diff options
| author | Antonio Murdaca <[email protected]> | 2017-02-09 16:02:42 +0000 |
|---|---|---|
| committer | Paul Moore <[email protected]> | 2017-08-22 19:38:18 +0000 |
| commit | 901ef845fa2469c211ce3b1e955d9e7245ab5d50 (patch) | |
| tree | b09c7e1bb1705c4db7dd5468b19fb7f243aa37b6 /security/selinux/hooks.c | |
| parent | lsm_audit: update my email address (diff) | |
| download | kernel-901ef845fa2469c211ce3b1e955d9e7245ab5d50.tar.gz kernel-901ef845fa2469c211ce3b1e955d9e7245ab5d50.zip | |
selinux: allow per-file labeling for cgroupfs
This patch allows genfscon per-file labeling for cgroupfs. For instance,
this allows to label the "release_agent" file within each
cgroup mount and limit writes to it.
Signed-off-by: Antonio Murdaca <[email protected]>
[PM: subject line and merge tweaks]
Signed-off-by: Paul Moore <[email protected]>
Diffstat (limited to 'security/selinux/hooks.c')
| -rw-r--r-- | security/selinux/hooks.c | 4 |
1 files changed, 3 insertions, 1 deletions
diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c index 2bd7b824b7f5..f803fdcde9cf 100644 --- a/security/selinux/hooks.c +++ b/security/selinux/hooks.c @@ -815,7 +815,9 @@ static int selinux_set_mnt_opts(struct super_block *sb, if (!strcmp(sb->s_type->name, "debugfs") || !strcmp(sb->s_type->name, "tracefs") || !strcmp(sb->s_type->name, "sysfs") || - !strcmp(sb->s_type->name, "pstore")) + !strcmp(sb->s_type->name, "pstore") || + !strcmp(sb->s_type->name, "cgroup") || + !strcmp(sb->s_type->name, "cgroup2")) sbsec->flags |= SE_SBGENFS; if (!sbsec->behavior) { |
