From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4EEA73CD8BE for ; Mon, 13 Apr 2026 13:41:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776087710; cv=none; b=MV5EgSdwTVxgh5ruybZR49scubSsX9CCI+oFWgUTJvmptOSZw54MFLt3Fmi37CoVQubyva5I37dttmwewAJ772N9MNTai5rW7EEW62XkfbCpfUCl3kLqc8A+eqcAnA+sdwj6i5Mp/iM5OrtFOHk9aNtjts0twQmVzyylRGN2VXk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776087710; c=relaxed/simple; bh=Sua5oNx2PUaNf9I0BmMj5auzMkGRUE7guKAhAZI6Y+E=; h=Message-ID:Date:MIME-Version:To:From:Subject:Content-Type; b=Vl5zm2PxCdt6sbJ/EMu9Gs+gLTCwzArYIDzdX9ltlesaUP9oI0GS1il3nUzNMDYKSlGT1+usmGP8MWIco9UIBLvRWkxveIS+14yz5SHt5OEN2Hsli36zKnwwdisJB2YCNHIxDbBEQlIBp27mCvcYfbyNkcgZYAaFK9slRjj143o= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=J/psik7G; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="J/psik7G" Received: from pps.filterd (m0360083.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 63CLPN5J3426044 for ; Mon, 13 Apr 2026 13:41:48 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h= content-transfer-encoding:content-type:date:from:message-id :mime-version:subject:to; s=pp1; bh=tir1LXMDJZWeHqY905sGexuHnOgt iwj8KGmNQAFY720=; b=J/psik7G7lLeDVqosy+s63+8U9PR+rymkn9gePqpMPG8 ni1IHeZAol+BStF5qof/Q32XWhQf6paUyOzTyNIXQ3Nr81VmBtO2D2sY9/Dvr35r glOwGTvX8zoiJ3pL6o+0zFybsqPVaIS0UPh1MMwaI+ldgGkgLckEHjTxI/RpJvwd zR2DunupRsLQlIiZMCDIl5Mq0m0wCUjFaJsXvjJOH2k5mjbgAp4PjAtQ/0e8DhEE K8lWU9RpU6pMB9uqBiCk7MXqnIclX5HnyEgC0TebXPJGu0FQMhYCGgDyqUiH94rv xzXMlMbYmrx6Pr3n60iVRf7y+cWdce5gqhUeN9d9Zw== Received: from ppma12.dal12v.mail.ibm.com (dc.9e.1632.ip4.static.sl-reverse.com [50.22.158.220]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4dfdt3qy55-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Mon, 13 Apr 2026 13:41:48 +0000 (GMT) Received: from pps.filterd (ppma12.dal12v.mail.ibm.com [127.0.0.1]) by ppma12.dal12v.mail.ibm.com (8.18.1.2/8.18.1.2) with ESMTP id 63DCaTa9015158 for ; Mon, 13 Apr 2026 13:41:47 GMT Received: from smtprelay05.dal12v.mail.ibm.com ([172.16.1.7]) by ppma12.dal12v.mail.ibm.com (PPS) with ESMTPS id 4dg0msdgc6-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Mon, 13 Apr 2026 13:41:47 +0000 Received: from smtpav05.wdc07v.mail.ibm.com (smtpav05.wdc07v.mail.ibm.com [10.39.53.232]) by smtprelay05.dal12v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 63DDfkcA19268164 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 13 Apr 2026 13:41:46 GMT Received: from smtpav05.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 27E2058053; Mon, 13 Apr 2026 13:41:46 +0000 (GMT) Received: from smtpav05.wdc07v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 51D6F58043; Mon, 13 Apr 2026 13:41:45 +0000 (GMT) Received: from [9.123.0.244] (unknown [9.123.0.244]) by smtpav05.wdc07v.mail.ibm.com (Postfix) with ESMTP; Mon, 13 Apr 2026 13:41:45 +0000 (GMT) Message-ID: <35f5edcc-bc12-4f4b-84c7-0ff9d007e2c5@linux.ibm.com> Date: Mon, 13 Apr 2026 19:11:43 +0530 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Content-Language: en-US To: linux-kernel@vger.kernel.org, Madhavan Srinivasan From: Samir M Subject: [mainline] LTP: lsm_list_modules02 test failing - syscall returns incorrect LSM IDs. Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-TM-AS-GCONF: 00 X-Proofpoint-ORIG-GUID: 1fndFW5oWcFl0IM_CEZrLumaPfnpaa0h X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNDEzMDEzMSBTYWx0ZWRfX1PnAv6zcycQt 84Z7AomBIzuQF4TBIqCYk/FiA0UjtU4//yJ2+sZVhKDxmrGT3z+crniHa41ylQ2KuNgO/0K5yOR EKHVr6znl2Ri2QwbRRsIKRo9fTndfgQCJAd2H056BJpCGnXP0RuQb+Xc3hOf7+pUyEJ/qC7Apu7 SjBr0OH+GHEIdXfSrFDE83IV9EUEM6HbEUNdKAQOlQmhyQD1eDXhDeCwxv08t8qIqgsjGnx13S9 5fIzdbthbIlj95ysguitGNWgNrKYnbMMcbXcs72dpIAv+PAMCYr4rylfLw+SI3Tg9SY9DgIhYFY xq01zoPwHkap1Ls7xYZXUhNfqfjJ1dX9F6FRz19uEVQLLbpy/fVAwC/kLTH6v402Jg3y7T/alHO