From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk1-f180.google.com (mail-qk1-f180.google.com [209.85.222.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9F5C71EF0BC for ; Tue, 21 Jan 2025 23:40:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.180 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1737502816; cv=none; b=ar/m2tmYeeFtLVS2IwRO6HrX9PmfoQbGK0UrlQvRPQuHvlDh04Lv3oj8mWfj1jm+K/QwWSuLfIYFfDNQl6nTtAuze+jqyXbpEm3+/TdP7Fc8AVi+3BuuURJ8ASM4OlHlkOzgRszzWre4PTN/gtKvZcAUN4Gr1QrPAQhT+2QebKo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1737502816; c=relaxed/simple; bh=pSwiYPlSqiDS39bXiWnOD9G7tmr+fbiAayyRrTmzXWA=; h=Date:Message-ID:From:To:Cc:Subject; b=SNElVM2z1AL533c/JNJjv5G3Nv0uOM8JZeE5NvZsaN2/u5uQUphKYCghGCcgiumJR6uxr1LMylXci3IqO6FD3tjt2y0iOx+NprYPuHxwfdXLOVg9AJ8ZZd1I0i7i15VjRBc9n8nJsQ3rB7OMWYOtWKz6NjbdHJEJJMQJwotLSIE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com; spf=pass smtp.mailfrom=paul-moore.com; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b=UhsS6yA5; arc=none smtp.client-ip=209.85.222.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b="UhsS6yA5" Received: by mail-qk1-f180.google.com with SMTP id af79cd13be357-7b6e5c74cb7so514868085a.2 for ; Tue, 21 Jan 2025 15:40:12 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=paul-moore.com; s=google; t=1737502811; x=1738107611; darn=vger.kernel.org; h=subject:cc:to:from:message-id:date:from:to:cc:subject:date :message-id:reply-to; bh=ZGKKV34zlfzM4tj8xlLWpq4U1VmTQkFTMB8ii94f/9g=; b=UhsS6yA50ColarU7JI2KN8hloO1FtXVg9cy2/rA/DOmDiERWbxnznG/O0cCRRXMIaj 5ZMOKtWbGqqKz72/9wTBD3h6x1WGO1oMEUFbOMTvJW6E5yfFKWLeV9Id4xtGGp4y1uxP 3NTe6AWTYo22XowvvRMh7DsjOMsSYyOpKjKP7T//fNLfSsW9mJK4+9rAsL34jO2Eu99w 6RBwRMMYK8NHgD8XO0OmGlYbNxbbjD6411rxLymJyGww+iC+w9MiTKFQ+78CEcfee55R fNVmITX8D2cPhjYGC14fS/BaS4VC/p6XjTA4XwNchLSA9caXdAmjrKm1Lc+23jBclGdP Qzsw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1737502811; x=1738107611; h=subject:cc:to:from:message-id:date:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=ZGKKV34zlfzM4tj8xlLWpq4U1VmTQkFTMB8ii94f/9g=; b=F/WbhYGyeFYGVOIL0A2dc38Oj67qWZMAm5X7ZHFzbvWWjormLUM8r0aqqb15VJ/r3i PdJAiknUnsAWIcZhaKG5MfPWTLM/pvkDZ11J+405W9IxAlYH+EkOkjpMOJ2JWLMVZDbt qB6Dusi+8k9CzSeLt4K0DuelpfWLWupHq+oK5oakp17zLUl3+tne+Itv4mwgTfifMF6z 6CcoHOx8FCMgcuqDRUBNNhPo5MK6Lyez+ho+8H82a3HAJqPQ+fTCTSDyKiZb+8/oxvSn Sv5HfhQQxBAE0+XuCCtb2bkBCGFvrxSaMriLj1ZqyqXW6UYgdcsyoXZCXU81vCRfrz/a AjIQ== X-Forwarded-Encrypted: i=1; AJvYcCXyXQWJXHf9L6FueVepmXvCGjySDbcr3S+FJVkhTgZuLLLcWCFxy4RHtnFCquT6WxtJ+sx0om1hNvfTPE4=@vger.kernel.org X-Gm-Message-State: AOJu0YyhkXqxBlMoeJCY/MbwIjfaKM6yyMvxbSopgNxkVVNAja1Hrtlu EX5a+wTAh6GiGFcKY5rJKEnIMx4MpNa8CkTC/HRIlqQsGSnjwLwJLEZG7SBqZBz/ph5oV+1FSkQ = X-Gm-Gg: ASbGncuhQboOojKUK23S3NQ5OEkvyPL1DC+XhE/Js+KpzN4w8ZSWEGFtbiqXMPH0cw2 +RwhE3GnGlBUoskhHc289vc0TNC5biQg63ID44g/pKqguo5bhMuy/oXndvteDh5DEdn0zMJRVpm mLilhK2/HMwukgCYxcSq/Fzd+Ce2Wa4O/W6nZoibbGo73vM63zL0ENtktBpg411sDt9iwa732W5 A96WydJXsWOZB3w28zyfiTalGpIuUrQNkhpash2Sg7LfKqa+u36Xjyxc1sTtezK X-Google-Smtp-Source: AGHT+IFJLsePXH34LfvxbtHxCNvBgBr6oLI3+mxWJhHJgBIBGsLCQ6yYdKKnMk1LxIfB2VYBheRUrw== X-Received: by 2002:a05:620a:4396:b0:7b1:48ff:6b56 with SMTP id af79cd13be357-7be6327979emr3166709485a.43.1737502811433; Tue, 21 Jan 2025 15:40:11 -0800 (PST) Received: from localhost ([70.22.175.108]) by smtp.gmail.com with UTF8SMTPSA id af79cd13be357-7be614d98dbsm608942685a.74.2025.01.21.15.40.