From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk1-f173.google.com (mail-qk1-f173.google.com [209.85.222.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4C3501A38F9 for ; Fri, 28 Aug 2026 01:10:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.173 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787879454; cv=none; b=JzdasFw0SZXjLPm2DTlms5I/mwxuYr+1nguOZxXXepR9giss1wYFEtsIxzdRwsbEaqgkaOpRJtrJGGHurNYGKDobEzHOVNMGqSAK4vb/S95JENV78KinkM4E3qb7jf7LOJAX36zVDoyG/6A0t2pgF90P7C78/QH/901gJgZH178= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787879454; c=relaxed/simple; bh=NFG1n41lVJCrqXWncd4MldYqy9CGGkGjSMKD/ApclJM=; h=Date:Message-ID:MIME-Version:Content-Type:From:To:Cc:Subject: References:In-Reply-To; b=tD15StsIVs56VaAAqoAHY+D+l6+Tey7Q4s/705mWVlkdwF2HjQvPNoypsicSe/xbXtPO9bxRs992smlmHDX8ziTYiZqMYHNAb/Cyh+jlvSwOexXrn81s++YBgJKVBSN8pMy3Ov4TjQGPPRKXdzivbHQQfps9xzYfPzwcNMYdvjU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com; spf=pass smtp.mailfrom=paul-moore.com; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b=DiexHerO; arc=none smtp.client-ip=209.85.222.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b="DiexHerO" Received: by mail-qk1-f173.google.com with SMTP id af79cd13be357-9390a2c8909so26091585a.0 for ; Thu, 27 Aug 2026 18:10:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=paul-moore.com; s=google; t=1787879449; x=1788484249; darn=vger.kernel.org; h=in-reply-to:references:subject:cc:to:from:content-transfer-encoding :content-type:mime-version:message-id:date:from:to:cc:subject:date :message-id:reply-to:content-type; bh=DqRGrR0heNmSPrtTW9+v9FKZZ7RwzxehXvY0MCzvxnw=; b=DiexHerO6+IFexSx6JA9an3k0XR2yhU62zhjz0PIvuFDUeoTTa7PZx2vVbdtp+2Z+z fc4/yiZkz88x+eA0bilvSLbQdQxku2hqt4Ux3oQ5feErrmumPEYW3wmV/eQBfe9H9pes eqhf0xDOkQR1MnNJEiEcdmlv+jiEkVtHG559KcdmkmqYb+5BIMgRvvc/FFNAE35xFpbJ xq5Xu7O3xZCNR+cu3iAw5LM66zHF0LGlOrjrNQ8ibx0WvKtE7KwaQFE8LCd4Xe+f8M8b Sr0Mx40iQRVtzFiLMhx9gxctNXDlX6yCP+vfYVWHbxjsSNA2WdBvVLLv5AcMBCBp31rk PZOg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787879449; x=1788484249; h=in-reply-to:references:subject:cc:to:from:content-transfer-encoding :content-type:mime-version:message-id:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=DqRGrR0heNmSPrtTW9+v9FKZZ7RwzxehXvY0MCzvxnw=; b=fPytubYynUYLGBissObBixhOJrTAsjs/O0LRdfCzsxt8CYeIa2LRVlINK2zwBzX6WD TMP28H/DPMwDZyPTUw5Nei2OfFtNY2KB1ZxuREjgzJiYHWFwFCjMJ548xU3BreB9FYdp QGTyJWPJJjnMK6F29PbbsIMYCnCmqNqS4s13yPcB1e4s3PlHmibeCXzs9jkKnVN6eY91 76ZsGlzfuuM8gqCjToIJCovbRacRpg3B1Ibj+WpYeM4LkOWWinfIuhHcQyWCT622F4F0 HhRdGmonXKNqjJC65z9rOdUjDhf0PeL7xoAN2S9NqhaLi+xc5MPBeOOR3ROtBf/1cgZl 6URA== X-Forwarded-Encrypted: i=1; AHgh+RpznSC5OYv5xGgEYAb47c40QO9RtaJRLYBzTP7CbfvaRM3h4I+gCXMUFd626SSdoMINZJhEz6F1tSdpIEpi@vger.kernel.org X-Gm-Message-State: AFuF++k9yp4nBnIGjeB1O086peJda524FGYXzAQf0Kag816JoQc0Cq5N tAAKxu65CgBv1G8iTpIiGQF8ARe49YV1+6CnzqO2DJ8Vz/W17vZbCPsO0X8385dRFQ== X-Gm-Gg: AR+sD10IYk7wL9Tp8xA419546TslfQW2IVTJcwE9HxulaySbc9OYWIGP8Gf9wKTXx1P srFsmc25khojcMJjZkRyk+h3QnXjwH7ZhpVLNrZwdElVGu35CLFhq8CxspqK8TwrPZWd0T300R5 hbYkYPkBKALJiP+jTqwVo5bBe/v+K9qSc20Ue9d8NTx/nekLSp3LSdGNPYL8au9+aKGqB6yld4O a37AayhX6rt38xPH55QtRzScq6qPReomHKIziQkoZiE9oEnqcyUipMKmJZgp7YUg+e+c3Ji7WzQ BwsKKeJbQUrtl7HBRI2xzHuhDCVy2fu7ElKlzlJO9/HHnFRFs4zfH7r3VKvkaXkM7PM+2MuADyt X2VauWXDzxprCNdA4J6qTyXFTucEj3KB9ROB56jefVBcongkJCV3K9hWNvnx8yNYk1KhLm1DX0x wlpFUuXcrJ13R/i4C+Ejf0WkCj4+BVp2GwVgXJV9dUxDY38durMBkRjk1IcQlpUvT7aq9HYHrcX olkueJD3sxMmBcScJW6cubXM3ke/j5orMwl1kABsBlf X-Received: by 2002:a05:620a:290a:b0:934:9524:2e89 with SMTP id af79cd13be357-93913809957mr300256985a.13.1787879448634; Thu, 27 Aug 2026 18:10:48 -0700 (PDT) Received: from localhost (pool-71-126-255-178.bstnma.fios.verizon.net. [71.126.255.178]) by smtp.gmail.com with ESMTPSA id af79cd13be357-9391725670dsm34787285a.19.2026.08.27.18.10.