SELinux/LSM/Smack Controls + Auditing For IO_uring Comes With Linux 5.16

Written by Michael Larabel in Linux Security on 3 November 2021 at 12:00 PM EDT. Add A Comment
LINUX SECURITY
In addition to IO_uring improvements in Linux 5.16 itself, the Security Enhanced Linux "SELinux" patches for this new kernel cycle bring controls and auditing around IO_uring.

With the SELinux patches sent out on Monday, there is now Linux Security Modules (LSM), SELinux, and Smack controls and auditing support for IO_uring.

The SELinux PR explains, "we were basically missing two things which we're adding here: establishment of a proper audit context so that auditing of io-uring ops works similarly to how it does for syscalls (with some io-uring additions because io-uring ops are *not* syscalls), additional LSM hooks to enable access control points for some of the more unusual io-uring features, e.g. credential overrides. The additional audit callouts and LSM hooks were done in conjunction with the io-uring folks, based on conversations and RFC patches earlier in the year."

See the SELinux pull request for more details on the IO_uring controls/auditing support and other security improvements to be found in this new kernel.
Related News
About The Author
Michael Larabel

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.

Popular News This Week