UPSTREAM: userfaultfd: use secure anon inodes for userfaultfd
This change gives userfaultfd file descriptors a real security context, allowing policy to act on them. Signed-off-by:Daniel Colascione <dancol@google.com> [LG: Remove owner inode from userfaultfd_ctx] [LG: Use anon_inode_getfd_secure() in userfaultfd syscall] [LG: Use inode of file in userfaultfd_read() in resolve_userfault_fork()] Signed-off-by:
Lokesh Gidra <lokeshgidra@google.com> Reviewed-by:
Eric Biggers <ebiggers@google.com> Signed-off-by:
Paul Moore <paul@paul-moore.com> (cherry picked from commit b537900f) Signed-off-by:
Lokesh Gidra <lokeshgidra@google.com> Bug: 160737021 Bug: 169683130 Change-Id: Ifd3faca4058bd9e4c51767aa0246e1c53ad410d4
Loading
Please sign in to comment