rfYmPmMgBvKtdMKzxEH0SptPP7CKpN0x6d3Ha5rNeKqiFvGjkGs9Wp9zlLLuKaQC2FTjQTYb6IX DBQsAWJ3AOVOg4vDEvw== X-Proofpoint-GUID: 1fndFW5oWcFl0IM_CEZrLumaPfnpaa0h X-Authority-Analysis: v=2.4 cv=WpEb99fv c=1 sm=1 tr=0 ts=69dcf29c cx=c_pps a=bLidbwmWQ0KltjZqbj+ezA==:117 a=bLidbwmWQ0KltjZqbj+ezA==:17 a=IkcTkHD0fZMA:10 a=A5OVakUREuEA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=iQ6ETzBq9ecOQQE5vZCe:22 a=VnNF1IyMAAAA:8 a=DrPPPXa7aYzGhMMBjJwA:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.51,FMLib:17.12.100.49 definitions=2026-04-13_03,2026-04-13_03,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 phishscore=0 bulkscore=0 adultscore=0 spamscore=0 malwarescore=0 clxscore=1015 lowpriorityscore=0 suspectscore=0 impostorscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2604010000 definitions=main-2604130131 Hi, I'm reporting a bug in the lsm_list_modules() syscall on kernel version 7.0.0-rc7. The syscall is returning LSM IDs that don't match the active LSMs shown in /sys/kernel/security/lsm. Problem Summary: ================ The lsm_list_modules() syscall returns LSM IDs for modules that are NOT active (safesetid, apparmor), while failing to return IDs for modules that ARE active (yama, ima). Active LSMs (from /sys/kernel/security/lsm): lockdown,capability,landlock,yama,selinux,bpf,ima,evm Kernel Configuration: ===================== # CONFIG_SECURITY_APPARMOR is not set # CONFIG_SECURITY_SAFESETID is not set This confirms AppArmor and SafeSetID are NOT compiled into the kernel. Test Output: ============ Running: /opt/ltp/testcases/bin/lsm_list_modules02 tst_buffers.c:57: TINFO: Test is using guarded buffers tst_test.c:2059: TINFO: LTP version: 20260130-105-g07b599e48 tst_test.c:2062: TINFO: Tested kernel: 7.0.0-rc7 #1 SMP PREEMPT ppc64le tst_kconfig.c:90: TINFO: Parsing kernel config '/lib/modules/7.0.0-rc7/build/.config' tst_test.c:1887: TINFO: Overall timeout per run is 0h 05m 24s lsm_list_modules02.c:40: TPASS: lsm_list_modules(ids, size, 0) returned 8 lsm_list_modules02.c:42: TPASS: lsm_num == lsm_names_count (8) lsm_list_modules02.c:43: TPASS: *size == lsm_num * sizeof(uint64_t) (64) lsm_list_modules02.c:110: TFAIL: 'safesetid' has not been found lsm_list_modules02.c:104: TPASS: 'capability' is enabled lsm_list_modules02.c:104: TPASS: 'bpf' is enabled lsm_list_modules02.c:110: TFAIL: 'apparmor' has not been found lsm_list_modules02.c:104: TPASS: 'selinux' is enabled lsm_list_modules02.c:104: TPASS: 'lockdown' is enabled lsm_list_modules02.c:104: TPASS: 'landlock' is enabled lsm_list_modules02.c:104: TPASS: 'evm' is enabled Summary: passed   9 failed   2 broken   0 skipped  0 warnings 0 The Issue: ========== The lsm_list_modules() syscall is returning: - safesetid (NOT in /sys/kernel/security/lsm and NOT compiled in kernel) - apparmor (NOT in /sys/kernel/security/lsm and NOT compiled in kernel) But it's NOT returning: - yama (IS in /sys/kernel/security/lsm) - ima (IS in /sys/kernel/security/lsm) Expected Behavior: ================== The lsm_list_modules() syscall should return LSM IDs that exactly match the active LSMs listed in /sys/kernel/security/lsm. It should not return IDs for LSMs that are not compiled into the kernel or not active. Reproduction Steps: =================== 1. Install LTP at /opt/ltp 2. Verify active LSMs: cat /sys/kernel/security/lsm 3. Check kernel config to confirm AppArmor and SafeSetID are not compiled 4. Run: /opt/ltp/testcases/bin/lsm_list_modules02 Environment: ============ Kernel Version: 7.0.0-rc7 Architecture: ppc64le LTP Version: 20260130-105-g07b599e48 This appears to be a bug in the lsm_list_modules() syscall implementation where it's not correctly reporting the active LSM modules. If you happen to fix the above issue, then please add below tag. Reported-by: Samir M Thanks, Samir