aboutsummaryrefslogtreecommitdiffstats
path: root/net
diff options
context:
space:
mode:
authorPaul Moore <paul.moore@hp.com>2007-03-02 16:19:02 -0500
committerDavid S. Miller <davem@sunset.davemloft.net>2007-03-02 23:37:36 -0500
commitc6387a8694506841389a6ac55175a8a984ae34e4 (patch)
treecd1894d17db5424f0d143cbddba1b582f11dcc2d /net
parent90719dbeafdb40a15105ff0c899485b43c2a2a55 (diff)
[NetLabel]: Verify sensitivity level has a valid CIPSO mapping
The current CIPSO engine has a problem where it does not verify that the given sensitivity level has a valid CIPSO mapping when the "std" CIPSO DOI type is used. The end result is that bad packets are sent on the wire which should have never been sent in the first place. This patch corrects this problem by verifying the sensitivity level mapping similar to what is done with the category mapping. This patch also changes the returned error code in this case to -EPERM to better match what the category mapping verification code returns. Signed-off-by: Paul Moore <paul.moore@hp.com> Acked-by: James Morris <jmorris@namei.org> Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net')
-rw-r--r--net/ipv4/cipso_ipv4.c7
1 files changed, 4 insertions, 3 deletions
diff --git a/net/ipv4/cipso_ipv4.c b/net/ipv4/cipso_ipv4.c
index 60aafb4a8adf..c976dd7e9758 100644
--- a/net/ipv4/cipso_ipv4.c
+++ b/net/ipv4/cipso_ipv4.c
@@ -732,11 +732,12 @@ static int cipso_v4_map_lvl_hton(const struct cipso_v4_doi *doi_def,
732 *net_lvl = host_lvl; 732 *net_lvl = host_lvl;
733 return 0; 733 return 0;
734 case CIPSO_V4_MAP_STD: 734 case CIPSO_V4_MAP_STD:
735 if (host_lvl < doi_def->map.std->lvl.local_size) { 735 if (host_lvl < doi_def->map.std->lvl.local_size &&
736 doi_def->map.std->lvl.local[host_lvl] < CIPSO_V4_INV_LVL) {
736 *net_lvl = doi_def->map.std->lvl.local[host_lvl]; 737 *net_lvl = doi_def->map.std->lvl.local[host_lvl];
737 return 0; 738 return 0;
738 } 739 }
739 break; 740 return -EPERM;
740 } 741 }
741 742
742 return -EINVAL; 743 return -EINVAL;
@@ -771,7 +772,7 @@ static int cipso_v4_map_lvl_ntoh(const struct cipso_v4_doi *doi_def,
771 *host_lvl = doi_def->map.std->lvl.cipso[net_lvl]; 772 *host_lvl = doi_def->map.std->lvl.cipso[net_lvl];
772 return 0; 773 return 0;
773 } 774 }
774 break; 775 return -EPERM;
775 } 776 }
776 777
777 return -EINVAL; 778 return -EINVAL;