From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f199.google.com (mail-pf1-f199.google.com [209.85.210.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3CE172ED154 for ; Thu, 13 Aug 2026 00:26:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.199 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786580809; cv=none; b=QiSVWwfC8I9bG1ayWzCQIS2ml+ZKYJzdKibr7/Wlq8TYVJ8TnzFiM/yrqAo2vL8cwq9Ak0pgcu1Qi7d66UCdF6ArQeLkoIyls3hjjGQ85o66bCYAu/JaGK5AkJDlC6iz2GBbvwvkI5MjRWrtjQuCuHniw354aZqakqnoPGdsk+I= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786580809; c=relaxed/simple; bh=5se711kePA411xaoz5RodsO+PLdGel9RlS6q8G/sC4I=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=bFkuQFW6m8fBH6Fvt82mpeQNoLph/w0aU1rAuVoAe9q1I22KEL8JgmBlchOx3VBmUbccJTqcRiAE9ktapC4Lcb/83BfJz3COEmWFW/ZdhDbmNcnObKAdvSizk5OKnCkPmPF1gw0vWOgTgNbGpZkgYj2j3h3PeQ4UgyBytDwKx5c= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--tweek.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=PLPeZ39k; arc=none smtp.client-ip=209.85.210.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--tweek.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="PLPeZ39k" Received: by mail-pf1-f199.google.com with SMTP id d2e1a72fcca58-848662cd2a1so1859223b3a.2 for ; Wed, 12 Aug 2026 17:26:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1786580807; x=1787185607; darn=vger.kernel.org; h=content-transfer-encoding:content-type:cc:to:from:subject :message-id:references:mime-version:in-reply-to:date:from:to:cc :subject:date:message-id:reply-to:content-type; bh=Qkjz+h+zNCGoWltKJetL2Y2JT1Z7HAkSp1FmTaM3CtU=; b=PLPeZ39kIdPQ9wekhs0NzjRWi0g5wU9Prl+htO8xBcFkU3JCSA1SE+liU26MJMGsE5 ByhTiXnyRWgD59RcAct4IrEAjcZoPU7NR2PqLOLU8tlCk4OOIG/1EBit6OoqTy1GFSFm H2OcpN+BH4NmrPKnvdV88+SKddhxHQkku6jYjGkny99+NX2knla7Q0mmxyARdUr6oBM6 E7jWGqVo7QBmfMo3FBp+I8LOM8XjJG3eIN8tFwTNCc1CD95G1GYCIEbsxN0gzpF3kS20 9ippzqsPZ2zOFqmAs8+5bVijVypsJbv8Vhx7af4d049+yxa3orpHGPpG0zuUakufFLSD CHng== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786580807; x=1787185607; h=content-transfer-encoding:content-type:cc:to:from:subject :message-id:references:mime-version:in-reply-to:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Qkjz+h+zNCGoWltKJetL2Y2JT1Z7HAkSp1FmTaM3CtU=; b=Tg3Nn6A0TFLqgyAlJlb2B9wwuO9yCEhb37bnklmhTrsU5gEZnKqpJ1W371tN8mhIRe xHaGzPNTTpZ5hqKLXx2nznwcL4j9uCQlDSbZK1krZiAml9tF0ipDPaT7C+d5guXsRhwE u1QSphKx2PxVSmciT98p3Ks/KKkmYiUmLZnCvGqvMJdeRbyoP9iecSSOWxiQZ5CdqgMC QXBeHrpGiOXhPdfvtJmOBCNicC/B8+GhL5XvL7I6B6+ZiatkFSHPW/mREnDoI/+wl6TI k1boZRYhp/StiwRXGtSFnLkmg+XWsiSMWQHqIchZ56p0+JX1BhEfCjC1k05UbIfY8EVj NhDg== X-Forwarded-Encrypted: i=1; AHgh+RoZhSgZkAh4suAmi4vfetkhl1BbcFMrngAax6t475ifLjQsrtKK7dQsi+gDIN4zumK3ej4VLRcuqi+sRXs=@vger.kernel.org X-Gm-Message-State: AOJu0YzywPAVwm6P3Z4nXClFgZalTbyBk+Q3Y/VnpuSgITuqYUTqsXfq Ji0/t7E+ivmIRB/KIlN7E8r76+b9dTbuvO9X/veWe8ffmscwUucsucRQbFQI5qi09PAMMZOAfpE LtA== X-Received: from pfx22.prod.google.com ([2002:a05:6a00:a456:b0:84b:50b5:d431]) (user=tweek job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:44cb:b0:848:4080:afe8 with SMTP id d2e1a72fcca58-84fc751547fmr1831794b3a.22.1786580807349; Wed, 12 Aug 2026 17:26:47 -0700 (PDT) Date: Thu, 13 Aug 2026 10:26:16 +1000 In-Reply-To: <20260813002618.3755631-1-tweek@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260813002618.3755631-1-tweek@google.com> X-Mailer: git-send-email 2.55.0.691.gc56d675ccc-goog Message-ID: <20260813002618.3755631-4-tweek@google.com> Subject: [PATCH bpf-next 3/5] selinux: use kernel sid in security_bpf_* From: "=?UTF-8?q?Thi=C3=A9baud=20Weksteen?=" To: Paul Moore , Stephen Smalley , Alexei Starovoitov , Daniel Borkmann , Andrii Nakryiko , Jeffrey Vander Stoep Cc: "=?UTF-8?q?Thi=C3=A9baud=20Weksteen?=" , Ondrej Mosnacek , Eric Suen , Blaise Boscaccy , Sid Nayyar , Neill Kapron , Eric Biggers , Greg Kroah-Hartman , KP Singh , bpf@vger.kernel.org, selinux@vger.kernel.org, linux-kernel@vger.kernel.org Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable The security_bpf hooks provides a boolean to indicate if the call is coming from within the kernel or not. If true, use the kernel SID instead of relying on the current process SID. For the token-aware functions, the kernel sid is used to decide on the access, but the caller remains owner of the object (program or map). Signed-off-by: Thi=C3=A9baud Weksteen --- security/selinux/hooks.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c index f197cf476190..e7c5993f6954 100644 --- a/security/selinux/hooks.c +++ b/security/selinux/hooks.c @@ -7181,7 +7181,7 @@ static int selinux_ib_alloc_security(void *ib_sec) static int selinux_bpf(int cmd, union bpf_attr *attr, unsigned int size, bool kernel) { - u32 sid =3D current_sid(); + u32 sid =3D kernel ? SECINITSID_KERNEL : current_sid(); int ret; =20 if (selinux_policycap_bpf_token_perms()) @@ -7296,7 +7296,7 @@ static int selinux_bpf_map_create(struct bpf_map *map= , union bpf_attr *attr, bpfsec->sid =3D current_sid(); =20 if (!token) - ssid =3D bpfsec->sid; + ssid =3D kernel ? SECINITSID_KERNEL : bpfsec->sid; else ssid =3D selinux_bpffs_creator_sid(attr->map_token_fd); =20 @@ -7314,7 +7314,7 @@ static int selinux_bpf_prog_load(struct bpf_prog *pro= g, union bpf_attr *attr, bpfsec->sid =3D current_sid(); =20 if (!token) - ssid =3D bpfsec->sid; + ssid =3D kernel ? SECINITSID_KERNEL : bpfsec->sid; else ssid =3D selinux_bpffs_creator_sid(attr->prog_token_fd); =20 --=20 2.55.0.691.gc56d675ccc-goog