From 5334d6a190f651ce4992ed2923305e15e6345eb4 Mon Sep 17 00:00:00 2001 From: "Stephen D. Smalley" Date: Wed, 13 Oct 2004 07:27:58 -0700 Subject: [PATCH] [PATCH] SELinux: retain ptracer SID across fork This fixes a bug in SELinux to retain the ptracer SID (if any) across fork. Otherwise, SELinux will always deny attempts by traced children to exec domain-changing programs even if the policy would have allowed the tracer to trace the new domains as well. Signed-off-by: Stephen Smalley Signed-off-by: James Morris Signed-off-by: Andrew Morton Signed-off-by: Linus Torvalds --- security/selinux/hooks.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c index d25ed880944ad..231d3f4863b3b 100644 --- a/security/selinux/hooks.c +++ b/security/selinux/hooks.c @@ -2625,6 +2625,11 @@ static int selinux_task_alloc_security(struct task_struct *tsk) tsec2->exec_sid = tsec1->exec_sid; tsec2->create_sid = tsec1->create_sid; + /* Retain ptracer SID across fork, if any. + This will be reset by the ptrace hook upon any + subsequent ptrace_attach operations. */ + tsec2->ptrace_sid = tsec1->ptrace_sid; + return 0; } -- 2.53.0