Skip to content

Commit 520b7aa

Browse files
sinkapborkmann
authored andcommitted
bpf: lsm: Initialize the BPF LSM hooks
* The hooks are initialized using the definitions in include/linux/lsm_hook_defs.h. * The LSM can be enabled / disabled with CONFIG_BPF_LSM. Signed-off-by: KP Singh <[email protected]> Signed-off-by: Daniel Borkmann <[email protected]> Reviewed-by: Brendan Jackman <[email protected]> Reviewed-by: Florent Revest <[email protected]> Acked-by: Kees Cook <[email protected]> Acked-by: James Morris <[email protected]> Link: https://lore.kernel.org/bpf/[email protected]
1 parent 9e4e01d commit 520b7aa

File tree

4 files changed

+38
-5
lines changed

4 files changed

+38
-5
lines changed

security/Kconfig

+5-5
Original file line numberDiff line numberDiff line change
@@ -277,11 +277,11 @@ endchoice
277277

278278
config LSM
279279
string "Ordered list of enabled LSMs"
280-
default "lockdown,yama,loadpin,safesetid,integrity,smack,selinux,tomoyo,apparmor" if DEFAULT_SECURITY_SMACK
281-
default "lockdown,yama,loadpin,safesetid,integrity,apparmor,selinux,smack,tomoyo" if DEFAULT_SECURITY_APPARMOR
282-
default "lockdown,yama,loadpin,safesetid,integrity,tomoyo" if DEFAULT_SECURITY_TOMOYO
283-
default "lockdown,yama,loadpin,safesetid,integrity" if DEFAULT_SECURITY_DAC
284-
default "lockdown,yama,loadpin,safesetid,integrity,selinux,smack,tomoyo,apparmor"
280+
default "lockdown,yama,loadpin,safesetid,integrity,smack,selinux,tomoyo,apparmor,bpf" if DEFAULT_SECURITY_SMACK
281+
default "lockdown,yama,loadpin,safesetid,integrity,apparmor,selinux,smack,tomoyo,bpf" if DEFAULT_SECURITY_APPARMOR
282+
default "lockdown,yama,loadpin,safesetid,integrity,tomoyo,bpf" if DEFAULT_SECURITY_TOMOYO
283+
default "lockdown,yama,loadpin,safesetid,integrity,bpf" if DEFAULT_SECURITY_DAC
284+
default "lockdown,yama,loadpin,safesetid,integrity,selinux,smack,tomoyo,apparmor,bpf"
285285
help
286286
A comma-separated list of LSMs, in initialization order.
287287
Any LSMs left off this list will be ignored. This can be

security/Makefile

+2
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,7 @@ subdir-$(CONFIG_SECURITY_YAMA) += yama
1212
subdir-$(CONFIG_SECURITY_LOADPIN) += loadpin
1313
subdir-$(CONFIG_SECURITY_SAFESETID) += safesetid
1414
subdir-$(CONFIG_SECURITY_LOCKDOWN_LSM) += lockdown
15+
subdir-$(CONFIG_BPF_LSM) += bpf
1516

1617
# always enable default capabilities
1718
obj-y += commoncap.o
@@ -30,6 +31,7 @@ obj-$(CONFIG_SECURITY_LOADPIN) += loadpin/
3031
obj-$(CONFIG_SECURITY_SAFESETID) += safesetid/
3132
obj-$(CONFIG_SECURITY_LOCKDOWN_LSM) += lockdown/
3233
obj-$(CONFIG_CGROUP_DEVICE) += device_cgroup.o
34+
obj-$(CONFIG_BPF_LSM) += bpf/
3335

3436
# Object integrity file lists
3537
subdir-$(CONFIG_INTEGRITY) += integrity

security/bpf/Makefile

+5
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
# SPDX-License-Identifier: GPL-2.0
2+
#
3+
# Copyright (C) 2020 Google LLC.
4+
5+
obj-$(CONFIG_BPF_LSM) := hooks.o

security/bpf/hooks.c

+26
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
// SPDX-License-Identifier: GPL-2.0
2+
3+
/*
4+
* Copyright (C) 2020 Google LLC.
5+
*/
6+
#include <linux/lsm_hooks.h>
7+
#include <linux/bpf_lsm.h>
8+
9+
static struct security_hook_list bpf_lsm_hooks[] __lsm_ro_after_init = {
10+
#define LSM_HOOK(RET, DEFAULT, NAME, ...) \
11+
LSM_HOOK_INIT(NAME, bpf_lsm_##NAME),
12+
#include <linux/lsm_hook_defs.h>
13+
#undef LSM_HOOK
14+
};
15+
16+
static int __init bpf_lsm_init(void)
17+
{
18+
security_add_hooks(bpf_lsm_hooks, ARRAY_SIZE(bpf_lsm_hooks), "bpf");
19+
pr_info("LSM support for eBPF active\n");
20+
return 0;
21+
}
22+
23+
DEFINE_LSM(bpf) = {
24+
.name = "bpf",
25+
.init = bpf_lsm_init,
26+
};

0 commit comments

Comments
 (0)