mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-07-22 02:17:36 -04:00
landlock: Account all audit data allocations to user space
Mark the kzalloc_flex() of struct landlock_details with GFP_KERNEL_ACCOUNT so the allocation is charged to the calling task, like the other Landlock per-domain allocations which have used GFP_KERNEL_ACCOUNT forever. Every property of landlock_details is caller-attributable: allocated by landlock_restrict_self(2), owned by the caller's landlock_hierarchy, contents are the caller's pid, uid, comm, and exe_path, lifetime bounded by the caller's domain. While the caller may not know nor control the size of this allocation (i.e. exe_path), this data should still be accounted for it. The deciding factor is whether userspace can trigger the allocation, not whether the size of the data is known nor controlled by the caller. This aligns with the kmemcg accounting policy established by commit5d097056c9("kmemcg: account certain kmem allocations to memcg"). No new failure modes: the hierarchy and ruleset are allocated before details and are already accounted, so landlock_restrict_self(2) already returns -ENOMEM under memcg pressure. This change widens that existing failure window slightly; it does not introduce a new error code. Cc: Günther Noack <gnoack@google.com> Cc: Paul Moore <paul@paul-moore.com> Cc: stable@vger.kernel.org Fixes:1d636984e0("landlock: Add AUDIT_LANDLOCK_DOMAIN and log domain status") Link: https://patch.msgid.link/20260513180309.165840-1-mic@digikod.net Signed-off-by: Mickaël Salaün <mic@digikod.net>
This commit is contained in:
@@ -90,11 +90,12 @@ static struct landlock_details *get_current_details(void)
|
||||
return ERR_CAST(buffer);
|
||||
|
||||
/*
|
||||
* Create the new details according to the path's length. Do not
|
||||
* allocate with GFP_KERNEL_ACCOUNT because it is independent from the
|
||||
* caller.
|
||||
* Create the new details according to the path's length. Account to
|
||||
* the calling task's memcg, like the other Landlock per-domain
|
||||
* allocations, even if it may not control the related size.
|
||||
*/
|
||||
details = kzalloc_flex(*details, exe_path, path_size);
|
||||
details =
|
||||
kzalloc_flex(*details, exe_path, path_size, GFP_KERNEL_ACCOUNT);
|
||||
if (!details)
|
||||
return ERR_PTR(-ENOMEM);
|
||||
|
||||
|
||||
@@ -33,10 +33,7 @@ enum landlock_log_status {
|
||||
* Rarely accessed, mainly when logging the first domain's denial.
|
||||
*
|
||||
* The contained pointers are initialized at the domain creation time and never
|
||||
* changed again. Contrary to most other Landlock object types, this one is
|
||||
* not allocated with GFP_KERNEL_ACCOUNT because its size may not be under the
|
||||
* caller's control (e.g. unknown exe_path) and the data is not explicitly
|
||||
* requested nor used by tasks.
|
||||
* changed again.
|
||||
*/
|
||||
struct landlock_details {
|
||||
/**
|
||||
|
||||
Reference in New Issue
Block a user