Re: [PATCH v4] security: Expand task_setscheduler LSM hook

Aaron Tomlin <[email protected]>
Newsgroups org.kernel.vger.selinux,org.kernel.vger.cgroups,org.kernel.vger.linux-fsdevel,org.kernel.vger.linux-kernel,org.kernel.vger.linux-mips,org.kernel.vger.linux-security-module
Message-ID <j3ybir7lqphxvep2tvmgqhmb6hzufmat7lcxonwkamagpjiwdc@n4cpxxdhqxm6>
On Tue, Jul 21, 2026 at 07:45:41AM -0700, Casey Schaufler wrote:
> On 7/19/2026 6:41 PM, Aaron Tomlin wrote:
> > At present, the task_setscheduler LSM hook provides security modules
> > with the opportunity to mediate changes to a task's scheduling policy by
> > inspecting the requested sched_attr. However, when invoked via
> > sched_setaffinity(), the hook lacks visibility into the actual CPU
> > affinity mask being requested. Consequently, security modules are
> > entirely blind to the target CPUs and cannot make granular access
> > control decisions based on spatial isolation.
> >
> > In modern multi-tenant and real-time environments, CPU isolation is a
> > critical boundary. The inability to audit or restrict specific CPU
> > pinning requests limits the effectiveness of security policies,
> > particularly when attempting to shield isolated or cryptographic cores
> > from unprivileged or compromised tasks.
> >
> > This patch expands the security_task_setscheduler() hook signature to
> > include a pointer to the requested cpumask alongside the existing
> > sched_attr. Because this is a shared hook used for multiple scheduling
> > attribute changes, call sites that do not modify CPU affinity are
> > updated to safely pass NULL for the mask. To protect against unverified
> > dereferences, the parameter is annotated with __nullable in the LSM hook
> > definition, ensuring the BPF verifier mandates explicit NULL checks for
> > attached eBPF programs.
> >
> > Historically, SELinux has governed all scheduling alterations under a
> > single, monolithic PROCESS__SETSCHED access vector. However, by
> > inspecting fields such as attr->sched_policy or attr->sched_priority, a
> > security module can introduce granular access controls. For instance,
> > differentiating between standard time-sharing policies and
> > latency-sensitive real-time policies.
> >
> > This change updates all in-tree security modules (SELinux and Smack) to
> > accommodate the new parameter mechanically, while providing LSMs with
> > the necessary context to enforce strict affinity policies.
> >
> > Signed-off-by: Aaron Tomlin <[email protected]>
> > ---
> > Changes since v3:
> >
> >  - Expanded the task_setscheduler LSM hook to accept the 'sched_attr'
> >    payload, enabling BPF and other LSMs to inspect scheduling attributes
> >    (Peter Zijlstra)
> >
> >  - Updated all call sites for security_task_setscheduler() to correctly
> >    pass the attr structure when available, or NULL otherwise
> >    (Peter Zijlstra)
> >
> >  - Added the necessary forward declaration for struct sched_attr to
> >    include/linux/security.h
> >
> >  - Linked to v3: https://lore.kernel.org/lkml/[email protected]/
> >
> > Changes since v2:
> >
> >  - Dropped patch 1. This is to be addressed by the cgroup cpuset
> >    maintainer (Waiman Long)
> >
> >  - Dropped patch 3. Will be submitted as a separate patch (Paul Moore)
> >
> >  - Linked to v2: https://lore.kernel.org/lkml/[email protected]/
> >
> > Changes since v1:
> >
> >  - Reordered the allocation and user-copy of new_mask in the MIPS
> >    architecture's mipsmt_sys_sched_setaffinity() to occur before the
> >    LSM hook is invoked. This ensures the security modules evaluate a fully
> >    populated mask rather than uninitialised memory, while cleanly handling
> >    error unwinding
> >
> >  - Updated cpuset_can_fork() to pass the destination cpuset's effective CPU
> >    mask instead of NULL
> >
> >  - Linked to v1: https://lore.kernel.org/lkml/[email protected]/
> >
> > Signed-off-by: Aaron Tomlin <[email protected]>
> 
> For the (trivial) Smack changes:
> Reviewed-by: Casey Schaufler <[email protected]>

Thank you Casey.

-- 
Aaron Tomlin
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEeQaE6/qKljiNHm6b4t6WWBnMd9YFAmpzLUMACgkQ4t6WWBnM
d9Zf+w/+ILuBMrjK1tRpjLojddWCTDkzwwS7/zPizufqmhj4yGKKUfg1/af/xh3d
pGG58y3DqEkHldjWX4JzlKCkH6B2mZUpOLF84Kj+XHNF5e9RhVaRAalmW9sS26X+
9L10XGY1hMNOp88fZl6Az3w+4n89d0C0XRkTsU5mL4sdKQPflwMDFiy9mcEAxs8T
qYzYFAuc5y7QLCSUPrUefi1nbHXDDtorDt+ohFCwhjxSZvcNJiXSVGMJPWCI9iNZ
FotLk4J/my7TKxsoQJxyFIp3A+OkNHgwrPp/usmEREtk7qq1nvvYGLB5PpjBdWw1
OuGJu9vwTK8Qvcn3pGHOGO2MG21p6PFdGQjg6f2gtD2bjxte/aom6sRHq3W3BXbm
kTuljDJJKdSWskU7WCw2XncO6h+qThorjAC9BGOntHZG1qJLOl0UYP5CK8rulJD4
cQYmKQATuLp64Ehs+KmGJ6i79j01+hq0BOhd3GMrkjm6FAb0UXJqyWjoGcrNdKmO
z860bY85hm9RN1LdVxcPg0YjGRaSocRxQYdkqkBsTrFwO9TErS/GGwkf/XoIPjOY
K9Qmxn7ZeS3cMrwY+2kmR6xnz9AY55uvNRqgIvM2tDjYyjzRoZrPUUOZjFb5JjDj
U81XsUl1bYnlu6YxMR5jWL/FAtcKYV996Wst/szmmeGtJZwIPI8=
=ghWr
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.