tree 70382b40681e709a8f7790d03cc00adbad4726fa
parent 08abe46b2cfcf5f815cd4961b1bf9e10b1714c6d
author Lokesh Gidra <lokeshgidra@google.com> 1610144540 -0800
committer Paul Moore <paul@paul-moore.com> 1610663304 -0500

security: add inode_init_security_anon() LSM hook

This change adds a new LSM hook, inode_init_security_anon(), that will
be used while creating secure anonymous inodes. The hook allows/denies
its creation and assigns a security context to the inode.

The new hook accepts an optional context_inode parameter that callers
can use to provide additional contextual information to security modules
for granting/denying permission to create an anon-inode of the same type.
This context_inode's security_context can also be used to initialize the
newly created anon-inode's security_context.

Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Reviewed-by: Eric Biggers <ebiggers@google.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
