From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from sonic304-16.consmr.mail.bf2.yahoo.com (sonic304-16.consmr.mail.bf2.yahoo.com [74.6.128.39]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4B88F38F656 for ; Wed, 15 Apr 2026 21:32:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.6.128.39 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776288725; cv=none; b=VAj9p8oOGionWmQlud82iVZw0T3yHSqKggdKkb0hLseTnThxgocObWcfxg3fF2j+lBAvHUtcfMVR6OsYXyTdJRcO7XVc7/iX4Orl3EZI2bMt5vkjuLi9ubnfwzLi4xhs70LrjdA1InhWbbEzv1uOUpf6++F4N8nusltAoJmmvRs= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776288725; c=relaxed/simple; bh=1VRzEwc9as955hJAJQZkD8aoU2tfmXZsG3lk/RyK87w=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=RPRXpkZsiCDUKom1WcSMpEo4cSdXSr6LpADy2d0Lj5yUxfsgQkopQpMraqrnTu5FlHL3U9W6XC87fL8qj3cTlyLpU+nxPzv2mVIfzf/eUwdxinLFMiZ8Gq6N3lw7hwGpT1xFzwXekc5lTNTeB7kvP7QwVt2MzW6mGz3hJcefuB0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=schaufler-ca.com; spf=none smtp.mailfrom=schaufler-ca.com; dkim=pass (2048-bit key) header.d=yahoo.com header.i=@yahoo.com header.b=Lzen8Ygq; arc=none smtp.client-ip=74.6.128.39 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=schaufler-ca.com Authentication-Results: smtp.subspace.kernel.org; spf=none smtp.mailfrom=schaufler-ca.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=yahoo.com header.i=@yahoo.com header.b="Lzen8Ygq" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1776288722; bh=PCIEZUDtvL4fKDuA56MB9W3LMeOH6yBvvyQFCUOW0uA=; h=Date:Subject:To:Cc:References:From:In-Reply-To:From:Subject:Reply-To; b=Lzen8YgqsJcRZaymd0GypzqtIX08oWXSgmtm6rEG/Y8glOaMX+YHX8AyxLeCzWBZ7s4jZYpPhhT31TzY8HHdKnBWvC3rzq8Z0FTxN4BP7FixfY65gEWVOj1BhC5wwT2qsRW+bwRBwEGYfbfmPjXiGmWacg1ZxSLBuro9aau1HfCf8cBqzQYDozEQDiil8fqxi85aCYOPQMEcAykVLXigYXZ/bHCZ1o7sJNE69ijQaSgAXP5NpgcJMTz8eolW18ybNuDHxkw3LbxmXk8MEmWiNtDNNE71RX7mlVExXHVCsdHzi2jmlWdRLbt253KbG9Vr3V0bl/Ec6kH5K0Ompu5V4A== X-SONIC-DKIM-SIGN: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1776288722; bh=beOyHWXL96lJreOhdbULagC+uJ1gVWy2cWmPiXA28u4=; h=X-Sonic-MF:Date:Subject:To:From:From:Subject; b=ePWwFsrZi4YYt4xtpZtSwf6F2+2v96uq+bCT3cbRvPSQJU+JzcglWAao71+/Wat+SvSv4oamsYwVapHQFIQZBTMJXmUMjCW18DCBlVtB5LgZgKqQu7vZM1rtn2se1fPcC1q7Ya7naTYaH9XkLRFkCY5KHSV9hU9DfPr1qLkxHKIR/kKxUx9dy9AOO+e0G7+D4/Wp4hwJ9g/MGhtmIssXBZJwolU51xatHZ5ToHrKhlYt3nkf2XuRxPf8boGOfcocEeWM09djTpkbsnbk+SL/o7ngZUUGvt0ydGvONPyId8KhQaI1POxd68O7fo+YYSwAfAxJZilPFhrY1mjcvnD4qA== X-YMail-OSG: OTWDq0wVM1kWBKlAClbtD.6W.Rgce4yInLQVN97jyOJxSa1hGgVXGNaz8TPVgxy wm5N0OZz2yEOydYM1i9uZWkp53km0ZmaQkIg_xaEAQozcV1Di9tdpXDzSQWS1GhrMcTVr3m201Bf 40FW9DxdNkcJtDsTRUNTPDV9kKxT42IPULUl3WPiN7iJCfkWKxlDyLXiE8eTt0KGHvmb.OoGEgBy AoXITcef2y4r_WqBS2gLbeKfpnr1RVZihFcNWgCsuIY63wgZbLoMSXSSjm1XtlxfjrPk.DP6XoZC biDFbDHSnoY5P9o7u2G.zZilDjVYT.qCa0GNh_g_RDahhSok_q3mp79XDGMCZAGQ.GG.syh6lTHX P7fXQ8bkTWUIQA8pTh0KLK6O_1mk6agZcCD3Ba8WhDTDCI7CxauFy.kkMolNdYB_qGXENI.wK3n3 eBbZ.zjPooFiUCULsa6jzGX.C7VFGzcpLXp1s9hOl1yvdRHIBO0LmhANf.o2aFhh7tnWhAssqd41 e_7RHNS.i_dixFkALoTeixj6VYYlduEwIzAcQU5DS8ILULg9kFLEmT4DNKPS0CkuuJeRHBCmrG3o AN0p75xLlz27f3QoKImoBCNd.2n7G78LfZfgTQ0Qjzg2SUpjIcYwmgzopERLZ92zOXS3Tciopgwy