diff options
Diffstat (limited to 'ipc/msg.c')
| -rw-r--r-- | ipc/msg.c | 11 |
1 files changed, 10 insertions, 1 deletions
| @@ -13,6 +13,9 @@ | |||
| 13 | * mostly rewritten, threaded and wake-one semantics added | 13 | * mostly rewritten, threaded and wake-one semantics added |
| 14 | * MSGMAX limit removed, sysctl's added | 14 | * MSGMAX limit removed, sysctl's added |
| 15 | * (c) 1999 Manfred Spraul <manfred@colorfullife.com> | 15 | * (c) 1999 Manfred Spraul <manfred@colorfullife.com> |
| 16 | * | ||
| 17 | * support for audit of ipc object properties and permission changes | ||
| 18 | * Dustin Kirkland <dustin.kirkland@us.ibm.com> | ||
| 16 | */ | 19 | */ |
| 17 | 20 | ||
| 18 | #include <linux/capability.h> | 21 | #include <linux/capability.h> |
| @@ -447,6 +450,11 @@ asmlinkage long sys_msgctl (int msqid, int cmd, struct msqid_ds __user *buf) | |||
| 447 | if (msg_checkid(msq,msqid)) | 450 | if (msg_checkid(msq,msqid)) |
| 448 | goto out_unlock_up; | 451 | goto out_unlock_up; |
| 449 | ipcp = &msq->q_perm; | 452 | ipcp = &msq->q_perm; |
| 453 | |||
| 454 | err = audit_ipc_obj(ipcp); | ||
| 455 | if (err) | ||
| 456 | goto out_unlock_up; | ||
| 457 | |||
| 450 | err = -EPERM; | 458 | err = -EPERM; |
| 451 | if (current->euid != ipcp->cuid && | 459 | if (current->euid != ipcp->cuid && |
| 452 | current->euid != ipcp->uid && !capable(CAP_SYS_ADMIN)) | 460 | current->euid != ipcp->uid && !capable(CAP_SYS_ADMIN)) |
| @@ -460,7 +468,8 @@ asmlinkage long sys_msgctl (int msqid, int cmd, struct msqid_ds __user *buf) | |||
| 460 | switch (cmd) { | 468 | switch (cmd) { |
| 461 | case IPC_SET: | 469 | case IPC_SET: |
| 462 | { | 470 | { |
| 463 | if ((err = audit_ipc_perms(setbuf.qbytes, setbuf.uid, setbuf.gid, setbuf.mode, ipcp))) | 471 | err = audit_ipc_set_perm(setbuf.qbytes, setbuf.uid, setbuf.gid, setbuf.mode, ipcp); |
| 472 | if (err) | ||
| 464 | goto out_unlock_up; | 473 | goto out_unlock_up; |
| 465 | 474 | ||
| 466 | err = -EPERM; | 475 | err = -EPERM; |
