-
- Downloads
security: allow finer granularity in permitting copy-up of security xattrs
Copying up xattrs is solely based on the security xattr name. For finer granularity add a dentry parameter to the security_inode_copy_up_xattr hook definition, allowing decisions to be based on the xattr content as well. Co-developed-by:Mimi Zohar <zohar@linux.ibm.com> Signed-off-by:
Stefan Berger <stefanb@linux.ibm.com> Acked-by:
Amir Goldstein <amir73il@gmail.com> Acked-by: Paul Moore <paul@paul-moore.com> (LSM,SELinux) Signed-off-by:
Mimi Zohar <zohar@linux.ibm.com>
Showing
- fs/overlayfs/copy_up.c 1 addition, 1 deletionfs/overlayfs/copy_up.c
- include/linux/lsm_hook_defs.h 2 additions, 1 deletioninclude/linux/lsm_hook_defs.h
- include/linux/security.h 2 additions, 2 deletionsinclude/linux/security.h
- security/integrity/evm/evm_main.c 1 addition, 1 deletionsecurity/integrity/evm/evm_main.c
- security/security.c 3 additions, 2 deletionssecurity/security.c
- security/selinux/hooks.c 1 addition, 1 deletionsecurity/selinux/hooks.c
- security/smack/smack_lsm.c 1 addition, 1 deletionsecurity/smack/smack_lsm.c
Loading
Please register or sign in to comment