[PATCH] tomoyo: Enforce connect policy in TCP Fast Open

Matthieu Buffet matthieu at buffet.re
Sun Sep 20 22:34:12 UTC 2026


Hi Tomoyo maintainers,

On 6/27/2026 7:28 AM, Tetsuo Handa wrote:
> I updated your patch like below in order to exclude kernel threads from this check.
> If we are OK to go with modifying individual LSM, I'll apply this change.
Archiving this patch, I see you have had no answer from other 
maintainers to your question about the approach taken (per-LSM instead 
of aiming for a hook-wide fix). Patches have indeed been merged for 
other affected LSMs:
4d587cd8a721 ("apparmor: mediate the implicit connect of TCP fast open 
sendmsg")
44c74d27d1b9 ("selinux: check connect-related permissions on TCP Fast Open")
33cb713db016 ("landlock: Fix TCP Fast Open connection bypass")

Have a nice day!

Matthieu



More information about the Linux-security-module-archive mailing list