[PATCH v4 bpf-next 0/6] Enable writing xattr from BPF programs
Song Liu
song at kernel.org
Tue Dec 17 06:38:15 UTC 2024
Add support to set and remove xattr from BPF program. Also add
security.bpf. xattr name prefix.
kfuncs are added to set and remove xattrs with security.bpf. name
prefix. Update kfuncs bpf_get_[file|dentry]_xattr to read xattrs
with security.bpf. name prefix. Note that BPF programs can read
user. xattrs, but not write and remove them.
Cover letter of v1 and v2:
Follow up discussion in LPC 2024 [1], that we need security.bpf xattr
prefix. This set adds "security.bpf." xattr name prefix, and allows
bpf kfuncs bpf_get_[file|dentry]_xattr() to read these xattrs.
[1] https://lpc.events/event/18/contributions/1940/
Changes v3 => v4
1. Do write permission check with inode locked. (Jan Kara)
2. Fix some source_inline warnings.
v3: https://lore.kernel.org/bpf/20241210220627.2800362-1-song@kernel.org/
Changes v2 => v3
1. Add kfuncs to set and remove xattr from BPF programs.
v2: https://lore.kernel.org/bpf/20241016070955.375923-1-song@kernel.org/
Changes v1 => v2
1. Update comment of bpf_get_[file|dentry]_xattr. (Jiri Olsa)
2. Fix comment for return value of bpf_get_[file|dentry]_xattr.
v1: https://lore.kernel.org/bpf/20241002214637.3625277-1-song@kernel.org/
Song Liu (6):
fs/xattr: bpf: Introduce security.bpf. xattr name prefix
selftests/bpf: Extend test fs_kfuncs to cover security.bpf. xattr
names
bpf: lsm: Add two more sleepable hooks
bpf: fs/xattr: Add BPF kfuncs to set and remove xattrs
selftests/bpf: Test kfuncs that set and remove xattr from BPF programs
selftests/bpf: Add __failure tests for set/remove xattr kfuncs
fs/bpf_fs_kfuncs.c | 262 +++++++++++++++++-
include/uapi/linux/xattr.h | 4 +
kernel/bpf/bpf_lsm.c | 2 +
tools/testing/selftests/bpf/bpf_kfuncs.h | 10 +
.../selftests/bpf/prog_tests/fs_kfuncs.c | 165 ++++++++++-
.../selftests/bpf/progs/test_get_xattr.c | 28 +-
.../bpf/progs/test_set_remove_xattr.c | 129 +++++++++
.../bpf/progs/test_set_remove_xattr_failure.c | 56 ++++
8 files changed, 636 insertions(+), 20 deletions(-)
create mode 100644 tools/testing/selftests/bpf/progs/test_set_remove_xattr.c
create mode 100644 tools/testing/selftests/bpf/progs/test_set_remove_xattr_failure.c
--
2.43.5
More information about the Linux-security-module-archive
mailing list