[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH v3] common: dom0less-bindings: introduce XSM labels


  • To: "Sergiy Kibrik" <Sergiy_Kibrik@xxxxxxxx>, "xen-devel@xxxxxxxxxxxxxxxxxxxx" <xen-devel@xxxxxxxxxxxxxxxxxxxx>
  • From: "Alejandro Vallejo" <alejandro.garciavallejo@xxxxxxx>
  • Date: Mon, 05 Oct 2026 16:20:13 +0200
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=amd.com; dmarc=pass action=none header.from=amd.com; dkim=pass header.d=amd.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=DdkQ090/RIKRtGEm0ll0/tOCZWXQzYWVSGBNfJ/gW/o=; b=OFoGPfrDIkIT6ICi4cjet6f3724OukIcpu1ksIy2sqnhO+smf18lIYGoMzgFKaGVdbNwBAqAdBFrXC8oAJU98l4/ZGqJzmaG/dxuSoJmHbn96pebtCZEFO3mFRHXqZgX3CYP5FL53J0EAVlUg/vUqQNPhVKjFBFzdp6y5mYh37v7Wj3ojWWJPqHqcgkGTFFVqIYwe8ulbBOAlkvL9QICZ+h4ZhOdkQUA7moHFWXxCretngWcIOVhfimKtLfWK7/Ivm3YE9VDEf1M1BXWB0M8SePkqGOuu+ngRtrqVGh5PBX8UOXcDn3zjiOd0nzP39LFeSn2HAmH96n9SA/jL00Dlw==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=AbORgdSLavhhKbtCoYIXW+rVSiyaZEe0Q7wNs23J++T74zHPu/2ICt9diLOj1/W2ulkYSpbKTVhpukowLmB2VhPHCsRa/BtJPgca3JGGZCRpzX4I+gISRLHetGq648J83/aSRZCOCjZ7ZgnzTICxIXJYxs6+HHne/Mw0osiAcRLDsaIC0FBCOmGqpbUL+UE2gB0Q88hvTUZFD3N+Xy9MSzL5BEG9Rqh/vWSVA8uOCCUKOTlu9KckYU+li4/QLen/oNqfKXB2L29HQGDpR4dw17ZZLBAIJtbh4abVebQvl5W7bhdpoxxlgsYtm5G0xWTydPd0tbsBvkT7+mkyK3KH4g==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=amd.com header.i="@amd.com" header.h="From:Date:Subject:Message-Id:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Authentication-results: mx.microsoft.com 1; dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=amd.com;
  • Cc: "Stefano Stabellini" <sstabellini@xxxxxxxxxx>, "Julien Grall" <julien@xxxxxxx>, "Bertrand Marquis" <bertrand.marquis@xxxxxxx>, "Volodymyr Babchuk" <Volodymyr_Babchuk@xxxxxxxx>, "Daniel P. Smith" <dpsmith@xxxxxxxxxxxxxxxxxxxx>, "Andrew Cooper" <andrew.cooper3@xxxxxxxxxx>, "Michal Orzel" <michal.orzel@xxxxxxx>, "Jan Beulich" <jbeulich@xxxxxxxx>
  • Delivery-date: Mon, 05 Oct 2026 14:20:41 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

On Fri Oct 2, 2026 at 12:25 PM CEST, Sergiy Kibrik wrote:
> Add "seclabel" property to be able to specify security label for a domain
> when XSM Flask is enabled, similar to xl configuration files.
>
> Currently guest domain can't be created by Xen in dom0less configuration when
> Flask is enabled, as domain is assigned "system_u:system_r:unlabeled_t" label
> by default, which Flask denies to create according to current policy.
>
> Because code from outside of flask can't directly execute its internal API
> a new routine flask_context_to_sid() introduced as part of XSM API exposed
> to rest of Xen, which is a direct wrapper for security_context_to_sid().
>
> Signed-off-by: Sergiy Kibrik <Sergiy_Kibrik@xxxxxxxx>
> CC: Daniel P. Smith <dpsmith@xxxxxxxxxxxxxxxxxxxx>
> CC: Andrew Cooper <andrew.cooper3@xxxxxxxxxx>
> CC: Michal Orzel <michal.orzel@xxxxxxx>
> CC: Jan Beulich <jbeulich@xxxxxxxx>
> ---
> changes in v3:
>  - panic if `seclabel` property found but FLASK is disabled
> changes in v2:
>  - add & use flask_context_to_sid() wrapper
> ---
>  docs/misc/arm/device-tree/booting.txt      |  7 +++++++
>  xen/common/device-tree/dom0less-bindings.c | 13 +++++++++++++
>  xen/include/xsm/xsm.h                      |  3 +++
>  xen/xsm/flask/hooks.c                      |  5 +++++
>  4 files changed, 28 insertions(+)
>
> diff --git a/docs/misc/arm/device-tree/booting.txt 
> b/docs/misc/arm/device-tree/booting.txt
> index bcb06bc796..d04455b744 100644
> --- a/docs/misc/arm/device-tree/booting.txt
> +++ b/docs/misc/arm/device-tree/booting.txt
> @@ -345,6 +345,11 @@ with the following properties:
>      not passed. This configuration requires static allocation 
> (xen,static-mem)
>      and direct mapping (direct-map).
>  
> +- seclabel
> +
> +    A string property specifying an XSM security label to this domain. 
> Domains
> +    will be classified “unlabeled” if this property not specified.

