blob: 2ee41a3a1dfdee623261c86e89116a968d548825 [file] [log] [blame]
Jeff Xu105ff532022-12-15 00:12:03 +00001/* SPDX-License-Identifier: GPL-2.0 */
2#ifndef LINUX_PID_SYSCTL_H
3#define LINUX_PID_SYSCTL_H
4
5#include <linux/pid_namespace.h>
6
7#if defined(CONFIG_SYSCTL) && defined(CONFIG_MEMFD_CREATE)
Jeff Xu105ff532022-12-15 00:12:03 +00008static int pid_mfd_noexec_dointvec_minmax(struct ctl_table *table,
9 int write, void *buf, size_t *lenp, loff_t *ppos)
10{
11 struct pid_namespace *ns = task_active_pid_ns(current);
12 struct ctl_table table_copy;
Aleksa Sarai9876cfe2023-08-14 18:41:00 +100013 int err, scope, parent_scope;
Jeff Xu105ff532022-12-15 00:12:03 +000014
15 if (write && !ns_capable(ns->user_ns, CAP_SYS_ADMIN))
16 return -EPERM;
17
18 table_copy = *table;
Jeff Xu105ff532022-12-15 00:12:03 +000019
Aleksa Sarai9876cfe2023-08-14 18:41:00 +100020 /* You cannot set a lower enforcement value than your parent. */
21 parent_scope = pidns_memfd_noexec_scope(ns->parent);
22 /* Equivalent to pidns_memfd_noexec_scope(ns). */
23 scope = max(READ_ONCE(ns->memfd_noexec_scope), parent_scope);
Jeff Xu105ff532022-12-15 00:12:03 +000024
Aleksa Sarai9876cfe2023-08-14 18:41:00 +100025 table_copy.data = &scope;
26 table_copy.extra1 = &parent_scope;
27
28 err = proc_dointvec_minmax(&table_copy, write, buf, lenp, ppos);
29 if (!err && write)
30 WRITE_ONCE(ns->memfd_noexec_scope, scope);
31 return err;
Jeff Xu105ff532022-12-15 00:12:03 +000032}
33
34static struct ctl_table pid_ns_ctl_table_vm[] = {
35 {
36 .procname = "memfd_noexec",
37 .data = &init_pid_ns.memfd_noexec_scope,
38 .maxlen = sizeof(init_pid_ns.memfd_noexec_scope),
39 .mode = 0644,
40 .proc_handler = pid_mfd_noexec_dointvec_minmax,
41 .extra1 = SYSCTL_ZERO,
42 .extra2 = SYSCTL_TWO,
43 },
44 { }
45};
Jeff Xu105ff532022-12-15 00:12:03 +000046static inline void register_pid_ns_sysctl_table_vm(void)
47{
Luis Chamberlain9e7c73c2023-03-02 12:28:23 -080048 register_sysctl("vm", pid_ns_ctl_table_vm);
Jeff Xu105ff532022-12-15 00:12:03 +000049}
50#else
Jeff Xu105ff532022-12-15 00:12:03 +000051static inline void register_pid_ns_sysctl_table_vm(void) {}
52#endif
53
54#endif /* LINUX_PID_SYSCTL_H */