This patch adds a new security attribute to Smack called
SMACK64EXEC. It defines label that is used while task is running. Exception: in smack_task_wait() child task is checked for write access to parent task using label inherited from the task that forked it. Fixed issues from previous submit: - SMACK64EXEC was not read when SMACK64 was not set. - inode security blob was not updated after setting SMACK64EXEC - inode security blob was not updated when removing SMACK64EXEC
Showing
- include/linux/xattr.h 2 additions, 0 deletionsinclude/linux/xattr.h
- security/smack/smack.h 30 additions, 0 deletionssecurity/smack/smack.h
- security/smack/smack_access.c 2 additions, 2 deletionssecurity/smack/smack_access.c
- security/smack/smack_lsm.c 142 additions, 50 deletionssecurity/smack/smack_lsm.c
- security/smack/smackfs.c 2 additions, 2 deletionssecurity/smack/smackfs.c
Loading
Please register or sign in to comment