From: Christian Brauner <brauner@kernel.org>
To: Jann Horn <jannh@google.com>
Cc: "Paul Moore" <paul@paul-moore.com>,
"James Morris" <jmorris@namei.org>,
"Serge E. Hallyn" <serge@hallyn.com>,
"Stephen Smalley" <stephen.smalley.work@gmail.com>,
"Jeff Xu" <jeffxu@google.com>,
"Thiébaud Weksteen" <tweek@google.com>,
"Alexander Viro" <viro@zeniv.linux.org.uk>,
"Jan Kara" <jack@suse.cz>,
linux-fsdevel@vger.kernel.org,
linux-security-module@vger.kernel.org,
"Ondrej Mosnacek" <omosnace@redhat.com>,
selinux@vger.kernel.org,
"Andrew Morton" <akpm@linux-foundation.org>,
"Liam R. Howlett" <liam@infradead.org>,
"Lorenzo Stoakes" <ljs@kernel.org>,
"Vlastimil Babka" <vbabka@kernel.org>,
"Pedro Falcato" <pfalcato@suse.de>,
"David Hildenbrand" <david@kernel.org>,
linux-mm@kvack.org
Subject: Re: [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS)
Date: Wed, 26 Aug 2026 15:01:21 +0200 [thread overview]
Message-ID: <20260826-rotor-heterogen-wollust-2091c20f5e30@brauner> (raw)
In-Reply-To: <20260826-juror-energetisch-hackordnung-83810c82adcf@brauner>
On Wed, Aug 26, 2026 at 12:29:14PM +0200, Christian Brauner wrote:
> On Tue, Aug 25, 2026 at 04:00:40PM +0200, Jann Horn wrote:
> > On Tue, Aug 25, 2026 at 3:19 PM Christian Brauner <brauner@kernel.org> wrote:
> > > On Tue, Aug 18, 2026 at 09:51:06PM +0200, Jann Horn wrote:
> > > > If the system is running with PROC_MEM_FORCE_ALWAYS, LSMs currently have no
> > > > good opportunity to block a process from overwriting read-only code in its
> > > > own address space through FOLL_FORCE writes via /proc/self/mem.
> > > > The security_ptrace_access_check() LSM hook is bypassed when a process
> > > > opens /proc/self/mem because this is considered "introspection".
> > > >
> > > > This causes a hole in SELinux EXECMEM enforcement, which tries to ensure
> > > > that a process cannot create executable anonymous pages.
> > > >
> > > > PROC_MEM_FORCE_PTRACE prevents that and ensures that such FOLL_FORCE
> > > > accesses are only possible when the LSM allows ptrace() attachment; but it
> > > > is unclear how quickly PROC_MEM_FORCE_PTRACE can be deployed in
> > > > environments running lots of third-party code, such as Android.
> > > >
> > > > So, introduce a new LSM hook that can forbid FOLL_FORCE specifically for
> > > > such "introspective" accesses.
> > > >
> > > > Signed-off-by: Jann Horn <jannh@google.com>
> > > > ---
> > > > fs/proc/base.c | 6 ++++++
> > > > include/linux/lsm_hook_defs.h | 1 +
> > > > include/linux/security.h | 6 ++++++
> > > > security/security.c | 15 +++++++++++++++
> > > > 4 files changed, 28 insertions(+)
> > > >
> > > > diff --git a/fs/proc/base.c b/fs/proc/base.c
> > > > index bec6197329dc..3dfaef49bb70 100644
> > > > --- a/fs/proc/base.c
> > > > +++ b/fs/proc/base.c
> > > > @@ -851,6 +851,8 @@ static int __mem_open(struct inode *inode, struct file *file, unsigned int mode)
> > > > /* private_data for proc_mem_operations */
> > > > struct mem_private {
> > > > struct mm_struct *mm;
> > > > + /* Was the ptrace access check bypassed due to introspection? */
> > > > + bool introspection;
> > > > };
> > > >
> > > > static int mem_open(struct inode *inode, struct file *file)
> > > > @@ -864,12 +866,14 @@ static int mem_open(struct inode *inode, struct file *file)
> > > > priv->mm = proc_mem_open(inode, PTRACE_MODE_ATTACH);
> > > > if (IS_ERR_OR_NULL(priv->mm))
> > > > return priv->mm ? PTR_ERR(priv->mm) : -ESRCH;
> > > > + priv->introspection = priv->mm == current->mm;
> > > > file->private_data = no_free_ptr(priv);
> > > > return 0;
> > > > }
> > > >
> > > > static bool proc_mem_foll_force(struct file *file, struct mm_struct *mm)
> > > > {
> > > > + struct mem_private *priv = file->private_data;
> > > > struct task_struct *task;
> > > > bool ptrace_active = false;
> > > >
> > > > @@ -886,6 +890,8 @@ static bool proc_mem_foll_force(struct file *file, struct mm_struct *mm)
> > > > }
> > > > return ptrace_active;
> > > > default:
> > > > + if (priv->introspection)
> > > > + return security_introspect_mem_foll_force(file->f_cred) == 0;
> > >
> > > Hm. Why not pass the reason to security_introspect_mem_foll_force() and
> > > call it unconditionally? Similarly it could also be called for the
> > > active ptracer case. Then you'd just need to pass a flag to the security
> > > hook and the LSM can decide based on that.
