diff options
author | Richard Haines <richard_c_haines@btinternet.com> | 2022-02-25 17:54:38 +0000 |
---|---|---|
committer | Paul Moore <paul@paul-moore.com> | 2022-02-25 15:35:19 -0500 |
commit | 65881e1db4e948614d9eb195b8e1197339822949 (patch) | |
tree | 5412d30772bda69f399724371c13d53cfa4c1d96 /security/selinux/include/policycap_names.h | |
parent | b97df7c098c531010e445da88d02b7bf7bf59ef6 (diff) | |
download | linux-65881e1db4e948614d9eb195b8e1197339822949.tar.bz2 |
selinux: allow FIOCLEX and FIONCLEX with policy capability
These ioctls are equivalent to fcntl(fd, F_SETFD, flags), which SELinux
always allows too. Furthermore, a failed FIOCLEX could result in a file
descriptor being leaked to a process that should not have access to it.
As this patch removes access controls, a policy capability needs to be
enabled in policy to always allow these ioctls.
Based-on-patch-by: Demi Marie Obenour <demiobenour@gmail.com>
Signed-off-by: Richard Haines <richard_c_haines@btinternet.com>
[PM: subject line tweak]
Signed-off-by: Paul Moore <paul@paul-moore.com>
Diffstat (limited to 'security/selinux/include/policycap_names.h')
-rw-r--r-- | security/selinux/include/policycap_names.h | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/security/selinux/include/policycap_names.h b/security/selinux/include/policycap_names.h index b89289f092c9..ebd64afe1def 100644 --- a/security/selinux/include/policycap_names.h +++ b/security/selinux/include/policycap_names.h @@ -12,7 +12,8 @@ const char *selinux_policycap_names[__POLICYDB_CAPABILITY_MAX] = { "always_check_network", "cgroup_seclabel", "nnp_nosuid_transition", - "genfs_seclabel_symlinks" + "genfs_seclabel_symlinks", + "ioctl_skip_cloexec" }; #endif /* _SELINUX_POLICYCAP_NAMES_H_ */ |