Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1234410

[PATCH 5/5] SELinux: Check against union label for file operations

From David Howells <dhowells@redhat.com>
Newsgroups linux.kernel
Subject [PATCH 5/5] SELinux: Check against union label for file operations
Date 2015-09-28 22:10 +0200
Message-ID <qdMUj-1fb-29@gated-at.bofh.it> (permalink)
References <qdMUh-1fb-3@gated-at.bofh.it>
Organization Red Hat UK Ltd. Registered Address: Red Hat UK Ltd, Amberley Place, 107-111 Peascod Street, Windsor, Berkshire, SI4 1TE, United Kingdom. Registered in England and Wales under Company Registration No. 3798903

Show all headers | View raw


File operations (eg. read, write) issued against a file that is attached to
the lower layer of a union file needs to be checked against the union-layer
label not the lower layer label.

The union label is stored in the file_security_struct rather than being
retrieved from one of the inodes.

Signed-off-by: David Howells <dhowells@redhat.com>
---

 security/selinux/hooks.c |   12 ++++++++++--
 1 file changed, 10 insertions(+), 2 deletions(-)

diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
index 522b070d9e2b..ecc883b6d463 100644
--- a/security/selinux/hooks.c
+++ b/security/selinux/hooks.c
@@ -1682,6 +1682,7 @@ static int file_has_perm(const struct cred *cred,
 			 struct file *file,
 			 u32 av)
 {
+	struct inode_security_struct *isec;
 	struct file_security_struct *fsec = file->f_security;
 	struct inode *inode = file_inode(file);
 	struct common_audit_data ad;
@@ -1702,8 +1703,15 @@ static int file_has_perm(const struct cred *cred,
 
 	/* av is zero if only checking access to the descriptor. */
 	rc = 0;
-	if (av)
-		rc = inode_has_perm(cred, inode, av, &ad);
+	if (av && likely(!IS_PRIVATE(inode))) {
+		if (fsec->union_isid) {
+			isec = inode->i_security;
+			rc = avc_has_perm(sid, fsec->union_isid, isec->sclass,
+					  av, &ad);
+		}
+		if (!rc)
+			rc = inode_has_perm(cred, inode, av, &ad);
+	}
 
 out:
 	return rc;

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 0/5] Security: Provide unioned file support David Howells <dhowells@redhat.com> - 2015-09-28 22:10 +0200
  [PATCH 3/5] SELinux: Stub in copy-up handling David Howells <dhowells@redhat.com> - 2015-09-28 22:10 +0200
  [PATCH 5/5] SELinux: Check against union label for file operations David Howells <dhowells@redhat.com> - 2015-09-28 22:10 +0200
  Re: [PATCH 0/5] Security: Provide unioned file support Stephen Smalley <sds@tycho.nsa.gov> - 2015-09-29 23:10 +0200
    Re: [PATCH 0/5] Security: Provide unioned file support Stephen Smalley <sds@tycho.nsa.gov> - 2015-09-30 16:50 +0200
      Re: [PATCH 0/5] Security: Provide unioned file support Daniel J Walsh <dwalsh@redhat.com> - 2015-09-30 17:20 +0200

csiph-web