selftests/bpf: Add tests verifying bpf lsm userns_create hook
authorFrederick Lawler <fred@cloudflare.com>
Mon, 15 Aug 2022 16:20:27 +0000 (11:20 -0500)
committerPaul Moore <paul@paul-moore.com>
Tue, 16 Aug 2022 21:39:59 +0000 (17:39 -0400)
commitd5810139cca39cf2854728b465f8bada4a445302
tree7a547866afe04a7158f1a5bbc600f928143bfac9
parent401e64b3a4af4c7a2f6a00337232a3cf0bb757ed
selftests/bpf: Add tests verifying bpf lsm userns_create hook

The LSM hook userns_create was introduced to provide LSM's an
opportunity to block or allow unprivileged user namespace creation. This
test serves two purposes: it provides a test eBPF implementation, and
tests the hook successfully blocks or allows user namespace creation.

This tests 3 cases:

        1. Unattached bpf program does not block unpriv user namespace
           creation.
        2. Attached bpf program allows user namespace creation given
           CAP_SYS_ADMIN privileges.
        3. Attached bpf program denies user namespace creation for a
           user without CAP_SYS_ADMIN.

Acked-by: KP Singh <kpsingh@kernel.org>
Signed-off-by: Frederick Lawler <fred@cloudflare.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
tools/testing/selftests/bpf/prog_tests/deny_namespace.c [new file with mode: 0644]
tools/testing/selftests/bpf/progs/test_deny_namespace.c [new file with mode: 0644]