This paragraph assumes FLASK=y, but many configurations of Xen do not ship it.

Perhaps it would be prudent to state what happens (kaboom) when you load
a DTB with this prop on a FLASK=n hypervisor.

> +
>  Under the "xen,domain" compatible node, one or more sub-nodes are present
>  for the DomU kernel and ramdisk.
>  
> @@ -422,6 +427,7 @@ chosen {
>          memory = <0 131072>;
>          cpus = <2>;
>          vpl011;
> +        seclabel = "system_u:system_r:domU_t";
>  
>          vcpu0 {
>              compatible = "xen,vcpu";
> @@ -453,6 +459,7 @@ chosen {
>          #size-cells = <0x1>;
>          memory = <0 65536>;
>          cpus = <1>;
> +        seclabel = "system_u:system_r:domU_t";
>  
>          module@0x4c000000 {
>              compatible = "multiboot,kernel", "multiboot,module";
> diff --git a/xen/common/device-tree/dom0less-bindings.c 
> b/xen/common/device-tree/dom0less-bindings.c
> index 41d72d0d58..01d5cc1bc9 100644
> --- a/xen/common/device-tree/dom0less-bindings.c
> +++ b/xen/common/device-tree/dom0less-bindings.c
> @@ -11,6 +11,8 @@
>  #include <public/bootfdt.h>
>  #include <public/domctl.h>
>  
> +#include <xsm/xsm.h>
> +
>  int __init parse_dom0less_node(struct dt_device_node *node,
>                                 struct boot_domain *bd)
>  {
> @@ -21,6 +23,7 @@ int __init parse_dom0less_node(struct dt_device_node *node,
>      bool has_dtb = false;
>      bool iommu = false;
>      const char *dom0less_iommu = NULL;
> +    const char *xsm_seclabel = NULL;
>  
>      if ( !dt_device_is_compatible(node, "xen,domain") )
>          return -ENOENT;
> @@ -141,5 +144,15 @@ int __init parse_dom0less_node(struct dt_device_node 
> *node,
>          panic("'llc-colors' found, but LLC coloring is disabled\n");
>  #endif
>  
> +    if ( !dt_property_read_string(node, "seclabel", &xsm_seclabel) )
> +    {
> +        if ( !IS_ENABLED(CONFIG_XSM_FLASK) )
> +            panic("'seclabel' found, but FLASK is disabled\n");
> +        else if ( flask_context_to_sid(xsm_seclabel, strlen(xsm_seclabel),

nit: else if could be plain if

> +                                     &d_cfg->ssidref) )
> +                panic("Invalid security context for domain: %s\n",
> +                      xsm_seclabel);

bad indentation of the panic statement. At the proper 4 blanks from the
conditional branch, panic() fits in 80 lines. Fewer with s/Invalid/Bad/.

> +    }
> +
>      return arch_parse_dom0less_node(node, bd);
>  }
> diff --git a/xen/include/xsm/xsm.h b/xen/include/xsm/xsm.h
> index 9809e005e0..73d058a8b2 100644
> --- a/xen/include/xsm/xsm.h
> +++ b/xen/include/xsm/xsm.h
> @@ -261,4 +261,7 @@ static inline bool has_xsm_magic(paddr_t start)
>  
>  #endif /* CONFIG_XSM */
>  
> +int flask_context_to_sid(const char *scontext,
> +                         uint32_t scontext_len, uint32_t *sid);

nit: with s/context/ctxt/ this fits in a single line, otherwise...

> +
>  #endif /* __XSM_H */
> diff --git a/xen/xsm/flask/hooks.c b/xen/xsm/flask/hooks.c
> index d65ba0aeae..0b44a2a3d9 100644
> --- a/xen/xsm/flask/hooks.c
> +++ b/xen/xsm/flask/hooks.c
> @@ -2016,6 +2016,11 @@ const struct xsm_ops *__init flask_init(
>      return &flask_ops;
>  }
>  
> +int flask_context_to_sid(const char *scontext, uint32_t scontext_len, 
> uint32_t *sid)

... this one needs to be split as it crosses the 80 columns boundary.

> +{
> +    return security_context_to_sid(scontext, scontext_len, sid);
> +}
> +
>  /*
>   * Local variables:
>   * mode: C

Cheers,
Alejandro




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.