]> git.hungrycats.org Git - linux/commitdiff
[PATCH] SELinux: retain ptracer SID across fork
authorStephen D. Smalley <sds@epoch.ncsc.mil>
Wed, 13 Oct 2004 14:27:58 +0000 (07:27 -0700)
committerLinus Torvalds <torvalds@ppc970.osdl.org>
Wed, 13 Oct 2004 14:27:58 +0000 (07:27 -0700)
This fixes a bug in SELinux to retain the ptracer SID (if any) across fork.
Otherwise, SELinux will always deny attempts by traced children to exec
domain-changing programs even if the policy would have allowed the tracer
to trace the new domains as well.

Signed-off-by: Stephen Smalley <sds@epoch.ncsc.mil>
Signed-off-by: James Morris <jmorris@redhat.com>
Signed-off-by: Andrew Morton <akpm@osdl.org>
Signed-off-by: Linus Torvalds <torvalds@osdl.org>
security/selinux/hooks.c

index d25ed880944ad4301b5f99d6cb6640170a5b1bfd..231d3f4863b3b4a848f24960ee52e0a7ee27a43f 100644 (file)
@@ -2625,6 +2625,11 @@ static int selinux_task_alloc_security(struct task_struct *tsk)
        tsec2->exec_sid = tsec1->exec_sid;
        tsec2->create_sid = tsec1->create_sid;
 
+       /* Retain ptracer SID across fork, if any.
+          This will be reset by the ptrace hook upon any
+          subsequent ptrace_attach operations. */
+       tsec2->ptrace_sid = tsec1->ptrace_sid;
+
        return 0;
 }