fs_kfuncs.rst 651 B

123456789101112131415161718192021
  1. .. SPDX-License-Identifier: GPL-2.0
  2. .. _fs_kfuncs-header-label:
  3. =====================
  4. BPF filesystem kfuncs
  5. =====================
  6. BPF LSM programs need to access filesystem data from LSM hooks. The following
  7. BPF kfuncs can be used to get these data.
  8. * ``bpf_get_file_xattr()``
  9. * ``bpf_get_fsverity_digest()``
  10. To avoid recursions, these kfuncs follow the following rules:
  11. 1. These kfuncs are only permitted from BPF LSM function.
  12. 2. These kfuncs should not call into other LSM hooks, i.e. security_*(). For
  13. example, ``bpf_get_file_xattr()`` does not use ``vfs_getxattr()``, because
  14. the latter calls LSM hook ``security_inode_getxattr``.