> >
> > A process which is attached as a ptracer can modify memory with (for
> > example) PTRACE_POKETEXT and registers with (for example)
> > PTRACE_SETREGS. LSMs that want to prevent such debugging operations
> > are supposed to prevent ptrace attachment with the ptrace_access_check
> > hook.
>
> Yeah, but as I said elsewhere that is very very coarse and you can't
> differentiate between the different operations performed on the other
> task.
>
> > I am just trying to plug the enforcement hole where ptrace-style
> > modification of process state is possible without going through
> > ptrace_access_check - which means just looking at these
> > "introspection" cases.
>
> It seems odd to just call a hook when it's introspection denied.
> And if that's the case why not also have a general hook in
> ptrace_may_access() itself in the introspection branch?
>
> I would actually have use-cases for this btw.
To be clear: I have no quarrels with this going in as is. I'm just
interested in how policy decision such as this can be made more
meaningful in general. If you have thoughts around this you want to
share, please do.
next prev parent reply other threads:[~2026-08-26 13:01 UTC|newest]
Thread overview: 37+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-18 19:51 [PATCH 0/3] proc,security,selinux: let SELinux block FOLL_FORCE for /proc/self/mem Jann Horn
2026-08-18 19:51 ` [PATCH 1/3] proc: refactor /proc/$pid/mem to use struct as private_data Jann Horn
2026-08-20 11:20 ` Jan Kara
2026-08-20 17:18 ` David Hildenbrand (Arm)
2026-08-21 18:34 ` Lorenzo Stoakes (ARM)
2026-08-18 19:51 ` [PATCH 2/3] proc: query LSMs for introspective mem access (if PROC_MEM_FORCE_ALWAYS) Jann Horn
2026-08-20 17:22 ` David Hildenbrand (Arm)
2026-08-20 18:44 ` Jann Horn
2026-08-21 14:18 ` David Hildenbrand (Arm)
2026-08-21 14:48 ` Jann Horn
2026-08-21 18:52 ` Lorenzo Stoakes (ARM)
2026-08-24 17:06 ` Jann Horn
2026-08-24 17:32 ` Lorenzo Stoakes (ARM)
2026-08-24 17:43 ` Jann Horn
2026-08-25 13:42 ` Lorenzo Stoakes (ARM)
2026-08-25 14:08 ` Jann Horn
2026-08-25 14:24 ` Lorenzo Stoakes (ARM)
2026-08-25 15:00 ` Jann Horn
2026-08-26 13:05 ` Lorenzo Stoakes (ARM)
2026-08-21 19:00 ` Lorenzo Stoakes (ARM)
2026-08-24 17:28 ` Jann Horn
2026-08-25 14:02 ` Lorenzo Stoakes (ARM)
2026-08-25 13:13 ` Christian Brauner
2026-08-25 13:46 ` Jann Horn
2026-08-26 10:26 ` Christian Brauner
2026-08-25 13:19 ` Christian Brauner
2026-08-25 14:00 ` Jann Horn
2026-08-26 10:29 ` Christian Brauner
2026-08-26 13:01 ` Christian Brauner [this message]
2026-08-26 16:17 ` Jann Horn
2026-08-18 19:51 ` [PATCH 3/3] selinux: require EXECMEM or PTRACE for FOLL_FORCE introspection Jann Horn
2026-08-19 14:54 ` Stephen Smalley
2026-08-20 15:23 ` Jann Horn
2026-08-21 13:52 ` Stephen Smalley
2026-08-21 15:07 ` Jann Horn
2026-08-21 18:56 ` Lorenzo Stoakes (ARM)
2026-08-24 17:17 ` Jann Horn
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260826-rotor-heterogen-wollust-2091c20f5e30@brauner \
--to=brauner@kernel.org \
--cc=akpm@linux-foundation.org \
--cc=david@kernel.org \
--cc=jack@suse.cz \
--cc=jannh@google.com \
--cc=jeffxu@google.com \
--cc=jmorris@namei.org \
--cc=liam@infradead.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=linux-security-module@vger.kernel.org \
--cc=ljs@kernel.org \
--cc=omosnace@redhat.com \
--cc=paul@paul-moore.com \
--cc=pfalcato@suse.de \
--cc=selinux@vger.kernel.org \
--cc=serge@hallyn.com \
--cc=stephen.smalley.work@gmail.com \
--cc=tweek@google.com \
--cc=vbabka@kernel.org \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox