From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yx1-f50.google.com (mail-yx1-f50.google.com [74.125.224.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CA270311977 for ; Fri, 31 Jul 2026 02:21:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.224.50 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785464488; cv=none; b=RYUTXuAjR/oghjHrTA40qMTd2cTqkHAD53J5O4gjXbwLyjIvQdIWrFUPoRAUtlz1Gnh+gf1lf0n4jD2zgxS8wYrmCuuNxOkG34qzrPowhHCtSGMFXbxqs2SBMrUlUVHzKedEYFxGvEVZE1z8PoUIGVtHWLlAYrutqgtADcyFsZo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785464488; c=relaxed/simple; bh=NL8mBC7WHXg65243KavwzxselJ8EusI6R5QSuWKlbs8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=CrqFeYSg7mheaalyUmlkr8suRcAlExT4xaY5F+5+2MA3zWORLiT3WRUJwZ3MPFbmum2/qKqo1VQtAApIYI8QRMR1F0GlVEdczZVhevoVCVpT2JQWZl0znLuJqTo8JKcZWroHACEQlWRrWeccEJWqRS2P6YKEOGa6/gWbUAc74Eg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=oiFkuMY3; arc=none smtp.client-ip=74.125.224.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="oiFkuMY3" Received: by mail-yx1-f50.google.com with SMTP id 956f58d0204a3-6689f36ae56so617306d50.3 for ; Thu, 30 Jul 2026 19:21:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785464484; x=1786069284; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=vTtFKNvHB2/Ojp2xHTtFD0mxvMCw7gVj2kPcAk5LXGw=; b=oiFkuMY3lsVKuL5Qqrwgzh1oEskSwGwnF/VvkkRpNEVvd7Ze1SZ7Sr6sFaEQP8VM1u +h5CM+4Mr3xQxgfXpsjb+lnScR40QZyEJ+4YzDr/LEyKL7uobe3hKZdfuN/K39k0ad/W JBClrrfN+8u3bU3jJfPLgDreaVabggDWRmMNcwISOKOZ7WmbTNAyn0lvt0zPIYM33dHA Nz38dwhtYkaEnZQoCbGkyr2M8zEk0zIAVspRyZt6H7iPbMYPFd/X++htTZUOkCdRmzBc kcIWZqDYX9VDa8LxGRu3rm/O2275AjVeiyQpVceoj2Y+G3uGe+SkX28InW5FQQnWKaJp Xqwg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785464484; x=1786069284; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=vTtFKNvHB2/Ojp2xHTtFD0mxvMCw7gVj2kPcAk5LXGw=; b=hkZ3F5R99bp2Z+aQEVpXMP52cNnEeUchT/aCAGUqDs8tFuNyvYk2IHvlBVOdX1nS1b A3O+7OYF9J+fP5MYL20yzUdSjSVe6Cn4UGHcpo/6yi5gSnG68iBWFhA3ZJ7yYHRRB7cg wIX7wBVCcinVTnGDqOHSYdGH3yo+CdX04NCyUi5P9d0mxkigEuTSTQCUW1UzVGaDDn+2 Vbq3zxiUBkoSs/qZI5j4txrC6jTfVgF+1Yz7l0ZflMPoLBN2ZMjKMWSq8nCbs+cQyPEa JotohXlDhiuSroR8Ln74XkXyaxXHTJW+1Q6iSqo/Jqi41ZAQ4UEV/vnnl/5nzWjLkugr J/Ew== X-Forwarded-Encrypted: i=1; AHgh+Rr5ySGVHRXrzjKeHCuRDXElNkSP0gckwNHTWk4Ysgt4+YeHhiNDuRysTFDKf03PdCU3R5NKKnaVwh83Eek=@vger.kernel.org X-Gm-Message-State: AOJu0YzMjq7Q0T9Z8TiOHVIdulSSA74AxkDsWtR5nFxxDXCzF9Uhihx4 FN/3b5C20ZkVPPwAPf8GDVo9sqPGTx/JInAqsFE+PcJ156Xo/xNJ0Pca X-Gm-Gg: AR+sD13/sYhs1kOiqBja84+hvqXHOTpcSiTZdMpYsgOg6Cwbsmko47/Dt1IULqErEfP uqGIcoKWCmyzW6ORQBFwHzLtZq6z/fLa30+XxZsfLlnT9VRhFaGHxfITUNuqu4aMKNcU7D95P72 F7ogcDyTNLhbDyXtKbS2AbcVD4KmQRblMkTmZsYTFlVMXcJWT26YoCn8qGguZPu322ERtRalcUl v1aP4acXTvXxWvbiXvy0z1f71H6+oyY6l0mKbh9lbFt+DzKilUlyy7eu7L8SfTjAbB4aV+yHYE/ l+kz3SU750fCYbaVv4tiShMDAzcAEIynbh23BOa3hKkyc6xUQ50zBUkV8fW4x+EOJ0p293ThUf1 