Re: [PATCH v2 6/7] Apparmor: hooks for secctx_to_lsmprop and update_lsmprop
John Johansen <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.netfilter.devel,gmane.linux.kernel.lsm,gmane.linux.kernel |
|---|---|
| Organization | Canonical |
| Message-ID | <[email protected]> |
the code itself looks right same nit on update_lsmprop as previous two patches. I know you are working within the insane constraints of the secid, but it really hurts that apparmor has a local xarray for secids, and now the LSM infra has one too. I know its a problem to be solved later, I am just griping about the current state of affairs. On 9/2/26 15:01, Casey Schaufler wrote: > Implement these hooks. > > Signed-off-by: Casey Schaufler <[email protected]> > --- > security/apparmor/include/secid.h | 4 ++++ > security/apparmor/lsm.c | 2 ++ > security/apparmor/secid.c | 21 +++++++++++++++++++++ > 3 files changed, 27 insertions(+) > > diff --git a/security/apparmor/include/secid.h b/security/apparmor/include/secid.h > index 6025d3849cf8..ba7adf2fc09e 100644 > --- a/security/apparmor/include/secid.h > +++ b/security/apparmor/include/secid.h > @@ -28,6 +28,10 @@ struct aa_label *aa_secid_to_label(u32 secid); > int apparmor_secid_to_secctx(u32 secid, struct lsm_context *cp); > int apparmor_lsmprop_to_secctx(struct lsm_prop *prop, struct lsm_context *cp); > int apparmor_secctx_to_secid(const char *secdata, u32 seclen, u32 *secid); > +int apparmor_secctx_to_lsmprop(const char *secdata, u32 seclen, > + struct lsm_prop *prop); > +void apparmor_update_lsmprop(struct lsm_prop *dest, struct lsm_prop *src, > + int lsmid); > void apparmor_release_secctx(struct lsm_context *cp); > > > diff --git a/security/apparmor/lsm.c b/security/apparmor/lsm.c > index 88d12e89d115..1f304b88eaf9 100644 > --- a/security/apparmor/lsm.c > +++ b/security/apparmor/lsm.c > @@ -1766,6 +1766,8 @@ static struct security_hook_list apparmor_hooks[] __ro_after_init = { > LSM_HOOK_INIT(secid_to_secctx, apparmor_secid_to_secctx), > LSM_HOOK_INIT(lsmprop_to_secctx, apparmor_lsmprop_to_secctx), > LSM_HOOK_INIT(secctx_to_secid, apparmor_secctx_to_secid), > + LSM_HOOK_INIT(secctx_to_lsmprop, apparmor_secctx_to_lsmprop), > + LSM_HOOK_INIT(update_lsmprop, apparmor_update_lsmprop), > LSM_HOOK_INIT(release_secctx, apparmor_release_secctx), > > #ifdef CONFIG_IO_URING > diff --git a/security/apparmor/secid.c b/security/apparmor/secid.c > index 28caf66b9033..d35fdbf074e0 100644 > --- a/security/apparmor/secid.c > +++ b/security/apparmor/secid.c > @@ -106,6 +106,27 @@ int apparmor_secctx_to_secid(const char *secdata, u32 seclen, u32 *secid) > return 0; > } > > +int apparmor_secctx_to_lsmprop(const char *secdata, u32 seclen, > + struct lsm_prop *prop) > +{ > + struct aa_label *label; > + > + label = aa_label_strn_parse(&root_ns->unconfined->label, secdata, > + seclen, GFP_KERNEL, false, false); > + if (IS_ERR(label)) > + return PTR_ERR(label); > + prop->apparmor.label = label; > + > + return 0; > +} > + > +void apparmor_update_lsmprop(struct lsm_prop *dest, struct lsm_prop *src, > + int lsmid) > +{ > + if (lsmid == LSM_ID_APPARMOR || lsmid == LSM_ID_UNDEF) > + dest->apparmor.label = src->apparmor.label; > +} > + > void apparmor_release_secctx(struct lsm_context *cp) > { > if (cp->id == LSM_ID_APPARMOR) {