mirror of
https://github.com/SELinuxProject/selinux
synced 2025-02-08 21:57:34 +00:00
Neverallow rules for ioctl extended permissions will pass in two cases: 1. If extended permissions exist for the source-target-class set the test will pass if the neverallow values are excluded. 2. If extended permissions do not exist for the source-target-class set the test will pass if the ioctl permission is not granted. Signed-off-by: Jeff Vander Stoep <jeffv@google.com> Acked-by: Nick Kralevich <nnk@google.com> Acked-by: Stephen Smalley <sds@tycho.nsa.gov> |
||
---|---|---|
.. | ||
avrule_block.h | ||
avtab.h | ||
conditional.h | ||
constraint.h | ||
context.h | ||
ebitmap.h | ||
expand.h | ||
flask_types.h | ||
flask.h | ||
hashtab.h | ||
hierarchy.h | ||
link.h | ||
mls_types.h | ||
module.h | ||
polcaps.h | ||
policydb.h | ||
services.h | ||
sidtab.h | ||
symtab.h | ||
util.h |