summaryrefslogtreecommitdiff
path: root/kernel
diff options
context:
space:
mode:
authorAaron Tomlin <atomlin@atomlin.com>2026-09-08 16:32:29 -0400
committerAndrew Morton <akpm@linux-foundation.org>2026-09-13 21:33:40 -0700
commitb83e83203582477b2ad0631e29e6fd88295cd9b1 (patch)
treeec6b4100ca0a82617ab8d2d87bd81355e317df96 /kernel
parent3b79943bad105d60c87daf2740f37263cba07211 (diff)
downloadlinux-next-b83e83203582477b2ad0631e29e6fd88295cd9b1.tar.gz
linux-next-b83e83203582477b2ad0631e29e6fd88295cd9b1.zip
module: extend module_blacklist parameter to built-in modules
Currently, the "module_blacklist=" command-line parameter only applies to loadable modules. If a module is built-in, the parameter is silently ignored. This patch extends the blacklisting functionality to built-in modules by intercepting their initialisation routines during early boot. To achieve this, we introduce a new ".initcall.modnames" memory section. For each built-in module, we use a standard C structure (i.e., struct initcall_modname) to map its initcall function pointer to its associated KBUILD_MODNAME string. This mapping is restricted only to files implementing built-in modules via module_init() to avoid mapping core kernel subsystems and save memory. During boot, built-in initcalls are executed sequentially via do_initcall_level() and do_pre_smp_initcalls(). We introduce a new wrapper function, do_one_initcall_builtin(), to cross-reference the initcall function pointer against the ".initcall.modnames" table. If a match is found and the module is present in the blacklist, the initcall is skipped. To make the blacklist functional on monolithic kernels, the command-line parameter parsing and the module_is_blacklisted() lookup function are decoupled from the loadable module subsystem and moved to init/main.c. This enables "module_blacklist=" to intercept built-in modules even on kernels built with CONFIG_MODULES=n. Link: https://lore.kernel.org/20260908203230.401020-3-atomlin@atomlin.com Signed-off-by: Aaron Tomlin <atomlin@atomlin.com> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Cc: Arnd Bergmann <arnd@arndb.de> Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Cc: Luis Chamberalin <mcgrof@kernel.org> Cc: "Masami Hiramatsu (Google)" <mhiramat@kernel.org> Cc: Miguel Ojeda <ojeda@kernel.org> Cc: Peter Zijlstra <peterz@infradead.org> Cc: Petr Pavlu <petr.pavlu@suse.com> Cc: Sami Tolvanen <samitolvanen@google.com>
Diffstat (limited to 'kernel')
-rw-r--r--kernel/module/main.c22
1 files changed, 1 insertions, 21 deletions
diff --git a/kernel/module/main.c b/kernel/module/main.c
index 9546f9c1c57c..d6749fa38490 100644
--- a/kernel/module/main.c
+++ b/kernel/module/main.c
@@ -2930,26 +2930,6 @@ int __weak module_frob_arch_sections(Elf_Ehdr *hdr,
return 0;
}
-/* module_blacklist is a comma-separated list of module names */
-static char *module_blacklist;
-static bool blacklisted(const char *module_name)
-{
- const char *p;
- size_t len;
-
- if (!module_blacklist)
- return false;
-
- for (p = module_blacklist; *p; p += len) {
- len = strcspn(p, ",");
- if (strlen(module_name) == len && parameqn(module_name, p, len))
- return true;
- if (p[len] == ',')
- len++;
- }
- return false;
-}
-core_param(module_blacklist, module_blacklist, charp, 0400);
static struct module *layout_and_allocate(struct load_info *info, int flags)
{
@@ -3402,7 +3382,7 @@ static int early_mod_check(struct load_info *info, int flags)
* Now that we know we have the correct module name, check
* if it's blacklisted.
*/
- if (blacklisted(info->name)) {
+ if (module_is_blacklisted(info->name)) {
pr_err("Module %s is blacklisted\n", info->name);
return -EPERM;
}