-
- Downloads
ipe: add permissive toggle
IPE, like SELinux, supports a permissive mode. This mode allows policy authors to test and evaluate IPE policy without it affecting their programs. When the mode is changed, a 1404 AUDIT_MAC_STATUS will be reported. This patch adds the following audit records: audit: MAC_STATUS enforcing=0 old_enforcing=1 auid=4294967295 ses=4294967295 enabled=1 old-enabled=1 lsm=ipe res=1 audit: MAC_STATUS enforcing=1 old_enforcing=0 auid=4294967295 ses=4294967295 enabled=1 old-enabled=1 lsm=ipe res=1 The audit record only emit when the value from the user input is different from the current enforce value. Signed-off-by:Deven Bowers <deven.desai@linux.microsoft.com> Signed-off-by:
Fan Wu <wufan@linux.microsoft.com> Signed-off-by:
Paul Moore <paul@paul-moore.com>
Showing
- security/ipe/audit.c 25 additions, 2 deletionssecurity/ipe/audit.c
- security/ipe/audit.h 1 addition, 0 deletionssecurity/ipe/audit.h
- security/ipe/eval.c 9 additions, 2 deletionssecurity/ipe/eval.c
- security/ipe/eval.h 1 addition, 0 deletionssecurity/ipe/eval.h
- security/ipe/fs.c 66 additions, 0 deletionssecurity/ipe/fs.c
Loading
Please register or sign in to comment