diff options
Diffstat (limited to 'security/selinux/netlink.c')
| -rw-r--r-- | security/selinux/netlink.c | 26 | 
1 files changed, 17 insertions, 9 deletions
diff --git a/security/selinux/netlink.c b/security/selinux/netlink.c index 36ac257cec9..828fb6a4e94 100644 --- a/security/selinux/netlink.c +++ b/security/selinux/netlink.c @@ -14,10 +14,13 @@  #include <linux/slab.h>  #include <linux/stddef.h>  #include <linux/kernel.h> +#include <linux/export.h>  #include <linux/skbuff.h> -#include <linux/netlink.h>  #include <linux/selinux_netlink.h>  #include <net/net_namespace.h> +#include <net/netlink.h> + +#include "security.h"  static struct sock *selnl; @@ -44,7 +47,7 @@ static void selnl_add_payload(struct nlmsghdr *nlh, int len, int msgtype, void *  {  	switch (msgtype) {  	case SELNL_MSG_SETENFORCE: { -		struct selnl_msg_setenforce *msg = NLMSG_DATA(nlh); +		struct selnl_msg_setenforce *msg = nlmsg_data(nlh);  		memset(msg, 0, len);  		msg->val = *((int *)data); @@ -52,7 +55,7 @@ static void selnl_add_payload(struct nlmsghdr *nlh, int len, int msgtype, void *  	}  	case SELNL_MSG_POLICYLOAD: { -		struct selnl_msg_policyload *msg = NLMSG_DATA(nlh); +		struct selnl_msg_policyload *msg = nlmsg_data(nlh);  		memset(msg, 0, len);  		msg->seqno = *((u32 *)data); @@ -73,12 +76,14 @@ static void selnl_notify(int msgtype, void *data)  	len = selnl_msglen(msgtype); -	skb = alloc_skb(NLMSG_SPACE(len), GFP_USER); +	skb = nlmsg_new(len, GFP_USER);  	if (!skb)  		goto oom;  	tmp = skb->tail; -	nlh = NLMSG_PUT(skb, 0, 0, msgtype, len); +	nlh = nlmsg_put(skb, 0, 0, msgtype, len, 0); +	if (!nlh) +		goto out_kfree_skb;  	selnl_add_payload(nlh, len, msgtype, data);  	nlh->nlmsg_len = skb->tail - tmp;  	NETLINK_CB(skb).dst_group = SELNLGRP_AVC; @@ -86,7 +91,7 @@ static void selnl_notify(int msgtype, void *data)  out:  	return; -nlmsg_failure: +out_kfree_skb:  	kfree_skb(skb);  oom:  	printk(KERN_ERR "SELinux:  OOM in %s\n", __func__); @@ -105,11 +110,14 @@ void selnl_notify_policyload(u32 seqno)  static int __init selnl_init(void)  { -	selnl = netlink_kernel_create(&init_net, NETLINK_SELINUX, -				      SELNLGRP_MAX, NULL, NULL, THIS_MODULE); +	struct netlink_kernel_cfg cfg = { +		.groups	= SELNLGRP_MAX, +		.flags	= NL_CFG_F_NONROOT_RECV, +	}; + +	selnl = netlink_kernel_create(&init_net, NETLINK_SELINUX, &cfg);  	if (selnl == NULL)  		panic("SELinux:  Cannot create netlink socket."); -	netlink_set_nonroot(NETLINK_SELINUX, NL_NONROOT_RECV);  	return 0;  }  | 
