Files
kernel/include/linux
Venkat Yekkirala 67f83cbf08 SELinux: Fix SA selection semantics
Fix the selection of an SA for an outgoing packet to be at the same
context as the originating socket/flow. This eliminates the SELinux
policy's ability to use/sendto SAs with contexts other than the socket's.

With this patch applied, the SELinux policy will require one or more of the
following for a socket to be able to communicate with/without SAs:

1. To enable a socket to communicate without using labeled-IPSec SAs:

allow socket_t unlabeled_t:association { sendto recvfrom }

2. To enable a socket to communicate with labeled-IPSec SAs:

allow socket_t self:association { sendto };
allow socket_t peer_sa_t:association { recvfrom };

Signed-off-by: Venkat Yekkirala <vyekkirala@TrustedCS.com>
Signed-off-by: James Morris <jmorris@namei.org>
2006-12-02 21:21:34 -08:00
..
2006-10-03 23:01:26 +02:00
2006-10-01 00:39:29 -07:00
2006-09-28 17:53:58 -07:00
2006-10-04 08:31:24 -04:00
2006-10-03 23:01:26 +02:00
2006-10-04 19:32:09 +02:00
2006-10-10 15:37:20 -07:00
2006-10-03 08:04:16 -07:00
2006-10-11 11:14:17 -07:00
2006-10-02 07:57:12 -07:00
2006-09-28 18:02:18 -07:00
2006-12-02 21:21:13 -08:00
2006-09-28 18:02:13 -07:00
2006-12-02 21:21:24 -08:00
2006-12-02 21:21:17 -08:00
2006-12-02 21:21:21 -08:00
2006-10-04 00:31:09 -07:00
2006-09-28 18:02:29 -07:00
2006-10-02 07:57:22 -07:00
2006-10-11 11:14:23 -07:00
2006-10-10 15:37:22 -07:00
2006-12-02 21:21:21 -08:00
2006-10-04 00:31:09 -07:00
2006-10-04 07:55:12 -07:00
2006-10-04 00:31:09 -07:00
2006-12-02 21:21:21 -08:00
2006-11-30 05:24:39 +01:00
2006-11-30 04:53:49 +01:00
2006-11-30 01:14:44 +00:00
2006-10-11 11:14:15 -07:00
2006-11-30 04:40:22 +01:00
2006-09-28 18:02:22 -07:00
2006-11-16 11:43:38 -08:00
2006-10-01 00:39:19 -07:00
2006-10-17 08:18:43 -07:00
2006-11-28 20:59:39 -08:00
2006-12-02 21:21:18 -08:00
2006-10-03 08:03:40 -07:00
2006-11-03 12:27:58 -08:00
2006-10-03 23:01:26 +02:00
2006-10-02 07:57:15 -07:00
2006-10-17 08:18:43 -07:00
2006-11-30 05:24:39 +01:00
2006-12-02 21:21:34 -08:00
2006-10-11 01:45:31 -04:00
2006-12-02 21:21:26 -08:00
2006-10-10 16:15:34 -07:00
2006-10-01 00:39:18 -07:00
2006-10-01 00:39:19 -07:00
2006-10-11 11:14:21 -07:00
2006-10-18 20:36:48 -07:00
2006-11-30 05:32:19 +01:00
2006-10-06 08:53:40 -07:00
2006-12-02 21:21:08 -08:00
2006-09-28 17:53:59 -07:00
2006-12-02 21:21:25 -08:00
2006-09-28 18:02:16 -07:00
2006-12-01 14:25:52 -08:00
2006-10-01 00:39:19 -07:00
2006-10-04 07:55:12 -07:00
2006-09-29 09:18:13 -07:00
2006-12-02 00:11:58 -05:00
2006-10-09 14:20:38 -07:00
2006-12-02 21:21:17 -08:00