summaryrefslogtreecommitdiffstats
path: root/sys/security/mac_biba
diff options
context:
space:
mode:
authorrwatson <rwatson@FreeBSD.org>2002-11-08 18:04:36 +0000
committerrwatson <rwatson@FreeBSD.org>2002-11-08 18:04:36 +0000
commitf3748b0c0b9b7ae4a57068095ab2eb98aaea333d (patch)
tree229b6b138af158da4b65f931e1632502f1dde91f /sys/security/mac_biba
parent95c4afbed0766fa2e0e178afbc7d5beb07b7d2da (diff)
downloadFreeBSD-src-f3748b0c0b9b7ae4a57068095ab2eb98aaea333d.zip
FreeBSD-src-f3748b0c0b9b7ae4a57068095ab2eb98aaea333d.tar.gz
Update MAC modules for changes in arguments for exec MAC policy
entry points to include an explicit execlabel. Approved by: re Obtained from: TrustedBSD Project Sponsored by: DARPA, Network Associates Laboratories
Diffstat (limited to 'sys/security/mac_biba')
-rw-r--r--sys/security/mac_biba/mac_biba.c18
1 files changed, 16 insertions, 2 deletions
diff --git a/sys/security/mac_biba/mac_biba.c b/sys/security/mac_biba/mac_biba.c
index 2770941..3268dd7 100644
--- a/sys/security/mac_biba/mac_biba.c
+++ b/sys/security/mac_biba/mac_biba.c
@@ -2044,9 +2044,23 @@ mac_biba_check_vnode_deleteacl(struct ucred *cred, struct vnode *vp,
static int
mac_biba_check_vnode_exec(struct ucred *cred, struct vnode *vp,
- struct label *label, struct image_params *imgp)
+ struct label *label, struct image_params *imgp,
+ struct label *execlabel)
{
- struct mac_biba *subj, *obj;
+ struct mac_biba *subj, *obj, *exec;
+ int error;
+
+ if (execlabel != NULL) {
+ /*
+ * We currently don't permit labels to be changed at
+ * exec-time as part of Biba, so disallow non-NULL
+ * Biba label elements in the execlabel.
+ */
+ exec = SLOT(execlabel);
+ error = biba_atmostflags(exec, 0);
+ if (error)
+ return (error);
+ }
if (!mac_biba_enabled)
return (0);
OpenPOWER on IntegriCloud