1
linux/security/selinux/include
Venkat Yekkirala 67f83cbf08 SELinux: Fix SA selection semantics
Fix the selection of an SA for an outgoing packet to be at the same
context as the originating socket/flow. This eliminates the SELinux
policy's ability to use/sendto SAs with contexts other than the socket's.

With this patch applied, the SELinux policy will require one or more of the
following for a socket to be able to communicate with/without SAs:

1. To enable a socket to communicate without using labeled-IPSec SAs:

allow socket_t unlabeled_t:association { sendto recvfrom }

2. To enable a socket to communicate with labeled-IPSec SAs:

allow socket_t self:association { sendto };
allow socket_t peer_sa_t:association { recvfrom };

Signed-off-by: Venkat Yekkirala <vyekkirala@TrustedCS.com>
Signed-off-by: James Morris <jmorris@namei.org>
2006-12-02 21:21:34 -08:00
..
av_inherit.h [SELINUX]: add security class for appletalk sockets 2006-06-17 21:29:51 -07:00
av_perm_to_string.h [MLSXFRM]: Granular IPSec associations for use in MLS environments 2006-09-22 14:53:20 -07:00
av_permissions.h [MLSXFRM]: Granular IPSec associations for use in MLS environments 2006-09-22 14:53:20 -07:00
avc_ss.h SELinux: export object class and permission definitions 2006-11-28 12:04:36 -05:00
avc.h Linux-2.6.12-rc2 2005-04-16 15:20:36 -07:00
class_to_string.h [PATCH] selinux: add hooks for key subsystem 2006-06-22 15:05:55 -07:00
common_perm_to_string.h Linux-2.6.12-rc2 2005-04-16 15:20:36 -07:00
conditional.h Linux-2.6.12-rc2 2005-04-16 15:20:36 -07:00
flask.h [PATCH] selinux: add hooks for key subsystem 2006-06-22 15:05:55 -07:00
initial_sid_to_string.h Linux-2.6.12-rc2 2005-04-16 15:20:36 -07:00
netif.h Linux-2.6.12-rc2 2005-04-16 15:20:36 -07:00
objsec.h [PATCH] SELinux: convert sbsec semaphore to a mutex 2006-09-26 08:48:53 -07:00
security.h [PATCH] selinux: add support for range transitions on object classes 2006-09-26 08:48:52 -07:00
selinux_netlabel.h [NetLabel]: protect the CIPSOv4 socket option from setsockopt() 2006-10-30 15:24:49 -08:00
xfrm.h SELinux: Fix SA selection semantics 2006-12-02 21:21:34 -08:00