The Linux Kernel Mailing List
 help / color / mirror / Atom feed
* [PATCH] selinux: bpf: check SBLABEL_MNT before isec init
       [not found] <01421d53-c379-4044-9da3-5990186303ef@iogearbox.net>
@ 2026-07-30 18:10 ` Carlos Llamas
  2026-07-30 18:50   ` Stephen Smalley
  2026-07-30 21:10   ` Paul Moore
  0 siblings, 2 replies; 5+ messages in thread
From: Carlos Llamas @ 2026-07-30 18:10 UTC (permalink / raw)
  To: Paul Moore, Stephen Smalley, Ondrej Mosnacek,
	Christian Brauner (Amutable), Daniel Borkmann
  Cc: kernel-team, linux-kernel, Alexei Starovoitov, linux-fsdevel,
	Carlos Llamas, stable, open list:SELINUX SECURITY MODULE,
	open list:BPF [MISC]:Keyword:(?:b|_)bpf(?:b|_)

selinux_inode_init_security() marks the isec as initialized before
checking if mount labeling is supported (SBLABEL_MNT). This was fine
until commit 9722955b5430 ("bpf: Add simple xattr support to bpffs"),
where genfscon bpffs mounts fail the SBLABEL_MNT check as expected (no
xattrs) and yet leave the isec->initialized. This breaks subsequent
calls to inode_doinit_with_dentry().

Do the SBLABEL_MNT check before the inode security is initialized.

Cc: stable@vger.kernel.org
Closes: https://lore.kernel.org/all/akWdcp6P0FkNDzBk@google.com/
Fixes: 9722955b5430 ("bpf: Add simple xattr support to bpffs")
Signed-off-by: Carlos Llamas <cmllamas@google.com>
---
 security/selinux/hooks.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
index 8d6945edae7a..09a12eb8652c 100644
--- a/security/selinux/hooks.c
+++ b/security/selinux/hooks.c
@@ -2980,6 +2980,10 @@ static int selinux_inode_init_security(struct inode *inode, struct inode *dir,
 	if (rc)
 		return rc;
 
+	if (!selinux_initialized() ||
+	    !(sbsec->flags & SBLABEL_MNT))
+		return -EOPNOTSUPP;
+
 	/* Possibly defer initialization to selinux_complete_init. */
 	if (sbsec->flags & SE_SBINITIALIZED) {
 		struct inode_security_struct *isec = selinux_inode(inode);
@@ -2988,10 +2992,6 @@ static int selinux_inode_init_security(struct inode *inode, struct inode *dir,
 		isec->initialized = LABEL_INITIALIZED;
 	}
 
-	if (!selinux_initialized() ||
-	    !(sbsec->flags & SBLABEL_MNT))
-		return -EOPNOTSUPP;
-
 	xattr = lsm_get_xattr_slot(xattrs, xattr_count);
 	if (xattr) {
 		rc = security_sid_to_context_force(newsid,
-- 
2.55.0.508.g3f0d502094-goog


^ permalink raw reply related	[flat|nested] 5+ messages in thread

* Re: [PATCH] selinux: bpf: check SBLABEL_MNT before isec init
  2026-07-30 18:10 ` [PATCH] selinux: bpf: check SBLABEL_MNT before isec init Carlos Llamas
@ 2026-07-30 18:50   ` Stephen Smalley
  2026-07-30 21:10   ` Paul Moore
  1 sibling, 0 replies; 5+ messages in thread
From: Stephen Smalley @ 2026-07-30 18:50 UTC (permalink / raw)
  To: Carlos Llamas
  Cc: Paul Moore, Ondrej Mosnacek, Christian Brauner (Amutable),
	Daniel Borkmann, kernel-team, linux-kernel, Alexei Starovoitov,
	linux-fsdevel, stable, open list:SELINUX SECURITY MODULE,
	open list:BPF [MISC]:Keyword:(?:b|_)bpf(?:b|_)

On Thu, Jul 30, 2026 at 2:10 PM Carlos Llamas <cmllamas@google.com> wrote:
>
> selinux_inode_init_security() marks the isec as initialized before
> checking if mount labeling is supported (SBLABEL_MNT). This was fine
> until commit 9722955b5430 ("bpf: Add simple xattr support to bpffs"),
> where genfscon bpffs mounts fail the SBLABEL_MNT check as expected (no
> xattrs) and yet leave the isec->initialized. This breaks subsequent
> calls to inode_doinit_with_dentry().
>
> Do the SBLABEL_MNT check before the inode security is initialized.
>
> Cc: stable@vger.kernel.org
> Closes: https://lore.kernel.org/all/akWdcp6P0FkNDzBk@google.com/
> Fixes: 9722955b5430 ("bpf: Add simple xattr support to bpffs")
> Signed-off-by: Carlos Llamas <cmllamas@google.com>

Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH] selinux: bpf: check SBLABEL_MNT before isec init
  2026-07-30 18:10 ` [PATCH] selinux: bpf: check SBLABEL_MNT before isec init Carlos Llamas
  2026-07-30 18:50   ` Stephen Smalley
@ 2026-07-30 21:10   ` Paul Moore
  2026-07-30 22:07     ` Carlos Llamas
  2026-07-30 22:15     ` [PATCH v2] " Carlos Llamas
  1 sibling, 2 replies; 5+ messages in thread
From: Paul Moore @ 2026-07-30 21:10 UTC (permalink / raw)
  To: Carlos Llamas, Stephen Smalley, Ondrej Mosnacek,
	Christian Brauner (Amutable), Daniel Borkmann
  Cc: kernel-team, linux-kernel, Alexei Starovoitov, linux-fsdevel,
	Carlos Llamas, stable, open list:SELINUX SECURITY MODULE,
	open list:BPF [MISC]:Keyword:(?:b|_)bpf(?:b|_)

On Jul 30, 2026 Carlos Llamas <cmllamas@google.com> wrote:
> 
> selinux_inode_init_security() marks the isec as initialized before
> checking if mount labeling is supported (SBLABEL_MNT). This was fine
> until commit 9722955b5430 ("bpf: Add simple xattr support to bpffs"),
> where genfscon bpffs mounts fail the SBLABEL_MNT check as expected (no
> xattrs) and yet leave the isec->initialized. This breaks subsequent
> calls to inode_doinit_with_dentry().
> 
> Do the SBLABEL_MNT check before the inode security is initialized.
> 
> Cc: stable@vger.kernel.org
> Closes: https://lore.kernel.org/all/akWdcp6P0FkNDzBk@google.com/
> Fixes: 9722955b5430 ("bpf: Add simple xattr support to bpffs")
> Signed-off-by: Carlos Llamas <cmllamas@google.com>
> Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
> ---
>  security/selinux/hooks.c | 8 ++++----
>  1 file changed, 4 insertions(+), 4 deletions(-)
> 
> diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
> index 8d6945edae7a..09a12eb8652c 100644
> --- a/security/selinux/hooks.c
> +++ b/security/selinux/hooks.c
> @@ -2980,6 +2980,10 @@ static int selinux_inode_init_security(struct inode *inode, struct inode *dir,
>  	if (rc)
>  		return rc;
>  
> +	if (!selinux_initialized() ||
> +	    !(sbsec->flags & SBLABEL_MNT))
> +		return -EOPNOTSUPP;

If we're moving this check, we should probably just move it to right
after we assign 'sbsec' at the top of the function.  The calls to
inode_mode_to_security() and selinux_determine_inode_label() aren't
doing anything useful in either the !selinux_initialized() or !SBLABEL_MNT
cases so let's avoid the unnecessary work.

>  	/* Possibly defer initialization to selinux_complete_init. */
>  	if (sbsec->flags & SE_SBINITIALIZED) {
>  		struct inode_security_struct *isec = selinux_inode(inode);
> @@ -2988,10 +2992,6 @@ static int selinux_inode_init_security(struct inode *inode, struct inode *dir,
>  		isec->initialized = LABEL_INITIALIZED;
>  	}
>  
> -	if (!selinux_initialized() ||
> -	    !(sbsec->flags & SBLABEL_MNT))
> -		return -EOPNOTSUPP;
> -
>  	xattr = lsm_get_xattr_slot(xattrs, xattr_count);
>  	if (xattr) {
>  		rc = security_sid_to_context_force(newsid,
> -- 
> 2.55.0.508.g3f0d502094-goog

--
paul-moore.com

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH] selinux: bpf: check SBLABEL_MNT before isec init
  2026-07-30 21:10   ` Paul Moore
@ 2026-07-30 22:07     ` Carlos Llamas
  2026-07-30 22:15     ` [PATCH v2] " Carlos Llamas
  1 sibling, 0 replies; 5+ messages in thread
From: Carlos Llamas @ 2026-07-30 22:07 UTC (permalink / raw)
  To: Paul Moore
  Cc: Stephen Smalley, Ondrej Mosnacek, Christian Brauner (Amutable),
	Daniel Borkmann, kernel-team, linux-kernel, Alexei Starovoitov,
	linux-fsdevel, stable, open list:SELINUX SECURITY MODULE,
	open list:BPF [MISC]:Keyword:(?:b|_)bpf(?:b|_)

