Re: [PATCH] iucv: properly clone LSM attributes to newly created child sockets

3 messages, 2 authors, 2016-06-13 · open the first message on its own page

Re: [PATCH] iucv: properly clone LSM attributes to newly created child sockets

From: Ursula Braun <hidden>
Date: 2016-06-13 10:08:54

quoted hunk
From: Paul Moore <paul@paul-moore.com>

Much like we had to do for AF_BLUETOOTH and AF_ALG, make sure we
properly clone the parent socket's LSM attributes to newly created
child sockets.

Signed-off-by: Paul Moore <paul@paul-moore.com>
---
net/iucv/af_iucv.c |    5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/net/iucv/af_iucv.c b/net/iucv/af_iucv.c
index fc3598a..a0d1e36 100644
--- a/net/iucv/af_iucv.c
+++ b/net/iucv/af_iucv.c
@@ -22,6 +22,7 @@
#include <linux/skbuff.h>
#include <linux/init.h>
#include <linux/poll.h>
+#include <linux/security.h>
#include <net/sock.h>
#include <asm/ebcdic.h>
#include <asm/cpcmd.h>
@@ -530,8 +531,10 @@ static void iucv_sock_close(struct sock *sk)
static void iucv_sock_init(struct sock *sk, struct sock *parent)
{
-                 if (parent)
+                 if (parent) {
                                  sk->sk_type = parent->sk_type;
+                                  security_sk_clone(parent, sk);
+                 }
}

static struct sock *iucv_sock_alloc(struct socket *sock, int proto,
gfp_t prio, int kern)
applied locally - thx. Your patch will now be submitted for inclusion
into net-next.

Regards, Ursula Braun
--
To unsubscribe from this list: send the line "unsubscribe linux-s390"
in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Re: [PATCH] iucv: properly clone LSM attributes to newly created child sockets

From: Paul Moore <paul@paul-moore.com>
Date: 2016-06-13 12:38:07

On Mon, Jun 13, 2016 at 6:08 AM, Ursula Braun [off-list ref] wrote:
quoted
From: Paul Moore <paul@paul-moore.com>

Much like we had to do for AF_BLUETOOTH and AF_ALG, make sure we
properly clone the parent socket's LSM attributes to newly created
child sockets.

Signed-off-by: Paul Moore <paul@paul-moore.com>
---
net/iucv/af_iucv.c |    5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/net/iucv/af_iucv.c b/net/iucv/af_iucv.c
index fc3598a..a0d1e36 100644
--- a/net/iucv/af_iucv.c
+++ b/net/iucv/af_iucv.c
@@ -22,6 +22,7 @@
#include <linux/skbuff.h>
#include <linux/init.h>
#include <linux/poll.h>
+#include <linux/security.h>
#include <net/sock.h>
#include <asm/ebcdic.h>
#include <asm/cpcmd.h>
@@ -530,8 +531,10 @@ static void iucv_sock_close(struct sock *sk)
static void iucv_sock_init(struct sock *sk, struct sock *parent)
{
-                 if (parent)
+                 if (parent) {
                                  sk->sk_type = parent->sk_type;
+                                  security_sk_clone(parent, sk);
+                 }
}

static struct sock *iucv_sock_alloc(struct socket *sock, int proto,
gfp_t prio, int kern)
applied locally - thx. Your patch will now be submitted for inclusion
into net-next.
Hi Ursula,

For what it's worth, I applied to the selinux#next branch last week,
it should be in the linux-next builds.

* git://git.infradead.org/users/pcmoore/selinux
* http://git.infradead.org/users/pcmoore/selinux

-- 
paul moore
www.paul-moore.com

Re: [PATCH] iucv: properly clone LSM attributes to newly created child sockets

From: Ursula Braun <hidden>
Date: 2016-06-13 14:38:08

On Mon, 2016-06-13 at 08:38 -0400, Paul Moore wrote:
On Mon, Jun 13, 2016 at 6:08 AM, Ursula Braun [off-list ref] wrote:
quoted
quoted
From: Paul Moore <paul@paul-moore.com>

Much like we had to do for AF_BLUETOOTH and AF_ALG, make sure we
properly clone the parent socket's LSM attributes to newly created
child sockets.

Signed-off-by: Paul Moore <paul@paul-moore.com>
---
net/iucv/af_iucv.c |    5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/net/iucv/af_iucv.c b/net/iucv/af_iucv.c
index fc3598a..a0d1e36 100644
--- a/net/iucv/af_iucv.c
+++ b/net/iucv/af_iucv.c
@@ -22,6 +22,7 @@
#include <linux/skbuff.h>
#include <linux/init.h>
#include <linux/poll.h>
+#include <linux/security.h>
#include <net/sock.h>
#include <asm/ebcdic.h>
#include <asm/cpcmd.h>
@@ -530,8 +531,10 @@ static void iucv_sock_close(struct sock *sk)
static void iucv_sock_init(struct sock *sk, struct sock *parent)
{
-                 if (parent)
+                 if (parent) {
                                  sk->sk_type = parent->sk_type;
+                                  security_sk_clone(parent, sk);
+                 }
}

static struct sock *iucv_sock_alloc(struct socket *sock, int proto,
gfp_t prio, int kern)
applied locally - thx. Your patch will now be submitted for inclusion
into net-next.
Hi Ursula,

For what it's worth, I applied to the selinux#next branch last week,
it should be in the linux-next builds.

* git://git.infradead.org/users/pcmoore/selinux
* http://git.infradead.org/users/pcmoore/selinux
ok, in this case I will not submit your patch myself.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help