All of lore.kernel.org
 help / color / mirror / Atom feed
* SECMARK: implementation question
@ 2009-10-11  4:27 Jacques Thomas
  2009-10-12 22:46 ` Paul Moore
  0 siblings, 1 reply; 3+ messages in thread
From: Jacques Thomas @ 2009-10-11  4:27 UTC (permalink / raw)
  To: SE Linux

Dear All,

If I understand correctly, the permission check for inbound packet (the 
"packet recv" operation) is performed by selinux_socket_sock_recv_skb, 
which hooks into the socket_sock_recv_skb hook.

Does anybody remember the rationale for doing the check there instead of 
the NF_INET_LOCAL_IN hook ?

I am asking that because the permission for outbound packets ("packet 
send") seems to be performed in the NF_INET_LOCAL_OUT. I am sure there 
should be a good reason for this asymetry, but I don't get it.

Thanks for your time,
Jacques Thomas

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2009-10-12 23:47 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-10-11  4:27 SECMARK: implementation question Jacques Thomas
2009-10-12 22:46 ` Paul Moore
2009-10-12 23:47   ` Jacques Thomas

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.