[RFC PATCH bpf-next 06/12] bpf: add a path ancestor iterator
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Tue Oct 6 00:30:53 UTC 2026
> Let BPF programs evaluate a path's ancestry with an open-coded iterator
> over the stepwise vfs_walk_ancestors() engine. The iteration holds a
> reference on its current position, which is what lets a program sleep
> between positions - a dput() of the last reference may - so the kfuncs
> are KF_SLEEPABLE and the iterator is available to sleepable programs
> only. That covers the LSM hooks a path-based policy attaches to:
> file_open, file_permission, the path_* hooks, mmap_file and bprm_* are
> all in the sleepable allowlist.
>
> bpf_iter_path_ancestors_next() hands each position to the program as an
> acquired reference of its own, to release with bpf_path_put(). The
> walk's own reference moves on with the walk and is dropped at the next
> step, so it cannot be what keeps a position alive: a program that saves
> a position's dentry, or hands one to a sleepable kfunc, needs it to
> outlive the step it came from. struct path is a value type with nothing
> [ ... ]
> slot from it, so growing it later would reject programs built against
> the smaller one. The walk mode is a parameter of the shared engine for
> the same reason - so that a mode added later is not an ABI change.
>
> Signed-off-by: Justin Suess <utilityemal77 at gmail.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261006002020.2890858-1-utilityemal77@gmail.com?part=6
More information about the Linux-security-module-archive
mailing list