From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-8.8 required=3.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_PATCH,MAILING_LIST_MULTI, SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id DE198C433DB for ; Tue, 12 Jan 2021 17:15:41 +0000 (UTC) Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by mail.kernel.org (Postfix) with ESMTP id 5D7982311C for ; Tue, 12 Jan 2021 17:15:41 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 5D7982311C Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=paul-moore.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=owner-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix) id 73B606B006C; Tue, 12 Jan 2021 12:15:40 -0500 (EST) Received: by kanga.kvack.org (Postfix, from userid 40) id 6EADB6B006E; Tue, 12 Jan 2021 12:15:40 -0500 (EST) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 5D90C6B0070; Tue, 12 Jan 2021 12:15:40 -0500 (EST) X-Delivered-To: linux-mm@kvack.org Received: from forelay.hostedemail.com (smtprelay0095.hostedemail.com [216.40.44.95]) by kanga.kvack.org (Postfix) with ESMTP id 49DFC6B006C for ; Tue, 12 Jan 2021 12:15:40 -0500 (EST) Received: from smtpin28.hostedemail.com (10.5.19.251.rfc1918.com [10.5.19.251]) by forelay03.hostedemail.com (Postfix) with ESMTP id D9EC5824556B for ; Tue, 12 Jan 2021 17:15:39 +0000 (UTC) X-FDA: 77697774798.28.roof64_270cfc727517 Received: from filter.hostedemail.com (10.5.16.251.rfc1918.com [10.5.16.251]) by smtpin28.hostedemail.com (Postfix) with ESMTP id AB1DC6C2C for ; Tue, 12 Jan 2021 17:15:38 +0000 (UTC) X-HE-Tag: roof64_270cfc727517 X-Filterd-Recvd-Size: 5437 Received: from mail-ej1-f50.google.com (mail-ej1-f50.google.com [209.85.218.50]) by imf29.hostedemail.com (Postfix) with ESMTP for ; Tue, 12 Jan 2021 17:15:37 +0000 (UTC) Received: by mail-ej1-f50.google.com with SMTP id f4so3500886ejx.7 for ; Tue, 12 Jan 2021 09:15:36 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=paul-moore-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=tlN+SR1GxJrZealRnBj4IK5rirhuxkSGuR3XMgHjbM8=; b=2JSJLgjjYoRmh4WKyhvwd7P5EYDVodgao689juYrDTUOryxHHdbBFMvk6F49hQeANI 0ncsHC6TWKiQttECpHZrIyibJPz+veA90aIDcBmWL8CoCxSzcbVkT+1W9ZlazKYMz/h2 1U+NJdpU2NaPSMv/3Vcpq2YAuJEHuqV6eG6jOOiBvDIozHbxI3BklrmCl45uL2220jUW ESl6nOXuVqKatMmHbrqSdiXJkN9Pim4J5Ue8lUTHALCuTETNbMgXoLGGXl/x8o30mu7E c4TyKsipejVO9TqPCAFj2Ot6gBV0ui2tytc4Nb1V65qr081j32kxNtvVrCJ0L/mppkvw eXHw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=tlN+SR1GxJrZealRnBj4IK5rirhuxkSGuR3XMgHjbM8=; b=UcUWuInESK469gGcohTfv14yZso4ijP7adZ7TteSHRkfYHEcK2NKAnQkWZeMLUaTeg DbpL/RmU4CSYq0+GjPkgeEuYDvv81WSISjmYA0rKIZiDvPPBTq3xXNRBGJYCmux8abs+ x+TC5zszJpL7DPn82QPxJHmpq74lfHf+BTMGU96oXMRjJm62KsSjINa2WGCD7hwxy1ja 6xJKpEvuxi5scQCTcMhHW/0N2bP2HAjHoY+pV5vOU4hza+8sNXYHRZ2q1mhoxPLj3wb0 yrNEEA6i2SJYbnWhCCxmYUxiECJseQbodHTwvofXAYUtvu+PRZgCaB23Xd3/90zOmOdu F48Q== X-Gm-Message-State: AOAM532uj/KOAcHCDE4CxNuWqXH8q5enXLiABaFqVHhHNf0WIQUgDjv5 WyJdnuNxjn854e4TCnm+jhgju0oDW+ZKLOWBw9LG X-Google-Smtp-Source: ABdhPJzveLbKd2/fd+yW9COqHniIV8xf3qTx7Ia1dcnpsn0rSIKQjLxMysH9YBtmMRiS0RAcwMxpM8nudC4fcrMjxEQ= X-Received: by 2002:a17:906:1393:: with SMTP id f19mr3814197ejc.431.1610471735707; Tue, 12 Jan 2021 09:15:35 -0800 (PST) MIME-Version: 1.0 References: <20210108222223.952458-1-lokeshgidra@google.com> In-Reply-To: <20210108222223.952458-1-lokeshgidra@google.com> From: Paul Moore Date: Tue, 12 Jan 2021 12:15:24 -0500 Message-ID: Subject: Re: [PATCH v15 0/4] SELinux support for anonymous inodes and UFFD To: Lokesh Gidra Cc: Andrea Arcangeli , Alexander Viro , James Morris , Stephen Smalley , Casey Schaufler , Eric Biggers , "Serge E. Hallyn" , Eric Paris , Daniel Colascione , Kees Cook , "Eric W. Biederman" , KP Singh , David Howells , Anders Roxell , Sami Tolvanen , Matthew Garrett , Randy Dunlap , "Joel Fernandes (Google)" , YueHaibing , Christian Brauner , Alexei Starovoitov , Adrian Reber , Aleksa Sarai , linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, selinux@vger.kernel.org, kaleshsingh@google.com, calin@google.com, surenb@google.com, jeffv@google.com, kernel-team@android.com, linux-mm@kvack.org, Andrew Morton , hch@infradead.org Content-Type: text/plain; charset="UTF-8" X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Fri, Jan 8, 2021 at 5:22 PM Lokesh Gidra wrote: > > Userfaultfd in unprivileged contexts could be potentially very > useful. We'd like to harden userfaultfd to make such unprivileged use > less risky. This patch series allows SELinux to manage userfaultfd > file descriptors and in the future, other kinds of > anonymous-inode-based file descriptor. ... > Daniel Colascione (3): > fs: add LSM-supporting anon-inode interface > selinux: teach SELinux about anonymous inodes > userfaultfd: use secure anon inodes for userfaultfd > > Lokesh Gidra (1): > security: add inode_init_security_anon() LSM hook > > fs/anon_inodes.c | 150 ++++++++++++++++++++-------- > fs/libfs.c | 5 - > fs/userfaultfd.c | 19 ++-- > include/linux/anon_inodes.h | 5 + > include/linux/lsm_hook_defs.h | 2 + > include/linux/lsm_hooks.h | 9 ++ > include/linux/security.h | 10 ++ > security/security.c | 8 ++ > security/selinux/hooks.c | 57 +++++++++++ > security/selinux/include/classmap.h | 2 + > 10 files changed, 213 insertions(+), 54 deletions(-) With several rounds of reviews done and the corresponding SELinux test suite looking close to being ready I think it makes sense to merge this via the SELinux tree. VFS folks, if you have any comments or objections please let me know soon. If I don't hear anything within the next day or two I'll go ahead and merge this for linux-next. Thanks. -- paul moore www.paul-moore.com