summaryrefslogtreecommitdiffstats
path: root/rust/helpers/security.c
diff options
context:
space:
mode:
authorEduard Zingerman <eddyz87@gmail.com>2026-09-04 17:05:56 -0700
committerAlexei Starovoitov <ast@kernel.org>2026-09-04 18:17:30 -0700
commit506ada89629ec7059b96ecfb0dc7d33ece0103ca (patch)
tree0b07297409b68d2333fb4f0eae7f3b072eb68d4c /rust/helpers/security.c
downloadlinux-stable-506ada89629ec7059b96ecfb0dc7d33ece0103ca.tar.gz
linux-stable-506ada89629ec7059b96ecfb0dc7d33ece0103ca.zip
bpf: mark a NULL kfunc argument precisegrafted
check_kfunc_arg() allows bpf_register_is_null() for nullable arguments w/o marking the underlying scalar register precise. Hence a checkpoint created on such a path would prune against arbitrary scalar value. Fixes: 3bda08b63670 ("bpf: Allow NULL buffers in bpf_dynptr_slice(_rw)") Signed-off-by: Eduard Zingerman <eddyz87@gmail.com> Link: https://lore.kernel.org/r/20260904-register-is-null-precise-fixes-v1-5-0f5a360ff15d@gmail.com Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Diffstat (limited to 'rust/helpers/security.c')
-rw-r--r--rust/helpers/security.c48
1 files changed, 48 insertions, 0 deletions
diff --git a/rust/helpers/security.c b/rust/helpers/security.c
new file mode 100644
index 000000000..8d0a25fcf
--- /dev/null
+++ b/rust/helpers/security.c
@@ -0,0 +1,48 @@
+// SPDX-License-Identifier: GPL-2.0
+
+#include <linux/security.h>
+
+#ifndef CONFIG_SECURITY
+__rust_helper void rust_helper_security_cred_getsecid(const struct cred *c,
+ u32 *secid)
+{
+ security_cred_getsecid(c, secid);
+}
+
+__rust_helper int rust_helper_security_secid_to_secctx(u32 secid,
+ struct lsm_context *cp)
+{
+ return security_secid_to_secctx(secid, cp);
+}
+
+__rust_helper void rust_helper_security_release_secctx(struct lsm_context *cp)
+{
+ security_release_secctx(cp);
+}
+
+__rust_helper int
+rust_helper_security_binder_set_context_mgr(const struct cred *mgr)
+{
+ return security_binder_set_context_mgr(mgr);
+}
+
+__rust_helper int
+rust_helper_security_binder_transaction(const struct cred *from,
+ const struct cred *to)
+{
+ return security_binder_transaction(from, to);
+}
+
+__rust_helper int
+rust_helper_security_binder_transfer_binder(const struct cred *from,
+ const struct cred *to)
+{
+ return security_binder_transfer_binder(from, to);
+}
+
+__rust_helper int rust_helper_security_binder_transfer_file(
+ const struct cred *from, const struct cred *to, const struct file *file)
+{
+ return security_binder_transfer_file(from, to, file);
+}
+#endif