summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLuis Ressel <aranea@aixah.de>2017-07-25 15:13:41 -0400
committerPaul Moore <paul@paul-moore.com>2017-07-25 15:13:41 -0400
commit2a764b529ae57bed61da2c90ff132b9fec97f80b (patch)
tree7b9b406884054bee958a81addab19bccc6d4fe03
parent31368ce83c59a5422ee621a38aeea98142d0ecf7 (diff)
downloadop-kernel-dev-2a764b529ae57bed61da2c90ff132b9fec97f80b.zip
op-kernel-dev-2a764b529ae57bed61da2c90ff132b9fec97f80b.tar.gz
selinux: Assign proper class to PF_UNIX/SOCK_RAW sockets
For PF_UNIX, SOCK_RAW is synonymous with SOCK_DGRAM (cf. net/unix/af_unix.c). This is a tad obscure, but libpcap uses it. Signed-off-by: Luis Ressel <aranea@aixah.de> Acked-by: Stephen Smalley <sds@tycho.nsa.gov> Signed-off-by: Paul Moore <paul@paul-moore.com>
-rw-r--r--security/selinux/hooks.c1
1 files changed, 1 insertions, 0 deletions
diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
index 33fd061..00ad46e 100644
--- a/security/selinux/hooks.c
+++ b/security/selinux/hooks.c
@@ -1303,6 +1303,7 @@ static inline u16 socket_type_to_security_class(int family, int type, int protoc
case SOCK_SEQPACKET:
return SECCLASS_UNIX_STREAM_SOCKET;
case SOCK_DGRAM:
+ case SOCK_RAW:
return SECCLASS_UNIX_DGRAM_SOCKET;
}
break;
OpenPOWER on IntegriCloud