09ebf2b59a
Add a (default disabled) definition for the extended_socket_class policy capability used to enable the use of separate socket security classes for all network address families rather than the generic socket class. The capability also enables the use of separate security classes for ICMP and SCTP sockets, which were previously mapped to rawip_socket class. Add definitions for the new socket classes and access vectors enabled by this capability. Add the new socket classes to the socket_class_set macro, which also covers allowing access by unconfined domains. Allowing access by other domains to the new socket security classes is left to future commits. The kernel support will be included in Linux 4.11+. Building policy with this capability enabled will require libsepol 2.7+. This change leaves the capability disabled by default. Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov> |
||
---|---|---|
.. | ||
Makefile | ||
access_vectors | ||
flask.py | ||
initial_sids | ||
security_classes |