_walk_parent() Song Liu
2025-06-03 13:46   ` Mickaël Salaün
2025-06-04 19:37     ` Song Liu
2025-06-05 16:47       ` Song Liu
2025-06-06 10:46         ` Mickaël Salaün
2025-06-03  6:59 ` [PATCH v2 bpf-next 3/4] bpf: Introduce path iterator Song Liu
2025-06-03 15:13   ` Alexei Starovoitov
2025-06-04 17:22     ` Christian Brauner
2025-06-03 18:40   ` Andrii Nakryiko
2025-06-03 20:49     ` Yonghong Song
2025-06-03 21:10       ` Song Liu
2025-06-03 21:09     ` Song Liu
2025-06-03 21:44       ` Andrii Nakryiko
2025-06-03 23:20         ` Song Liu
2025-06-04 20:37           ` Andrii Nakryiko
2025-06-05 19:27   ` Matt Bobrowski
2025-06-05 21:14     ` Song Liu
2025-06-03  6:59 ` [PATCH v2 bpf-next 4/4] selftests/bpf: Add tests for bpf " Song Liu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).