|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [PATCH v3] common: dom0less-bindings: introduce XSM labels
On 03-Oct-26 23:34, Daniel P. Smith wrote:
> On 10/2/26 6:25 AM, Sergiy Kibrik wrote:
>> Add "seclabel" property to be able to specify security label for a domain
>> when XSM Flask is enabled, similar to xl configuration files.
>>
>> Currently guest domain can't be created by Xen in dom0less configuration when
>> Flask is enabled, as domain is assigned "system_u:system_r:unlabeled_t" label
>> by default, which Flask denies to create according to current policy.
>>
>> Because code from outside of flask can't directly execute its internal API
>> a new routine flask_context_to_sid() introduced as part of XSM API exposed
>> to rest of Xen, which is a direct wrapper for security_context_to_sid().
>>
>> Signed-off-by: Sergiy Kibrik <Sergiy_Kibrik@xxxxxxxx>
>> CC: Daniel P. Smith <dpsmith@xxxxxxxxxxxxxxxxxxxx>
>> CC: Andrew Cooper <andrew.cooper3@xxxxxxxxxx>
>> CC: Michal Orzel <michal.orzel@xxxxxxx>
>> CC: Jan Beulich <jbeulich@xxxxxxxx>
>> ---
>> changes in v3:
>> - panic if `seclabel` property found but FLASK is disabled
>> changes in v2:
>> - add & use flask_context_to_sid() wrapper
>> ---
>
> <snip/>
>
>> diff --git a/xen/common/device-tree/dom0less-bindings.c
>> b/xen/common/device-tree/dom0less-bindings.c
>> index 41d72d0d58..01d5cc1bc9 100644
>> --- a/xen/common/device-tree/dom0less-bindings.c
>> +++ b/xen/common/device-tree/dom0less-bindings.c
>> @@ -11,6 +11,8 @@
>> #include <public/bootfdt.h>
>> #include <public/domctl.h>
>>
>> +#include <xsm/xsm.h>
>> +
>> int __init parse_dom0less_node(struct dt_device_node *node,
>> struct boot_domain *bd)
>> {
>> @@ -21,6 +23,7 @@ int __init parse_dom0less_node(struct dt_device_node *node,
>> bool has_dtb = false;
>> bool iommu = false;
>> const char *dom0less_iommu = NULL;
>> + const char *xsm_seclabel = NULL;
>>
>> if ( !dt_device_is_compatible(node, "xen,domain") )
>> return -ENOENT;
>> @@ -141,5 +144,15 @@ int __init parse_dom0less_node(struct dt_device_node
>> *node,
>> panic("'llc-colors' found, but LLC coloring is disabled\n");
>> #endif
>>
>> + if ( !dt_property_read_string(node, "seclabel", &xsm_seclabel) )
>> + {
>> + if ( !IS_ENABLED(CONFIG_XSM_FLASK) )
>> + panic("'seclabel' found, but FLASK is disabled\n");
>
> Ultimately it's up to you, but I'm not sure you really will want to
> panic here. I personally would warn it was set but ignored because FLASK
> is not enabled.
I explicitly requested this in v2 to match the user/Xen contract we want on Arm
(we want to panic on unsatisfied user requests to prevent silent degradation of
functionality).
~Michal
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |