security: pass asoc to sctp_assoc_request and sctp_sk_clone
This patch is to move secid and peer_secid from endpoint to association, and pass asoc to sctp_assoc_request and sctp_sk_clone instead of ep. As ep is the local endpoint and asoc represents a connection, and in SCTP one sk/ep could have multiple asoc/connection, saving secid/peer_secid for new asoc will overwrite the old asoc's. Note that since asoc can be passed as NULL, security_sctp_assoc_request() is moved to the place right after the new_asoc is created in sctp_sf_do_5_1B_init() and sctp_sf_do_unexpected_init(). v1->v2: - fix the description of selinux_netlbl_skbuff_setsid(), as Jakub noticed. - fix the annotation in selinux_sctp_assoc_request(), as Richard Noticed. Fixes: 72e89f50 ("security: Add support for SCTP security hooks") Reported-by:Prashanth Prahlad <pprahlad@redhat.com> Reviewed-by:
Richard Haines <richard_c_haines@btinternet.com> Tested-by:
Richard Haines <richard_c_haines@btinternet.com> Signed-off-by:
Xin Long <lucien.xin@gmail.com> Signed-off-by:
David S. Miller <davem@davemloft.net>
Showing
- Documentation/security/SCTP.rst 14 additions, 14 deletionsDocumentation/security/SCTP.rst
- include/linux/lsm_hook_defs.h 2 additions, 2 deletionsinclude/linux/lsm_hook_defs.h
- include/linux/lsm_hooks.h 4 additions, 4 deletionsinclude/linux/lsm_hooks.h
- include/linux/security.h 5 additions, 5 deletionsinclude/linux/security.h
- include/net/sctp/structs.h 10 additions, 10 deletionsinclude/net/sctp/structs.h
- net/sctp/sm_statefuns.c 13 additions, 13 deletionsnet/sctp/sm_statefuns.c
- net/sctp/socket.c 2 additions, 3 deletionsnet/sctp/socket.c
- security/security.c 4 additions, 4 deletionssecurity/security.c
- security/selinux/hooks.c 11 additions, 11 deletionssecurity/selinux/hooks.c
- security/selinux/include/netlabel.h 2 additions, 2 deletionssecurity/selinux/include/netlabel.h
- security/selinux/netlabel.c 9 additions, 9 deletionssecurity/selinux/netlabel.c
Loading
Please register or sign in to comment