aboutsummaryrefslogtreecommitdiffstats
path: root/Documentation/security
diff options
context:
space:
mode:
authorRichard Haines <richard_c_haines@btinternet.com>2018-03-19 13:33:36 -0400
committerPaul Moore <paul@paul-moore.com>2018-03-20 16:26:15 -0400
commitd3cc2cd7c8d7adfb43075036878e319d5893280d (patch)
treed32051445aa3bb3692760e35a54d8d2e5be7ba74 /Documentation/security
parent68741a8adab900fafb407532e6bae0887f14fbe0 (diff)
selinux: Update SELinux SCTP documentation
Update SELinux-sctp.rst "SCTP Peer Labeling" section to reflect how the association permission is validated. Reported-by: Dominick Grift <dac.override@gmail.com> Signed-off-by: Richard Haines <richard_c_haines@btinternet.com> Signed-off-by: Paul Moore <paul@paul-moore.com>
Diffstat (limited to 'Documentation/security')
-rw-r--r--Documentation/security/SELinux-sctp.rst11
1 files changed, 6 insertions, 5 deletions
diff --git a/Documentation/security/SELinux-sctp.rst b/Documentation/security/SELinux-sctp.rst
index 2f66bf30658a..a332cb1c5334 100644
--- a/Documentation/security/SELinux-sctp.rst
+++ b/Documentation/security/SELinux-sctp.rst
@@ -116,11 +116,12 @@ statement as shown in the following example::
116SCTP Peer Labeling 116SCTP Peer Labeling
117=================== 117===================
118An SCTP socket will only have one peer label assigned to it. This will be 118An SCTP socket will only have one peer label assigned to it. This will be
119assigned during the establishment of the first association. Once the peer 119assigned during the establishment of the first association. Any further
120label has been assigned, any new associations will have the ``association`` 120associations on this socket will have their packet peer label compared to
121permission validated by checking the socket peer sid against the received 121the sockets peer label, and only if they are different will the
122packets peer sid to determine whether the association should be allowed or 122``association`` permission be validated. This is validated by checking the
123denied. 123socket peer sid against the received packets peer sid to determine whether
124the association should be allowed or denied.
124 125
125NOTES: 126NOTES:
126 1) If peer labeling is not enabled, then the peer context will always be 127 1) If peer labeling is not enabled, then the peer context will always be