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 21 Jan 2025 15:40:10 -0800 (PST) Date: Tue, 21 Jan 2025 18:40:10 -0500 Message-ID: From: Paul Moore To: Linus Torvalds Cc: linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [GIT PULL] lsm/lsm-pr-20250121 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Linus, Fifteen LSM framework patches for the v6.14 merge window, a summary is below: - Improved handling of LSM "secctx" strings through lsm_context struct The LSM secctx string interface is from an older time when only one LSM was supported, migrate over to the lsm_context struct to better support the different LSMs we now have and make it easier to support new LSMs in the future. These changes explain the Rust, VFS, and networking changes in the diffstat. - Only build lsm_audit.c if CONFIG_SECURITY and CONFIG_AUDIT are enabled Small tweak to be a bit smarter about when we build the LSM's common audit helpers. - Check for absurdly large policies from userspace in SafeSetID SafeSetID policies rules are fairly small, basically just "UID:UID", it easy to impose a limit of KMALLOC_MAX_SIZE on policy writes which helps quiet a number of syzbot related issues. While work is being done to address the syzbot issues through other mechanisms, this is a trivial and relatively safe fix that we can do now. - Various minor improvements and cleanups A collection of improvements to the kernel selftests, constification of some function parameters, removing redundant assignments, and local variable renames to improve readability. Paul -- The following changes since commit 40384c840ea1944d7c5a392e8975ed088ecf0b37: Linux 6.13-rc1 (2024-12-01 14:28:56 -0800) are available in the Git repository at: https://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/lsm.git tags/lsm-pr-20250121 for you to fetch changes up to 714d87c90a766e6917f7d69f618b864d350f09d3: lockdown: initialize local array before use to quiet static analysis (2025-01-05 12:48:43 -0500) ---------------------------------------------------------------- lsm/stable-6.14 PR 20250121 ---------------------------------------------------------------- Alice Ryhl (1): rust: replace lsm context+len with lsm_context Amit Vadhavana (1): selftests: refactor the lsm `flags_overset_lsm_set_self_attr` test Casey Schaufler (7): lsm: ensure the correct LSM context releaser lsm: replace context+len with lsm_context lsm: use lsm_context in security_inode_getsecctx lsm: lsm_context in security_dentry_init_security lsm: secctx provider check on release binder: initialize lsm_context structure net: corrections for security_secid_to_secctx returns Christian Göttsche (2): lsm: constify function parameters lsm: rename variable to avoid shadowing Colin Ian King (1): security: remove redundant assignment to return variable Leo Stone (1): safesetid: check size of policy writes Mickaël Salaün (1): lsm: Only build lsm_audit.c if CONFIG_SECURITY and CONFIG_AUDIT are set Tanya Agarwal (1): lockdown: initialize local array before use to quiet static analysis drivers/android/binder.c | 25 +--- fs/ceph/super.h | 3 fs/ceph/xattr.c | 12 - fs/fuse/dir.c | 35 ++--- fs/nfs/nfs4proc.c | 22 ++- fs/nfsd/nfs4xdr.c | 22 +-- include/linux/lsm_audit.h | 14 ++ include/linux/lsm_hook_defs.h | 13 -- include/linux/security.h | 37 +++--- include/net/scm.h | 12 - kernel/audit.c | 33 ++--- kernel/auditsc.c | 27 +--- net/ipv4/ip_sockglue.c | 12 - net/netfilter/nf_conntrack_netlink.c | 20 +-- net/netfilter/nf_conntrack_standalone.c | 11 - net/netfilter/nfnetlink_queue.c | 26 ++-- net/netlabel/netlabel_unlabeled.c | 44 ++----- net/netlabel/netlabel_user.c | 10 - rust/helpers/security.c | 8 - rust/kernel/security.rs | 38 ++---- security/Kconfig | 5 security/Makefile | 2 security/apparmor/include/secid.h | 7 - security/apparmor/secid.c | 34 +++-- security/lockdown/lockdown.c | 2 security/lsm_audit.c | 8 - security/safesetid/securityfs.c | 3 security/security.c | 67 ++++------- security/selinux/hooks.c | 49 +++++--- security/smack/smack_lsm.c | 52 ++++---- tools/testing/selftests/lsm/lsm_set_self_attr_test.c | 7 - 31 files changed, 351 insertions(+), 309 deletions(-) -- paul-moore.com