[PATCH] iucv: properly clone LSM attributes to newly created child sockets

Subsystems: networking [general], s390 iucv network layer, the rest

STALE3716d

3 messages, 2 authors, 2016-06-09 · open the first message on its own page

[PATCH] iucv: properly clone LSM attributes to newly created child sockets

From: Paul Moore <hidden>
Date: 2016-06-09 12:59:55

From: Paul Moore <paul@paul-moore.com>

Much like we had to do for AF_BLUETOOTH and AF_ALG, make sure we
properly clone the parent socket's LSM attributes to newly created
child sockets.

Signed-off-by: Paul Moore <paul@paul-moore.com>
---
 net/iucv/af_iucv.c |    5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/net/iucv/af_iucv.c b/net/iucv/af_iucv.c
index fc3598a..a0d1e36 100644
--- a/net/iucv/af_iucv.c
+++ b/net/iucv/af_iucv.c
@@ -22,6 +22,7 @@
 #include <linux/skbuff.h>
 #include <linux/init.h>
 #include <linux/poll.h>
+#include <linux/security.h>
 #include <net/sock.h>
 #include <asm/ebcdic.h>
 #include <asm/cpcmd.h>
@@ -530,8 +531,10 @@ static void iucv_sock_close(struct sock *sk)
 
 static void iucv_sock_init(struct sock *sk, struct sock *parent)
 {
-	if (parent)
+	if (parent) {
 		sk->sk_type = parent->sk_type;
+		security_sk_clone(parent, sk);
+	}
 }
 
 static struct sock *iucv_sock_alloc(struct socket *sock, int proto, gfp_t prio, int kern)

Re: [PATCH] iucv: properly clone LSM attributes to newly created child sockets

From: Paul Moore <hidden>
Date: 2016-06-09 13:01:52

On Thu, Jun 9, 2016 at 8:59 AM, Paul Moore [off-list ref] wrote:
From: Paul Moore <paul@paul-moore.com>

Much like we had to do for AF_BLUETOOTH and AF_ALG, make sure we
properly clone the parent socket's LSM attributes to newly created
child sockets.

Signed-off-by: Paul Moore <paul@paul-moore.com>
---
 net/iucv/af_iucv.c |    5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)
Another small, and obvious, fix so I'm going to merge it into
selinux#next now, but if anyone has an objection please let me know.
quoted hunk
diff --git a/net/iucv/af_iucv.c b/net/iucv/af_iucv.c
index fc3598a..a0d1e36 100644
--- a/net/iucv/af_iucv.c
+++ b/net/iucv/af_iucv.c
@@ -22,6 +22,7 @@
 #include <linux/skbuff.h>
 #include <linux/init.h>
 #include <linux/poll.h>
+#include <linux/security.h>
 #include <net/sock.h>
 #include <asm/ebcdic.h>
 #include <asm/cpcmd.h>
@@ -530,8 +531,10 @@ static void iucv_sock_close(struct sock *sk)

 static void iucv_sock_init(struct sock *sk, struct sock *parent)
 {
-       if (parent)
+       if (parent) {
                sk->sk_type = parent->sk_type;
+               security_sk_clone(parent, sk);
+       }
 }

 static struct sock *iucv_sock_alloc(struct socket *sock, int proto, gfp_t prio, int kern)
-- 
paul moore
security @ redhat

Re: [PATCH] iucv: properly clone LSM attributes to newly created child sockets

From: David Miller <davem@davemloft.net>
Date: 2016-06-09 19:01:09

From: Paul Moore <redacted>
Date: Thu, 9 Jun 2016 09:01:52 -0400
On Thu, Jun 9, 2016 at 8:59 AM, Paul Moore [off-list ref] wrote:
quoted
From: Paul Moore <paul@paul-moore.com>

Much like we had to do for AF_BLUETOOTH and AF_ALG, make sure we
properly clone the parent socket's LSM attributes to newly created
child sockets.

Signed-off-by: Paul Moore <paul@paul-moore.com>
---
 net/iucv/af_iucv.c |    5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)
Another small, and obvious, fix so I'm going to merge it into
selinux#next now, but if anyone has an objection please let me know.
This is fine.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help