mirror of
				https://github.com/torvalds/linux.git
				synced 2025-11-04 10:40:15 +02:00 
			
		
		
		
	The security_task_getsecid_subj() LSM hook invites misuse by allowing callers to specify a task even though the hook is only safe when the current task is referenced. Fix this by removing the task_struct argument to the hook, requiring LSM implementations to use the current task. While we are changing the hook declaration we also rename the function to security_current_getsecid_subj() in an effort to reinforce that the hook captures the subjective credentials of the current task and not an arbitrary task on the system. Reviewed-by: Serge Hallyn <serge@hallyn.com> Reviewed-by: Casey Schaufler <casey@schaufler-ca.com> Signed-off-by: Paul Moore <paul@paul-moore.com>
		
			
				
	
	
		
			49 lines
		
	
	
	
		
			1.2 KiB
		
	
	
	
		
			C
		
	
	
	
	
	
			
		
		
	
	
			49 lines
		
	
	
	
		
			1.2 KiB
		
	
	
	
		
			C
		
	
	
	
	
	
/* SPDX-License-Identifier: GPL-2.0-or-later */
 | 
						|
/*
 | 
						|
 * NetLabel NETLINK Interface
 | 
						|
 *
 | 
						|
 * This file defines the NETLINK interface for the NetLabel system.  The
 | 
						|
 * NetLabel system manages static and dynamic label mappings for network
 | 
						|
 * protocols such as CIPSO and RIPSO.
 | 
						|
 *
 | 
						|
 * Author: Paul Moore <paul@paul-moore.com>
 | 
						|
 */
 | 
						|
 | 
						|
/*
 | 
						|
 * (c) Copyright Hewlett-Packard Development Company, L.P., 2006
 | 
						|
 */
 | 
						|
 | 
						|
#ifndef _NETLABEL_USER_H
 | 
						|
#define _NETLABEL_USER_H
 | 
						|
 | 
						|
#include <linux/types.h>
 | 
						|
#include <linux/skbuff.h>
 | 
						|
#include <linux/capability.h>
 | 
						|
#include <linux/audit.h>
 | 
						|
#include <net/netlink.h>
 | 
						|
#include <net/genetlink.h>
 | 
						|
#include <net/netlabel.h>
 | 
						|
 | 
						|
/* NetLabel NETLINK helper functions */
 | 
						|
 | 
						|
/**
 | 
						|
 * netlbl_netlink_auditinfo - Fetch the audit information from a NETLINK msg
 | 
						|
 * @audit_info: NetLabel audit information
 | 
						|
 */
 | 
						|
static inline void netlbl_netlink_auditinfo(struct netlbl_audit *audit_info)
 | 
						|
{
 | 
						|
	security_current_getsecid_subj(&audit_info->secid);
 | 
						|
	audit_info->loginuid = audit_get_loginuid(current);
 | 
						|
	audit_info->sessionid = audit_get_sessionid(current);
 | 
						|
}
 | 
						|
 | 
						|
/* NetLabel NETLINK I/O functions */
 | 
						|
 | 
						|
int netlbl_netlink_init(void);
 | 
						|
 | 
						|
/* NetLabel Audit Functions */
 | 
						|
 | 
						|
struct audit_buffer *netlbl_audit_start_common(int type,
 | 
						|
					      struct netlbl_audit *audit_info);
 | 
						|
 | 
						|
#endif
 |