On Thu, Jul 30, 2026 at 05:10:00PM -0400, Paul Moore wrote:
> On Jul 30, 2026 Carlos Llamas <cmllamas@google.com> wrote:
> > 
> > selinux_inode_init_security() marks the isec as initialized before
> > checking if mount labeling is supported (SBLABEL_MNT). This was fine
> > until commit 9722955b5430 ("bpf: Add simple xattr support to bpffs"),
> > where genfscon bpffs mounts fail the SBLABEL_MNT check as expected (no
> > xattrs) and yet leave the isec->initialized. This breaks subsequent
> > calls to inode_doinit_with_dentry().
> > 
> > Do the SBLABEL_MNT check before the inode security is initialized.
> > 
> > Cc: stable@vger.kernel.org
> > Closes: https://lore.kernel.org/all/akWdcp6P0FkNDzBk@google.com/
> > Fixes: 9722955b5430 ("bpf: Add simple xattr support to bpffs")
> > Signed-off-by: Carlos Llamas <cmllamas@google.com>
> > Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
> > ---
> >  security/selinux/hooks.c | 8 ++++----
> >  1 file changed, 4 insertions(+), 4 deletions(-)
> > 
> > diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
> > index 8d6945edae7a..09a12eb8652c 100644
> > --- a/security/selinux/hooks.c
> > +++ b/security/selinux/hooks.c
> > @@ -2980,6 +2980,10 @@ static int selinux_inode_init_security(struct inode *inode, struct inode *dir,
> >  	if (rc)
> >  		return rc;
> >  
> > +	if (!selinux_initialized() ||
> > +	    !(sbsec->flags & SBLABEL_MNT))
> > +		return -EOPNOTSUPP;
> 
> If we're moving this check, we should probably just move it to right
> after we assign 'sbsec' at the top of the function.  The calls to
> inode_mode_to_security() and selinux_determine_inode_label() aren't
> doing anything useful in either the !selinux_initialized() or !SBLABEL_MNT
> cases so let's avoid the unnecessary work.

Ha! That is a really good point. Let me move the check further up then.

^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH v2] selinux: bpf: check SBLABEL_MNT before isec init
  2026-07-30 21:10   ` Paul Moore
  2026-07-30 22:07     ` Carlos Llamas
@ 2026-07-30 22:15     ` Carlos Llamas
  1 sibling, 0 replies; 5+ messages in thread
From: Carlos Llamas @ 2026-07-30 22:15 UTC (permalink / raw)
  To: Paul Moore, Stephen Smalley, Ondrej Mosnacek,
	Christian Brauner (Amutable), Daniel Borkmann
  Cc: kernel-team, linux-kernel, Alexei Starovoitov, linux-fsdevel,
	Carlos Llamas, stable, open list:SELINUX SECURITY MODULE,
	open list:BPF [MISC]:Keyword:(?:b|_)bpf(?:b|_)

selinux_inode_init_security() marks the isec as initialized before
checking if mount labeling is supported (SBLABEL_MNT). This was fine
until commit 9722955b5430 ("bpf: Add simple xattr support to bpffs"),
where genfscon bpffs mounts fail the SBLABEL_MNT check as expected (no
xattrs) and yet leave the isec->initialized. This breaks subsequent
calls to inode_doinit_with_dentry().

Do the SBLABEL_MNT check before the inode security is initialized.

Cc: stable@vger.kernel.org
Closes: https://lore.kernel.org/all/akWdcp6P0FkNDzBk@google.com/
Fixes: 9722955b5430 ("bpf: Add simple xattr support to bpffs")
Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
Signed-off-by: Carlos Llamas <cmllamas@google.com>
---
v2:
  - Move the check further at the top per Paul's feedback.
  - Collect Stephen's Ack.

v1:
  https://lore.kernel.org/all/20260730181008.3654413-1-cmllamas@google.com/

 security/selinux/hooks.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
index 8d6945edae7a..18dd28b2bb13 100644
--- a/security/selinux/hooks.c
+++ b/security/selinux/hooks.c
@@ -2974,6 +2974,10 @@ static int selinux_inode_init_security(struct inode *inode, struct inode *dir,
 
 	sbsec = selinux_superblock(dir->i_sb);
 
+	if (!selinux_initialized() ||
+	    !(sbsec->flags & SBLABEL_MNT))
+		return -EOPNOTSUPP;
+
 	newsid = crsec->create_sid;
 	newsclass = inode_mode_to_security_class(inode->i_mode);
 	rc = selinux_determine_inode_label(crsec, dir, qstr, newsclass, &newsid);
@@ -2988,10 +2992,6 @@ static int selinux_inode_init_security(struct inode *inode, struct inode *dir,
 		isec->initialized = LABEL_INITIALIZED;
 	}
 
-	if (!selinux_initialized() ||
-	    !(sbsec->flags & SBLABEL_MNT))
-		return -EOPNOTSUPP;
-
 	xattr = lsm_get_xattr_slot(xattrs, xattr_count);
 	if (xattr) {
 		rc = security_sid_to_context_force(newsid,
-- 
2.55.0.508.g3f0d502094-goog


^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-07-30 22:15 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] <01421d53-c379-4044-9da3-5990186303ef@iogearbox.net>
2026-07-30 18:10 ` [PATCH] selinux: bpf: check SBLABEL_MNT before isec init Carlos Llamas
2026-07-30 18:50   ` Stephen Smalley
2026-07-30 21:10   ` Paul Moore
2026-07-30 22:07     ` Carlos Llamas
2026-07-30 22:15     ` [PATCH v2] " Carlos Llamas

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox