selinux: allow FIOCLEX and FIONCLEX with policy capability
stable inclusion from stable-v5.10.110 commit 448857f58009fd950f4d732e8f1e4fcf859cb4b1 bugzilla: https://gitee.com/openeuler/kernel/issues/I574AL Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=448857f58009fd950f4d732e8f1e4fcf859cb4b1 -------------------------------- [ Upstream commit 65881e1d ] These ioctls are equivalent to fcntl(fd, F_SETFD, flags), which SELinux always allows too. Furthermore, a failed FIOCLEX could result in a file descriptor being leaked to a process that should not have access to it. As this patch removes access controls, a policy capability needs to be enabled in policy to always allow these ioctls. Based-on-patch-by: NDemi Marie Obenour <demiobenour@gmail.com> Signed-off-by: NRichard Haines <richard_c_haines@btinternet.com> [PM: subject line tweak] Signed-off-by: NPaul Moore <paul@paul-moore.com> Signed-off-by: NSasha Levin <sashal@kernel.org> Signed-off-by: NYu Liao <liaoyu15@huawei.com> Reviewed-by: NWei Li <liwei391@huawei.com> Signed-off-by: NZheng Zengkai <zhengzengkai@huawei.com>
Showing
想要评论请 注册 或 登录