Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] The WARN_ON_ONCE for a dispatch miss is bypassed if the caller erroneously passes LSM_ID_BPF, resulting in a silent leak.
--
--- Patch [2]: [PATCH bpf-next 02/13] lsm: Add LSM hook security_policy_kptr_put ---
commit 6653ce935258422e0de519b7ec4e4610455b2e51
Author: Justin Suess <[email protected]>
lsm: Add LSM hook security_policy_kptr_put
This commit adds a generic LSM hook for releasing a reference obtained
through security_policy_kptr_from_fd(). The hook uses targeted dispatch
by lsmid and includes a warning on a dispatch miss to prevent silent leaks.
> diff --git a/security/security.c b/security/security.c
> index 14fd8b878cd07..fd535bd00c244 100644
> --- a/security/security.c
> +++ b/security/security.c
[ ... ]
> @@ -5479,6 +5479,33 @@ int security_policy_kptr_from_fd(u64 lsmid, int fd,
> return LSM_RET_DEFAULT(policy_kptr_from_fd);
> }
>
> +/**
> + * security_policy_kptr_put() - Put a reference on an LSM policy object
> + * @lsmid: LSM_ID_* value of the LSM owning @policy
> + * @policy: the policy object, in the member of the LSM identified by
> + * @lsmid
> + *
> + * Release a reference previously obtained with
> + * security_policy_kptr_from_fd(). Only the hook implementation
> + * of the LSM identified by @lsmid is called, and @policy must have
> + * been obtained from that same LSM. An implementation must support
> + * being called from a context that cannot sleep: the release of BPF
> + * managed references may be driven from object destructors.
> + */
> +void security_policy_kptr_put(u64 lsmid, union lsm_policy_kptr *policy)
> +{
> + struct lsm_static_call *scall;
> +
> + lsm_for_each_hook(scall, policy_kptr_put) {
> + if (scall->hl->lsmid->id != lsmid)
> + continue;
> + scall->hl->hook.policy_kptr_put(policy);
> + return;
> + }
> + /* A held reference implies the matching LSM implements the hook. */
> + WARN_ON_ONCE(1);
> +}
[Severity: Medium]
Will this warning be bypassed if a caller mistakenly passes LSM_ID_BPF?
The commit message states that a dispatch miss means a caller passed the
wrong lsmid, and that the shim warns instead of silently leaking the
reference.
However, since the BPF LSM automatically registers a void-returning stub for
all LSM hooks (bpf_lsm_policy_kptr_put), it appears the dispatch loop will
match LSM_ID_BPF, call the empty stub, and return early.
Could this result in a silent leak without triggering the WARN_ON_ONCE(1)?
--
Sashiko AI review · https://sashiko.dev/#/patchset/[email protected]?part=2
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.