Thread (2 messages) 2 messages, 2 authors, 2026-09-04

Re: [PATCH v2] lsm: expose mount idmaps to inode hooks

flat view

From: Christian Brauner <brauner@kernel.org>
Date: 2026-09-04 09:46:05
Also in: linux-fsdevel

On Tue, Sep 01, 2026 at 02:50:23PM +0200, Daan De Meyer via B4 Relay wrote:
From: Daan De Meyer <redacted>

OverlayFS performs upper-layer operations through inode-based security
hooks. Those hooks receive the upper inode and dentry, but not the mount
idmap used by the VFS operation. An LSM therefore cannot distinguish an
identity-mapped upper from an idmapped one or make the same ownership
decision as the VFS.

Pass the mount idmap through the create, link, symlink, mkdir, mknod, and
permission hooks. Update the in-tree LSM implementations and non-VFS
callers accordingly.

Extend the BPF LSM selftest to verify that both the identity idmap and an
idmapped mount idmap reach each hook.

Signed-off-by: Daan De Meyer <redacted>
---
OverlayFS performs upper-layer operations through inode-based security
hooks. Those hooks receive the upper inode and dentry, but not the mount
idmap used by the VFS operation.

The security layer cannot distinguish an identity-mapped upper from an
idmapped one or make the same ownership decision as the VFS. The VFS
layer already passes the idmap down into all relevant inode operations
so this just brings the security hooks to parity.

So pass the mount idmap through the create, link, symlink, mkdir, mknod,
and permission hooks. Update the in-tree security implementations and
non-VFS callers accordingly.

systemd has been shipping systemd-nsresourced for quite a while now. It
relies on inode and path hooks to perform ownership checks using a bpf lsm.
To make this actually secure we need to be able to calculate the on-disk
ownership from the idmap.
---
Changes in v2:
- Squash the implementation and selftest into a single patch.
- Add the missing Signed-off-by trailer.
- Link to v1: https://patch.msgid.link/20260824-lsm-mount-idmaps-v1-0-0414a9641c85@amutable.com
---
 fs/cachefiles/security.c                          |   4 +-
 fs/namei.c                                        |  18 +-
 include/linux/lsm_hook_defs.h                     |  23 +--
 include/linux/security.h                          |  58 +++---
 security/security.c                               |  40 ++--
 security/selinux/hooks.c                          |  19 +-
 security/smack/smack_lsm.c                        |   9 +-
 tools/testing/selftests/bpf/prog_tests/test_lsm.c | 231 ++++++++++++++++++++++
 tools/testing/selftests/bpf/progs/lsm.c           |  79 ++++++++
 9 files changed, 410 insertions(+), 71 deletions(-)
Oh, what happened to the earlier series? The first series did split
tests and so on correctly into a separate patch. This lumps test and
semantic changes together. We generally don't do this in the kernel. So
please do resend.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help