yCK65MgTPVZ5BKNBwRd5qxwDf0FBmVAPEhU5ZhPw9k.NIUN13Fmbh3t8EQ7c0wJU4UUTYAWoGELY .LJrht6FcvDWGCYBfkzbVmb6XFam4HNtRSKaUTlA9OiHwHtm4gMX6iAVbf.ULGI8J3eJrnntvS0p XpUvYDl0cC3V.rXaUlnGmT7GMnjYPfVDhGwbXH9KtEfnW30DQXVtyassb5E4w9w8Vf7IngNVsRXO mn3heo2tZw.TslL5cexILIeli0HuHhHv1gRQeKHyrrreLLWuSlxsrfNCTw1L1pITqKrl_dgGrjyu viLWNKZR5sCA6YzRt6RbMZQt5xVnI0HbQwMsQWV_gN5.f2AruKDVsBxY4TFUyvDhbJjwFNlf3fz2 UVUZFtplvxfr5uMIzH2lrhuZ1GGcR0IjajNfhfkiXLpQs9ENLFaZ4fjYKayEcBz5vZ51jv_PSS64 4K8wVVo4mekXJZGTTq1T8UA0tcFgUGXEBuIXeAVcudJcqwA0mfOcXvy1_5jPVTKsMvLeCcN65g6w xrm73ukJDYwf.jg46aqpYnZ6TPb.GN0YXJIRAb9s2BOY0f4DZxCSMUXfAdsLJOxSCd9OC8VMQsIU gmw5mLLKSQQWibutpi_be0SxKGt3H1XNppl0cQ7R99F8GcVjzUNg0y9dGrr34MOOURzBwF3U33Ku K8LCt.8.s_uWAIRmEKnx6a.V1bPc1dUMi_NIyNSxu.i2B1kHAPIkQgYd8HRjO4E3fM_qPEonpCnI skpVSJd3.ApsyiDhpSaV1ChED8ZpoUR4gG42uRBcYph2GHBrpLPUAC2LeOuFRWfAWXf.t.pcgEtd I8.UAg67i33D8xJhxToGhcBAnnFzFVSU0F8X2ApA.R4cvXHwS6ZBOO_7n5mk6N2LjeT8O5D87MHa YsbmoFSX3my0K6SGsK4XAgU.IuU4.sRCz52du8xWXED03Gi9wbAKiSdf7dok7tBZ7eOoBFGnKsXx G5aUNd9kJb6PXeflkbmlkl.Hs5P9Vsi8qtExRZMzAot9nsj2JxmaUkbKB9tHX1vrw_3Qx6syt5_. BVYaEa2QtTpNlEdb.hpQJTLRIT5szY2eni9XytJwEoClRDx5LWvfA9V10yoTKxAu5F_Df4GD..UB bd.4yenjrfIj3EkXhPq3NBD3gAwoVihMUlAl3ODeP29zNpyOq0_N0WAiC6APoM07UeLtKQyjRvE. qnp9CFNvRm7fPc5FDQJeNuDkfKYHAQjzJIvKrokib13kmBLEV5owRT_LJ1ubfTS8aeSlgP5SNQIE kOdiOmBLN0dOFrUYyr8ZwYTJVNITmEKnN5uDKN28VKEMM7BwTMxmAAOxmndwH1xJH0Ae6jLHZfJv qxgF70jsVRzidZkW32xeYRfkwwhxR1woQAEr0QbYBG2sdw3GyfzgdHXaDZLdQS1EWuQh3h5N.BeU mHAuyoXwIrnAH89NmLZq0xjL6gWB1FuxCdLDovUk8Oxny3CjWzGWxtLnW6L7xlF5SHDrqX6bu3mq ue50btk6e7y1bf2iXuJf1pQAdHL5rTGCQi5z5ROlkBGtq_MzNHPTQSjrKvrZYdvCHiFwjRie0rI1 8d2LalaiufdwZdKZYuWCgbmv.p9efZbZyLJR8Zs1qEF8r8gNBIpCazw-- X-Sonic-MF: X-Sonic-ID: 2d41aabe-9af5-437d-8e9e-568444c670cb Received: from sonic.gate.mail.ne1.yahoo.com by sonic304.consmr.mail.bf2.yahoo.com with HTTP; Wed, 15 Apr 2026 21:32:02 +0000 Received: by hermes--production-gq1-6dfcf9f8b-h78wr (Yahoo Inc. Hermes SMTP Server) with ESMTPA ID b799781f33bb01013e1e244a638df756; Wed, 15 Apr 2026 21:21:52 +0000 (UTC) Message-ID: Date: Wed, 15 Apr 2026 14:21:50 -0700 Precedence: bulk X-Mailing-List: linux-security-module@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v2 0/4] Firmware LSM hook To: Paul Moore Cc: Jason Gunthorpe , Leon Romanovsky , Roberto Sassu , KP Singh , Matt Bobrowski , Alexei Starovoitov , Daniel Borkmann , John Fastabend , Andrii Nakryiko , Martin KaFai Lau , Eduard Zingerman , Song Liu , Yonghong Song , Stanislav Fomichev , Hao Luo , Jiri Olsa , Shuah Khan , Saeed Mahameed , Itay Avraham , Dave Jiang , Jonathan Cameron , bpf@vger.kernel.org, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, linux-rdma@vger.kernel.org, Chiara Meiohas , Maher Sanalla , linux-security-module@vger.kernel.org, Casey Schaufler References: <20260331-fw-lsm-hook-v2-0-78504703df1f@nvidia.com> <20260409121230.GA720371@unreal> <2dd138a2ae87f90c55dbc3178d9c798294fd4450.camel@huaweicloud.com> <20260409124553.GB720371@unreal> <20260412090006.GA21470@unreal> <20260413164220.GP3694781@ziepe.ca> <20260413231920.GS3694781@ziepe.ca> <4cf6b20b-f53b-4b5e-ba03-c7ac01bec0c2@schaufler-ca.com> <53a532e8-5981-49b4-896e-0bf5021ff78b@schaufler-ca.com> Content-Language: