Received: by 2002:a25:8b91:0:0:0:0:0 with SMTP id j17csp770331ybl; Thu, 23 Jan 2020 07:26:41 -0800 (PST) X-Google-Smtp-Source: APXvYqxkzrDUXeS7pLGLjuQvc7TOJV/He+3xGpVMswEyNmpeZKUUCDeaGCS4MRk5xCld3w8X8xbe X-Received: by 2002:a05:6808:84:: with SMTP id s4mr11057081oic.60.1579793201446; Thu, 23 Jan 2020 07:26:41 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1579793201; cv=none; d=google.com; s=arc-20160816; b=OCE8KY+/v+tvbY+ZNpywr4hEWSjPyOVSb61WoeKDKUCWhlGQnPWmZodxJxZOOUNPpy 9wbahxd0kkA7do0WHGtikafjiYTO7fuLgHM1olycIWIIaUEKTKvnAdsTWOCHpD+lbVrx 0k++ShN+py5ICyHsSCs76PDSYtI62n769mLDIGm4mYNu/w8sNfkzOwCIUw9zuiDYDTgm SUfvwtg+FjKyNqcoJ0+aidtmFeAZjD3vmLSjlxJKwPpsgQBeWBLwXLLTRKmw6NI0WgG8 WxiLeizZX2QuHdUhgntT35T/qiPJxkue+1n9Y+BVWi71QMFZoYL7GYkfPLNdkjNXVpsc 6bMA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :dkim-signature; bh=TOgW7lcXGtnBKERztN8ZYLITTM6bIMZTuIfirqHWInE=; b=YwcKPZefud6xqosvZPyrArqLDpBXybaK1sgJrmznnT322eBmu2Ha/jQER3Er2N3qoH 8IhAvNlXm9dohOV3vdDljIWEZZxHduk+ZhP+Og8geX4DlxmfvT2EMk748dIc2NMPch0u UAwe2FYx4Cj9rvzEveQCc9MEYRVK2WHlJ8lyHwyYZo1EjyAmdL6mWweAgUUMfA+scguP aiactAf4PUPh4FdIwV+l3gqVK3JKHGuMOUURyU5Q+lujgirtF0EkEru9a9M/qLoSvwix cxWd7oqUq5eeevGNag1cZGKhRsjMCKycu8FDrbHlV39cxD7HkBecq8QthqzFV7Yh12Vj FS8w== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b="Sd/REqC2"; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id w18si1260870otl.54.2020.01.23.07.26.29; Thu, 23 Jan 2020 07:26:41 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@chromium.org header.s=google header.b="Sd/REqC2"; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=chromium.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1729164AbgAWPZP (ORCPT + 99 others); Thu, 23 Jan 2020 10:25:15 -0500 Received: from mail-pf1-f195.google.com ([209.85.210.195]:32844 "EHLO mail-pf1-f195.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1729149AbgAWPZO (ORCPT ); Thu, 23 Jan 2020 10:25:14 -0500 Received: by mail-pf1-f195.google.com with SMTP id z16so1703181pfk.0 for ; Thu, 23 Jan 2020 07:25:14 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=TOgW7lcXGtnBKERztN8ZYLITTM6bIMZTuIfirqHWInE=; b=Sd/REqC2xMx3gXm3vWuonOosNbIknnr7sb8eU7WJ45Jkxi5hbmo3Rh9zHsOOlZ680F dX2+GfvsBxzesS7kOJJWI0kLHbMedyxut5gEPoZXqhRmXKzSDAPLK4mLWzPlAH3qi0Kw 3fVx4g9e4N9XWruZLaoMzM+T5xinGEs2JOno8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=TOgW7lcXGtnBKERztN8ZYLITTM6bIMZTuIfirqHWInE=; b=d6Wbs2VTI0L6b5ULUD6uT/a9wRQzHmKaj6fB+otNw+XbV/fPTu4mVyz0kMYs+cUGs1 n+9Ii9c1qoLe5ntcNWXGnOZYzQ3z6IHdcn+YLisX/xDMWdPLJHgIzr1AVl3hAsR3eggi BjDpLoMuTYVP3nXX5jj9yDPat9tV/atfoRD+wb+Xtd7oAj70KfAXhNb/tyxMNTHMDIof V7X7Rsd42HP6nyUYiHrbn0Ve5Rp23s+CY1TgDAvmO1xwLvZLdU6Y+/soihfFEkMXcZmB lfForC3LAhPve4C0EWdDIGZzTC6WOaNB/FphcGxNUXpaWgUIklTN/by6Oq9WjdTC4Bux 1+Aw== X-Gm-Message-State: APjAAAXQenFVFFfS9GYs3kPYMkf7R1N862GMjng4hNj1geoNx4W8UhgB Czjbz+xnMQu2ocG9NKZKksRz0tptqtcp1g== X-Received: by 2002:a65:6794:: with SMTP id e20mr4475292pgr.152.1579793113577; Thu, 23 Jan 2020 07:25:13 -0800 (PST) Received: from kpsingh-kernel.localdomain ([2a00:79e1:abc:122:bd8d:3f7b:87f7:16d1]) by smtp.gmail.com with ESMTPSA id v5sm3108118pfn.122.2020.01.23.07.25.