public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH] Trace event for capable().
@ 2012-05-17 19:50 Auke Kok
  2012-05-18 22:25 ` Serge Hallyn
                   ` (2 more replies)
  0 siblings, 3 replies; 12+ messages in thread
From: Auke Kok @ 2012-05-17 19:50 UTC (permalink / raw)
  To: Serge Hallyn; +Cc: Auke Kok, linux-security-module, linux-kernel, Eric Paris

Add a simple trace event for capable().

There's been a lot of discussion around capable(), and there
are plenty of tools to help reduce capabilities' usage from
userspace. A major gap however is that it's almost impossible
to see or verify which bits are requested from either userspace
or in the kernel.

This patch adds a minimal tracer that will print out which
CAPs are requested and whether the request was granted.

Signed-off-by: Auke Kok <auke-jan.h.kok@intel.com>
Cc: linux-security-module@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Cc: Serge Hallyn <serge.hallyn@canonical.com>
Cc: Eric Paris <eparis@redhat.com>
---
 include/trace/events/capabilities.h |   33 +++++++++++++++++++++++++++++++++
 kernel/capability.c                 |    5 +++++
 2 files changed, 38 insertions(+)
 create mode 100644 include/trace/events/capabilities.h

diff --git a/include/trace/events/capabilities.h b/include/trace/events/capabilities.h
new file mode 100644
index 0000000..97997fa
--- /dev/null
+++ b/include/trace/events/capabilities.h
@@ -0,0 +1,33 @@
+#undef TRACE_SYSTEM
+#define TRACE_SYSTEM capabilities
+
+#if !defined(_TRACE_CAPABILITIES_H) || defined(TRACE_HEADER_MULTI_READ)
+#define _TRACE_CAPABILITIES_H
+
+#include <linux/tracepoint.h>
+
+TRACE_EVENT(capable,
+
+	TP_PROTO(pid_t pid, int cap, bool rc),
+
+	TP_ARGS(pid, cap, rc),
+
+	TP_STRUCT__entry(
+		__field(pid_t, pid)
+		__field(int, cap)
+		__field(bool, rc)
+	),
+
+	TP_fast_assign(
+		__entry->pid = pid;
+		__entry->cap = cap;
+		__entry->rc = rc;
+	),
+
+	TP_printk("pid=%d cap=%d rc=%d", __entry->pid, __entry->cap, __entry->rc)
+);
+
+#endif /* _TRACE_CAPABILITIES_H */
+
+/* This part must be outside protection */
+#include <trace/define_trace.h>
diff --git a/kernel/capability.c b/kernel/capability.c
index 3f1adb6..2941f37 100644
--- a/kernel/capability.c
+++ b/kernel/capability.c
@@ -17,6 +17,9 @@
 #include <linux/user_namespace.h>
 #include <asm/uaccess.h>
 
+#define CREATE_TRACE_POINTS
+#include <trace/events/capabilities.h>
+
 /*
  * Leveraged for setting/resetting capabilities
  */
@@ -386,8 +389,10 @@ bool ns_capable(struct user_namespace *ns, int cap)
 
 	if (security_capable(current_cred(), ns, cap) == 0) {
 		current->flags |= PF_SUPERPRIV;
+		trace_capable(current->pid, cap, true);
 		return true;
 	}
+	trace_capable(current->pid, cap, false);
 	return false;
 }
 EXPORT_SYMBOL(ns_capable);
-- 
1.7.10


^ permalink raw reply related	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2012-05-22 14:50 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-05-17 19:50 [PATCH] Trace event for capable() Auke Kok
2012-05-18 22:25 ` Serge Hallyn
2012-05-18 23:11   ` Kok, Auke-jan H
2012-05-18 22:33 ` richard -rw- weinberger
2012-05-18 23:09   ` Kok, Auke-jan H
2012-05-18 23:19     ` Serge Hallyn
2012-05-20 13:10       ` Serge E. Hallyn
2012-05-19  6:59 ` Eric W. Biederman
2012-05-19 18:39   ` Kok, Auke-jan H
2012-05-22  0:03     ` Eric W. Biederman
2012-05-22  2:17       ` Kok, Auke-jan H
2012-05-22 14:50         ` Eric W. Biederman

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox