summaryrefslogtreecommitdiff
path: root/security
diff options
context:
space:
mode:
authorLinus Torvalds <torvalds@linux-foundation.org>2026-09-03 13:36:21 -0700
committerLinus Torvalds <torvalds@linux-foundation.org>2026-09-03 13:36:21 -0700
commita500db7819c50db59e55f1b4fa1c3baa5a2616f3 (patch)
tree67974d29e48055c28bac6ba89bc94a659c470f54 /security
parent36b03c3e270a2a4cf73202e07a93bd3a9ebd86c7 (diff)
parent4299767d772d4e498998e32157e45841178ab192 (diff)
downloadlinux-a500db7819c50db59e55f1b4fa1c3baa5a2616f3.tar.gz
linux-a500db7819c50db59e55f1b4fa1c3baa5a2616f3.zip
Merge tag 'selinux-pr-20260903' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux
Pull SELinux fixes from Paul Moore: "Two SELinux fixes: one to fix how we lookup a BPF token's creator label to prevent a possible TOCTOU, and one to update Ondrej's email address" * tag 'selinux-pr-20260903' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux: MAINTAINERS, mailmap: update email address for Ondrej Mosnáček selinux: fix BPF token permission checks
Diffstat (limited to 'security')
-rw-r--r--security/selinux/hooks.c36
1 files changed, 10 insertions, 26 deletions
diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
index 035aaf113d1d..e5e17f100aae 100644
--- a/security/selinux/hooks.c
+++ b/security/selinux/hooks.c
@@ -7267,24 +7267,6 @@ static int selinux_bpf_prog(struct bpf_prog *prog)
BPF__PROG_RUN, NULL);
}
-static u32 selinux_bpffs_creator_sid(u32 fd)
-{
- struct path path;
- struct super_block *sb;
- struct superblock_security_struct *sbsec;
-
- CLASS(fd, f)(fd);
-
- if (fd_empty(f))
- return SECSID_NULL;
-
- path = fd_file(f)->f_path;
- sb = path.dentry->d_sb;
- sbsec = selinux_superblock(sb);
-
- return sbsec->creator_sid;
-}
-
static int selinux_bpf_map_create(struct bpf_map *map, union bpf_attr *attr,
struct bpf_token *token, bool kernel)
{
@@ -7297,7 +7279,7 @@ static int selinux_bpf_map_create(struct bpf_map *map, union bpf_attr *attr,
if (!token)
ssid = bpfsec->sid;
else
- ssid = selinux_bpffs_creator_sid(attr->map_token_fd);
+ ssid = selinux_bpf_token_security(token)->grantor_sid;
return avc_has_perm(ssid, bpfsec->sid, SECCLASS_BPF, BPF__MAP_CREATE,
NULL);
@@ -7315,7 +7297,7 @@ static int selinux_bpf_prog_load(struct bpf_prog *prog, union bpf_attr *attr,
if (!token)
ssid = bpfsec->sid;
else
- ssid = selinux_bpffs_creator_sid(attr->prog_token_fd);
+ ssid = selinux_bpf_token_security(token)->grantor_sid;
return avc_has_perm(ssid, bpfsec->sid, SECCLASS_BPF, BPF__PROG_LOAD,
NULL);
@@ -7329,12 +7311,14 @@ static int selinux_bpf_token_create(struct bpf_token *token,
const struct path *path)
{
struct bpf_security_struct *bpfsec;
- u32 sid = selinux_bpffs_creator_sid(attr->token_create.bpffs_fd);
+ struct superblock_security_struct *sbsec;
int err;
+ sbsec = selinux_superblock(path->dentry->d_sb);
+
bpfsec = selinux_bpf_token_security(token);
bpfsec->sid = current_sid();
- bpfsec->grantor_sid = sid;
+ bpfsec->grantor_sid = sbsec->creator_sid;
bpfsec->perms = 0;
/**
@@ -7343,15 +7327,15 @@ static int selinux_bpf_token_create(struct bpf_token *token,
* in the allowed_cmds bitmap.
*/
if (bpf_token_cmd(token, BPF_MAP_CREATE)) {
- err = avc_has_perm(bpfsec->sid, sid, SECCLASS_BPF,
- BPF__MAP_CREATE_AS, NULL);
+ err = avc_has_perm(bpfsec->sid, bpfsec->grantor_sid,
+ SECCLASS_BPF, BPF__MAP_CREATE_AS, NULL);
if (err)
return err;
bpfsec->perms |= BPF__MAP_CREATE;
}
if (bpf_token_cmd(token, BPF_PROG_LOAD)) {
- err = avc_has_perm(bpfsec->sid, sid, SECCLASS_BPF,
- BPF__PROG_LOAD_AS, NULL);
+ err = avc_has_perm(bpfsec->sid, bpfsec->grantor_sid,
+ SECCLASS_BPF, BPF__PROG_LOAD_AS, NULL);
if (err)
return err;
bpfsec->perms |= BPF__PROG_LOAD;