Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1671062
| From | Stephen Smalley <sds@tycho.nsa.gov> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH] selinux: Assign proper class to PF_UNIX/SOCK_RAW sockets |
| Date | 2017-06-20 22:10 +0200 |
| Message-ID | <tUxDj-4LL-3@gated-at.bofh.it> (permalink) |
| References | <tUcyS-86s-13@gated-at.bofh.it> <tUxjY-4nI-21@gated-at.bofh.it> |
| Organization | National Security Agency |
On Tue, 2017-06-20 at 15:49 -0400, Paul Moore wrote: > On Mon, Jun 19, 2017 at 5:33 PM, Luis Ressel <aranea@aixah.de> wrote: > > For PF_UNIX, SOCK_RAW is synonymous with SOCK_DGRAM (cf. > > net/unix/af_unix.c). This is a tad obscure, but libpcap uses it. > > > > Signed-off-by: Luis Ressel <aranea@aixah.de> > > Acked-by: Stephen Smalley <sds@tycho.nsa.gov> > > --- > > security/selinux/hooks.c | 1 + > > 1 file changed, 1 insertion(+) > > My only concern is what effect this will have on existing policy. > Prior to this patch PF_UNIX/SOCK_RAW will result in the generic > "socket" class where after this patch it will result in the > "unix_dgram_socket". I believe this is the right change, but it > seems > like this should be wrapped by a policy capability, yes? I doubt it is worth a policy capability. Permission to create/use socket tends to be far rarer than permission to create/use unix_dgram_socket; looks like we never allow the former without the latter in Fedora, for example. > > > diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c > > index 819fd6858b49..1a331fba4a3c 100644 > > --- a/security/selinux/hooks.c > > +++ b/security/selinux/hooks.c > > @@ -1275,6 +1275,7 @@ static inline u16 > > socket_type_to_security_class(int family, int type, int protoc > > case SOCK_SEQPACKET: > > return SECCLASS_UNIX_STREAM_SOCKET; > > case SOCK_DGRAM: > > + case SOCK_RAW: > > return SECCLASS_UNIX_DGRAM_SOCKET; > > } > > break; > > -- > > 2.13.1 > >
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Re: [PATCH] selinux: Assign proper class to PF_UNIX/SOCK_RAW sockets Paul Moore <paul@paul-moore.com> - 2017-06-20 21:50 +0200
Re: [PATCH] selinux: Assign proper class to PF_UNIX/SOCK_RAW sockets Stephen Smalley <sds@tycho.nsa.gov> - 2017-06-20 22:10 +0200
Re: [PATCH] selinux: Assign proper class to PF_UNIX/SOCK_RAW sockets Paul Moore <paul@paul-moore.com> - 2017-06-20 23:50 +0200
Re: [PATCH] selinux: Assign proper class to PF_UNIX/SOCK_RAW sockets Luis Ressel <aranea@aixah.de> - 2017-06-21 11:50 +0200
Re: [PATCH] selinux: Assign proper class to PF_UNIX/SOCK_RAW sockets Paul Moore <paul@paul-moore.com> - 2017-06-21 21:10 +0200
csiph-web