From: Nikolay Borisov <nik.borisov@suse.com>
To: xiujianfeng <xiujianfeng@huawei.com>,
Nicolas Bouchinet <nicolas.bouchinet@oss.cyber.gouv.fr>
Cc: linux-security-module@vger.kernel.org,
linux-kernel@vger.kernel.org, paul@paul-moore.com,
serge@hallyn.com, jmorris@namei.org, dan.j.williams@intel.com
Subject: Re: [PATCH v2 0/3] Allow individual features to be locked down
Date: Tue, 5 Aug 2025 11:03:00 +0300 [thread overview]
Message-ID: <3be6b1c2-4b54-4107-8bdd-67d5cbcff58c@suse.com> (raw)
In-Reply-To: <42b2cf1b-417e-1594-d525-f4c84f7405b0@huawei.com>
On 8/5/25 09:57, xiujianfeng wrote:
>
>
> On 2025/7/29 20:25, Nikolay Borisov wrote:
>>
>>
>> On 29.07.25 г. 15:16 ч., Nicolas Bouchinet wrote:
>>> Hi Nikolay,
>>>
>>> Thanks for you patch.
>>>
>>> Quoting Kees [1], Lockdown is "about creating a bright line between
>>> uid-0 and ring-0".
>>>
>>> Having a bitmap enabled Lockdown would mean that Lockdown reasons could
>>> be activated independently. I fear this would lead to a false sense of
>>> security, locking one reason alone often permits Lockdown restrictions
>>> bypass. i.e enforcing kernel module signature verification but not
>>> blocking accesses to `/dev/{k,}mem` or authorizing gkdb which can be
>>> used to disable the module signature enforcement.
>>>
>>> If one wants to restrict accesses to `/dev/mem`,
>>> `security_locked_down(LOCKDOWN_DEV_MEM)` should be sufficient.
>>>
>>> My understanding of your problem is that this locks too much for your
>>> usecase and you want to restrict reasons of Lockdown independently in
>>> case it has not been enabled in "integrity" mode by default ?
>>>
>>> Can you elaborate more on the usecases for COCO ?
>>
>> Initially this patchset was supposed to allow us selectively disable
>> /dev/iomem access in a CoCo context [0]. As evident from Dan's initial
>> response that point pretty much became moot as the issue was fixed in a
>> different way. However, later [1] he came back and said that actually
>> this patch could be useful in a similar context. So This v2 is
>> essentially following up on that.
>
> Hi Nikolay,
>
> I share a similar view with Nicolas, namely that using a bitmap
> implementation would compromise the goal of Lockdown.
>
> After reading the threads below, I understand you aim is to block user
> access to /dev/mem, but without having Lockdown integrity mode enabled
> to block other reasons, right? How about using BPF LSM? It seems it
> could address your requirements.
>
Well the use case that my change allows (barring the original issue) is
say if someone wants LOCKDOWN_INTEGRITY_MAX + 1 or 2 things from the
CONFIDENTIALY_MAX level.
>>
>>
>> [0]
>> https://lore.kernel.org/all/67f69600ed221_71fe2946f@dwillia2-xfh.jf.intel.com.notmuch/
>>
>> [1]
>> https://lore.kernel.org/all/68226ad551afd_29032945b@dwillia2-xfh.jf.intel.com.notmuch/
>>
>> <snip>
next prev parent reply other threads:[~2025-08-05 8:03 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-07-28 11:15 Nikolay Borisov
2025-07-28 11:15 ` [PATCH v2 1/3] lockdown: Switch implementation to using bitmap Nikolay Borisov
2025-07-28 12:47 ` Serge E. Hallyn
2025-07-28 13:21 ` Serge E. Hallyn
2025-08-05 22:18 ` dan.j.williams
2025-07-28 11:15 ` [PATCH v2 2/3] lockdown/kunit: Introduce kunit tests Nikolay Borisov
2025-07-28 12:49 ` Serge E. Hallyn
2025-07-28 22:04 ` kernel test robot
2025-07-29 7:46 ` Nikolay Borisov
2025-07-29 23:28 ` Philip Li
2025-07-29 7:30 ` kernel test robot
2025-07-28 11:15 ` [PATCH v2 3/3] lockdown: Use snprintf in lockdown_read Nikolay Borisov
2025-07-28 12:39 ` Serge E. Hallyn
2025-08-05 7:56 ` Nikolay Borisov
2025-08-05 22:30 ` dan.j.williams
2025-07-29 12:16 ` [PATCH v2 0/3] Allow individual features to be locked down Nicolas Bouchinet
2025-07-29 12:25 ` Nikolay Borisov
2025-08-05 6:57 ` xiujianfeng
2025-08-05 8:03 ` Nikolay Borisov [this message]
2025-08-05 23:28 ` dan.j.williams
2025-08-14 8:59 ` Nicolas Bouchinet
2025-08-14 10:02 ` Nikolay Borisov
2025-08-14 10:51 ` Nicolas Bouchinet
2025-08-05 23:43 ` dan.j.williams
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=3be6b1c2-4b54-4107-8bdd-67d5cbcff58c@suse.com \
--to=nik.borisov@suse.com \
--cc=dan.j.williams@intel.com \
--cc=jmorris@namei.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=nicolas.bouchinet@oss.cyber.gouv.fr \
--cc=paul@paul-moore.com \
--cc=serge@hallyn.com \
--cc=xiujianfeng@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®