[PATCH bpf-next 1/7] bpf: Allow BPF LSM programs to attach to more hooks
From: Anton Protopopov <hidden>
Date: 2026-08-31 10:59:02
Also in:
bpf, netdev
Subsystem:
bpf [core], bpf [general] (safe dynamic programs and tools), bpf [security & lsm] (security audit and enforcement using bpf), the rest · Maintainers:
Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko, Eduard Zingerman, Kumar Kartikeya Dwivedi, KP Singh, Matt Bobrowski, Linus Torvalds
The BPF LSM programs are allowed to attach to LSM hooks, all of which are defined in the <lsm_hook_defs.h> header file. From BPF's point of view the set of attachment points is defined in the bpf_lsm_hooks BTF set. By analogy with existing code, add a new header file <bpf_lsm_hook_defs.h> which will also be included in the bpf_lsm_hooks BTF set. This change allows attaching BPF LSM programs to more functions. The actual hooks are added in subsequent commits. Each BPF hook calls a [__weak] noinline function each time a hook is reached. This may be too expensive for hot paths if a BPF program is not attached. A future commit will optimize this by adding a per-hook static key and inc/dec it on attach/detach. This way disabled hooks will be bypassed efficiently. Signed-off-by: Anton Protopopov <redacted> --- MAINTAINERS | 1 + include/linux/bpf_lsm.h | 12 ++++++++++++ include/linux/bpf_lsm_hook_defs.h | 6 ++++++ kernel/bpf/bpf_lsm.c | 2 ++ 4 files changed, 21 insertions(+) create mode 100644 include/linux/bpf_lsm_hook_defs.h
diff --git a/MAINTAINERS b/MAINTAINERS
index 460cb7268845..d01dd1f096fc 100644
--- a/MAINTAINERS
+++ b/MAINTAINERS@@ -5035,6 +5035,7 @@ L: bpf@vger.kernel.org S: Maintained F: Documentation/bpf/prog_lsm.rst F: include/linux/bpf_lsm.h +F: include/linux/bpf_lsm_hook_defs.h F: kernel/bpf/bpf_lsm.c F: kernel/bpf/bpf_lsm_proto.c F: kernel/trace/bpf_trace.c
diff --git a/include/linux/bpf_lsm.h b/include/linux/bpf_lsm.h
index dda272d78f01..1e54c7cca27a 100644
--- a/include/linux/bpf_lsm.h
+++ b/include/linux/bpf_lsm.h@@ -16,9 +16,19 @@ extern bool bpf_lsm_initialized __ro_after_init; +/* + * Technically, checking bpf_lsm_initialized is not necessary. + * But if it is off, then this means that all security_* calls + * do not call BPF, and it doesn't look reasonable to enable + * only "non-LSM" bpf hooks... + */ +#define bpf_lsm_hook(NAME, ...) \ + (bpf_lsm_initialized ? bpf_lsm_##NAME(__VA_ARGS__) : 0) + #define LSM_HOOK(RET, DEFAULT, NAME, ...) \ RET bpf_lsm_##NAME(__VA_ARGS__); #include <linux/lsm_hook_defs.h> +#include <linux/bpf_lsm_hook_defs.h> #undef LSM_HOOK struct bpf_storage_blob {
@@ -114,6 +124,8 @@ static inline bool bpf_lsm_hook_returns_errno(u32 btf_id) { return true; } + +#define bpf_lsm_hook(NAME, ...) 0 #endif /* CONFIG_BPF_LSM */ #endif /* _LINUX_BPF_LSM_H */
diff --git a/include/linux/bpf_lsm_hook_defs.h b/include/linux/bpf_lsm_hook_defs.h
new file mode 100644
index 000000000000..29bc0b514d16
--- /dev/null
+++ b/include/linux/bpf_lsm_hook_defs.h@@ -0,0 +1,6 @@ +/* SPDX-License-Identifier: GPL-2.0 */ + +/* + * This is a set of BPF LSM hooks, which are _not_ fully implemented + * as LSM hooks. Thus, they only can be used by BPF LSM programs. + */
diff --git a/kernel/bpf/bpf_lsm.c b/kernel/bpf/bpf_lsm.c
index 82c5988417a0..add344ea2691 100644
--- a/kernel/bpf/bpf_lsm.c
+++ b/kernel/bpf/bpf_lsm.c@@ -28,11 +28,13 @@ __weak noinline RET bpf_lsm_##NAME(__VA_ARGS__) \ } #include <linux/lsm_hook_defs.h> +#include <linux/bpf_lsm_hook_defs.h> #undef LSM_HOOK #define LSM_HOOK(RET, DEFAULT, NAME, ...) BTF_ID(func, bpf_lsm_##NAME) BTF_SET_START(bpf_lsm_hooks) #include <linux/lsm_hook_defs.h> +#include <linux/bpf_lsm_hook_defs.h> #undef LSM_HOOK BTF_SET_END(bpf_lsm_hooks)
--
2.43.0