Received: by 2002:a05:6358:11c7:b0:104:8066:f915 with SMTP id i7csp638249rwl; Wed, 5 Apr 2023 05:57:18 -0700 (PDT) X-Google-Smtp-Source: AKy350bnbBdxNMSZPeQL3PPoZ/gpsBrH4gDcdJbyB2dsJ26geyY+Ha1p6IA5AxZnryZdX/BidrVh X-Received: by 2002:a05:6a20:66a7:b0:e1:204e:ddd5 with SMTP id o39-20020a056a2066a700b000e1204eddd5mr5688620pzh.15.1680699437915; Wed, 05 Apr 2023 05:57:17 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1680699437; cv=none; d=google.com; s=arc-20160816; b=i0qnTdmlVJQlEBZhEWDlwe2riZx2rSasNvvnJWeAa3A+g9WQE4q7JLPcwTc44rqdUF 9BtTop0fPHVXw5FcMYqzN9h5G1QOLwnirkL/P0B9ZDyu55w0Q/nLMNzscCpPM5f0buRK Qldne8Uv/uy+JC1RC4JKDhMAJ6uoWeHD4IzFW/2ytX8D2v7Ls06H//EvduwxTuTXLdRD Y3W18ZhcZ2syGvcDXSDCuaTyGLEJ2qjiHxSyxK6gps8wcFXLOnz8+8owT1J0YSTF1qeA SBBich+5MZ5r0PxN+vNMDIj6MJFl12HbH0OtYwLTeKMH9jnDfr0m7/kPKtvhTTYFEe1t /JCw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :message-id:date:subject:cc:to:dkim-signature:from; bh=8jSMehI3NmhiQSs4S6ALsvgGoTEzZsyVpigKpvyvIMQ=; b=wx1sFcbUxXc7GG6xz4QpMeQcEVHT7FXdNj4JQj0PSIKoWN3nixmjkUH36ZtvKbseGl 5WWPeZYq/3UGLOHzeS0AdqsgalTZeFsVdDQsek6OvaA15HGzPVtrflLVaMrWtjBxuToq aqyqofpuAo3qKkvur64q4Zxv+J78tsOc+4jYrRj5UeTUcGLhY2KkdXV9HDIcjrP/6mC/ Uih6WEviG3gRUl35TUV+eXHZOpGe6+SWTv6ZPpYJ1zL3jM01Ib1rd88xz+lpS854Qi1M MxBNL1c5ndwWnsm36uYvMVMQ4COZ+mVekwWT201/1w4y/eSySGQ5cp4O9+8W1RrVj42D CW4w== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@swemel.ru header.s=mail header.b=FxLX8o09; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=swemel.ru Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id q74-20020a632a4d000000b005131739af72si5774017pgq.755.2023.04.05.05.57.05; Wed, 05 Apr 2023 05:57:17 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@swemel.ru header.s=mail header.b=FxLX8o09; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=swemel.ru Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S237745AbjDEMxP (ORCPT + 99 others); Wed, 5 Apr 2023 08:53:15 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:59362 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232465AbjDEMxO (ORCPT ); Wed, 5 Apr 2023 08:53:14 -0400 Received: from mx.swemel.ru (mx.swemel.ru [95.143.211.150]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id A52251FFE; Wed, 5 Apr 2023 05:53:11 -0700 (PDT) From: Denis Arefev DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=swemel.ru; s=mail; t=1680699188; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=8jSMehI3NmhiQSs4S6ALsvgGoTEzZsyVpigKpvyvIMQ=; b=FxLX8o09yM2S0bA/+HUGYBcyyZYWUad7hCBh69Sv0x0Mu25Y99ITwdHN6q4IR43mWhzWzT RSVuWFmWy47ZJYc9velx3Z9T7P7TU9NvGJ989bhBbiVKgOjwTHGFjJKyw4EUNNH2bGw12e hLhBYXLzmaZ3S9axo2drB/zYo19HNbk= To: "David S. Miller" Cc: Eric Dumazet , Jakub Kicinski , Paolo Abeni , netdev@vger.kernel.org, linux-kernel@vger.kernel.org, trufanov@swemel.ru, vfh@swemel.ru Subject: [PATCH] net: Added security socket Date: Wed, 5 Apr 2023 15:53:08 +0300 Message-Id: <20230405125308.57821-1-arefev@swemel.ru> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Spam-Status: No, score=-0.2 required=5.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DKIM_VALID_EF,SPF_HELO_NONE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Added security_socket_connect kernel_connect is in kernel space, but kernel_connect is used in RPC requests (/net/sunrpc/xprtsock.c), and the RPC protocol is used by the NFS server. This is how we protect the TCP connection initiated by the client. Signed-off-by: Denis Arefev --- net/socket.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/net/socket.c b/net/socket.c index 9c92c0e6c4da..9afa2b44a9e5 100644 --- a/net/socket.c +++ b/net/socket.c @@ -3526,6 +3526,12 @@ EXPORT_SYMBOL(kernel_accept); int kernel_connect(struct socket *sock, struct sockaddr *addr, int addrlen, int flags) { + int err; + + err = security_socket_connect(sock, (struct sockaddr *)addr, addrlen); + if (err) + return err; + return sock->ops->connect(sock, addr, addrlen, flags); } EXPORT_SYMBOL(kernel_connect); -- 2.25.1