diff options
author | 2017-05-17 11:31:48 -0400 | |
---|---|---|
committer | 2017-05-18 19:01:00 +0200 | |
commit | 09879cfc8abb8884cd11fe9ee3125e866190e207 (patch) | |
tree | 1b7f0cc5992ee277e80f0f2e6a9d46278c3eab78 /policy/flask/access_vectors | |
parent | refpolicy: Define getrlimit permission for class process (diff) | |
download | hardened-refpolicy-09879cfc8abb8884cd11fe9ee3125e866190e207.tar.gz hardened-refpolicy-09879cfc8abb8884cd11fe9ee3125e866190e207.tar.bz2 hardened-refpolicy-09879cfc8abb8884cd11fe9ee3125e866190e207.zip |
refpolicy: Define smc_socket security class
Linux kernel commit da69a5306ab9 ("selinux: support distinctions among all
network address families") triggers a build error if a new address family
is added without defining a corresponding SELinux security class. As a
result, the smc_socket class was added to the kernel to resolve a build
failure as part of merge commit 3051bf36c25d that introduced AF_SMC circa
Linux 4.11. Define this security class and its access vector, note that it
is enabled as part of the extended_socket_class policy capability, and add
it to the socket_class_set macro.
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Diffstat (limited to 'policy/flask/access_vectors')
-rw-r--r-- | policy/flask/access_vectors | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/policy/flask/access_vectors b/policy/flask/access_vectors index 6204e687f..7652a313f 100644 --- a/policy/flask/access_vectors +++ b/policy/flask/access_vectors @@ -1059,3 +1059,6 @@ inherits socket class qipcrtr_socket inherits socket + +class smc_socket +inherits socket |