Re: [PATCH v2] lsm: expose mount idmaps to inode hooks
flat view
From: Christian Brauner <brauner@kernel.org>
Date: 2026-09-04 09:46:05
Also in:
linux-fsdevel
On Tue, Sep 01, 2026 at 02:50:23PM +0200, Daan De Meyer via B4 Relay wrote:
From: Daan De Meyer <redacted> OverlayFS performs upper-layer operations through inode-based security hooks. Those hooks receive the upper inode and dentry, but not the mount idmap used by the VFS operation. An LSM therefore cannot distinguish an identity-mapped upper from an idmapped one or make the same ownership decision as the VFS. Pass the mount idmap through the create, link, symlink, mkdir, mknod, and permission hooks. Update the in-tree LSM implementations and non-VFS callers accordingly. Extend the BPF LSM selftest to verify that both the identity idmap and an idmapped mount idmap reach each hook. Signed-off-by: Daan De Meyer <redacted> --- OverlayFS performs upper-layer operations through inode-based security hooks. Those hooks receive the upper inode and dentry, but not the mount idmap used by the VFS operation. The security layer cannot distinguish an identity-mapped upper from an idmapped one or make the same ownership decision as the VFS. The VFS layer already passes the idmap down into all relevant inode operations so this just brings the security hooks to parity. So pass the mount idmap through the create, link, symlink, mkdir, mknod, and permission hooks. Update the in-tree security implementations and non-VFS callers accordingly. systemd has been shipping systemd-nsresourced for quite a while now. It relies on inode and path hooks to perform ownership checks using a bpf lsm. To make this actually secure we need to be able to calculate the on-disk ownership from the idmap. --- Changes in v2: - Squash the implementation and selftest into a single patch. - Add the missing Signed-off-by trailer. - Link to v1: https://patch.msgid.link/20260824-lsm-mount-idmaps-v1-0-0414a9641c85@amutable.com --- fs/cachefiles/security.c | 4 +- fs/namei.c | 18 +- include/linux/lsm_hook_defs.h | 23 +-- include/linux/security.h | 58 +++--- security/security.c | 40 ++-- security/selinux/hooks.c | 19 +- security/smack/smack_lsm.c | 9 +- tools/testing/selftests/bpf/prog_tests/test_lsm.c | 231 ++++++++++++++++++++++ tools/testing/selftests/bpf/progs/lsm.c | 79 ++++++++ 9 files changed, 410 insertions(+), 71 deletions(-)
Oh, what happened to the earlier series? The first series did split tests and so on correctly into a separate patch. This lumps test and semantic changes together. We generally don't do this in the kernel. So please do resend.