• Paul Moore's avatar
    selinux: implement the security_uring_cmd() LSM hook · f4d653dc
    Paul Moore authored
    Add a SELinux access control for the iouring IORING_OP_URING_CMD
    command.  This includes the addition of a new permission in the
    existing "io_uring" object class: "cmd".  The subject of the new
    permission check is the domain of the process requesting access, the
    object is the open file which points to the device/file that is the
    target of the IORING_OP_URING_CMD operation.  A sample policy rule
    is shown below:
    
      allow <domain> <file>:io_uring { cmd };
    
    Cc: stable@vger.kernel.org
    Fixes: ee692a21 ("fs,io_uring: add infrastructure for uring-cmd")
    Signed-off-by: default avatarPaul Moore <paul@paul-moore.com>
    f4d653dc
classmap.h 8.25 KB