[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <3f2a695a148db9e1daae8c07d9ce5c85@paul-moore.com>
Date: Thu, 14 Mar 2024 16:31:05 -0400
From: Paul Moore <paul@...l-moore.com>
To: Linus Torvalds <torvalds@...ux-foundation.org>
Cc: linux-security-module@...r.kernel.org, linux-kernel@...r.kernel.org
Subject: [GIT PULL] lsm/lsm-pr-20240314
Hi Linus,
Two patches to address issues with the LSM syscalls that we shipped in
Linux v6.8. The first patch might be a bit controversial, but the
second is a rather straightforward fix; more on both below.
The first fix from Casey addresses a problem that should have been
caught during the ~16 month (?) review cycle, but sadly was not. The
good news is that Dmitry caught it very quickly once Linux v6.8 was
released. The core issue is the use of size_t parameters to pass
buffer sizes back and forth in the syscall; while we could have solved
this with a compat syscall definition, given the newness of the syscalls
I wanted to attempt to just redefine the size_t parameters as u32 types
and avoid the work associated with a set of compat syscalls. However,
this is technically a change in the syscall's signature/API so I can
understand if you're opposed to this, even if the syscalls are less
than a week old.
The second fix is a rather trivial fix to allow userspace to call into
the lsm_get_self_attr() syscall with a NULL buffer to quickly determine
a minimum required size for the buffer. We do have kselftests for this
very case, I'm not sure why I didn't notice the failure; I'm going to
guess stupidity, tired eyes, I dunno. My apologies we didn't catch
this earlier.
I would like if you could merge these patches, I believe fixing the
syscall signature problem now poses very little risk and will help us
avoid the management overhead of compat syscall variants in the future.
However, I'll understand if you're opposed, just let me know and I'll
get you a compat version of this pull request as soon as we can get
something written/tested/verfified.
Thanks,
-Paul
--
The following changes since commit b0546776ad3f332e215cebc0b063ba4351971cca:
Merge tag 'printk-for-6.9' of
git://git.kernel.org/pub/scm/linux/kernel/git/printk/linux
(2024-03-12 20:54:50 -0700)
are available in the Git repository at:
https://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/lsm.git
tags/lsm-pr-20240314
for you to fetch changes up to eaf0e7a3d2711018789e9fdb89191d19aa139c47:
lsm: handle the NULL buffer case in lsm_fill_user_ctx()
(2024-03-14 11:31:26 -0400)
----------------------------------------------------------------
lsm/stable-6.9 PR 20240314
----------------------------------------------------------------
Casey Schaufler (1):
lsm: use 32-bit compatible data types in LSM syscalls
Paul Moore (1):
lsm: handle the NULL buffer case in lsm_fill_user_ctx()
include/linux/lsm_hook_defs.h | 4 ++--
include/linux/security.h | 8 ++++----
include/linux/syscalls.h | 6 +++---
security/apparmor/lsm.c | 4 ++--
security/lsm_syscalls.c | 10 +++++-----
security/security.c | 20 +++++++++++-----
security/selinux/hooks.c | 4 ++--
security/smack/smack_lsm.c | 4 ++--
tools/testing/selftests/lsm/common.h | 6 +++---
tools/testing/selftests/lsm/lsm_get_self_attr_test.c | 10 +++++-----
tools/testing/selftests/lsm/lsm_list_modules_test.c | 8 ++++----
tools/testing/selftests/lsm/lsm_set_self_attr_test.c | 6 +++---
12 files changed, 48 insertions(+), 42 deletions(-)
--
paul-moore.com
Powered by blists - more mailing lists