Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1234410
| From | David Howells <dhowells@redhat.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH 5/5] SELinux: Check against union label for file operations |
| Date | 2015-09-28 22:10 +0200 |
| Message-ID | <qdMUj-1fb-29@gated-at.bofh.it> (permalink) |
| References | <qdMUh-1fb-3@gated-at.bofh.it> |
| Organization | Red Hat UK Ltd. Registered Address: Red Hat UK Ltd, Amberley Place, 107-111 Peascod Street, Windsor, Berkshire, SI4 1TE, United Kingdom. Registered in England and Wales under Company Registration No. 3798903 |
File operations (eg. read, write) issued against a file that is attached to
the lower layer of a union file needs to be checked against the union-layer
label not the lower layer label.
The union label is stored in the file_security_struct rather than being
retrieved from one of the inodes.
Signed-off-by: David Howells <dhowells@redhat.com>
---
security/selinux/hooks.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
index 522b070d9e2b..ecc883b6d463 100644
--- a/security/selinux/hooks.c
+++ b/security/selinux/hooks.c
@@ -1682,6 +1682,7 @@ static int file_has_perm(const struct cred *cred,
struct file *file,
u32 av)
{
+ struct inode_security_struct *isec;
struct file_security_struct *fsec = file->f_security;
struct inode *inode = file_inode(file);
struct common_audit_data ad;
@@ -1702,8 +1703,15 @@ static int file_has_perm(const struct cred *cred,
/* av is zero if only checking access to the descriptor. */
rc = 0;
- if (av)
- rc = inode_has_perm(cred, inode, av, &ad);
+ if (av && likely(!IS_PRIVATE(inode))) {
+ if (fsec->union_isid) {
+ isec = inode->i_security;
+ rc = avc_has_perm(sid, fsec->union_isid, isec->sclass,
+ av, &ad);
+ }
+ if (!rc)
+ rc = inode_has_perm(cred, inode, av, &ad);
+ }
out:
return rc;
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 0/5] Security: Provide unioned file support David Howells <dhowells@redhat.com> - 2015-09-28 22:10 +0200
[PATCH 3/5] SELinux: Stub in copy-up handling David Howells <dhowells@redhat.com> - 2015-09-28 22:10 +0200
[PATCH 5/5] SELinux: Check against union label for file operations David Howells <dhowells@redhat.com> - 2015-09-28 22:10 +0200
Re: [PATCH 0/5] Security: Provide unioned file support Stephen Smalley <sds@tycho.nsa.gov> - 2015-09-29 23:10 +0200
Re: [PATCH 0/5] Security: Provide unioned file support Stephen Smalley <sds@tycho.nsa.gov> - 2015-09-30 16:50 +0200
Re: [PATCH 0/5] Security: Provide unioned file support Daniel J Walsh <dwalsh@redhat.com> - 2015-09-30 17:20 +0200
csiph-web