kernel-hacking-2024-linux-s.../security/selinux/include
Paul Moore 220deb966e SELinux: Better integration between peer labeling subsystems
Rework the handling of network peer labels so that the different peer labeling
subsystems work better together.  This includes moving both subsystems to a
single "peer" object class which involves not only changes to the permission
checks but an improved method of consolidating multiple packet peer labels.
As part of this work the inbound packet permission check code has been heavily
modified to handle both the old and new behavior in as sane a fashion as
possible.

Signed-off-by: Paul Moore <paul.moore@hp.com>
Signed-off-by: James Morris <jmorris@namei.org>
2008-01-30 08:17:25 +11:00
..
av_inherit.h
av_perm_to_string.h SELinux: Add a new peer class and permissions to the Flask definitions 2008-01-30 08:17:24 +11:00
av_permissions.h SELinux: Add a new peer class and permissions to the Flask definitions 2008-01-30 08:17:24 +11:00
avc.h SELinux: Only store the network interface's ifindex 2008-01-30 08:17:22 +11:00
avc_ss.h
class_to_string.h SELinux: Add a new peer class and permissions to the Flask definitions 2008-01-30 08:17:24 +11:00
common_perm_to_string.h
conditional.h
flask.h SELinux: Add a new peer class and permissions to the Flask definitions 2008-01-30 08:17:24 +11:00
initial_sid_to_string.h
netif.h SELinux: Convert the netif code to use ifindex values 2008-01-30 08:17:21 +11:00
netlabel.h SELinux: Better integration between peer labeling subsystems 2008-01-30 08:17:25 +11:00
netnode.h SELinux: Add a network node caching mechanism similar to the sel_netif_*() functions 2008-01-30 08:17:23 +11:00
objsec.h SELinux: Better integration between peer labeling subsystems 2008-01-30 08:17:25 +11:00
security.h SELinux: Better integration between peer labeling subsystems 2008-01-30 08:17:25 +11:00
xfrm.h [SELINUX]: Fix 2.6.20-rc6 build when no xfrm 2007-01-26 19:03:48 -08:00