[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <YGNYWyRFwAt6Woel@sashalap>
Date: Tue, 30 Mar 2021 12:56:59 -0400
From: Sasha Levin <sashal@...nel.org>
To: David Brazdil <dbrazdil@...gle.com>
Cc: stable@...r.kernel.org, "David S . Miller" <davem@...emloft.net>,
Stefano Garzarella <sgarzare@...hat.com>,
Greg Kroah-Hartman <gregkh@...uxfoundation.org>,
James Morris <jamorris@...ux.microsoft.com>,
Jorgen Hansen <jhansen@...are.com>,
Jeff Vander Stoep <jeffv@...gle.com>, netdev@...r.kernel.org,
linux-kernel@...r.kernel.org
Subject: Re: [PATCH pre-5.10] selinux: vsock: Set SID for socket returned by
accept()
On Mon, Mar 29, 2021 at 06:24:43PM +0000, David Brazdil wrote:
>[Backport of commit 1f935e8e72ec28dddb2dc0650b3b6626a293d94b to all
>stable branches from 4.4 to 5.4, inclusive]
>
>For AF_VSOCK, accept() currently returns sockets that are unlabelled.
>Other socket families derive the child's SID from the SID of the parent
>and the SID of the incoming packet. This is typically done as the
>connected socket is placed in the queue that accept() removes from.
>
>Reuse the existing 'security_sk_clone' hook to copy the SID from the
>parent (server) socket to the child. There is no packet SID in this
>case.
Queued up, thanks!
--
Thanks,
Sasha
Powered by blists - more mailing lists