diff options
| author | Rafal Krypa <[email protected]> | 2015-06-02 09:23:48 +0000 |
|---|---|---|
| committer | Casey Schaufler <[email protected]> | 2015-06-02 18:53:42 +0000 |
| commit | c0d77c884461fc0dec0411e49797dc3f3651c31b (patch) | |
| tree | c526c2ae841b0fc358d29af69cddcdb63ae72431 /scripts/asn1_compiler.c | |
| parent | Smack: fix seq operations in smackfs (diff) | |
| download | kernel-c0d77c884461fc0dec0411e49797dc3f3651c31b.tar.gz kernel-c0d77c884461fc0dec0411e49797dc3f3651c31b.zip | |
Smack: allow multiple labels in onlycap
Smack onlycap allows limiting of CAP_MAC_ADMIN and CAP_MAC_OVERRIDE to
processes running with the configured label. But having single privileged
label is not enough in some real use cases. On a complex system like Tizen,
there maybe few programs that need to configure Smack policy in run-time
and running them all with a single label is not always practical.
This patch extends onlycap feature for multiple labels. They are configured
in the same smackfs "onlycap" interface, separated by spaces.
Signed-off-by: Rafal Krypa <[email protected]>
Diffstat (limited to 'scripts/asn1_compiler.c')
0 files changed, 0 insertions, 0 deletions
