-
- Downloads
apparmor: add base infastructure for socket mediation
Provide a basic mediation of sockets. This is not a full net mediation but just whether a spcific family of socket can be used by an application, along with setting up some basic infrastructure for network mediation to follow. the user space rule hav the basic form of NETWORK RULE = [ QUALIFIERS ] 'network' [ DOMAIN ] [ TYPE | PROTOCOL ] DOMAIN = ( 'inet' | 'ax25' | 'ipx' | 'appletalk' | 'netrom' | 'bridge' | 'atmpvc' | 'x25' | 'inet6' | 'rose' | 'netbeui' | 'security' | 'key' | 'packet' | 'ash' | 'econet' | 'atmsvc' | 'sna' | 'irda' | 'pppox' | 'wanpipe' | 'bluetooth' | 'netlink' | 'unix' | 'rds' | 'llc' | 'can' | 'tipc' | 'iucv' | 'rxrpc' | 'isdn' | 'phonet' | 'ieee802154' | 'caif' | 'alg' | 'nfc' | 'vsock' | 'mpls' | 'ib' | 'kcm' ) ',' TYPE = ( 'stream' | 'dgram' | 'seqpacket' | 'rdm' | 'raw' | 'packet' ) PROTOCOL = ( 'tcp' | 'udp' | 'icmp' ) eg. network, network inet, Signed-off-by:John Johansen <john.johansen@canonical.com> Acked-by:
Seth Arnold <seth.arnold@canonical.com>
Showing
- security/apparmor/.gitignore 1 addition, 0 deletionssecurity/apparmor/.gitignore
- security/apparmor/Makefile 41 additions, 2 deletionssecurity/apparmor/Makefile
- security/apparmor/apparmorfs.c 1 addition, 0 deletionssecurity/apparmor/apparmorfs.c
- security/apparmor/file.c 30 additions, 0 deletionssecurity/apparmor/file.c
- security/apparmor/include/audit.h 17 additions, 9 deletionssecurity/apparmor/include/audit.h
- security/apparmor/include/net.h 114 additions, 0 deletionssecurity/apparmor/include/net.h
- security/apparmor/include/perms.h 3 additions, 2 deletionssecurity/apparmor/include/perms.h
- security/apparmor/include/policy.h 13 additions, 0 deletionssecurity/apparmor/include/policy.h
- security/apparmor/lib.c 3 additions, 2 deletionssecurity/apparmor/lib.c
- security/apparmor/lsm.c 387 additions, 0 deletionssecurity/apparmor/lsm.c
- security/apparmor/net.c 184 additions, 0 deletionssecurity/apparmor/net.c
- security/apparmor/policy_unpack.c 46 additions, 1 deletionsecurity/apparmor/policy_unpack.c
Loading
Please register or sign in to comment