From: Daan De Meyer via B4 Relay <devnull+daan.amutable.com@kernel.org>
To: brauner@kernel.org, jack@suse.cz, paul@paul-moore.com,
viro@zeniv.linux.org.uk
Cc: linux-security-module@vger.kernel.org, linux-fsdevel@vger.kernel.org
Subject: [PATCH 0/2] lsm: expose mount idmaps to inode hooks
Date: Mon, 24 Aug 2026 15:28:11 +0200 [thread overview]
Message-ID: <20260824-lsm-mount-idmaps-v1-0-0414a9641c85@amutable.com> (raw)
OverlayFS performs upper-layer operations through inode-based security
hooks. Those hooks receive the upper inode and dentry, but not the mount
idmap used by the VFS operation.
The security layer cannot distinguish an identity-mapped upper from an
idmapped one or make the same ownership decision as the VFS. The VFS
layer already passes the idmap down into all relevant inode operations
so this just brings the security hooks to parity.
So pass the mount idmap through the create, link, symlink, mkdir, mknod,
and permission hooks. Update the in-tree security implementations and
non-VFS callers accordingly.
systemd has been shipping systemd-nsresourced for quite a while now. It
relies on inode and path hooks to perform ownership checks using a bpf lsm.
To make this actually secure we need to be able to calculate the on-disk
ownership from the idmap.
---
Daan De Meyer (2):
lsm: expose mount idmaps to inode hooks
selftests/bpf: verify mount idmaps reach inode hooks
fs/cachefiles/security.c | 4 +-
fs/namei.c | 18 +-
include/linux/lsm_hook_defs.h | 23 +--
include/linux/security.h | 58 +++---
security/security.c | 40 ++--
security/selinux/hooks.c | 19 +-
security/smack/smack_lsm.c | 9 +-
tools/testing/selftests/bpf/prog_tests/test_lsm.c | 231 ++++++++++++++++++++++
tools/testing/selftests/bpf/progs/lsm.c | 79 ++++++++
9 files changed, 410 insertions(+), 71 deletions(-)
---
base-commit: 0a0d1d55dad570724bf8c7ea83409639cfb4be9b
change-id: 20260824-lsm-mount-idmaps-9d9b994fe1a1
Best regards,
--
Daan De Meyer <daan@amutable.com>
next reply other threads:[~2026-08-24 13:28 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-24 13:28 Daan De Meyer via B4 Relay [this message]
2026-08-24 13:28 ` [PATCH 1/2] lsm: expose mount idmaps to inode hooks Daan De Meyer via B4 Relay
2026-08-24 13:28 ` [PATCH 2/2] selftests/bpf: verify mount idmaps reach " Daan De Meyer via B4 Relay
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260824-lsm-mount-idmaps-v1-0-0414a9641c85@amutable.com \
--to=devnull+daan.amutable.com@kernel.org \
--cc=brauner@kernel.org \
--cc=daan@amutable.com \
--cc=jack@suse.cz \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=paul@paul-moore.com \
--cc=viro@zeniv.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox