From patchwork Tue Aug 29 21:03:57 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Casey Schaufler X-Patchwork-Id: 9928323 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id 92970602B9 for ; Tue, 29 Aug 2017 21:04:03 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 84ED128A66 for ; Tue, 29 Aug 2017 21:04:03 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 79F6928A6E; Tue, 29 Aug 2017 21:04:03 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-6.8 required=2.0 tests=BAYES_00,DKIM_SIGNED, RCVD_IN_DNSWL_HI,T_DKIM_INVALID autolearn=ham version=3.3.1 Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 1534928A66 for ; Tue, 29 Aug 2017 21:04:03 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751270AbdH2VEC (ORCPT ); Tue, 29 Aug 2017 17:04:02 -0400 Received: from nm6-vm1.bullet.mail.ne1.yahoo.com ([98.138.91.71]:35785 "EHLO nm6-vm1.bullet.mail.ne1.yahoo.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751240AbdH2VEC (ORCPT ); Tue, 29 Aug 2017 17:04:02 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1504040641; bh=2z8OneZcOJT0MmTs8QyPo/uukBkLmo66XMWoWa02s+E=; h=Subject:To:Cc:References:From:Date:In-Reply-To:From:Subject; b=nu6wv+0b1fDAaQMQDXjaAF45c2JkZHe1H7yADM7x/xDphRVBYtjrMqMLO8CHUYum1AFoR5XpB7bZS3LMV6dRcgSvlRSjG535s3v8RDpZslrzHyCBWRlE1vyJ8IzOpAwZrI81d3wVj4rEHn1knxuc6ByDQN/3n/KSRKfKqU4p9cDx1pfqmz2rtvyDvKCe99S3rtQiX0st+Tiz/QXh4XlP+NDWaEXFK47JKvxoG2BchsFI4T9vp22qAMkVaH6blwK8VJeigbMiOz5HpXWvGL0PbRbCKYOjDg3HY+2H+jaDrYp1M18UAfblSeaZY8SDD+eW4rZW0O6Uw3/AS6shB3YW8A== Received: from [98.138.100.114] by nm6.bullet.mail.ne1.yahoo.com with NNFMP; 29 Aug 2017 21:04:01 -0000 Received: from [98.138.84.37] by tm105.bullet.mail.ne1.yahoo.com with NNFMP; 29 Aug 2017 21:04:01 -0000 Received: from [127.0.0.1] by smtp105.mail.ne1.yahoo.com with NNFMP; 29 Aug 2017 21:04:01 -0000 X-Yahoo-Newman-Id: 347998.96599.bm@smtp105.mail.ne1.yahoo.com X-Yahoo-Newman-Property: ymail-3 X-YMail-OSG: sL0OMwQVM1knergIwv2aXAc_jEf3ZZYRtYU4ZeXINQhT4Iy Qw8FGaYEuOUlOJ76.WEImbfF.2PUUkdBhmSrSFgyoIdu7bvD2b52AVi.eMmQ FnrO7cmsFPnxbCFrvuFDftR2o6KImrJ_HBtUKQI4hZoB9CUu_ATlJKA3vUtw EFGZDfJ9Q2Z.ch_6xdcITuZApx9ILQWXyyetrhkghq3MSNh9lTaH0t0OBK4R Div7OwTX0lZ3_TCOuYOW6awFEkeUJ1Fdt6kaA.Bu4UUKz7WQAmrVk.pwmv8o 2nfGdrng2rcs2YQdIxms_cz4xd6Q.RIRbTHMh7SZ5EpRFI4VboZASrkU_2HM c6aMnC8zDXzcyVifXjl.teDuviJXReGN86FbYFZNCJ5sGFu_AXgFEfO_PP0X k4A1.XbItr5lh_5Ej6.qoNkeLs2WTC72ZQbgKUZVIj1.wqq.4apFOEx1Do6L I0p57MtdnbiwCt5Mjgp8lM10XZ6K5Ry.UNKAT67cldRppj9L_JFrIQfCEB4k p9JRgNsV1TFoOANrTh7HfA0F4hFk- X-Yahoo-SMTP: OIJXglSswBDfgLtXluJ6wiAYv6_cnw-- Subject: [PATCH 10/11] LSM: Complete task_alloc hook To: LSM , James Morris Cc: John Johansen , Tetsuo Handa , Paul Moore , Stephen Smalley , Kees Cook , Casey Schaufler References: From: Casey Schaufler Message-ID: <31d9d21d-8261-a061-a010-d5fb4b3e341e@schaufler-ca.com> Date: Tue, 29 Aug 2017 14:03:57 -0700 User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.3.0 MIME-Version: 1.0 In-Reply-To: Content-Language: en-US Sender: owner-linux-security-module@vger.kernel.org Precedence: bulk List-ID: X-Virus-Scanned: ClamAV using ClamSMTP Subject: [PATCH 10/11] LSM: Complete task_alloc hook The Task alloc hook needs to allocate the data. Signed-off-by: Casey Schaufler --- security/security.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/security/security.c b/security/security.c index 6ebcc89004ef..a66663ac932b 100644 --- a/security/security.c +++ b/security/security.c @@ -1387,6 +1387,10 @@ int security_file_open(struct file *file, const struct cred *cred) int security_task_alloc(struct task_struct *task, unsigned long clone_flags) { + int rc = lsm_task_alloc(task); + + if (rc) + return rc; return call_int_hook(task_alloc, 0, task, clone_flags); }