|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [PATCH v3] common: dom0less-bindings: introduce XSM labels
On Fri Oct 2, 2026 at 12:25 PM CEST, Sergiy Kibrik wrote:
> Add "seclabel" property to be able to specify security label for a domain
> when XSM Flask is enabled, similar to xl configuration files.
>
> Currently guest domain can't be created by Xen in dom0less configuration when
> Flask is enabled, as domain is assigned "system_u:system_r:unlabeled_t" label
> by default, which Flask denies to create according to current policy.
>
> Because code from outside of flask can't directly execute its internal API
> a new routine flask_context_to_sid() introduced as part of XSM API exposed
> to rest of Xen, which is a direct wrapper for security_context_to_sid().
>
> Signed-off-by: Sergiy Kibrik <Sergiy_Kibrik@xxxxxxxx>
> CC: Daniel P. Smith <dpsmith@xxxxxxxxxxxxxxxxxxxx>
> CC: Andrew Cooper <andrew.cooper3@xxxxxxxxxx>
> CC: Michal Orzel <michal.orzel@xxxxxxx>
> CC: Jan Beulich <jbeulich@xxxxxxxx>
> ---
> changes in v3:
> - panic if `seclabel` property found but FLASK is disabled
> changes in v2:
> - add & use flask_context_to_sid() wrapper
> ---
> docs/misc/arm/device-tree/booting.txt | 7 +++++++
> xen/common/device-tree/dom0less-bindings.c | 13 +++++++++++++
> xen/include/xsm/xsm.h | 3 +++
> xen/xsm/flask/hooks.c | 5 +++++
> 4 files changed, 28 insertions(+)
>
> diff --git a/docs/misc/arm/device-tree/booting.txt
> b/docs/misc/arm/device-tree/booting.txt
> index bcb06bc796..d04455b744 100644
> --- a/docs/misc/arm/device-tree/booting.txt
> +++ b/docs/misc/arm/device-tree/booting.txt
> @@ -345,6 +345,11 @@ with the following properties:
> not passed. This configuration requires static allocation
> (xen,static-mem)
> and direct mapping (direct-map).
>
> +- seclabel
> +
> + A string property specifying an XSM security label to this domain.
> Domains
> + will be classified “unlabeled” if this property not specified.
This paragraph assumes FLASK=y, but many configurations of Xen do not ship it.
Perhaps it would be prudent to state what happens (kaboom) when you load
a DTB with this prop on a FLASK=n hypervisor.
> +
> Under the "xen,domain" compatible node, one or more sub-nodes are present
> for the DomU kernel and ramdisk.
>
> @@ -422,6 +427,7 @@ chosen {
> memory = <0 131072>;
> cpus = <2>;
> vpl011;
> + seclabel = "system_u:system_r:domU_t";
>
> vcpu0 {
> compatible = "xen,vcpu";
> @@ -453,6 +459,7 @@ chosen {
> #size-cells = <0x1>;
> memory = <0 65536>;
> cpus = <1>;
> + seclabel = "system_u:system_r:domU_t";
>
> module@0x4c000000 {
> compatible = "multiboot,kernel", "multiboot,module";
> diff --git a/xen/common/device-tree/dom0less-bindings.c
> b/xen/common/device-tree/dom0less-bindings.c
> index 41d72d0d58..01d5cc1bc9 100644
> --- a/xen/common/device-tree/dom0less-bindings.c
> +++ b/xen/common/device-tree/dom0less-bindings.c
> @@ -11,6 +11,8 @@
> #include <public/bootfdt.h>
> #include <public/domctl.h>
>
> +#include <xsm/xsm.h>
> +
> int __init parse_dom0less_node(struct dt_device_node *node,
> struct boot_domain *bd)
> {
> @@ -21,6 +23,7 @@ int __init parse_dom0less_node(struct dt_device_node *node,
> bool has_dtb = false;
> bool iommu = false;
> const char *dom0less_iommu = NULL;
> + const char *xsm_seclabel = NULL;
>
> if ( !dt_device_is_compatible(node, "xen,domain") )
> return -ENOENT;
> @@ -141,5 +144,15 @@ int __init parse_dom0less_node(struct dt_device_node
> *node,
> panic("'llc-colors' found, but LLC coloring is disabled\n");
> #endif
>
> + if ( !dt_property_read_string(node, "seclabel", &xsm_seclabel) )
> + {
> + if ( !IS_ENABLED(CONFIG_XSM_FLASK) )
> + panic("'seclabel' found, but FLASK is disabled\n");
> + else if ( flask_context_to_sid(xsm_seclabel, strlen(xsm_seclabel),
nit: else if could be plain if
> + &d_cfg->ssidref) )
> + panic("Invalid security context for domain: %s\n",
> + xsm_seclabel);
bad indentation of the panic statement. At the proper 4 blanks from the
conditional branch, panic() fits in 80 lines. Fewer with s/Invalid/Bad/.
> + }
> +
> return arch_parse_dom0less_node(node, bd);
> }
> diff --git a/xen/include/xsm/xsm.h b/xen/include/xsm/xsm.h
> index 9809e005e0..73d058a8b2 100644
> --- a/xen/include/xsm/xsm.h
> +++ b/xen/include/xsm/xsm.h
> @@ -261,4 +261,7 @@ static inline bool has_xsm_magic(paddr_t start)
>
> #endif /* CONFIG_XSM */
>
> +int flask_context_to_sid(const char *scontext,
> + uint32_t scontext_len, uint32_t *sid);
nit: with s/context/ctxt/ this fits in a single line, otherwise...
> +
> #endif /* __XSM_H */
> diff --git a/xen/xsm/flask/hooks.c b/xen/xsm/flask/hooks.c
> index d65ba0aeae..0b44a2a3d9 100644
> --- a/xen/xsm/flask/hooks.c
> +++ b/xen/xsm/flask/hooks.c
> @@ -2016,6 +2016,11 @@ const struct xsm_ops *__init flask_init(
> return &flask_ops;
> }
>
> +int flask_context_to_sid(const char *scontext, uint32_t scontext_len,
> uint32_t *sid)
... this one needs to be split as it crosses the 80 columns boundary.
> +{
> + return security_context_to_sid(scontext, scontext_len, sid);
> +}
> +
> /*
> * Local variables:
> * mode: C
Cheers,
Alejandro
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |