SELinux Security Module development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
Cc: selinux@vger.kernel.org
Subject: Re: [PATCH v4] selinux: implement namespace_init and namespace_install hooks
Date: Mon, 21 Sep 2026 13:45:53 +0000	[thread overview]
Message-ID: <20260921134554.15D051F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260921132825.17526-1-stephen.smalley.work@gmail.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] selinux: missing SECINITSID_KERNEL fallback for initial namespaces in setns
- [Medium] selinux: audit logs report zero ns_id during namespace creation
--

commit 7cfaed9361f973ecdd7fd2e074c01074e97b7cd5
Author: Daniel Durning <danieldurning.work@gmail.com>

selinux: implement namespace_init and namespace_install hooks
    
This commit adds implementations for the namespace_init and
namespace_install hooks to control namespace creation and setns
operations via SELinux. It defines new security classes for different
namespace types and saves the creator's SID in the namespace security
blob for validation.

> diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
> index f2394cf6646e5..cd7ec2c90d1d0 100644
> --- a/security/selinux/hooks.c
> +++ b/security/selinux/hooks.c

[ ... ]

> @@ -7184,6 +7211,41 @@ static int selinux_inode_getsecctx(struct inode *inode, struct lsm_context *cp)
>  	cp->id = LSM_ID_SELINUX;
>  	return 0;
>  }
> +
> +static int selinux_namespace_init(struct ns_common *ns)
> +{
> +	struct common_audit_data ad;
> +	struct ns_security_struct *nssec = selinux_ns(ns);
> +	u16 sclass = ns_type_to_security_class(ns);
> +	u32 sid = current_sid();
> +
> +	ad.type = LSM_AUDIT_DATA_NS;
> +	ad.u.ns.ns_type = ns->ns_type;
> +	ad.u.ns.ns_id = ns->ns_id;

[Severity: Medium]
Will this audit log record an ns_id of 0 for all namespace creation events?

During namespace creation, ns_common_init() initializes ns->ns_id to 0 and
immediately calls security_namespace_init(). The actual namespace ID isn't
assigned until ns_tree_gen_id() is called later in the lifecycle.

Because selinux_namespace_init() reads ns->ns_id before it is assigned, does
this leave the audit logs ineffective for correlating namespace lifecycle
events?

> +
> +	nssec->sid = sid;
> +	if (ns->inum == MNT_NS_ANON_INO)
> +		return avc_has_perm(sid, sid, sclass,
> +					MNT_NAMESPACE__CREATE_ANON, &ad);
> +
> +	return avc_has_perm(sid, sid, sclass, NAMESPACE__CREATE, &ad);
> +}
> +
> +static int selinux_namespace_install(const struct nsset *nsset,
> +				  struct ns_common *ns)
> +{
> +	struct common_audit_data ad;
> +	struct ns_security_struct *nssec = selinux_ns(ns);
> +	u16 sclass = ns_type_to_security_class(ns);
> +	u32 sid = current_sid();
> +
> +	ad.type = LSM_AUDIT_DATA_NS;
> +	ad.u.ns.ns_type = ns->ns_type;
> +	ad.u.ns.ns_id = ns->ns_id;
> +
> +	return avc_has_perm(sid, nssec->sid, sclass, NAMESPACE__SETNS, &ad);

[Severity: High]
Is the fallback to SECINITSID_KERNEL missing here?

The commit message states: "We fall back to SECINITSID_KERNEL if ns_common is
pointing to an init namespace, since these are created before policy load and
will be lacking a security blob."

However, this line unconditionally dereferences nssec->sid. If setns() targets
an initial namespace (where ns->ns_security might be uninitialized or NULL),
could this result in a NULL pointer dereference or an evaluation against
SECINITSID_UNLABELED instead of SECINITSID_KERNEL?

> +}
> +

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260921132825.17526-1-stephen.smalley.work@gmail.com?part=1

      reply	other threads:[~2026-09-21 13:45 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-21 13:28 [PATCH v4] selinux: implement namespace_init and namespace_install hooks Stephen Smalley
2026-09-21 13:45 ` sashiko-bot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260921134554.15D051F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=selinux@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox