selinux: fix a sock regression in selinux_ip_postroute_compat()
Unfortunately we can't rely on nf_hook_state->sk being the proper originating socket so revert to using skb_to_full_sk(skb). Fixes: 1d1e1ded ("selinux: make better use of the nf_hook_state passed to the NF hooks") Reported-by:Linux Kernel Functional Testing <lkft@linaro.org> Suggested-by:
Florian Westphal <fw@strlen.de> Signed-off-by:
Paul Moore <paul@paul-moore.com>
Loading
Please register or sign in to comment