mirror of
https://mirrors.bfsu.edu.cn/git/linux.git
synced 2024-11-11 21:38:32 +08:00
6326948f94
The security_task_getsecid_subj() LSM hook invites misuse by allowing callers to specify a task even though the hook is only safe when the current task is referenced. Fix this by removing the task_struct argument to the hook, requiring LSM implementations to use the current task. While we are changing the hook declaration we also rename the function to security_current_getsecid_subj() in an effort to reinforce that the hook captures the subjective credentials of the current task and not an arbitrary task on the system. Reviewed-by: Serge Hallyn <serge@hallyn.com> Reviewed-by: Casey Schaufler <casey@schaufler-ca.com> Signed-off-by: Paul Moore <paul@paul-moore.com>
50 lines
1.2 KiB
C
50 lines
1.2 KiB
C
/* SPDX-License-Identifier: GPL-2.0-or-later */
|
|
/*
|
|
* NetLabel NETLINK Interface
|
|
*
|
|
* This file defines the NETLINK interface for the NetLabel system. The
|
|
* NetLabel system manages static and dynamic label mappings for network
|
|
* protocols such as CIPSO and RIPSO.
|
|
*
|
|
* Author: Paul Moore <paul@paul-moore.com>
|
|
*/
|
|
|
|
/*
|
|
* (c) Copyright Hewlett-Packard Development Company, L.P., 2006
|
|
*/
|
|
|
|
#ifndef _NETLABEL_USER_H
|
|
#define _NETLABEL_USER_H
|
|
|
|
#include <linux/types.h>
|
|
#include <linux/skbuff.h>
|
|
#include <linux/capability.h>
|
|
#include <linux/audit.h>
|
|
#include <net/netlink.h>
|
|
#include <net/genetlink.h>
|
|
#include <net/netlabel.h>
|
|
|
|
/* NetLabel NETLINK helper functions */
|
|
|
|
/**
|
|
* netlbl_netlink_auditinfo - Fetch the audit information from a NETLINK msg
|
|
* @audit_info: NetLabel audit information
|
|
*/
|
|
static inline void netlbl_netlink_auditinfo(struct netlbl_audit *audit_info)
|
|
{
|
|
security_current_getsecid_subj(&audit_info->secid);
|
|
audit_info->loginuid = audit_get_loginuid(current);
|
|
audit_info->sessionid = audit_get_sessionid(current);
|
|
}
|
|
|
|
/* NetLabel NETLINK I/O functions */
|
|
|
|
int netlbl_netlink_init(void);
|
|
|
|
/* NetLabel Audit Functions */
|
|
|
|
struct audit_buffer *netlbl_audit_start_common(int type,
|
|
struct netlbl_audit *audit_info);
|
|
|
|
#endif
|