selinux/libsepol
Chris PeBenito 01723ac2ce libsepol: Add always_check_network policy capability
Currently the packet class in SELinux is not checked if there are no
SECMARK rules in the security or mangle netfilter tables.  Similarly, the
peer class is not checked if there is no NetLabel or labeled IPSEC.  Some
systems prefer that these classes are always checked, for example, to
protect the system should the netfilter rules fail to load or if the
nefilter rules were maliciously flushed.

Add the always_check_network policy capability which, when enabled, treats
these mechanisms as enabled, even if there are no labeling rules.

Signed-off-by: Chris PeBenito <cpebenito@tresys.com>
Signed-off-by: Eric Paris <eparis@redhat.com>
2012-09-12 14:30:24 -04:00
..
include libsepol: Add always_check_network policy capability 2012-09-12 14:30:24 -04:00
man whole tree: default make target to all not install 2011-09-16 11:54:04 -04:00
src libsepol: Add always_check_network policy capability 2012-09-12 14:30:24 -04:00
tests reactivate attribute mapping unit test 2010-03-24 13:55:23 -04:00
utils libsepol: Android/MacOS X build support 2012-06-28 11:21:15 -04:00
.gitignore Add subdirectory .gitignore files. 2009-10-20 21:25:55 -04:00
Android.mk libsepol: Android/MacOS X build support 2012-06-28 11:21:15 -04:00
COPYING initial import from svn trunk revision 2950 2008-08-19 15:30:36 -04:00
ChangeLog Version bumps for upstream push 2012-06-28 14:02:29 -04:00
Makefile initial import from svn trunk revision 2950 2008-08-19 15:30:36 -04:00
VERSION Version bumps for upstream push 2012-06-28 14:02:29 -04:00