selftests/bpf: Verify load-time signed loader metadata

The signed gen_loader no longer checks its metadata map from within
BPF; the kernel does it at BPF_PROG_LOAD by folding the loader's frozen
exclusive fd_array maps into the signature. Exercise that path end to
end. Extend with more test cases (e.g. map-less program, asserting the
LSM admission hook observes BPF_SIG_UNSIGNED and BPF_SIG_VERIFIED), and
retire the subtests that asserted the old in-loader check, which no
longer exists.

  # LDLIBS=-static PKG_CONFIG='pkg-config --static' ./vmtest.sh -- ./test_progs -t signed_loader
  [...]
  #412/1   signed_loader/loadtime_no_map:OK
  #412/2   signed_loader/loadtime_with_map:OK
  #412/3   signed_loader/metadata_match:OK
  #412/4   signed_loader/signature_enforced:OK
  #412/5   signed_loader/signed_nonexcl_fd_array_rejected:OK
  #412/6   signed_loader/signed_unfrozen_fd_array_rejected:OK
  #412/7   signed_loader/signed_nonarray_fd_array_rejected:OK
  #412/8   signed_loader/signed_btf_fd_array_rejected:OK
  #412/9   signed_loader/signed_module_kfunc_rejected:OK
  #412/10  signed_loader/signature_failure_logs:OK
  #412/11  signed_loader/signature_too_large:OK
  #412/12  signed_loader/signature_zero_size:OK
  #412/13  signed_loader/signature_bad_keyring:OK
  #412/14  signed_loader/metadata_ctx_max_entries_ignored:OK
  #412/15  signed_loader/metadata_ctx_initial_value_ignored:OK
  #412/16  signed_loader/signature_authenticates_insns:OK
  #412/17  signed_loader/signature_authenticates_metadata:OK
  #412/18  signed_loader/hash_requires_frozen:OK
  #412/19  signed_loader/no_update_after_freeze:OK
  #412/20  signed_loader/freeze_writable_mmap:OK
  #412/21  signed_loader/no_writable_mmap_frozen:OK
  #412/22  signed_loader/map_hash_matches_libbpf:OK
  #412/23  signed_loader/map_hash_multi_element:OK
  #412/24  signed_loader/map_hash_bad_size:OK
  #412/25  signed_loader/map_hash_unsupported_type:OK
  #412/26  signed_loader/lsm_signature_verdict:OK
  #412/27  signed_loader/signed_no_fd_array:OK
  #412/28  signed_loader/signed_map_by_fd_rejected:OK
  #412/29  signed_loader/signed_sparse_fd_array_rejected:OK
  #412     signed_loader:OK
  Summary: 1/29 PASSED, 0 SKIPPED, 0 FAILED

Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20260708075343.358712-8-daniel@iogearbox.net
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
This commit is contained in:
Daniel Borkmann
2026-07-08 09:53:42 +02:00
committed by Kumar Kartikeya Dwivedi
parent 77e5f3c914
commit 99b321dde7
2 changed files with 891 additions and 193 deletions

File diff suppressed because it is too large Load Diff

View File

@@ -4,10 +4,11 @@
/*
* Minimal, map-less program. Driven through libbpf's gen_loader (gen_hash)
* by prog_tests/signed_loader.c so the generated light-skeleton loader (with
* the emit_signature_match metadata check) can be exercised against good
* and tampered metadata. A socket filter needs no load-time attach resolution,
* and having no maps keeps the generated loader's ctx trivial (0 maps, 1 prog).
* by prog_tests/signed_loader.c so the generated light-skeleton loader can be
* exercised against good and tampered metadata, which the kernel now verifies
* at load time via the insns||metadata signature. A socket filter needs no
* load-time attach resolution, and having no maps keeps the generated loader's
* ctx trivial (0 maps, 1 prog).
*/
SEC("socket")
int probe(void *ctx)