Add nnp_nosuid_transition policycap and related class/perm definitions.

This commit is contained in:
Chris PeBenito 2017-08-05 12:13:21 -04:00
parent 933280d8f7
commit 1637a8b407
3 changed files with 15 additions and 0 deletions

View File

@ -388,6 +388,11 @@ class process
getrlimit
}
class process2
{
nnp_transition
nosuid_transition
}
#
# Define the access vector interpretation for ipc-related objects

View File

@ -188,4 +188,6 @@ class kcm_socket
class qipcrtr_socket
class smc_socket
class process2
# FLASK

View File

@ -83,3 +83,11 @@ policycap open_perms;
# Requires libsepol 2.7+ to build policy with this enabled.
#
policycap extended_socket_class;
# Enable NoNewPrivileges support. Requires libsepol 2.7+
# and kernel 4.14 (estimated).
#
# Checks enabled;
# process2: nnp_transition, nosuid_transition
#
#policycap nnp_nosuid_transition;