[PATCH] tomoyo: Enforce connect policy in TCP Fast Open
Tetsuo Handa
penguin-kernel at I-love.SAKURA.ne.jp
Sun Oct 4 14:20:47 UTC 2026
On 2026/09/21 7:34, Matthieu Buffet wrote:
> Hi Tomoyo maintainers,
>
> On 6/27/2026 7:28 AM, Tetsuo Handa wrote:
>> I updated your patch like below in order to exclude kernel threads from this check.
>> If we are OK to go with modifying individual LSM, I'll apply this change.
> Archiving this patch, I see you have had no answer from other maintainers to your
> question about the approach taken (per-LSM instead of aiming for a hook-wide fix).
> Patches have indeed been merged for other affected LSMs:
> 4d587cd8a721 ("apparmor: mediate the implicit connect of TCP fast open sendmsg")
> 44c74d27d1b9 ("selinux: check connect-related permissions on TCP Fast Open")
> 33cb713db016 ("landlock: Fix TCP Fast Open connection bypass")
>
> Have a nice day!
>
> Matthieu
Thank you for letting me know.
I am currently modifying your patch into a series that can please sashiko's review.
Since sashiko finds many corner cases, I need to make several trial and errors.
Please wait patiently.
More information about the Linux-security-module-archive
mailing list