[PATCH RFC v2 3/5] LSM: Security module checking for side-channel dangers
From: Schaufler, Casey <hidden>
Date: 2018-08-20 15:31:27
Also in:
lkml, selinux
-----Original Message----- From: Jann Horn [mailto:jannh at google.com] Sent: Friday, August 17, 2018 4:53 PM To: Schaufler, Casey <redacted> Cc: Kernel Hardening <redacted>; kernel list [off-list ref]; linux-security-module <linux-security- module at vger.kernel.org>; selinux at tycho.nsa.gov; Hansen, Dave [off-list ref]; Dock, Deneen T [off-list ref]; kristen at linux.intel.com; Arjan van de Ven [off-list ref] Subject: Re: [PATCH RFC v2 3/5] LSM: Security module checking for side- channel dangers On Sat, Aug 18, 2018 at 12:17 AM Casey Schaufler [off-list ref] wrote:quoted
From: Casey Schaufler <redacted> The sidechannel LSM checks for cases where a side-channel attack may be dangerous based on security attributes of tasks. This includes: Effective UID of the tasks is different Capablity sets are different Tasks are in different namespaces An option is also provided to assert that task are never to be considered safe. This is high paranoia, and expensive as well. Signed-off-by: Casey Schaufler <redacted>[...]quoted
+#ifdef CONFIG_SECURITY_SIDECHANNEL_UIDS +static int safe_by_uid(struct task_struct *p) +{ + const struct cred *ccred = current_real_cred(); + const struct cred *pcred = get_task_cred(p); + + /* + * Credential checks. Considered safe if: + * UIDs are the same + */ + if (ccred != pcred && ccred->euid.val != pcred->euid.val) + return -EACCES; + return 0; +}This function looks bogus. get_task_cred() bumps the refcount on the returned cred struct pointer, but you don't drop it. You probably want to use something that doesn't fiddle with the refcount at all here to avoid cacheline bouncing - possibly a raw rcu_dereference_protected() if there are no better helpers. Same thing for the other get_task_cred() calls further down in the patch.
Thanks. Looks like I whacked out v2 a bit hastily.