• E
    SELinux: call cap_file_mmap in selinux_file_mmap · 8cf948e7
    Eric Paris 提交于
    Currently SELinux does not check CAP_SYS_RAWIO in the file_mmap hook.  This
    means there is no DAC check on the ability to mmap low addresses in the
    memory space.  This function adds the DAC check for CAP_SYS_RAWIO while
    maintaining the selinux check on mmap_zero.  This means that processes
    which need to mmap low memory will need CAP_SYS_RAWIO and mmap_zero but will
    NOT need the SELinux sys_rawio capability.
    Signed-off-by: NEric Paris <eparis@redhat.com>
    Signed-off-by: NJames Morris <jmorris@namei.org>
    8cf948e7
hooks.c 136.5 KB