[PATCH] tomoyo: Enforce connect policy in TCP Fast Open
Matthieu Buffet
matthieu at buffet.re
Sun Sep 20 22:34:12 UTC 2026
Hi Tomoyo maintainers,
On 6/27/2026 7:28 AM, Tetsuo Handa wrote:
> I updated your patch like below in order to exclude kernel threads from this check.
> If we are OK to go with modifying individual LSM, I'll apply this change.
Archiving this patch, I see you have had no answer from other
maintainers to your question about the approach taken (per-LSM instead
of aiming for a hook-wide fix). Patches have indeed been merged for
other affected LSMs:
4d587cd8a721 ("apparmor: mediate the implicit connect of TCP fast open
sendmsg")
44c74d27d1b9 ("selinux: check connect-related permissions on TCP Fast Open")
33cb713db016 ("landlock: Fix TCP Fast Open connection bypass")
Have a nice day!
Matthieu
More information about the Linux-security-module-archive
mailing list