netlabel: Cleanup the Smack/NetLabel code to fix incoming TCP connections
authorPaul Moore <paul.moore@hp.com>
Fri, 27 Mar 2009 21:10:54 +0000 (17:10 -0400)
committerJames Morris <jmorris@namei.org>
Sat, 28 Mar 2009 04:01:37 +0000 (15:01 +1100)
commit07feee8f812f7327a46186f7604df312c8c81962
tree73eac643b60532aa82d7680a7de193ba2b62eddd
parent8651d5c0b1f874c5b8307ae2b858bc40f9f02482
netlabel: Cleanup the Smack/NetLabel code to fix incoming TCP connections

This patch cleans up a lot of the Smack network access control code.  The
largest changes are to fix the labeling of incoming TCP connections in a
manner similar to the recent SELinux changes which use the
security_inet_conn_request() hook to label the request_sock and let the label
move to the child socket via the normal network stack mechanisms.  In addition
to the incoming TCP connection fixes this patch also removes the smk_labled
field from the socket_smack struct as the minor optimization advantage was
outweighed by the difficulty in maintaining it's proper state.

Signed-off-by: Paul Moore <paul.moore@hp.com>
Acked-by: Casey Schaufler <casey@schaufler-ca.com>
Signed-off-by: James Morris <jmorris@namei.org>
include/net/netlabel.h
net/netlabel/netlabel_kapi.c
security/smack/smack.h
security/smack/smack_lsm.c