Skip to content

Commit 9f74411

Browse files
committed
landlock: Log TCP bind and connect denials
Add audit support to socket_bind and socket_connect hooks. The related blockers are: - net.bind_tcp - net.connect_tcp Audit event sample: type=LANDLOCK_DENY msg=audit(1729738800.349:44): domain=195ba459b blockers=net.connect_tcp daddr=127.0.0.1 dest=80 Cc: Günther Noack <gnoack@google.com> Cc: Konstantin Meskhidze <konstantin.meskhidze@huawei.com> Cc: Mikhail Ivanov <ivanov.mikhail1@huawei-partners.com> Link: https://lore.kernel.org/r/20250320190717.2287696-16-mic@digikod.net Signed-off-by: Mickaël Salaün <mic@digikod.net>
1 parent 20fd295 commit 9f74411

3 files changed

Lines changed: 60 additions & 4 deletions

File tree

security/landlock/audit.c

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -41,6 +41,13 @@ static const char *const fs_access_strings[] = {
4141

4242
static_assert(ARRAY_SIZE(fs_access_strings) == LANDLOCK_NUM_ACCESS_FS);
4343

44+
static const char *const net_access_strings[] = {
45+
[BIT_INDEX(LANDLOCK_ACCESS_NET_BIND_TCP)] = "net.bind_tcp",
46+
[BIT_INDEX(LANDLOCK_ACCESS_NET_CONNECT_TCP)] = "net.connect_tcp",
47+
};
48+
49+
static_assert(ARRAY_SIZE(net_access_strings) == LANDLOCK_NUM_ACCESS_NET);
50+
4451
static __attribute_const__ const char *
4552
get_blocker(const enum landlock_request_type type,
4653
const unsigned long access_bit)
@@ -58,6 +65,11 @@ get_blocker(const enum landlock_request_type type,
5865
if (WARN_ON_ONCE(access_bit >= ARRAY_SIZE(fs_access_strings)))
5966
return "unknown";
6067
return fs_access_strings[access_bit];
68+
69+
case LANDLOCK_REQUEST_NET_ACCESS:
70+
if (WARN_ON_ONCE(access_bit >= ARRAY_SIZE(net_access_strings)))
71+
return "unknown";
72+
return net_access_strings[access_bit];
6173
}
6274

6375
WARN_ON_ONCE(1);

security/landlock/audit.h

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,7 @@ enum landlock_request_type {
1818
LANDLOCK_REQUEST_PTRACE = 1,
1919
LANDLOCK_REQUEST_FS_CHANGE_TOPOLOGY,
2020
LANDLOCK_REQUEST_FS_ACCESS,
21+
LANDLOCK_REQUEST_NET_ACCESS,
2122
};
2223

2324
/*

security/landlock/net.c

Lines changed: 47 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -7,10 +7,12 @@
77
*/
88

99
#include <linux/in.h>
10+
#include <linux/lsm_audit.h>
1011
#include <linux/net.h>
1112
#include <linux/socket.h>
1213
#include <net/ipv6.h>
1314

15+
#include "audit.h"
1416
#include "common.h"
1517
#include "cred.h"
1618
#include "limits.h"
@@ -55,6 +57,7 @@ static int current_check_access_socket(struct socket *const sock,
5557
};
5658
const struct landlock_cred_security *const subject =
5759
landlock_get_applicable_subject(current_cred(), masks, NULL);
60+
struct lsm_network_audit audit_net = {};
5861

5962
if (!subject)
6063
return 0;
@@ -68,18 +71,48 @@ static int current_check_access_socket(struct socket *const sock,
6871

6972
switch (address->sa_family) {
7073
case AF_UNSPEC:
71-
case AF_INET:
74+
case AF_INET: {
75+
const struct sockaddr_in *addr4;
76+
7277
if (addrlen < sizeof(struct sockaddr_in))
7378
return -EINVAL;
74-
port = ((struct sockaddr_in *)address)->sin_port;
79+
80+
addr4 = (struct sockaddr_in *)address;
81+
port = addr4->sin_port;
82+
83+
if (access_request == LANDLOCK_ACCESS_NET_CONNECT_TCP) {
84+
audit_net.dport = port;
85+
audit_net.v4info.daddr = addr4->sin_addr.s_addr;
86+
} else if (access_request == LANDLOCK_ACCESS_NET_BIND_TCP) {
87+
audit_net.sport = port;
88+
audit_net.v4info.saddr = addr4->sin_addr.s_addr;
89+
} else {
90+
WARN_ON_ONCE(1);
91+
}
7592
break;
93+
}
7694

7795
#if IS_ENABLED(CONFIG_IPV6)
78-
case AF_INET6:
96+
case AF_INET6: {
97+
const struct sockaddr_in6 *addr6;
98+
7999
if (addrlen < SIN6_LEN_RFC2133)
80100
return -EINVAL;
81-
port = ((struct sockaddr_in6 *)address)->sin6_port;
101+
102+
addr6 = (struct sockaddr_in6 *)address;
103+
port = addr6->sin6_port;
104+
105+
if (access_request == LANDLOCK_ACCESS_NET_CONNECT_TCP) {
106+
audit_net.dport = port;
107+
audit_net.v6info.daddr = addr6->sin6_addr;
108+
} else if (access_request == LANDLOCK_ACCESS_NET_BIND_TCP) {
109+
audit_net.sport = port;
110+
audit_net.v6info.saddr = addr6->sin6_addr;
111+
} else {
112+
WARN_ON_ONCE(1);
113+
}
82114
break;
115+
}
83116
#endif /* IS_ENABLED(CONFIG_IPV6) */
84117

85118
default:
@@ -149,6 +182,16 @@ static int current_check_access_socket(struct socket *const sock,
149182
ARRAY_SIZE(layer_masks)))
150183
return 0;
151184

185+
audit_net.family = address->sa_family;
186+
landlock_log_denial(subject,
187+
&(struct landlock_request){
188+
.type = LANDLOCK_REQUEST_NET_ACCESS,
189+
.audit.type = LSM_AUDIT_DATA_NET,
190+
.audit.u.net = &audit_net,
191+
.access = access_request,
192+
.layer_masks = &layer_masks,
193+
.layer_masks_size = ARRAY_SIZE(layer_masks),
194+
});
152195
return -EACCES;
153196
}
154197

0 commit comments

Comments
 (0)