On Thu, Feb 1, 2018 at 11:20 AM, Mark Salyzyn salyzyn@android.com wrote:
On 02/01/2018 08:00 AM, Paul Moore wrote:
On Thu, Feb 1, 2018 at 10:37 AM, Mark Salyzyn salyzyn@android.com wrote:
In the absence of commit a4298e4522d6 ("net: add SOCK_RCU_FREE socket flag") and all the associated infrastructure changes to take advantage of a RCU grace period before freeing, there is a heightened possibility that a security check is performed while an ill-timed setsockopt call races in from user space. It then is prudent to null check sk_security, and if the case, reject the permissions.
. . . ---[ end trace 7b5aaf788fef6174 ]---
Signed-off-by: Mark Salyzyn salyzyn@android.com Signed-off-by: Paul Moore paul@linuxfoundation.org
No, in the previous thread I gave my ack, not my sign-off; please be more careful in the future. It may seem silly, especially in this particular case, but it is an important distinction when things like the DCO are concerned.
Anyway, here is my ack again.
Acked-by: Paul Moore paul@paul-moore.com
Ok, both Greg KH and yours should be considered Acked-By. Been overstepping this boundary for _years_.
One more note, which I didn't realize until I hit reply and the email bounced: you used a @linuxfoundation.org email address for me which is clearly not right. I'm sure it's just a typo, but it's another thing that needs to be corrected.
AFAIK Signed-off-by is still pending from Stephen Smalley sds@tycho.nsa.gov before this can roll in.
Obviously the more acks the better, but you've got mine which should be sufficient in this case. The MAINTAINER file currently lists three people for SELinux: Stephen, Eric, and myself. I'm responsible for the traditional maintainer tasks: tree management, PRs to Linus, patch review, emptying the waste bin at the end of the week, etc. Stephen maintains the deep historical knowledge and understanding that comes with developing the technology/project from it's inception many, many years ago; no matter how well I may understand SELinux, Stephen will always have me beat. Eric is basically my predecessor, having ventured off to the brave new world of containers and Kubernetes; he is listed out of respect for his contributions and also to safeguard us against the all important "bus factor", while he is not as active as he once was, he still holds a wealth of SELinux knowledge.