]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
selinux/nlmsg: add XFRM_MSG_MAPPING
authorNicolas Dichtel <nicolas.dichtel@6wind.com>
Fri, 10 Apr 2015 14:24:28 +0000 (16:24 +0200)
committerSasha Levin <sasha.levin@oracle.com>
Sun, 28 Jun 2015 17:39:25 +0000 (13:39 -0400)
[ Upstream commit bd2cba07381a6dba60bc1c87ed8b37931d244da1 ]

This command is missing.

Fixes: 3a2dfbe8acb1 ("xfrm: Notify changes in UDP encapsulation via netlink")
CC: Martin Willi <martin@strongswan.org>
Reported-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: Nicolas Dichtel <nicolas.dichtel@6wind.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
security/selinux/nlmsgtab.c

index 404a81186c11ae038a4eac5484a4c5fc8aecab4a..902b5e9cec7e10158db072a1e1dfa0deb9c2ac65 100644 (file)
@@ -106,6 +106,7 @@ static struct nlmsg_perm nlmsg_xfrm_perms[] =
        { XFRM_MSG_GETSADINFO,  NETLINK_XFRM_SOCKET__NLMSG_READ  },
        { XFRM_MSG_NEWSPDINFO,  NETLINK_XFRM_SOCKET__NLMSG_WRITE },
        { XFRM_MSG_GETSPDINFO,  NETLINK_XFRM_SOCKET__NLMSG_READ  },
+       { XFRM_MSG_MAPPING,     NETLINK_XFRM_SOCKET__NLMSG_READ  },
 };
 
 static struct nlmsg_perm nlmsg_audit_perms[] =