aboutsummaryrefslogtreecommitdiffstats
path: root/kernels/coral/selinux.patch
diff options
context:
space:
mode:
Diffstat (limited to 'kernels/coral/selinux.patch')
-rw-r--r--kernels/coral/selinux.patch73
1 files changed, 73 insertions, 0 deletions
diff --git a/kernels/coral/selinux.patch b/kernels/coral/selinux.patch
new file mode 100644
index 0000000..c40f729
--- /dev/null
+++ b/kernels/coral/selinux.patch
@@ -0,0 +1,73 @@
+From 760f8522ce08a24abac3208290f93fe3fffc0d6c Mon Sep 17 00:00:00 2001
+From: Paulo Alcantara <paulo@paulo.ac>
+Date: Sun, 24 Feb 2019 21:55:28 -0300
+Subject: selinux: use kernel linux/socket.h for genheaders and mdp
+
+commit dfbd199a7cfe3e3cd8531e1353cdbd7175bfbc5e upstream.
+
+When compiling genheaders and mdp from a newer host kernel, the
+following error happens:
+
+ In file included from scripts/selinux/genheaders/genheaders.c:18:
+ ./security/selinux/include/classmap.h:238:2: error: #error New
+ address family defined, please update secclass_map. #error New
+ address family defined, please update secclass_map. ^~~~~
+ make[3]: *** [scripts/Makefile.host:107:
+ scripts/selinux/genheaders/genheaders] Error 1 make[2]: ***
+ [scripts/Makefile.build:599: scripts/selinux/genheaders] Error 2
+ make[1]: *** [scripts/Makefile.build:599: scripts/selinux] Error 2
+ make[1]: *** Waiting for unfinished jobs....
+
+Instead of relying on the host definition, include linux/socket.h in
+classmap.h to have PF_MAX.
+
+Cc: stable@vger.kernel.org
+Signed-off-by: Paulo Alcantara <paulo@paulo.ac>
+Acked-by: Stephen Smalley <sds@tycho.nsa.gov>
+[PM: manually merge in mdp.c, subject line tweaks]
+Signed-off-by: Paul Moore <paul@paul-moore.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ scripts/selinux/genheaders/genheaders.c | 1 -
+ scripts/selinux/mdp/mdp.c | 1 -
+ security/selinux/include/classmap.h | 1 +
+ 3 files changed, 1 insertion(+), 2 deletions(-)
+
+diff --git a/scripts/selinux/genheaders/genheaders.c b/scripts/selinux/genheaders/genheaders.c
+index fa48fabcb330..3cc4893d98cc 100644
+--- a/scripts/selinux/genheaders/genheaders.c
++++ b/scripts/selinux/genheaders/genheaders.c
+@@ -9,7 +9,6 @@
+ #include <string.h>
+ #include <errno.h>
+ #include <ctype.h>
+-#include <sys/socket.h>
+
+ struct security_class_mapping {
+ const char *name;
+diff --git a/scripts/selinux/mdp/mdp.c b/scripts/selinux/mdp/mdp.c
+index ffe8179f5d41..c29fa4a6228d 100644
+--- a/scripts/selinux/mdp/mdp.c
++++ b/scripts/selinux/mdp/mdp.c
+@@ -32,7 +32,6 @@
+ #include <stdlib.h>
+ #include <unistd.h>
+ #include <string.h>
+-#include <sys/socket.h>
+
+ static void usage(char *name)
+ {
+diff --git a/security/selinux/include/classmap.h b/security/selinux/include/classmap.h
+index cc35695d97b4..45ef6a0c17cc 100644
+--- a/security/selinux/include/classmap.h
++++ b/security/selinux/include/classmap.h
+@@ -1,5 +1,6 @@
+ /* SPDX-License-Identifier: GPL-2.0 */
+ #include <linux/capability.h>
++#include <linux/socket.h>
+
+ #define COMMON_FILE_SOCK_PERMS "ioctl", "read", "write", "create", \
+ "getattr", "setattr", "lock", "relabelfrom", "relabelto", "append", "map"
+--
+cgit 1.2-0.3.lf.el7
+