Skip to content
体验新版
项目
组织
正在加载...
登录
切换导航
打开侧边栏
openeuler
raspberrypi-kernel
提交
cdac74dd
R
raspberrypi-kernel
项目概览
openeuler
/
raspberrypi-kernel
通知
13
Star
1
Fork
0
代码
文件
提交
分支
Tags
贡献者
分支图
Diff
Issue
0
列表
看板
标记
里程碑
合并请求
0
Wiki
0
Wiki
分析
仓库
DevOps
项目成员
Pages
R
raspberrypi-kernel
项目概览
项目概览
详情
发布
仓库
仓库
文件
提交
分支
标签
贡献者
分支图
比较
Issue
0
Issue
0
列表
看板
标记
里程碑
合并请求
0
合并请求
0
Pages
分析
分析
仓库分析
DevOps
Wiki
0
Wiki
成员
成员
收起侧边栏
关闭侧边栏
动态
分支图
创建新Issue
提交
Issue看板
提交
cdac74dd
编写于
6月 21, 2017
作者:
J
James Morris
浏览文件
操作
浏览文件
下载
差异文件
Merge branch 'smack-for-4.13' of
git://github.com/cschaufler/smack-next
into next
上级
e4b08527
f28e783f
变更
4
隐藏空白更改
内联
并排
Showing
4 changed file
with
31 addition
and
18 deletion
+31
-18
security/smack/smack.h
security/smack/smack.h
+1
-1
security/smack/smack_access.c
security/smack/smack_access.c
+11
-8
security/smack/smack_lsm.c
security/smack/smack_lsm.c
+1
-1
security/smack/smack_netfilter.c
security/smack/smack_netfilter.c
+18
-8
未找到文件。
security/smack/smack.h
浏览文件 @
cdac74dd
...
...
@@ -320,7 +320,7 @@ int smk_netlbl_mls(int, char *, struct netlbl_lsm_secattr *, int);
struct
smack_known
*
smk_import_entry
(
const
char
*
,
int
);
void
smk_insert_entry
(
struct
smack_known
*
skp
);
struct
smack_known
*
smk_find_entry
(
const
char
*
);
int
smack_privileged
(
int
cap
);
bool
smack_privileged
(
int
cap
);
void
smk_destroy_label_list
(
struct
list_head
*
list
);
/*
...
...
security/smack/smack_access.c
浏览文件 @
cdac74dd
...
...
@@ -627,35 +627,38 @@ DEFINE_MUTEX(smack_onlycap_lock);
* Is the task privileged and allowed to be privileged
* by the onlycap rule.
*
* Returns
1 if the task is allowed to be privileged, 0
if it's not.
* Returns
true if the task is allowed to be privileged, false
if it's not.
*/
int
smack_privileged
(
int
cap
)
bool
smack_privileged
(
int
cap
)
{
struct
smack_known
*
skp
=
smk_of_current
();
struct
smack_known_list_elem
*
sklep
;
int
rc
;
/*
* All kernel tasks are privileged
*/
if
(
unlikely
(
current
->
flags
&
PF_KTHREAD
))
return
1
;
return
true
;
if
(
!
capable
(
cap
))
return
0
;
rc
=
cap_capable
(
current_cred
(),
&
init_user_ns
,
cap
,
SECURITY_CAP_AUDIT
);
if
(
rc
)
return
false
;
rcu_read_lock
();
if
(
list_empty
(
&
smack_onlycap_list
))
{
rcu_read_unlock
();
return
1
;
return
true
;
}
list_for_each_entry_rcu
(
sklep
,
&
smack_onlycap_list
,
list
)
{
if
(
sklep
->
smk_label
==
skp
)
{
rcu_read_unlock
();
return
1
;
return
true
;
}
}
rcu_read_unlock
();
return
0
;
return
false
;
}
security/smack/smack_lsm.c
浏览文件 @
cdac74dd
...
...
@@ -1915,7 +1915,7 @@ static int smack_file_receive(struct file *file)
smk_ad_init
(
&
ad
,
__func__
,
LSM_AUDIT_DATA_PATH
);
smk_ad_setfield_u_fs_path
(
&
ad
,
file
->
f_path
);
if
(
S_ISSOCK
(
inode
->
i_mode
)
)
{
if
(
inode
->
i_sb
->
s_magic
==
SOCKFS_MAGIC
)
{
sock
=
SOCKET_I
(
inode
);
ssp
=
sock
->
sk
->
sk_security
;
tsp
=
current_security
();
...
...
security/smack/smack_netfilter.c
浏览文件 @
cdac74dd
...
...
@@ -18,6 +18,7 @@
#include <linux/netfilter_ipv6.h>
#include <linux/netdevice.h>
#include <net/inet_sock.h>
#include <net/net_namespace.h>
#include "smack.h"
#if IS_ENABLED(CONFIG_IPV6)
...
...
@@ -74,20 +75,29 @@ static struct nf_hook_ops smack_nf_ops[] = {
#endif
/* IPV6 */
};
static
int
__init
smack_nf_ip_init
(
void
)
static
int
__net_init
smack_nf_register
(
struct
net
*
net
)
{
return
nf_register_net_hooks
(
net
,
smack_nf_ops
,
ARRAY_SIZE
(
smack_nf_ops
));
}
static
void
__net_exit
smack_nf_unregister
(
struct
net
*
net
)
{
int
err
;
nf_unregister_net_hooks
(
net
,
smack_nf_ops
,
ARRAY_SIZE
(
smack_nf_ops
));
}
static
struct
pernet_operations
smack_net_ops
=
{
.
init
=
smack_nf_register
,
.
exit
=
smack_nf_unregister
,
};
static
int
__init
smack_nf_ip_init
(
void
)
{
if
(
smack_enabled
==
0
)
return
0
;
printk
(
KERN_DEBUG
"Smack: Registering netfilter hooks
\n
"
);
err
=
nf_register_hooks
(
smack_nf_ops
,
ARRAY_SIZE
(
smack_nf_ops
));
if
(
err
)
pr_info
(
"Smack: nf_register_hooks: error %d
\n
"
,
err
);
return
0
;
return
register_pernet_subsys
(
&
smack_net_ops
);
}
__initcall
(
smack_nf_ip_init
);
编辑
预览
Markdown
is supported
0%
请重试
或
添加新附件
.
添加附件
取消
You are about to add
0
people
to the discussion. Proceed with caution.
先完成此消息的编辑!
取消
想要评论请
注册
或
登录