From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yw1-f172.google.com (mail-yw1-f172.google.com [209.85.128.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 850B9372685 for ; Thu, 21 May 2026 16:06:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.172 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779379618; cv=none; b=XWRhIvV02zUh+X36XANDpu9BvUEMkk0xpLpRWuejlJx5KHNp1zDU51CC3jEc40n0qce60So+26RW0GYEGNahtaFf5lKF0QhEHki5X/Qk8vKJUzulqnBPulNq4Sdj4gEnJetKBW5b+UozfKKVDQ05OTEAnXus2amxdgXU0DNSS2A= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779379618; c=relaxed/simple; bh=BU308g11FtLppIAB/aDcWxQuNwgPLrw8nrpt0uybx18=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=eJZwCCtXg55csuNy6X8crXb+2++saHNNH/JLlrw6nfVYJpO9hB2KR8BkucDy+OashvVKVKnu7aEd7UJ+FtCH9KnSszHraFe1itxcgy4+Ayu67n/w2RdCfRyVw++pKgSLcRquNmPECE0lETzbdlnOSQi3SIPtknH40zCK8pDwgrs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=PU9RvFuA; arc=none smtp.client-ip=209.85.128.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="PU9RvFuA" Received: by mail-yw1-f172.google.com with SMTP id 00721157ae682-7c04749d739so42539717b3.3 for ; Thu, 21 May 2026 09:06:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1779379616; x=1779984416; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=6hdgfN+G4et8ibY6iXu0zvGvxBXNyZHs8s+cU+ttE2o=; b=PU9RvFuAnzPfWcAz6zit6qNVxwWsV8TgMRcINpvOEnueBAObjFNRvUu98SizdW3/nX C8pdc75DSOW16NRhdfNO1TDQySCU92wfpEcxsFZ04rM+clH5V7BalUmZkzWFlMkUWTOM d1ubVH1rDhQyScdJdI3fZ3V6CP9apCQ+pAuV9m8/qmrcqo3Gr6lRzZYYSALpp1dDAXff 2x5BfihaRtxWN7m/cfBT6/KnB7bEYR7KKbD5pfPYT/JHNxe+bovu9TQ3dDTMo3WLWOc1 va8t9CHl8D/Fei6y6jeFlQPy5S7ol4ECz7Dm90+IWREQfB7ZLX5yQyG2UzIPGFqh/b/P KMAg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779379616; x=1779984416; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=6hdgfN+G4et8ibY6iXu0zvGvxBXNyZHs8s+cU+ttE2o=; b=BgExfLYhzLJte1IAUwZDwzR+G/1Ux4R8SOmvaHqCMr9wHn8DVt/nl9BTp0KNpxm3R2 7mOdTqNaPa5FoYjOXM8Y8TSObjkuuxExwqi6fq94SemjM6X1JpaXiCxYuyy8BbYg+8YE LSZQFMUPbL4Y+FOWUZTCIopASvt60qAxLtXfWRz/8BjCbPJRSbWiMT/Q0mbAHKVNpDGO URVOIWGAHUs/mrqMdAS7gWPJ01SFYS4QIZZcR7bOtae7FADU+Xt8+3pAWaWy9CzyrwFj 9FiLFwVeS3PCX2KPfXmuFIK0ILmyu1HvoWsCsm139p0pgvkbtL8TKphaBCVilJJ6PDHO CI7g== X-Gm-Message-State: AOJu0YxIYm5TkC+vhB/vrPPPDWB2KGGMnMSMo684CVM/yMLdek3howno HaL+5osEsQ5sVMVksCQ3RO2M/OM5VRcyUIMDzggCqZwKOJSXalYBX8Ap X-Gm-Gg: Acq92OGidP6mXKe5NsLBKVM/3HYmV5M+Iv6fNNQuV4tNJN/OiIG8RjLzivLksmrofik MqJxjlA6+qPZTEtWRRsTh3EJqX4EE/Nj0ZNunVFsPtdIHND5oypPiwxgl38QVWFMNlZt0piNbr3 JzQKSG3F1LifrHXoeF37OXt2JyS4JQ6BexkKWkkr4STl2IEJheqRQYloBMqNPzXBL6SOyTvVpme UmI+QOo7ATjhqthR6KYCUR0yjfF5VKLHEV+dCd/1wWPDIzxvr5vuMKd3H64hO9L1zbNRfeSMrRI TgywdlbMG6/CxZwcLgJX747ZC6/QytpgFtLKLnmrxTDHAHmcRRRowJQGiTwzmBLACfmwXk6TsVg 0DptvFZnKZNhT3ZaiMUCOIH+5hJKC4wlUyjdOpVqTA/cPHOWEAgzNIu0FD5ZA6yfeVMP1rR5IUz WAAqbmhnlA6xM5cTSP4QSGxEHz7g59RG+b1WVipJorAbH5mBM0ANLwcPN/9iTftsBdjYXW13d78 gTg+qoNXQ== X-Received: by 2002:a05:690c:4d46:b0:7bd:5d03:dc1a with SMTP id 00721157ae682-7d20a6ab26emr36274407b3.1.1779379616568; Thu, 21 May 2026 09:06:56 -0700 (PDT) Received: from zenbox.prizrak.me ([2600:1700:18fb:6011:c2cf:2e92:9a48:97a]) by smtp.gmail.com with ESMTPSA id 00721157ae682-7d2c7abad87sm4657587b3.2.2026.05.21.09.06.56 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 21 May 2026 09:06:56 -0700 (PDT) From: Justin Suess To: gnoack3000@gmail.com, mic@digikod.net Cc: linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, Justin Suess Subject: [PATCH 1/6] landlock: Add kern_ipc_perm credential blob structs Date: Thu, 21 May 2026 12:06:35 -0400 Message-ID: <20260521160640.1716746-2-utilityemal77@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260521160640.1716746-1-utilityemal77@gmail.com> References: <20260521160640.1716746-1-utilityemal77@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Add landlock_kern_ipc_perm_security, tracking ownership of SysV IPC objects. The struct contains the creating task's Landlock credential (@owner_subject) and a @kind enum identifying which SysV IPC object this blob describes. The LSM core allocates the IPC blob for every kern_ipc_perm regardless of object kind, so the generic ipc_permission hook needs to be able to tell which objects it should enforce a given scope on. An enum makes it straightforward to extend Landlock to sem and shm scoping later without revisiting the blob layout. Define the size of this struct in the lbs_ipc field for the Landlock blob sizes. Signed-off-by: Justin Suess --- security/landlock/setup.c | 1 + security/landlock/task.h | 50 +++++++++++++++++++++++++++++++++++++++ 2 files changed, 51 insertions(+) diff --git a/security/landlock/setup.c b/security/landlock/setup.c index 47dac1736f10..44aff2d734e9 100644 --- a/security/landlock/setup.c +++ b/security/landlock/setup.c @@ -32,6 +32,7 @@ struct lsm_blob_sizes landlock_blob_sizes __ro_after_init = { .lbs_file = sizeof(struct landlock_file_security), .lbs_inode = sizeof(struct landlock_inode_security), .lbs_superblock = sizeof(struct landlock_superblock_security), + .lbs_ipc = sizeof(struct landlock_kern_ipc_perm_security), }; int landlock_errata __ro_after_init; diff --git a/security/landlock/task.h b/security/landlock/task.h index 7c00360219a2..0fb82e5e347c 100644 --- a/security/landlock/task.h +++ b/security/landlock/task.h @@ -9,6 +9,56 @@ #ifndef _SECURITY_LANDLOCK_TASK_H #define _SECURITY_LANDLOCK_TASK_H +#include +#include + +#include "cred.h" +#include "setup.h" + +/** + * enum landlock_sysv_ipc_kind - Kind of SysV IPC object backed by a blob + * + * @LANDLOCK_SYSV_IPC_UNSET: Blob has not been tagged by a Landlock IPC + * allocation hook. This is the zero value used for sem and shm + * objects that Landlock does not currently scope, as well as for + * any future kind that has not yet been wired up. + * @LANDLOCK_SYSV_IPC_MSG_QUEUE: Blob belongs to a SysV message queue. + */ +enum landlock_sysv_ipc_kind { + LANDLOCK_SYSV_IPC_UNSET = 0, + LANDLOCK_SYSV_IPC_MSG_QUEUE, +}; + +/** + * struct landlock_kern_ipc_perm_security - IPC object security blob + * + * Enable provenance tracking of SysV IPC objects to scope IPC accesses. + * The LSM core allocates a blob for every kern_ipc_perm regardless of the + * underlying object kind (msg queue, semaphore, shared memory), so callers + * that act on a subset of object kinds must consult @kind before + * interpreting @owner_subject. + */ +struct landlock_kern_ipc_perm_security { + /** + * @owner_subject: Landlock credential of the task that created the + * kernel IPC object. Only meaningful when @kind is not + * %LANDLOCK_SYSV_IPC_UNSET. + */ + struct landlock_cred_security owner_subject; + /** + * @kind: Kind of SysV IPC object this blob describes. Set by the + * matching alloc hook; %LANDLOCK_SYSV_IPC_UNSET for objects whose + * kind Landlock does not currently track. + */ + enum landlock_sysv_ipc_kind kind; +}; + +static inline struct landlock_kern_ipc_perm_security * +landlock_kern_ipc_perm(const struct kern_ipc_perm *const perm) +{ + return perm->security + landlock_blob_sizes.lbs_ipc; +} + __init void landlock_add_task_hooks(void); #endif /* _SECURITY_LANDLOCK_TASK_H */ -- 2.53.0