Skip to content
GitLab
Explore
Sign in
Primary navigation
Search or go to…
Project
S
sepolicy
Manage
Activity
Members
Plan
Wiki
Code
Repository
Branches
Commits
Tags
Repository graph
Compare revisions
Snippets
Deploy
Releases
Package Registry
Model registry
Operate
Terraform modules
Analyze
Contributor analytics
Repository analytics
Model experiments
Help
Help
Support
GitLab documentation
Compare GitLab plans
Community forum
Contribute to GitLab
Provide feedback
Keyboard shortcuts
?
Snippets
Groups
Projects
Show more breadcrumbs
CodeLinaro
public-release-test
platform
system
sepolicy
Commits
5c484443
Commit
5c484443
authored
6 years ago
by
Treehugger Robot
Committed by
Gerrit Code Review
6 years ago
Browse files
Options
Downloads
Plain Diff
Merge "Update access_vectors"
parents
ced51ddd
ea1775dc
No related branches found
No related tags found
No related merge requests found
Changes
3
Hide whitespace changes
Inline
Side-by-side
Showing
3 changed files
private/access_vectors
+15
-0
15 additions, 0 deletions
private/access_vectors
private/security_classes
+8
-1
8 additions, 1 deletion
private/security_classes
public/global_macros
+2
-2
2 additions, 2 deletions
public/global_macros
with
25 additions
and
3 deletions
private/access_vectors
+
15
−
0
View file @
5c484443
...
@@ -547,6 +547,16 @@ inherits socket
...
@@ -547,6 +547,16 @@ inherits socket
class netlink_crypto_socket
class netlink_crypto_socket
inherits socket
inherits socket
class infiniband_pkey
{
access
}
class infiniband_endport
{
manage_subnet
}
#
#
# Define the access vector interpretation for controlling capabilities
# Define the access vector interpretation for controlling capabilities
# in user namespaces
# in user namespaces
...
@@ -573,6 +583,8 @@ class sctp_socket
...
@@ -573,6 +583,8 @@ class sctp_socket
inherits socket
inherits socket
{
{
node_bind
node_bind
name_connect
association
}
}
class icmp_socket
class icmp_socket
...
@@ -729,3 +741,6 @@ class drmservice {
...
@@ -729,3 +741,6 @@ class drmservice {
finalizeDecryptUnit
finalizeDecryptUnit
pread
pread
}
}
class xdp_socket
inherits socket
This diff is collapsed.
Click to expand it.
private/security_classes
+
8
−
1
View file @
5c484443
...
@@ -35,7 +35,6 @@ class packet_socket
...
@@ -35,7 +35,6 @@ class packet_socket
class key_socket
class key_socket
class unix_stream_socket
class unix_stream_socket
class unix_dgram_socket
class unix_dgram_socket
class bpf
# sysv-ipc-related classes
# sysv-ipc-related classes
class sem
class sem
...
@@ -93,6 +92,10 @@ class netlink_scsitransport_socket
...
@@ -93,6 +92,10 @@ class netlink_scsitransport_socket
class netlink_rdma_socket
class netlink_rdma_socket
class netlink_crypto_socket
class netlink_crypto_socket
# Infiniband
class infiniband_pkey
class infiniband_endport
# Capability checks when on a non-init user namespace
# Capability checks when on a non-init user namespace
class cap_userns
class cap_userns
class cap2_userns
class cap2_userns
...
@@ -132,6 +135,10 @@ class smc_socket
...
@@ -132,6 +135,10 @@ class smc_socket
class process2
class process2
class bpf
class xdp_socket
# Property service
# Property service
class property_service # userspace
class property_service # userspace
...
...
This diff is collapsed.
Click to expand it.
public/global_macros
+
2
−
2
View file @
5c484443
...
@@ -12,8 +12,8 @@ define(`dir_file_class_set', `{ dir file_class_set }')
...
@@ -12,8 +12,8 @@ define(`dir_file_class_set', `{ dir file_class_set }')
define(`socket_class_set', `{ socket tcp_socket udp_socket rawip_socket netlink_socket packet_socket key_socket unix_stream_socket unix_dgram_socket appletalk_socket netlink_route_socket netlink_tcpdiag_socket netlink_nflog_socket netlink_xfrm_socket netlink_selinux_socket netlink_audit_socket netlink_dnrt_socket netlink_kobject_uevent_socket tun_socket netlink_iscsi_socket netlink_fib_lookup_socket netlink_connector_socket netlink_netfilter_socket netlink_generic_socket netlink_scsitransport_socket netlink_rdma_socket netlink_crypto_socket sctp_socket icmp_socket ax25_socket ipx_socket netrom_socket atmpvc_socket x25_socket rose_socket decnet_socket atmsvc_socket rds_socket irda_socket pppox_socket llc_socket can_socket tipc_socket bluetooth_socket iucv_socket rxrpc_socket isdn_socket phonet_socket ieee802154_socket caif_socket alg_socket nfc_socket vsock_socket kcm_socket qipcrtr_socket smc_socket }')
define(`socket_class_set', `{ socket tcp_socket udp_socket rawip_socket netlink_socket packet_socket key_socket unix_stream_socket unix_dgram_socket appletalk_socket netlink_route_socket netlink_tcpdiag_socket netlink_nflog_socket netlink_xfrm_socket netlink_selinux_socket netlink_audit_socket netlink_dnrt_socket netlink_kobject_uevent_socket tun_socket netlink_iscsi_socket netlink_fib_lookup_socket netlink_connector_socket netlink_netfilter_socket netlink_generic_socket netlink_scsitransport_socket netlink_rdma_socket netlink_crypto_socket sctp_socket icmp_socket ax25_socket ipx_socket netrom_socket atmpvc_socket x25_socket rose_socket decnet_socket atmsvc_socket rds_socket irda_socket pppox_socket llc_socket can_socket tipc_socket bluetooth_socket iucv_socket rxrpc_socket isdn_socket phonet_socket ieee802154_socket caif_socket alg_socket nfc_socket vsock_socket kcm_socket qipcrtr_socket smc_socket }')
define(`dgram_socket_class_set', `{ udp_socket unix_dgram_socket }')
define(`dgram_socket_class_set', `{ udp_socket unix_dgram_socket }')
define(`stream_socket_class_set', `{ tcp_socket unix_stream_socket }')
define(`stream_socket_class_set', `{ tcp_socket unix_stream_socket
sctp_socket
}')
define(`unpriv_socket_class_set', `{ tcp_socket udp_socket unix_stream_socket unix_dgram_socket }')
define(`unpriv_socket_class_set', `{ tcp_socket udp_socket unix_stream_socket unix_dgram_socket
sctp_socket
}')
define(`ipc_class_set', `{ sem msgq shm ipc }')
define(`ipc_class_set', `{ sem msgq shm ipc }')
...
...
This diff is collapsed.
Click to expand it.
Preview
0%
Loading
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Save comment
Cancel
Please
register
or
sign in
to comment