SELinux Security Module development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
Cc: selinux@vger.kernel.org
Subject: Re: [PATCH v5] selinux: implement namespace_init and namespace_install hooks
Date: Mon, 21 Sep 2026 13:48:30 +0000	[thread overview]
Message-ID: <20260921134830.ADFE41F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260921133145.17768-2-stephen.smalley.work@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] selinux: audit log records ns_id=0 for all namespace creations
--

commit ee58aea3229beb02443b58cad2bfbb58dd22830b
Author: Daniel Durning <danieldurning.work@gmail.com>

selinux: implement namespace_init and namespace_install hooks

Add implementations of the namespace_init and namespace_install
hooks for SELinux. Corresponding permissions are defined for each
hook (create and setns, respectively).

> diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
> index f2394cf6646e5..cd7ec2c90d1d0 100644
> --- a/security/selinux/hooks.c
> +++ b/security/selinux/hooks.c
[ ... ]
> @@ -7184,6 +7211,41 @@ static int selinux_inode_getsecctx(struct inode *inode, struct lsm_context *cp)
>  	cp->id = LSM_ID_SELINUX;
>  	return 0;
>  }
> +
> +static int selinux_namespace_init(struct ns_common *ns)
> +{
> +	struct common_audit_data ad;
> +	struct ns_security_struct *nssec = selinux_ns(ns);
> +	u16 sclass = ns_type_to_security_class(ns);
> +	u32 sid = current_sid();
> +
> +	ad.type = LSM_AUDIT_DATA_NS;
> +	ad.u.ns.ns_type = ns->ns_type;
> +	ad.u.ns.ns_id = ns->ns_id;

[Severity: Medium]
Will this regression result in the audit log systematically recording an
ns_id of 0 for every namespace creation?

Looking at __ns_common_init() in kernel/nscommon.c, it initializes ns->ns_id
to 0 just before the security_namespace_init() hook is invoked:

kernel/nscommon.c:__ns_common_init() {
	ns->ns_id = 0;
	ns->ns_type = ns_type;
	...
	ret = security_namespace_init(ns);
}

The actual namespace ID appears to be generated only after the namespace
infrastructure finishes invoking the security hooks. For example, in
alloc_mnt_ns() in fs/namespace.c:

fs/namespace.c:alloc_mnt_ns() {
	if (anon)
		ret = ns_common_init_inum(new_ns, MNT_NS_ANON_INO);
	else
		ret = ns_common_init(new_ns);
	if (ret) {
		kfree(new_ns);
		dec_mnt_namespaces(ucounts);
		return ERR_PTR(ret);
	}
	ns_tree_gen_id(new_ns);
}

Could this timing behavior prevent properly correlating namespace creation
events with subsequent actions in the security audit logs, since the actual
ID isn't assigned until after the audit record is generated?

> +
> +	nssec->sid = sid;
> +	if (ns->inum == MNT_NS_ANON_INO)
> +		return avc_has_perm(sid, sid, sclass,
> +					MNT_NAMESPACE__CREATE_ANON, &ad);
> +
> +	return avc_has_perm(sid, sid, sclass, NAMESPACE__CREATE, &ad);
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260921133145.17768-2-stephen.smalley.work@gmail.com?part=1

      reply	other threads:[~2026-09-21 13:48 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-21 13:31 [PATCH v5] selinux: implement namespace_init and namespace_install hooks Stephen Smalley
2026-09-21 13:48 ` sashiko-bot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260921134830.ADFE41F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=selinux@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox