mirror of
https://github.com/torvalds/linux.git
synced 2026-10-05 11:24:03 +02:00
Network denial events now report the port from their one authoritative validated address through one signed field. Verify this value directly without inferring a source or destination role. Exercise a nonzero IPv4 TCP bind, an explicit-zero IPv4 UDP bind, a synthetic-zero IPv6 UDP autobind, and a family-only AF_UNSPEC UDP send. Require exactly one event with the exact policy blocker for each shape. The value -1 distinguishes a family-only address with no validated port from the two valid port-zero cases. Test coverage for security/landlock is 91.6% of 2625 lines according to LLVM 22. Cc: Günther Noack <gnoack@google.com> Cc: Steven Rostedt <rostedt@goodmis.org> Link: https://patch.msgid.link/20260918185036.608651-9-mic@digikod.net [mic: Add test coverage] Signed-off-by: Mickaël Salaün <mic@digikod.net> |
||
|---|---|---|
| .. | ||
| accounting | ||
| arch | ||
| bootconfig | ||
| bpf | ||
| build | ||
| certs | ||
| cgroup | ||
| counter | ||
| crypto | ||
| debugging | ||
| dma | ||
| docs | ||
| firewire | ||
| firmware | ||
| gpio | ||
| hv | ||
| iio | ||
| include | ||
| kvm/kvm_stat | ||
| laptop | ||
| leds | ||
| lib | ||
| memory-model | ||
| mm | ||
| net | ||
| objtool | ||
| pcmcia | ||
| perf | ||
| platform/x86/amd | ||
| power | ||
| rcu | ||
| sched | ||
| sched_ext | ||
| scripts | ||
| sound | ||
| spi | ||
| testing | ||
| thermal | ||
| time | ||
| tracing | ||
| unittests | ||
| usb | ||
| verification | ||
| virtio | ||
| wmi | ||
| workqueue | ||
| writeback | ||
| Makefile | ||