en-US From: Casey Schaufler In-Reply-To: Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Mailer: WebService/1.1.25495 mail.backend.jedi.jws.acl:role.jedi.acl.token.atz.jws.hermes.yahoo On 4/15/2026 2:03 PM, Paul Moore wrote: > On Tue, Apr 14, 2026 at 6:42 PM Casey Schaufler wrote: >> On 4/14/2026 1:44 PM, Paul Moore wrote: >>> On Tue, Apr 14, 2026 at 4:10 PM Casey Schaufler wrote: >>>> On 4/14/2026 12:09 PM, Paul Moore wrote: >>>>> On Tue, Apr 14, 2026 at 1:05 PM Casey Schaufler wrote: > .. > >> CMW MLS and SELinux MLS can be mapped. They have the same components. > Yes, one of the fields in a full SELinux label can be an MLS field, > but that doesn't mean there isn't translation needed. The important > point is that security label translation, mapping, etc. is necessary, > possible, and has been proven to work across a variety of systems. I'm not especially concerned about translation between systems. The problem at hand is negotiating between LSMs on the same system. > >>>> SELinux transmits the MLS component of the security context. Smack passes >>>> the text of its context. >>> Arguably the NetLabel/CIPSO interoperability challenge between SELinux >>> and Smack is due more to differences in how Smack encodes its security >>> labels into MLS attributes than from any inherent interop limitation. >> Yes. That is correct. The big issue I see is that SELinux does not represent >> the entire context in the CIPSO header. Thus, you're up against many SELinux >> contexts having the same wire representation, where Smack will have a unique >> on wire for each context ... > That isn't always true is it? From my understanding of the "cipso2" > interface an admin could easily map multiple Smack labels to a single > CIPSO label. True, but you can't map multiple Smack labels to the same CIPSO label without introducing ambiguity. > It's important to remember that if you wanted to utilize CIPSO to > communicate between SELinux and Smack, the label translation is not > between SELinux and Smack but rather between SELinux and CIPSO as well > as between Smack and CIPSO. > >>>>> Use of the NetLabel translation cache, e.g. netlbl_cache_add(), would >>>>> require some additional work to convert over to a lsm_prop instead of >>>>> a u32/secid, but if you look at the caching code that should be >>>>> trivial. It might be as simple as adding a lsm_prop to the >>>>> netlbl_lsm_secattr::attr struct since the cache stores a full secattr >>>>> and not just a u32/secid. >>>> Indeed. But with no viable users it seems like a lower priority task. >>> You need to be very careful about those "viable users" claims ... >> Today there are no users. > That you are aware of at the moment. You are also well aware of my > feelings on this issue and ultimately I'm the one who has to sign off > on that stuff. Understood. There are a serious number of considerations that need to be worked through. > >> There are other problems (e.g. mount options) that have yet to be addressed. > The existence of one problem does not mean another does not exist. True enough.