On Thu, 21 Sep 2006, paul.moore@hp.com wrote:
Fix a problem where NetLabel would always set the value of
sk_security_struct->peer_sid in selinux_netlbl_sock_graft() to the context of
the socket, causing problems when users would query the context of the
connection. This patch fixes this so that the value in
sk_security_struct->peer_sid is only set when the connection is NetLabel based,
otherwise the value is untouched.
I'll let Thomas comment on the Netlink changes, as he's been working with
you on them.
These changes otherwise seem ok. How much testing has this had with and
without Netlabel enabled?
- James
--
James Morris
[off-list ref]