[PATCH v2 6/7] Apparmor: hooks for secctx_to_lsmprop and update_lsmprop

John Johansen john.johansen at canonical.com
Thu Sep 3 09:39:24 UTC 2026


the code itself looks right
same nit on update_lsmprop as previous two patches.

I know you are working within the insane constraints of the secid, but it really
hurts that apparmor has a local xarray for secids, and now the LSM infra has
one too. I know its a problem to be solved later, I am just griping about the
current state of affairs.


On 9/2/26 15:01, Casey Schaufler wrote:
> Implement these hooks.
> 
> Signed-off-by: Casey Schaufler <casey at schaufler-ca.com>
> ---
>   security/apparmor/include/secid.h |  4 ++++
>   security/apparmor/lsm.c           |  2 ++
>   security/apparmor/secid.c         | 21 +++++++++++++++++++++
>   3 files changed, 27 insertions(+)
> 
> diff --git a/security/apparmor/include/secid.h b/security/apparmor/include/secid.h
> index 6025d3849cf8..ba7adf2fc09e 100644
> --- a/security/apparmor/include/secid.h
> +++ b/security/apparmor/include/secid.h
> @@ -28,6 +28,10 @@ struct aa_label *aa_secid_to_label(u32 secid);
>   int apparmor_secid_to_secctx(u32 secid, struct lsm_context *cp);
>   int apparmor_lsmprop_to_secctx(struct lsm_prop *prop, struct lsm_context *cp);
>   int apparmor_secctx_to_secid(const char *secdata, u32 seclen, u32 *secid);
> +int apparmor_secctx_to_lsmprop(const char *secdata, u32 seclen,
> +			       struct lsm_prop *prop);
> +void apparmor_update_lsmprop(struct lsm_prop *dest, struct lsm_prop *src,
> +			     int lsmid);
>   void apparmor_release_secctx(struct lsm_context *cp);
>   
>   
> diff --git a/security/apparmor/lsm.c b/security/apparmor/lsm.c
> index 88d12e89d115..1f304b88eaf9 100644
> --- a/security/apparmor/lsm.c
> +++ b/security/apparmor/lsm.c
> @@ -1766,6 +1766,8 @@ static struct security_hook_list apparmor_hooks[] __ro_after_init = {
>   	LSM_HOOK_INIT(secid_to_secctx, apparmor_secid_to_secctx),
>   	LSM_HOOK_INIT(lsmprop_to_secctx, apparmor_lsmprop_to_secctx),
>   	LSM_HOOK_INIT(secctx_to_secid, apparmor_secctx_to_secid),
> +	LSM_HOOK_INIT(secctx_to_lsmprop, apparmor_secctx_to_lsmprop),
> +	LSM_HOOK_INIT(update_lsmprop, apparmor_update_lsmprop),
>   	LSM_HOOK_INIT(release_secctx, apparmor_release_secctx),
>   
>   #ifdef CONFIG_IO_URING
> diff --git a/security/apparmor/secid.c b/security/apparmor/secid.c
> index 28caf66b9033..d35fdbf074e0 100644
> --- a/security/apparmor/secid.c
> +++ b/security/apparmor/secid.c
> @@ -106,6 +106,27 @@ int apparmor_secctx_to_secid(const char *secdata, u32 seclen, u32 *secid)
>   	return 0;
>   }
>   
> +int apparmor_secctx_to_lsmprop(const char *secdata, u32 seclen,
> +			       struct lsm_prop *prop)
> +{
> +	struct aa_label *label;
> +
> +	label = aa_label_strn_parse(&root_ns->unconfined->label, secdata,
> +				    seclen, GFP_KERNEL, false, false);
> +	if (IS_ERR(label))
> +		return PTR_ERR(label);
> +	prop->apparmor.label = label;
> +
> +	return 0;
> +}
> +
> +void apparmor_update_lsmprop(struct lsm_prop *dest, struct lsm_prop *src,
> +			     int lsmid)
> +{
> +	if (lsmid == LSM_ID_APPARMOR || lsmid == LSM_ID_UNDEF)
> +		dest->apparmor.label = src->apparmor.label;
> +}
> +
>   void apparmor_release_secctx(struct lsm_context *cp)
>   {
>   	if (cp->id == LSM_ID_APPARMOR) {




More information about the Linux-security-module-archive mailing list