[RFC] bpf-lsm: scoped one-shot userspace authorization binding for exec
Eric Robles
erobles3224 at gmail.com
Sun Sep 20 01:05:25 UTC 2026
Hello BPF and LSM reviewers,
I’m requesting review of a narrow BPF-LSM authorization pattern that
is already running as a live prototype.
The problem being tested is simple: how can an external userspace
authorization decision be bound to one exact exec consequence so that
the kernel enforces the final allow/deny rather than merely receiving
a post-execution log?
Prototype flow:
1. Fork the child and stop it before exec.
2. Resolve and measure the exact executable: path, argv, device/inode,
size/timestamps, SHA-256, running kernel, and active LSM chain.
3. Bind those facts into the userspace authorization decision.
4. Only after PERMIT + execution_authorized=true, re-check the
executable identity and write a short-lived one-shot BPF map grant.
5. Resume the child.
6. A BPF-LSM program at bprm_check_security matches the governed TGID
+ executable device/inode.
7. Matching live grant: consume the grant and allow exec.
8. Missing, expired, or mismatched grant: return -EACCES.
Live result on Ubuntu 26.04.1 / Linux 7.0.0-31-generic:
- authorized governed exec: succeeded
- governed child deliberately given no grant: denied by Linux with
EACCES before exec
- BPF LSM active in the live LSM chain
- governed / exec_grants / events maps pinned and active
- 25/25 local tests green
- 6/6 adversarial ProofGate cases green
The review question is specifically about the kernel-facing binding
pattern, not about moving the external policy engine into the kernel.
I would value feedback on:
- whether TGID + dev_t + inode is a sufficiently strong exec binding
for this pattern;
- remaining TOCTOU concerns between userspace revalidation and
bprm_check_security;
- one-shot/TTL grant cleanup semantics;
- whether an existing kernel primitive would provide a stronger or
simpler authorization binding.
Linux-focused repo:
https://github.com/KnowledgeeKZA3224/linux-coherence-gate
Live proof:
https://github.com/KnowledgeeKZA3224/linux-coherence-gate/blob/main/LIVE_PROOF.md
BPF-LSM source:
https://github.com/KnowledgeeKZA3224/linux-coherence-gate/blob/main/kernel_integration/scqos_exec_gate.bpf.c
Userspace launcher:
https://github.com/KnowledgeeKZA3224/linux-coherence-gate/blob/main/kernel_integration/scqos_kernel_exec.py
No claim is being made that Linux itself was patched, or that every
Linux operation is governed. The proven boundary is explicitly
enrolled process exec through the existing BPF-LSM hook.
Assisted-by: LLM
Knowledgee KZA
http://SupremeComputation.org
More information about the Linux-security-module-archive
mailing list