Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1572429

[PATCH] security: selinux: allow changing labels for cgroupfs

From Antonio Murdaca <amurdaca@redhat.com>
Newsgroups linux.kernel
Subject [PATCH] security: selinux: allow changing labels for cgroupfs
Date 2017-02-02 15:50 +0100
Message-ID <t6qRX-5if-21@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Show all headers | View raw


This patch allows changing labels for cgroup mounts. Previously, running
chcon on cgroupfs would throw an "Operation not supported". This patch
specifically whitelist cgroupfs.

The patch could also allow containers to write only to the systemd cgroup
for instance, while the other cgroups are kept with cgroup_t label.

Signed-off-by: Antonio Murdaca <runcom@redhat.com>
---
 security/selinux/hooks.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
index 3b955c6..4e84211 100644
--- a/security/selinux/hooks.c
+++ b/security/selinux/hooks.c
@@ -480,6 +480,7 @@ static int selinux_is_sblabel_mnt(struct super_block *sb)
 		sbsec->behavior == SECURITY_FS_USE_NATIVE ||
 		/* Special handling. Genfs but also in-core setxattr handler */
 		!strcmp(sb->s_type->name, "sysfs") ||
+		!strcmp(sb->s_type->name, "cgroup") ||
 		!strcmp(sb->s_type->name, "pstore") ||
 		!strcmp(sb->s_type->name, "debugfs") ||
 		!strcmp(sb->s_type->name, "tracefs") ||
-- 
2.9.3

Back to linux.kernel | Previous | NextNext in thread | Find similar | Unroll thread


Thread

[PATCH] security: selinux: allow changing labels for cgroupfs Antonio Murdaca <amurdaca@redhat.com> - 2017-02-02 15:50 +0100
  Re: [PATCH] security: selinux: allow changing labels for cgroupfs Gary Tierney <gary.tierney@gmx.com> - 2017-02-02 16:10 +0100
    Re: [PATCH] security: selinux: allow changing labels for cgroupfs Antonio Murdaca <amurdaca@redhat.com> - 2017-02-02 16:40 +0100

csiph-web