aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorDavid Herrmann <dh.herrmann@gmail.com>2018-05-04 10:28:21 -0400
committerJames Morris <james.morris@microsoft.com>2018-05-04 15:48:54 -0400
commit0b811db2cb2aabc910e53d34ebb95a15997c33e7 (patch)
tree4f4d96751c0c98a8f81a79526585c73cf4df51e8
parentd47cd9450d3b1fcf6ce7c7022f442a69a7b7322e (diff)
selinux: provide socketpair callback
Make sure to implement the new socketpair callback so the SO_PEERSEC call on socketpair(2)s will return correct information. Acked-by: Serge Hallyn <serge@hallyn.com> Acked-by: Stephen Smalley <sds@tycho.nsa.gov> Signed-off-by: Tom Gundersen <teg@jklm.no> Signed-off-by: David Herrmann <dh.herrmann@gmail.com> Signed-off-by: James Morris <james.morris@microsoft.com>
-rw-r--r--security/selinux/hooks.c13
1 files changed, 13 insertions, 0 deletions
diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
index 4cafe6a19167..02ebd1585eaf 100644
--- a/security/selinux/hooks.c
+++ b/security/selinux/hooks.c
@@ -4569,6 +4569,18 @@ static int selinux_socket_post_create(struct socket *sock, int family,
4569 return err; 4569 return err;
4570} 4570}
4571 4571
4572static int selinux_socket_socketpair(struct socket *socka,
4573 struct socket *sockb)
4574{
4575 struct sk_security_struct *sksec_a = socka->sk->sk_security;
4576 struct sk_security_struct *sksec_b = sockb->sk->sk_security;
4577
4578 sksec_a->peer_sid = sksec_b->sid;
4579 sksec_b->peer_sid = sksec_a->sid;
4580
4581 return 0;
4582}
4583
4572/* Range of port numbers used to automatically bind. 4584/* Range of port numbers used to automatically bind.
4573 Need to determine whether we should perform a name_bind 4585 Need to determine whether we should perform a name_bind
4574 permission check between the socket and the port number. */ 4586 permission check between the socket and the port number. */
@@ -6999,6 +7011,7 @@ static struct security_hook_list selinux_hooks[] __lsm_ro_after_init = {
6999 7011
7000 LSM_HOOK_INIT(socket_create, selinux_socket_create), 7012 LSM_HOOK_INIT(socket_create, selinux_socket_create),
7001 LSM_HOOK_INIT(socket_post_create, selinux_socket_post_create), 7013 LSM_HOOK_INIT(socket_post_create, selinux_socket_post_create),
7014 LSM_HOOK_INIT(socket_socketpair, selinux_socket_socketpair),
7002 LSM_HOOK_INIT(socket_bind, selinux_socket_bind), 7015 LSM_HOOK_INIT(socket_bind, selinux_socket_bind),
7003 LSM_HOOK_INIT(socket_connect, selinux_socket_connect), 7016 LSM_HOOK_INIT(socket_connect, selinux_socket_connect),
7004 LSM_HOOK_INIT(socket_listen, selinux_socket_listen), 7017 LSM_HOOK_INIT(socket_listen, selinux_socket_listen),