Link: https://lore.kernel.org/r/20260217200002.683975158@linuxfoundation.org Tested-by: Florian Fainelli <florian.fainelli@broadcom.com> Tested-by: Takeshi Ogasawara <takeshi.ogasawara@futuring-girl.com> Tested-by: Peter Schneider <pschneider1968@googlemail.com> Tested-by: Jon Hunter <jonathanh@nvidia.com> Tested-by: Salvatore Bonaccorso <carnil@debian.org> Tested-by: Brett A C Sheffield <bacs@librecast.net> Tested-by: Mark Brown <broonie@kernel.org> Tested-by: Luna Jernberg <droidbittin@gmail.com> Tested-by: Ronald Warsow <rwarsow@gmx.de> Tested-by: Justin M. Forbes <jforbes@fedoraproject.org> Tested-by: Ron Economos <re@w6rz.net> Tested-by: Miguel Ojeda <ojeda@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
21 lines
749 B
ReStructuredText
21 lines
749 B
ReStructuredText
.. SPDX-License-Identifier: GPL-2.0
|
|
|
|
=================
|
|
LSM/SeLinux secid
|
|
=================
|
|
|
|
flowi structure:
|
|
|
|
The secid member in the flow structure is used in LSMs (e.g. SELinux) to indicate
|
|
the label of the flow. This label of the flow is currently used in selecting
|
|
matching labeled xfrm(s).
|
|
|
|
If this is an outbound flow, the label is derived from the socket, if any, or
|
|
the incoming packet this flow is being generated as a response to (e.g. tcp
|
|
resets, timewait ack, etc.). It is also conceivable that the label could be
|
|
derived from other sources such as process context, device, etc., in special
|
|
cases, as may be appropriate.
|
|
|
|
If this is an inbound flow, the label is derived from the IPSec security
|
|
associations, if any, used by the packet.
|