lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <YGNYWyRFwAt6Woel@sashalap>
Date:   Tue, 30 Mar 2021 12:56:59 -0400
From:   Sasha Levin <sashal@...nel.org>
To:     David Brazdil <dbrazdil@...gle.com>
Cc:     stable@...r.kernel.org, "David S . Miller" <davem@...emloft.net>,
        Stefano Garzarella <sgarzare@...hat.com>,
        Greg Kroah-Hartman <gregkh@...uxfoundation.org>,
        James Morris <jamorris@...ux.microsoft.com>,
        Jorgen Hansen <jhansen@...are.com>,
        Jeff Vander Stoep <jeffv@...gle.com>, netdev@...r.kernel.org,
        linux-kernel@...r.kernel.org
Subject: Re: [PATCH pre-5.10] selinux: vsock: Set SID for socket returned by
 accept()

On Mon, Mar 29, 2021 at 06:24:43PM +0000, David Brazdil wrote:
>[Backport of commit 1f935e8e72ec28dddb2dc0650b3b6626a293d94b to all
>stable branches from 4.4 to 5.4, inclusive]
>
>For AF_VSOCK, accept() currently returns sockets that are unlabelled.
>Other socket families derive the child's SID from the SID of the parent
>and the SID of the incoming packet. This is typically done as the
>connected socket is placed in the queue that accept() removes from.
>
>Reuse the existing 'security_sk_clone' hook to copy the SID from the
>parent (server) socket to the child. There is no packet SID in this
>case.

Queued up, thanks!

-- 
Thanks,
Sasha

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