]> git.baikalelectronics.ru Git - kernel.git/commit
SELinux: return -ECONNREFUSED from ip_postroute to signal fatal error
authorEric Paris <eparis@redhat.com>
Tue, 16 Nov 2010 11:52:57 +0000 (11:52 +0000)
committerDavid S. Miller <davem@davemloft.net>
Wed, 17 Nov 2010 18:54:35 +0000 (10:54 -0800)
commite3b098a576c91ec42e2518ab67efc72ad8a78792
tree9ab2495097fa2944404ab41bfb3038de374f5626
parent41a72ac0af98141d04c6657f8b3779bc7e9468a0
SELinux: return -ECONNREFUSED from ip_postroute to signal fatal error

The SELinux netfilter hooks just return NF_DROP if they drop a packet.  We
want to signal that a drop in this hook is a permanant fatal error and is not
transient.  If we do this the error will be passed back up the stack in some
places and applications will get a faster interaction that something went
wrong.

Signed-off-by: Eric Paris <eparis@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
security/selinux/hooks.c