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 27 Aug 2026 18:10:47 -0700 (PDT) Date: Thu, 27 Aug 2026 21:10:46 -0400 Message-ID: Precedence: bulk X-Mailing-List: linux-fsdevel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Mailer: pstg-pwork:20260827_1122/pstg-lib:20260827_1501/pstg-pwork:20260827_1122 From: Paul Moore To: Jann Horn , James Morris , "Serge E. Hallyn" , Stephen Smalley , Jeff Xu , =?utf-8?q?Thi=C3=A9baud_Weksteen?= Cc: Alexander Viro , Christian Brauner , Jan Kara , linux-fsdevel@vger.kernel.org, linux-security-module@vger.kernel.org, Ondrej Mosnacek , selinux@vger.kernel.org, Andrew Morton , "Liam R. Howlett" , Lorenzo Stoakes , Vlastimil Babka , Pedro Falcato , David Hildenbrand , linux-mm@kvack.org, Jann Horn Subject: Re: [PATCH v2 3/3] selinux: require PROCESS__PTRACE for FOLL_FORCE introspection References: <20260825-selinux-pokemem-v2-3-b46bc64916d8@google.com> In-Reply-To: <20260825-selinux-pokemem-v2-3-b46bc64916d8@google.com> On Aug 25, 2026 Jann Horn wrote: > > On systems configured with PROC_MEM_FORCE_ALWAYS, ensure that a process can > only create anonymous executable memory via /proc/self/mem if it has > PROCESS__PTRACE (like when using /proc/$pid/mem of another process). > > This closes a hole in code integrity enforcement that Project Zero has used > in a remote Android exploit chain: > It was possible to use a memory corruption bug in a service without > EXECMEM/EXECMOD/PTRACE permission to overwrite executable code via > /proc/self/mem, which made it possible to load and run shellcode containing > a kernel exploit. > > Signed-off-by: Jann Horn > Acked-by: Stephen Smalley > Acked-by: Lorenzo Stoakes (ARM) > --- > security/selinux/hooks.c | 22 ++++++++++++++++++++++ > 1 file changed, 22 insertions(+) > > diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c > index 18dd28b2bb13..2c2c60e9e0fe 100644 > --- a/security/selinux/hooks.c > +++ b/security/selinux/hooks.c > @@ -2157,6 +2157,27 @@ static int selinux_ptrace_traceme(struct task_struct *parent) > SECCLASS_PROCESS, PROCESS__PTRACE, NULL); > } > > +/* > + * Decide whether it should be possible to read non-readable VMAs and write > + * non-writable VMAs via /proc/self/mem. > + * This only applies to systems configured with PROC_MEM_FORCE_ALWAYS, and only > + * triggers on accesses that are not visible to selinux_ptrace_access_check() > + * because of the introspection exceptions in may_access_mm() and > + * __ptrace_may_access(). > + * > + * This allows a process to overwrite read-only code in its own address space. > + * > + * Creating an audit record on denial doesn't make sense here, since we can't > + * tell whether FOLL_FORCE matters for the accessed VMAs. > + */ > +static int selinux_mem_foll_force_opened_by_owner(const struct cred *subject) > +{ > + struct av_decision avd; > + u32 sid = cred_sid(subject); > + > + return avc_has_perm_noaudit(sid, sid, SECCLASS_PROCESS, PROCESS__PTRACE, 0, &avd); > +} I realize not all of the SELinux hook callbacks use proper kdoc comments, but I'm trying to fix that. If you could make this a kdoc function header comment I would appreciate it. -- paul-moore.com