[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH v3] common: dom0less-bindings: introduce XSM labels


  • To: "Daniel P. Smith" <dpsmith@xxxxxxxxxxxxxxxxxxxx>, Sergiy Kibrik <Sergiy_Kibrik@xxxxxxxx>, "xen-devel@xxxxxxxxxxxxxxxxxxxx" <xen-devel@xxxxxxxxxxxxxxxxxxxx>
  • From: "Orzel, Michal" <michal.orzel@xxxxxxx>
  • Date: Mon, 5 Oct 2026 13:18:20 +0200
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 165.204.84.17) smtp.rcpttodomain=apertussolutions.com smtp.mailfrom=amd.com; dmarc=pass (p=quarantine sp=quarantine pct=100) action=none header.from=amd.com; dkim=none (message not signed); arc=none (0)
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=pO0A2nt1kh4fhy/HQuaKlMRaisCjegx2Wo6tPOv36cU=; b=bKEeuDNQt1ZoZINmi2uZS6ephep0Nyp46mD4nKaFT+SlqSvhE0A2ryR57/5h9k/LaZ1g18sqfI5y5zvX0ZvV+QEYezGJO4t+Xm1undchFyP2tftzQ7NHxOd3LI+TJH/OSkcJsfTfWdfBkH8EKtMY1NE19Do4sa8Kdyb3SBrN6O09XLcXy8NyKN3tu+xL5KaDfd44OHpSuodio+rMP4xixjVxXJkz/RonB37ZRaK+hAaxOzkjGHcoHnaSJHQLxjKsWazOoYjTrTlF+CNIXZyo2oMf6qVW1dfg2DPFEi+5NlltPIROf2borIdBdDjovQamZAlhXCfC7Mq69yMMo79eJA==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=IcJwrJavRaMXGsF7AN+HbqM6K6J04CPb4tk8TJtXx11WBehWEBuLWLht3kb8+os99e+1sHG7YHO6tlsFXJHj9SMQQs7Ny32pINBaZELPKZTKaUhVf5/pD/eVwDH6RZgz2BrFJ3xfd3bLi3Q3jiprhlxqezMRYTDv24vktcp2r2OBmdbLO+1eX54vHru5z7ZBzYpwDfS0yyK515HW/rzXq2/1Q7jBNnGLcN9n6gOXX7Xb2Yo/ONlPIMJl88KCKMzrH6dxpehA49H5yAHce0IuHPv+Y1gzHYg7EmUkvppvyf5v6avJTlh6vdSpS5sCYwP1BMg/U8AMrC1QG6MCiapQWg==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=amd.com header.i="@amd.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Cc: Stefano Stabellini <sstabellini@xxxxxxxxxx>, Julien Grall <julien@xxxxxxx>, Bertrand Marquis <bertrand.marquis@xxxxxxx>, Volodymyr Babchuk <Volodymyr_Babchuk@xxxxxxxx>, Andrew Cooper <andrew.cooper3@xxxxxxxxxx>, Jan Beulich <jbeulich@xxxxxxxx>
  • Delivery-date: Mon, 05 Oct 2026 11:18:39 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>


On 03-Oct-26 23:34, Daniel P. Smith wrote:
> On 10/2/26 6:25 AM, Sergiy Kibrik wrote:
>> Add "seclabel" property to be able to specify security label for a domain
>> when XSM Flask is enabled, similar to xl configuration files.
>>
>> Currently guest domain can't be created by Xen in dom0less configuration when
>> Flask is enabled, as domain is assigned "system_u:system_r:unlabeled_t" label
>> by default, which Flask denies to create according to current policy.
>>
>> Because code from outside of flask can't directly execute its internal API
>> a new routine flask_context_to_sid() introduced as part of XSM API exposed
>> to rest of Xen, which is a direct wrapper for security_context_to_sid().
>>
>> Signed-off-by: Sergiy Kibrik <Sergiy_Kibrik@xxxxxxxx>
>> CC: Daniel P. Smith <dpsmith@xxxxxxxxxxxxxxxxxxxx>
>> CC: Andrew Cooper <andrew.cooper3@xxxxxxxxxx>
>> CC: Michal Orzel <michal.orzel@xxxxxxx>
>> CC: Jan Beulich <jbeulich@xxxxxxxx>
>> ---
>> changes in v3:
>>   - panic if `seclabel` property found but FLASK is disabled
>> changes in v2:
>>   - add & use flask_context_to_sid() wrapper
>> ---
> 
> <snip/>
> 
>> diff --git a/xen/common/device-tree/dom0less-bindings.c 
>> b/xen/common/device-tree/dom0less-bindings.c
>> index 41d72d0d58..01d5cc1bc9 100644
>> --- a/xen/common/device-tree/dom0less-bindings.c
>> +++ b/xen/common/device-tree/dom0less-bindings.c
>> @@ -11,6 +11,8 @@
>>   #include <public/bootfdt.h>
>>   #include <public/domctl.h>
>>   
>> +#include <xsm/xsm.h>
>> +
>>   int __init parse_dom0less_node(struct dt_device_node *node,
>>                                  struct boot_domain *bd)
>>   {
>> @@ -21,6 +23,7 @@ int __init parse_dom0less_node(struct dt_device_node *node,
>>       bool has_dtb = false;
>>       bool iommu = false;
>>       const char *dom0less_iommu = NULL;
>> +    const char *xsm_seclabel = NULL;
>>   
>>       if ( !dt_device_is_compatible(node, "xen,domain") )
>>           return -ENOENT;
>> @@ -141,5 +144,15 @@ int __init parse_dom0less_node(struct dt_device_node 
>> *node,
>>           panic("'llc-colors' found, but LLC coloring is disabled\n");
>>   #endif
>>   
>> +    if ( !dt_property_read_string(node, "seclabel", &xsm_seclabel) )
>> +    {
>> +        if ( !IS_ENABLED(CONFIG_XSM_FLASK) )
>> +            panic("'seclabel' found, but FLASK is disabled\n");
> 
> Ultimately it's up to you, but I'm not sure you really will want to 
> panic here. I personally would warn it was set but ignored because FLASK 
> is not enabled.
I explicitly requested this in v2 to match the user/Xen contract we want on Arm
(we want to panic on unsatisfied user requests to prevent silent degradation of
functionality).

~Michal




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.