Thread (19 messages) 19 messages, 3 authors, 2006-08-30

Re: [PATCH 1/6] NetLabel: correctly initialize the NetLabel fields

From: James Morris <jmorris@namei.org>
Date: 2006-08-29 16:51:18
Also in: selinux

On Tue, 29 Aug 2006, paul.moore@hp.com wrote:
+void selinux_netlbl_sk_security_init(struct sk_security_struct *ssec,
+				     int family)
+{
+        if (family == PF_INET)
No tab.
+		ssec->nlbl_state = NLBL_REQUIRE;
+	else
+		ssec->nlbl_state = NLBL_UNSET;
+}
It doesn't look like this code handles ipv4 packets mapped on ipv6 
sockets.  See the test elsewhere in the SELinux code:

	if (family == PF_INET6 && skb->protocol == ntohs(ETH_P_IP))


Also, can you verify that you've tested these fixes and that they resolve 
all issues that you've encountered?



-- 
James Morris
[off-list ref]
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help