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 23 Jan 2020 07:25:12 -0800 (PST) From: KP Singh To: linux-kernel@vger.kernel.org, bpf@vger.kernel.org, linux-security-module@vger.kernel.org Cc: Brendan Jackman , Florent Revest , Thomas Garnier , Alexei Starovoitov , Daniel Borkmann , James Morris , Kees Cook , Thomas Garnier , Michael Halcrow , Paul Turner , Brendan Gregg , Jann Horn , Matthew Garrett , Christian Brauner , =?UTF-8?q?Micka=C3=ABl=20Sala=C3=BCn?= , Florent Revest , Brendan Jackman , Martin KaFai Lau , Song Liu , Yonghong Song , "Serge E. Hallyn" , Mauro Carvalho Chehab , "David S. Miller" , Greg Kroah-Hartman , Nicolas Ferre , Stanislav Fomichev , Quentin Monnet , Andrey Ignatov , Joe Stringer Subject: [PATCH bpf-next v3 03/10] bpf: lsm: Introduce types for eBPF based LSM Date: Thu, 23 Jan 2020 07:24:33 -0800 Message-Id: <20200123152440.28956-4-kpsingh@chromium.org> X-Mailer: git-send-email 2.20.1 In-Reply-To: <20200123152440.28956-1-kpsingh@chromium.org> References: <20200123152440.28956-1-kpsingh@chromium.org> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: KP Singh A new eBPF program type BPF_PROG_TYPE_LSM with an expected attach type of BPF_LSM_MAC. Attachment to LSM hooks is not implemented in this patch. On defining the types for the program, the macros expect that _prog_ops and _verifier_ops exist. This is implicitly required by the macro: BPF_PROG_TYPE(BPF_PROG_TYPE_LSM, lsm, ...) Signed-off-by: KP Singh Reviewed-by: Brendan Jackman Reviewed-by: Florent Revest Reviewed-by: Thomas Garnier --- include/linux/bpf_types.h | 4 ++++ include/uapi/linux/bpf.h | 2 ++ kernel/bpf/syscall.c | 6 ++++++ security/bpf/Makefile | 2 +- security/bpf/ops.c | 28 ++++++++++++++++++++++++++++ tools/include/uapi/linux/bpf.h | 2 ++ tools/lib/bpf/libbpf_probes.c | 1 + 7 files changed, 44 insertions(+), 1 deletion(-) create mode 100644 security/bpf/ops.c diff --git a/include/linux/bpf_types.h b/include/linux/bpf_types.h index c81d4ece79a4..c36790b202e3 100644 --- a/include/linux/bpf_types.h +++ b/include/linux/bpf_types.h @@ -70,6 +70,10 @@ BPF_PROG_TYPE(BPF_PROG_TYPE_STRUCT_OPS, bpf_struct_ops, void *, void *) BPF_PROG_TYPE(BPF_PROG_TYPE_EXT, bpf_extension, void *, void *) +#ifdef CONFIG_SECURITY_BPF +BPF_PROG_TYPE(BPF_PROG_TYPE_LSM, lsm, + void *, void *) +#endif /* CONFIG_SECURITY_BPF */ #endif BPF_MAP_TYPE(BPF_MAP_TYPE_ARRAY, array_map_ops) diff --git a/include/uapi/linux/bpf.h b/include/uapi/linux/bpf.h index f1d74a2bd234..2f1e24a8c4a4 100644 --- a/include/uapi/linux/bpf.h +++ b/include/uapi/linux/bpf.h @@ -181,6 +181,7 @@ enum bpf_prog_type { BPF_PROG_TYPE_TRACING, BPF_PROG_TYPE_STRUCT_OPS, BPF_PROG_TYPE_EXT, + BPF_PROG_TYPE_LSM, }; enum bpf_attach_type { @@ -210,6 +211,7 @@ enum bpf_attach_type { BPF_TRACE_RAW_TP, BPF_TRACE_FENTRY, BPF_TRACE_FEXIT, + BPF_LSM_MAC, __MAX_BPF_ATTACH_TYPE }; diff --git a/kernel/bpf/syscall.c b/kernel/bpf/syscall.c index a91ad518c050..eab4a36ee889 100644 --- a/kernel/bpf/syscall.c +++ b/kernel/bpf/syscall.c @@ -2396,6 +2396,9 @@ static int bpf_prog_attach(const union bpf_attr *attr) case BPF_LIRC_MODE2: ptype = BPF_PROG_TYPE_LIRC_MODE2; break; + case BPF_LSM_MAC: + ptype = BPF_PROG_TYPE_LSM; + break; case BPF_FLOW_DISSECTOR: ptype = BPF_PROG_TYPE_FLOW_DISSECTOR; break; @@ -2427,6 +2430,9 @@ static int bpf_prog_attach(const union bpf_attr *attr) case BPF_PROG_TYPE_LIRC_MODE2: ret = lirc_prog_attach(attr, prog); break; + case BPF_PROG_TYPE_LSM: + ret = -EOPNOTSUPP; + break; case BPF_PROG_TYPE_FLOW_DISSECTOR: ret = skb_flow_dissector_bpf_prog_attach(attr, prog); break; diff --git a/security/bpf/Makefile b/security/bpf/Makefile index 26a0ab6f99b7..c78a8a056e7e 100644 --- a/security/bpf/Makefile +++ b/security/bpf/Makefile @@ -2,4 +2,4 @@ # # Copyright 2019 Google LLC. -obj-$(CONFIG_SECURITY_BPF) := lsm.o +obj-$(CONFIG_SECURITY_BPF) := lsm.o ops.o diff --git a/security/bpf/ops.c b/security/bpf/ops.c new file mode 100644 index 000000000000..81c2bd9c0495 --- /dev/null +++ b/security/bpf/ops.c @@ -0,0 +1,28 @@ +// SPDX-License-Identifier: GPL-2.0 + +/* + * Copyright 2019 Google LLC. + */ + +#include +#include + +const struct bpf_prog_ops lsm_prog_ops = { +}; + +static const struct bpf_func_proto *get_bpf_func_proto( + enum bpf_func_id func_id, const struct bpf_prog *prog) +{ + switch (func_id) { + case BPF_FUNC_map_lookup_elem: + return &bpf_map_lookup_elem_proto; + case BPF_FUNC_get_current_pid_tgid: + return &bpf_get_current_pid_tgid_proto; + default: + return NULL; + } +} + +const struct bpf_verifier_ops lsm_verifier_ops = { + .get_func_proto = get_bpf_func_proto, +}; diff --git a/tools/include/uapi/linux/bpf.h b/tools/include/uapi/linux/bpf.h index f1d74a2bd234..2f1e24a8c4a4 100644 --- a/tools/include/uapi/linux/bpf.h +++ b/tools/include/uapi/linux/bpf.h @@ -181,6 +181,7 @@ enum bpf_prog_type { BPF_PROG_TYPE_TRACING, BPF_PROG_TYPE_STRUCT_OPS, BPF_PROG_TYPE_EXT, + BPF_PROG_TYPE_LSM, }; enum bpf_attach_type { @@ -210,6 +211,7 @@ enum bpf_attach_type { BPF_TRACE_RAW_TP, BPF_TRACE_FENTRY, BPF_TRACE_FEXIT, + BPF_LSM_MAC, __MAX_BPF_ATTACH_TYPE }; diff --git a/tools/lib/bpf/libbpf_probes.c b/tools/lib/bpf/libbpf_probes.c index b782ebef6ac9..2c92059c0c90 100644 --- a/tools/lib/bpf/libbpf_probes.c +++ b/tools/lib/bpf/libbpf_probes.c @@ -108,6 +108,7 @@ probe_load(enum bpf_prog_type prog_type, const struct bpf_insn *insns, case BPF_PROG_TYPE_TRACING: case BPF_PROG_TYPE_STRUCT_OPS: case BPF_PROG_TYPE_EXT: + case BPF_PROG_TYPE_LSM: default: break; } -- 2.20.1