• Paul Moore's avatar
    lsm: Add hooks to the TUN driver · 2b980dbd
    Paul Moore authored
    The TUN driver lacks any LSM hooks which makes it difficult for LSM modules,
    such as SELinux, to enforce access controls on network traffic generated by
    TUN users; this is particularly problematic for virtualization apps such as
    QEMU and KVM.  This patch adds three new LSM hooks designed to control the
    creation and attachment of TUN devices, the hooks are:
    
     * security_tun_dev_create()
       Provides access control for the creation of new TUN devices
    
     * security_tun_dev_post_create()
       Provides the ability to create the necessary socket LSM state for newly
       created TUN devices
    
     * security_tun_dev_attach()
       Provides access control for attaching to existing, persistent TUN devices
       and the ability to update the TUN device's socket LSM state as necessary
    Signed-off-by: default avatarPaul Moore <paul.moore@hp.com>
    Acked-by: default avatarEric Paris <eparis@parisplace.org>
    Acked-by: default avatarSerge Hallyn <serue@us.ibm.com>
    Acked-by: default avatarDavid S. Miller <davem@davemloft.net>
    Signed-off-by: default avatarJames Morris <jmorris@namei.org>
    2b980dbd
security.c 31.5 KB