All of lore.kernel.org
 help / color / mirror / Atom feed
* VSOCK & getpeercon()
@ 2021-01-16 12:48 Marc-André Lureau
  2021-01-22 16:27 ` Paul Moore
  0 siblings, 1 reply; 4+ messages in thread
From: Marc-André Lureau @ 2021-01-16 12:48 UTC (permalink / raw)
  To: selinux; +Cc: Gerd Hoffmann, Stefano Garzarella, paul

Hi,

getpeercon() isn't implemented for VSOCK. Note, I am not very familiar
with SELinux, but I was porting some applications that uses AF_UNIX to
AF_VSOCK and reached that point.

I found some previous discussions about VSOCK & LSM from 2013, but the
reasons it was abandoned don't seem so clear or valid to me:
https://lore.kernel.org/selinux/1803195.0cVPJuGAEx@sifl/

To me, SELinux could always associate a VSOCK with a process context,
at the very least, and thus enforce some communication policies. No?

thanks

-- 
Marc-André Lureau

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2021-01-22 19:35 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-01-16 12:48 VSOCK & getpeercon() Marc-André Lureau
2021-01-22 16:27 ` Paul Moore
2021-01-22 17:13   ` Casey Schaufler
2021-01-22 19:02     ` Paul Moore

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.