diff options
| author | Aaron Tomlin <atomlin@atomlin.com> | 2026-09-08 16:32:29 -0400 |
|---|---|---|
| committer | Andrew Morton <akpm@linux-foundation.org> | 2026-09-13 21:33:40 -0700 |
| commit | b83e83203582477b2ad0631e29e6fd88295cd9b1 (patch) | |
| tree | ec6b4100ca0a82617ab8d2d87bd81355e317df96 /kernel | |
| parent | 3b79943bad105d60c87daf2740f37263cba07211 (diff) | |
| download | linux-next-b83e83203582477b2ad0631e29e6fd88295cd9b1.tar.gz linux-next-b83e83203582477b2ad0631e29e6fd88295cd9b1.zip | |
module: extend module_blacklist parameter to built-in modules
Currently, the "module_blacklist=" command-line parameter only applies to
loadable modules. If a module is built-in, the parameter is silently
ignored. This patch extends the blacklisting functionality to built-in
modules by intercepting their initialisation routines during early boot.
To achieve this, we introduce a new ".initcall.modnames" memory section.
For each built-in module, we use a standard C structure (i.e., struct
initcall_modname) to map its initcall function pointer to its associated
KBUILD_MODNAME string. This mapping is restricted only to files
implementing built-in modules via module_init() to avoid mapping core
kernel subsystems and save memory.
During boot, built-in initcalls are executed sequentially via
do_initcall_level() and do_pre_smp_initcalls(). We introduce a new
wrapper function, do_one_initcall_builtin(), to cross-reference the
initcall function pointer against the ".initcall.modnames" table. If a
match is found and the module is present in the blacklist, the initcall is
skipped.
To make the blacklist functional on monolithic kernels, the command-line
parameter parsing and the module_is_blacklisted() lookup function are
decoupled from the loadable module subsystem and moved to init/main.c.
This enables "module_blacklist=" to intercept built-in modules even on
kernels built with CONFIG_MODULES=n.
Link: https://lore.kernel.org/20260908203230.401020-3-atomlin@atomlin.com
Signed-off-by: Aaron Tomlin <atomlin@atomlin.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Cc: Arnd Bergmann <arnd@arndb.de>
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Cc: Luis Chamberalin <mcgrof@kernel.org>
Cc: "Masami Hiramatsu (Google)" <mhiramat@kernel.org>
Cc: Miguel Ojeda <ojeda@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Petr Pavlu <petr.pavlu@suse.com>
Cc: Sami Tolvanen <samitolvanen@google.com>
Diffstat (limited to 'kernel')
| -rw-r--r-- | kernel/module/main.c | 22 |
1 files changed, 1 insertions, 21 deletions
diff --git a/kernel/module/main.c b/kernel/module/main.c index 9546f9c1c57c..d6749fa38490 100644 --- a/kernel/module/main.c +++ b/kernel/module/main.c @@ -2930,26 +2930,6 @@ int __weak module_frob_arch_sections(Elf_Ehdr *hdr, return 0; } -/* module_blacklist is a comma-separated list of module names */ -static char *module_blacklist; -static bool blacklisted(const char *module_name) -{ - const char *p; - size_t len; - - if (!module_blacklist) - return false; - - for (p = module_blacklist; *p; p += len) { - len = strcspn(p, ","); - if (strlen(module_name) == len && parameqn(module_name, p, len)) - return true; - if (p[len] == ',') - len++; - } - return false; -} -core_param(module_blacklist, module_blacklist, charp, 0400); static struct module *layout_and_allocate(struct load_info *info, int flags) { @@ -3402,7 +3382,7 @@ static int early_mod_check(struct load_info *info, int flags) * Now that we know we have the correct module name, check * if it's blacklisted. */ - if (blacklisted(info->name)) { + if (module_is_blacklisted(info->name)) { pr_err("Module %s is blacklisted\n", info->name); return -EPERM; } |
