Link: https://lore.kernel.org/r/20260217200002.683975158@linuxfoundation.org Tested-by: Florian Fainelli <florian.fainelli@broadcom.com> Tested-by: Takeshi Ogasawara <takeshi.ogasawara@futuring-girl.com> Tested-by: Peter Schneider <pschneider1968@googlemail.com> Tested-by: Jon Hunter <jonathanh@nvidia.com> Tested-by: Salvatore Bonaccorso <carnil@debian.org> Tested-by: Brett A C Sheffield <bacs@librecast.net> Tested-by: Mark Brown <broonie@kernel.org> Tested-by: Luna Jernberg <droidbittin@gmail.com> Tested-by: Ronald Warsow <rwarsow@gmx.de> Tested-by: Justin M. Forbes <jforbes@fedoraproject.org> Tested-by: Ron Economos <re@w6rz.net> Tested-by: Miguel Ojeda <ojeda@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
22 lines
651 B
ReStructuredText
22 lines
651 B
ReStructuredText
.. SPDX-License-Identifier: GPL-2.0
|
|
|
|
.. _fs_kfuncs-header-label:
|
|
|
|
=====================
|
|
BPF filesystem kfuncs
|
|
=====================
|
|
|
|
BPF LSM programs need to access filesystem data from LSM hooks. The following
|
|
BPF kfuncs can be used to get these data.
|
|
|
|
* ``bpf_get_file_xattr()``
|
|
|
|
* ``bpf_get_fsverity_digest()``
|
|
|
|
To avoid recursions, these kfuncs follow the following rules:
|
|
|
|
1. These kfuncs are only permitted from BPF LSM function.
|
|
2. These kfuncs should not call into other LSM hooks, i.e. security_*(). For
|
|
example, ``bpf_get_file_xattr()`` does not use ``vfs_getxattr()``, because
|
|
the latter calls LSM hook ``security_inode_getxattr``.
|