[PATCH bpf-next 07/13] bpf: Add the LSM policy kfunc infrastructure

bot+bpf-ci at kernel.org bot+bpf-ci at kernel.org
Fri Jul 31 22:24:13 UTC 2026


> Prepare kernel/bpf/bpf_lsm.c to host kfuncs that let BPF programs
> apply a userspace-created Landlock ruleset to an execution. The
> kfuncs will be thin front ends to the generic LSM policy kptr hooks
> (security_policy_kptr_from_fd(), security_policy_kptr_put(),
> security_bprm_enforce_policy_kptr()), invoked with LSM_ID_LANDLOCK
> so that the LSM framework's targeted dispatch only ever reaches
> Landlock's hook implementations.
>
> Because of the hook indirection, kernel/bpf/ has no build-time
> dependency on Landlock: the kfuncs are registered whenever
> CONFIG_BPF_LSM is enabled, and calling them while Landlock is
> compiled out or not enabled in the LSM order fails at runtime with
> -EOPNOTSUPP through the dispatch miss, keeping BPF program loading
> independent of the boot-time LSM configuration.
>
> Add the section hosting the kfuncs: struct bpf_landlock_ruleset, the
> opaque BTF-typed handle for a Landlock ruleset that only Landlock
> resolves; the kfunc id set, registered for both BPF_PROG_TYPE_LSM and
> BPF_PROG_TYPE_SYSCALL; and the kfunc filter.  The two program types
> share their kfunc lookup buckets with other program types, so
> restricting the kfuncs to them requires a filter.  The set starts
> empty and the filter has no per-kfunc rules yet; the following
> patches add the kfuncs together with their filter rules.

This isn't a bug, but could the last paragraph be trimmed to the
shared-bucket rationale? The rest enumerates what the diff already shows,
and the same sentence about shared buckets appears as a comment above the
filter function.

> diff --git a/kernel/bpf/bpf_lsm.c b/kernel/bpf/bpf_lsm.c
> index d847a180489f9..dd58c5bd01193 100644
> --- a/kernel/bpf/bpf_lsm.c
> +++ b/kernel/bpf/bpf_lsm.c
> @@ -473,3 +473,53 @@ int bpf_lsm_get_retval_range(const struct bpf_prog *prog,
>  	}
>  	return 0;
>  }
> +
> +/* LSM policy kfuncs */
> +
> +/*
> + * Opaque handle for a Landlock ruleset.  Only Landlock resolves it.
> + */
> +struct bpf_landlock_ruleset {};
> +
> +BTF_KFUNCS_START(bpf_landlock_kfunc_ids)
> +BTF_KFUNCS_END(bpf_landlock_kfunc_ids)

[ ... ]

> +static int __init bpf_lsm_policy_kfunc_init(void)
> +{
> +	int ret;
> +
> +	ret = register_btf_kfunc_id_set(BPF_PROG_TYPE_LSM,
> +					&bpf_landlock_kfunc_set);
> +	if (ret)
> +		return ret;
> +
> +	return register_btf_kfunc_id_set(BPF_PROG_TYPE_SYSCALL,
> +					&bpf_landlock_kfunc_set);
> +}
> +late_initcall(bpf_lsm_policy_kfunc_init);

This isn't a bug, but since the empty set makes both
register_btf_kfunc_id_set() calls return early in btf_populate_kfunc_set(),
this patch has no effect on its own.

Would it read more naturally folded into the patch that adds the first
kfunc, so the set, the filter arms, and the registration land together with
a user?


---
AI reviewed your patch. Please fix the bug or email reply why it's not a bug.
See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md

CI run summary: https://github.com/kernel-patches/bpf/actions/runs/30599733854


More information about the Linux-security-module-archive mailing list