2N0EQGKSfF3BqnfjDwk83dh6LgnwfBIXP4UmCR9DUnsZFauZP0vGHdUdunxYLb1AIF7VNHt2Cyd UzZMKjTNBZdimvD2nxn/KiCXjqQHnSZbMQ/foV4IgUNGgQgAZzZS6qa4kFC6Ofm3KHdcJZpLDnT IqeYdfqNnD8rk2IMuoQzk8= X-Received: by 2002:a05:690c:3705:b0:80d:66b2:850 with SMTP id 00721157ae682-81fcc1238e6mr120377b3.42.1785464484423; Thu, 30 Jul 2026 19:21:24 -0700 (PDT) Received: from zenbox ([2600:1700:18fb:6011:e94:8a83:feea:6720]) by smtp.gmail.com with ESMTPSA id 00721157ae682-81fb8b26e8bsm20519047b3.47.2026.07.30.19.21.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 30 Jul 2026 19:21:24 -0700 (PDT) From: Justin Suess To: ast@kernel.org, daniel@iogearbox.net, andrii@kernel.org, kpsingh@kernel.org, paul@paul-moore.com, mic@digikod.net, viro@zeniv.linux.org.uk, brauner@kernel.org, kees@kernel.org Cc: gnoack@google.com, jack@suse.cz, song@kernel.org, yonghong.song@linux.dev, martin.lau@linux.dev, m@maowtm.org, bpf@vger.kernel.org, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, Justin Suess Subject: [PATCH bpf-next 08/13] bpf: Add the bpf_landlock_put_ruleset kfunc and ruleset destructor Date: Thu, 30 Jul 2026 22:20:41 -0400 Message-ID: <20260731022047.189137-9-utilityemal77@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260731022047.189137-1-utilityemal77@gmail.com> References: <20260731022047.189137-1-utilityemal77@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Add the release kfunc for Landlock ruleset references: bpf_landlock_put_ruleset(ruleset) KF_RELEASE It is a thin front end to security_policy_kptr_put(), invoked with LSM_ID_LANDLOCK; the handle travels in the Landlock member of union lsm_policy_kptr, staying typed end to end. A ruleset reference is meant to be handed over through a map kptr field, so also register a destructor for struct bpf_landlock_ruleset: map-held references are dropped on map teardown. The release path may thus run from a context that cannot sleep, which the policy_kptr_put() hook contract requires implementations to support. The release kfunc is available to both program types the kfunc set is registered for. For BPF_PROG_TYPE_LSM, the filter only accepts programs attached to the bprm_creds_for_exec() or bprm_creds_from_file() hooks, where the upcoming enforcement kfunc is specified to operate, and rejects BPF_LSM_CGROUP programs, which run under classic RCU; KF_SLEEPABLE limits the callers to sleepable programs. Signed-off-by: Justin Suess --- kernel/bpf/bpf_lsm.c | 67 +++++++++++++++++++++++++++++++++++++++++++- 1 file changed, 66 insertions(+), 1 deletion(-) diff --git a/kernel/bpf/bpf_lsm.c b/kernel/bpf/bpf_lsm.c index dd58c5bd0119..877dd0352607 100644 --- a/kernel/bpf/bpf_lsm.c +++ b/kernel/bpf/bpf_lsm.c @@ -14,8 +14,10 @@ #include #include #include +#include #include #include +#include /* For every LSM hook that allows attachment of BPF