Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux
1
fork

Configure Feed

Select the types of activity you want to include in your feed.

bpf: Add security_file_post_open() LSM hook to sleepable_lsm_hooks

The new generic LSM hook security_file_post_open() was recently added
to the LSM framework in commit 8f46ff5767b0b ("security: Introduce
file_post_open hook"). Let's proactively add this generic LSM hook to
the sleepable_lsm_hooks BTF ID set, because I can't see there being
any strong reasons not to, and it's only a matter of time before
someone else comes around and asks for it to be there.

security_file_post_open() is inherently sleepable as it's purposely
situated in the kernel that allows LSMs to directly read out the
contents of the backing file if need be. Additionally, it's called
directly after security_file_open(), and that LSM hook in itself
already exists in the sleepable_lsm_hooks BTF ID set.

Signed-off-by: Matt Bobrowski <mattbobrowski@google.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20240618192923.379852-1-mattbobrowski@google.com

authored by

Matt Bobrowski and committed by
Daniel Borkmann
6ddf3a9a 651337c7

+1
+1
kernel/bpf/bpf_lsm.c
··· 280 280 BTF_ID(func, bpf_lsm_file_ioctl) 281 281 BTF_ID(func, bpf_lsm_file_lock) 282 282 BTF_ID(func, bpf_lsm_file_open) 283 + BTF_ID(func, bpf_lsm_file_post_open) 283 284 BTF_ID(func, bpf_lsm_file_receive) 284 285 285 286 BTF_ID(func, bpf_lsm_inode_create)