cregit-Linux how code gets into the kernel

Release 4.11 security/min_addr.c

Directory: security
#include <linux/init.h>
#include <linux/mm.h>
#include <linux/security.h>
#include <linux/sysctl.h>

/* amount of vm to protect from userspace access by both DAC and the LSM*/

unsigned long mmap_min_addr;
/* amount of vm to protect from userspace using CAP_SYS_RAWIO (DAC) */

unsigned long dac_mmap_min_addr = CONFIG_DEFAULT_MMAP_MIN_ADDR;
/* amount of vm to protect from userspace using the LSM = CONFIG_LSM_MMAP_MIN_ADDR */

/*
 * Update mmap_min_addr = max(dac_mmap_min_addr, CONFIG_LSM_MMAP_MIN_ADDR)
 */

static void update_mmap_min_addr(void) { #ifdef CONFIG_LSM_MMAP_MIN_ADDR if (dac_mmap_min_addr > CONFIG_LSM_MMAP_MIN_ADDR) mmap_min_addr = dac_mmap_min_addr; else mmap_min_addr = CONFIG_LSM_MMAP_MIN_ADDR; #else mmap_min_addr = dac_mmap_min_addr; #endif }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris34100.00%1100.00%
Total34100.00%1100.00%

/* * sysctl handler which just sets dac_mmap_min_addr = the new value and then * calls update_mmap_min_addr() so non MAP_FIXED hints get rounded properly */
int mmap_min_addr_handler(struct ctl_table *table, int write, void __user *buffer, size_t *lenp, loff_t *ppos) { int ret; if (write && !capable(CAP_SYS_RAWIO)) return -EPERM; ret = proc_doulongvec_minmax(table, write, buffer, lenp, ppos); update_mmap_min_addr(); return ret; }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris5078.12%133.33%
Kees Cook1421.88%266.67%
Total64100.00%3100.00%


static int __init init_mmap_min_addr(void) { update_mmap_min_addr(); return 0; }

Contributors

PersonTokensPropCommitsCommitProp
Eric Paris1493.33%150.00%
H Hartley Sweeten16.67%150.00%
Total15100.00%2100.00%

pure_initcall(init_mmap_min_addr);

Overall Contributors

PersonTokensPropCommitsCommitProp
Eric Paris13089.66%125.00%
Kees Cook149.66%250.00%
H Hartley Sweeten10.69%125.00%
Total145100.00%4100.00%
Directory: security
Information contained on this website is for historical information purposes only and does not indicate or represent copyright ownership.
Created with cregit.