programs, declare a nop * function where a BPF program can be attached. Notably, we qualify each with @@ -481,9 +483,49 @@ int bpf_lsm_get_retval_range(const struct bpf_prog *prog, */ struct bpf_landlock_ruleset {}; +/* + * The sleepable LSM hooks bpf_landlock_put_ruleset() may be called + * from. + */ +BTF_SET_START(bpf_landlock_kfunc_hooks) +BTF_ID(func, bpf_lsm_bprm_creds_for_exec) +BTF_ID(func, bpf_lsm_bprm_creds_from_file) +BTF_SET_END(bpf_landlock_kfunc_hooks) + +__bpf_kfunc_start_defs(); + +/** + * bpf_landlock_put_ruleset - Put a Landlock ruleset + * @ruleset: Landlock ruleset to put + * + * Release an acquired reference on a Landlock ruleset. + */ +__bpf_kfunc void bpf_landlock_put_ruleset(struct bpf_landlock_ruleset *ruleset) +{ + union lsm_policy_kptr policy = { .landlock.ruleset = ruleset }; + + security_policy_kptr_put(LSM_ID_LANDLOCK, &policy); +} + +/* Destructor for referenced bpf_landlock_ruleset kptrs. */ +__bpf_kfunc void bpf_landlock_put_ruleset_dtor(void *ruleset) +{ + union lsm_policy_kptr policy = { .landlock.ruleset = ruleset }; + + security_policy_kptr_put(LSM_ID_LANDLOCK, &policy); +} +CFI_NOSEAL(bpf_landlock_put_ruleset_dtor); + +__bpf_kfunc_end_defs(); + BTF_KFUNCS_START(bpf_landlock_kfunc_ids) +BTF_ID_FLAGS(func, bpf_landlock_put_ruleset, KF_RELEASE | KF_SLEEPABLE) BTF_KFUNCS_END(bpf_landlock_kfunc_ids) +BTF_ID_LIST(bpf_landlock_dtor_ids) +BTF_ID(struct, bpf_landlock_ruleset) +BTF_ID(func, bpf_landlock_put_ruleset_dtor) + /* * BPF_PROG_TYPE_LSM and BPF_PROG_TYPE_SYSCALL share their kfunc * lookup buckets with other program types, so restricting the LSM @@ -498,6 +540,17 @@ static int bpf_landlock_kfunc_filter(const struct bpf_prog *prog, u32 kfunc_id) case BPF_PROG_TYPE_SYSCALL: return 0; case BPF_PROG_TYPE_LSM: + /* + * BPF_LSM_CGROUP programs run under classic RCU and + * cannot sleep. + */ + if (prog->expected_attach_type == BPF_LSM_CGROUP) + return -EACCES; + + if (!btf_id_set_contains(&bpf_landlock_kfunc_hooks, + prog->aux->attach_btf_id)) + return -EACCES; + return 0; default: return -EACCES; @@ -512,6 +565,12 @@ static const struct btf_kfunc_id_set bpf_landlock_kfunc_set = { static int __init bpf_lsm_policy_kfunc_init(void) { + const struct btf_id_dtor_kfunc bpf_landlock_dtors[] = { + { + .btf_id = bpf_landlock_dtor_ids[0], + .kfunc_btf_id = bpf_landlock_dtor_ids[1], + }, + }; int ret; ret = register_btf_kfunc_id_set(BPF_PROG_TYPE_LSM, @@ -519,7 +578,13 @@ static int __init bpf_lsm_policy_kfunc_init(void) if (ret) return ret; - return register_btf_kfunc_id_set(BPF_PROG_TYPE_SYSCALL, + ret = register_btf_kfunc_id_set(BPF_PROG_TYPE_SYSCALL, &bpf_landlock_kfunc_set); + if (ret) + return ret; + + return register_btf_id_dtor_kfuncs(bpf_landlock_dtors, + ARRAY_SIZE(bpf_landlock_dtors), + THIS_MODULE); } late_initcall(bpf_lsm_policy_kfunc_init); -- 2.54.0