selinux: allow FIOCLEX and FIONCLEX with policy capability
These ioctls are equivalent to fcntl(fd, F_SETFD, flags), which SELinux always allows too. Furthermore, a failed FIOCLEX could result in a file descriptor being leaked to a process that should not have access to it. As this patch removes access controls, a policy capability needs to be enabled in policy to always allow these ioctls. Based-on-patch-by:Demi Marie Obenour <demiobenour@gmail.com> Signed-off-by:
Richard Haines <richard_c_haines@btinternet.com> [PM: subject line tweak] Signed-off-by:
Paul Moore <paul@paul-moore.com>
Showing
- security/selinux/hooks.c 6 additions, 0 deletionssecurity/selinux/hooks.c
- security/selinux/include/policycap.h 1 addition, 0 deletionssecurity/selinux/include/policycap.h
- security/selinux/include/policycap_names.h 2 additions, 1 deletionsecurity/selinux/include/policycap_names.h
- security/selinux/include/security.h 7 additions, 0 deletionssecurity/selinux/include/security.h
Please register or sign in to comment