mirror of
				git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
				synced 2025-09-18 22:14:16 +00:00 
			
		
		
		
	 6326948f94
			
		
	
	
		6326948f94
		
	
	
	
	
		
			
			The security_task_getsecid_subj() LSM hook invites misuse by allowing callers to specify a task even though the hook is only safe when the current task is referenced. Fix this by removing the task_struct argument to the hook, requiring LSM implementations to use the current task. While we are changing the hook declaration we also rename the function to security_current_getsecid_subj() in an effort to reinforce that the hook captures the subjective credentials of the current task and not an arbitrary task on the system. Reviewed-by: Serge Hallyn <serge@hallyn.com> Reviewed-by: Casey Schaufler <casey@schaufler-ca.com> Signed-off-by: Paul Moore <paul@paul-moore.com>
		
			
				
	
	
		
			49 lines
		
	
	
	
		
			1.2 KiB
		
	
	
	
		
			C
		
	
	
	
	
	
			
		
		
	
	
			49 lines
		
	
	
	
		
			1.2 KiB
		
	
	
	
		
			C
		
	
	
	
	
	
| /* SPDX-License-Identifier: GPL-2.0-or-later */
 | |
| /*
 | |
|  * NetLabel NETLINK Interface
 | |
|  *
 | |
|  * This file defines the NETLINK interface for the NetLabel system.  The
 | |
|  * NetLabel system manages static and dynamic label mappings for network
 | |
|  * protocols such as CIPSO and RIPSO.
 | |
|  *
 | |
|  * Author: Paul Moore <paul@paul-moore.com>
 | |
|  */
 | |
| 
 | |
| /*
 | |
|  * (c) Copyright Hewlett-Packard Development Company, L.P., 2006
 | |
|  */
 | |
| 
 | |
| #ifndef _NETLABEL_USER_H
 | |
| #define _NETLABEL_USER_H
 | |
| 
 | |
| #include <linux/types.h>
 | |
| #include <linux/skbuff.h>
 | |
| #include <linux/capability.h>
 | |
| #include <linux/audit.h>
 | |
| #include <net/netlink.h>
 | |
| #include <net/genetlink.h>
 | |
| #include <net/netlabel.h>
 | |
| 
 | |
| /* NetLabel NETLINK helper functions */
 | |
| 
 | |
| /**
 | |
|  * netlbl_netlink_auditinfo - Fetch the audit information from a NETLINK msg
 | |
|  * @audit_info: NetLabel audit information
 | |
|  */
 | |
| static inline void netlbl_netlink_auditinfo(struct netlbl_audit *audit_info)
 | |
| {
 | |
| 	security_current_getsecid_subj(&audit_info->secid);
 | |
| 	audit_info->loginuid = audit_get_loginuid(current);
 | |
| 	audit_info->sessionid = audit_get_sessionid(current);
 | |
| }
 | |
| 
 | |
| /* NetLabel NETLINK I/O functions */
 | |
| 
 | |
| int netlbl_netlink_init(void);
 | |
| 
 | |
| /* NetLabel Audit Functions */
 | |
| 
 | |
| struct audit_buffer *netlbl_audit_start_common(int type,
 | |
| 					      struct netlbl_audit *audit_info);
 | |
| 
 | |
| #endif
 |