selinux: Fix send_sigiotask hook
authorStephen Smalley <sds@tycho.nsa.gov>
Mon, 4 May 2009 19:43:18 +0000 (15:43 -0400)
committerJames Morris <jmorris@namei.org>
Mon, 4 May 2009 22:31:03 +0000 (08:31 +1000)
The CRED patch incorrectly converted the SELinux send_sigiotask hook to
use the current task SID rather than the target task SID in its
permission check, yielding the wrong permission check.  This fixes the
hook function.  Detected by the ltp selinux testsuite and confirmed to
correct the test failure.

Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
security/selinux/hooks.c

index ba808ef..2fcad7c 100644 (file)
@@ -3153,7 +3153,7 @@ static int selinux_file_send_sigiotask(struct task_struct *tsk,
                                       struct fown_struct *fown, int signum)
 {
        struct file *file;
-       u32 sid = current_sid();
+       u32 sid = task_sid(tsk);
        u32 perm;
        struct file_security_struct *fsec;