Smack: Fix the bug smackcipso can't set CIPSO correctly
Bug report: https://tizendev.org/bugs/browse/TDIS-3891 The reason is userspace libsmack only use "smackfs/cipso2" long-label interface, but the code's logical is still for orginal fixed length label. Now update smack_cipso_apply() to support flexible label (<=256 including tailing '\0') There is also a bug in kernel/security/smack/smackfs.c: When smk_set_cipso() parsing the CIPSO setting from userspace, the offset of CIPSO level should be "strlen(label)+1" instead of "strlen(label)" Signed-off-by: Passion,Zhao <passion.zhao@intel.com>
This commit is contained in:
parent
8cd77a0bd4
commit
0fcfee61d6
|
@ -881,7 +881,7 @@ static ssize_t smk_set_cipso(struct file *file, const char __user *buf,
|
||||||
if (format == SMK_FIXED24_FMT)
|
if (format == SMK_FIXED24_FMT)
|
||||||
rule += SMK_LABELLEN;
|
rule += SMK_LABELLEN;
|
||||||
else
|
else
|
||||||
rule += strlen(skp->smk_known);
|
rule += strlen(skp->smk_known) + 1;
|
||||||
|
|
||||||
ret = sscanf(rule, "%d", &maplevel);
|
ret = sscanf(rule, "%d", &maplevel);
|
||||||
if (ret != 1 || maplevel > SMACK_CIPSO_MAXLEVEL)
|
if (ret != 1 || maplevel > SMACK_CIPSO_MAXLEVEL)
|
||||||
|
|
Loading…
Reference in New Issue