diff options
author | Maciej Żenczykowski <maze@google.com> | 2012-03-21 00:52:00 +0000 |
---|---|---|
committer | Pablo Neira Ayuso <pablo@netfilter.org> | 2012-03-23 11:24:30 +0100 |
commit | c0aa38e22e8a09fcb1898ad0e042eaf6314d2d42 (patch) | |
tree | 6c4df30f78f66235cb610b018f4dbf8a5cee1621 /extensions/libxt_LED.c | |
parent | 61b8f7ecb64b3b6fe04d2a6ad9598f66e42ceea8 (diff) |
src: mark newly opened fds as FD_CLOEXEC (close on exec)
By default, Unix-like systems leak file descriptors after fork/exec
call. I think this seem to result in SELinux spotting a strange AVC
log messages according to what I can find on the web.
Fedora 18 iptables source includes this change.
Maciej says:
"iptables does potentially fork/exec modprobe to load modules.
That can cause a selinux 'domain'/'role'/whatever-it-is-called crossing.
You can do automated inspection of what gets carried across such
privilege changes and any unexpected open file descriptors flag
problems, patches like this cut down on the noise."
Signed-off-by: Maciej enczykowski <maze@google.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'extensions/libxt_LED.c')
0 files changed, 0 insertions, 0 deletions