From 506ada89629ec7059b96ecfb0dc7d33ece0103ca Mon Sep 17 00:00:00 2001 From: Eduard Zingerman Date: Fri, 4 Sep 2026 17:05:56 -0700 Subject: bpf: mark a NULL kfunc argument precise check_kfunc_arg() allows bpf_register_is_null() for nullable arguments w/o marking the underlying scalar register precise. Hence a checkpoint created on such a path would prune against arbitrary scalar value. Fixes: 3bda08b63670 ("bpf: Allow NULL buffers in bpf_dynptr_slice(_rw)") Signed-off-by: Eduard Zingerman Link: https://lore.kernel.org/r/20260904-register-is-null-precise-fixes-v1-5-0f5a360ff15d@gmail.com Signed-off-by: Alexei Starovoitov --- rust/helpers/security.c | 48 ++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 48 insertions(+) create mode 100644 rust/helpers/security.c (limited to 'rust/helpers/security.c') diff --git a/rust/helpers/security.c b/rust/helpers/security.c new file mode 100644 index 000000000..8d0a25fcf --- /dev/null +++ b/rust/helpers/security.c @@ -0,0 +1,48 @@ +// SPDX-License-Identifier: GPL-2.0 + +#include + +#ifndef CONFIG_SECURITY +__rust_helper void rust_helper_security_cred_getsecid(const struct cred *c, + u32 *secid) +{ + security_cred_getsecid(c, secid); +} + +__rust_helper int rust_helper_security_secid_to_secctx(u32 secid, + struct lsm_context *cp) +{ + return security_secid_to_secctx(secid, cp); +} + +__rust_helper void rust_helper_security_release_secctx(struct lsm_context *cp) +{ + security_release_secctx(cp); +} + +__rust_helper int +rust_helper_security_binder_set_context_mgr(const struct cred *mgr) +{ + return security_binder_set_context_mgr(mgr); +} + +__rust_helper int +rust_helper_security_binder_transaction(const struct cred *from, + const struct cred *to) +{ + return security_binder_transaction(from, to); +} + +__rust_helper int +rust_helper_security_binder_transfer_binder(const struct cred *from, + const struct cred *to) +{ + return security_binder_transfer_binder(from, to); +} + +__rust_helper int rust_helper_security_binder_transfer_file( + const struct cred *from, const struct cred *to, const struct file *file) +{ + return security_binder_transfer_file(from, to, file); +} +#endif -- cgit v1.3.1