kernel_optimize_test/security/selinux/ss
Paul Moore 220deb966e SELinux: Better integration between peer labeling subsystems
Rework the handling of network peer labels so that the different peer labeling
subsystems work better together.  This includes moving both subsystems to a
single "peer" object class which involves not only changes to the permission
checks but an improved method of consolidating multiple packet peer labels.
As part of this work the inbound packet permission check code has been heavily
modified to handle both the old and new behavior in as sane a fashion as
possible.

Signed-off-by: Paul Moore <paul.moore@hp.com>
Signed-off-by: James Morris <jmorris@namei.org>
2008-01-30 08:17:25 +11:00
..
avtab.c security/selinux: Add missing "space" 2008-01-25 11:29:44 +11:00
avtab.h SELinux: add more validity checks on policy load 2007-11-08 08:56:23 +11:00
conditional.c SELinux: add more validity checks on policy load 2007-11-08 08:56:23 +11:00
conditional.h
constraint.h
context.h
ebitmap.c SELinux: fix bug in new ebitmap code. 2007-11-08 08:55:10 +11:00
ebitmap.h SELinux: kills warnings in Improve SELinux performance when AVC misses 2007-10-17 08:59:36 +10:00
hashtab.c
hashtab.h
Makefile
mls_types.h
mls.c NetLabel: Add secid token support to the NetLabel secattr struct 2008-01-30 08:17:19 +11:00
mls.h SELinux: add more validity checks on policy load 2007-11-08 08:56:23 +11:00
policydb.c SELinux: Add a capabilities bitmap to SELinux policy version 22 2008-01-30 08:17:23 +11:00
policydb.h SELinux: Add a capabilities bitmap to SELinux policy version 22 2008-01-30 08:17:23 +11:00
services.c SELinux: Better integration between peer labeling subsystems 2008-01-30 08:17:25 +11:00
services.h
sidtab.c
sidtab.h
symtab.c
symtab.h