summaryrefslogtreecommitdiff
path: root/security/apparmor
diff options
context:
space:
mode:
authorJohn Johansen <john.johansen@canonical.com>2026-02-09 03:31:35 -0800
committerJohn Johansen <john.johansen@canonical.com>2026-08-10 22:49:42 -0700
commit27908a4356f02f06ca4d5d25f456091aa44167d2 (patch)
tree953f76d8c90bb16165bec927ad10b65a8f4e7822 /security/apparmor
parenta7bc8ccbd279216b0d6eb265423f49d93a7882d6 (diff)
downloadlinux-next-27908a4356f02f06ca4d5d25f456091aa44167d2.tar.gz
linux-next-27908a4356f02f06ca4d5d25f456091aa44167d2.zip
apparmor: move sock_rcv_skb() next to inet_conn_request
both of these fns are using ifdef CONFIG_NETWORK_SECMARK and related to AppArmor's secmark based mediation, so move them together. Reviewed-by: Georgia Garcia <georgia.garcia@canonical.com> Signed-off-by: John Johansen <john.johansen@canonical.com>
Diffstat (limited to 'security/apparmor')
-rw-r--r--security/apparmor/lsm.c69
1 files changed, 33 insertions, 36 deletions
diff --git a/security/apparmor/lsm.c b/security/apparmor/lsm.c
index 9d28cbe396fc..9c5dcaf2fec3 100644
--- a/security/apparmor/lsm.c
+++ b/security/apparmor/lsm.c
@@ -1553,42 +1553,6 @@ static int apparmor_socket_shutdown(struct socket *sock, int how)
return aa_sock_perm(OP_SHUTDOWN, AA_MAY_SHUTDOWN, sock);
}
-#ifdef CONFIG_NETWORK_SECMARK
-/**
- * apparmor_socket_sock_rcv_skb - check perms before associating skb to sk
- * @sk: sk to associate @skb with
- * @skb: skb to check for perms
- *
- * Note: can not sleep may be called with locks held
- *
- * don't want protocol specific in __skb_recv_datagram()
- * to deny an incoming connection socket_sock_rcv_skb()
- */
-static int apparmor_socket_sock_rcv_skb(struct sock *sk, struct sk_buff *skb)
-{
- struct aa_sk_ctx *ctx = aa_sock(sk);
- int error;
-
- if (!skb->secmark)
- return 0;
-
- /*
- * If reach here before socket_post_create hook is called, in which
- * case label is null, drop the packet.
- */
- if (!rcu_access_pointer(ctx->label))
- return -EACCES;
-
- rcu_read_lock();
- error = apparmor_secmark_check(rcu_dereference(ctx->label), OP_RECVMSG,
- AA_MAY_RECEIVE, skb->secmark, sk);
- rcu_read_unlock();
-
- return error;
-}
-#endif
-
-
static struct aa_label *sk_peer_get_label(struct sock *sk)
{
struct aa_sk_ctx *ctx = aa_sock(sk);
@@ -1689,6 +1653,39 @@ static void apparmor_sock_graft(struct sock *sk, struct socket *parent)
}
#ifdef CONFIG_NETWORK_SECMARK
+/**
+ * apparmor_socket_sock_rcv_skb - check perms before associating skb to sk
+ * @sk: sk to associate @skb with
+ * @skb: skb to check for perms
+ *
+ * Note: can not sleep may be called with locks held
+ *
+ * don't want protocol specific in __skb_recv_datagram()
+ * to deny an incoming connection socket_sock_rcv_skb()
+ */
+static int apparmor_socket_sock_rcv_skb(struct sock *sk, struct sk_buff *skb)
+{
+ struct aa_sk_ctx *ctx = aa_sock(sk);
+ int error;
+
+ if (!skb->secmark)
+ return 0;
+
+ /*
+ * If reach here before socket_post_create hook is called, in which
+ * case label is null, drop the packet.
+ */
+ if (!rcu_access_pointer(ctx->label))
+ return -EACCES;
+
+ rcu_read_lock();
+ error = apparmor_secmark_check(rcu_dereference(ctx->label), OP_RECVMSG,
+ AA_MAY_RECEIVE, skb->secmark, sk);
+ rcu_read_unlock();
+
+ return error;
+}
+
static int apparmor_inet_conn_request(const struct sock *sk, struct sk_buff *skb,
struct request_sock *req)
{