John Johansen
f8eb8a1324
apparmor: add the ability to report a sha1 hash of loaded policy
...
Provide userspace the ability to introspect a sha1 hash value for each
profile currently loaded.
Signed-off-by: John Johansen <john.johansen@canonical.com >
Acked-by: Seth Arnold <seth.arnold@canonical.com >
2013-08-14 11:42:08 -07:00
John Johansen
84f1f78742
apparmor: export set of capabilities supported by the apparmor module
...
Signed-off-by: John Johansen <john.johansen@canonical.com >
Acked-by: Seth Arnold <seth.arnold@canonical.com >
2013-08-14 11:42:07 -07:00
John Johansen
43c422eda9
apparmor: fix apparmor OOPS in audit_log_untrustedstring+0x1c/0x40
...
The capability defines have moved causing the auto generated names
of capabilities that apparmor uses in logging to be incorrect.
Fix the autogenerated table source to uapi/linux/capability.h
Reported-by: YanHong <clouds.yan@gmail.com >
Reported-by: Krzysztof Kolasa <kkolasa@winsoft.pl >
Analyzed-by: Al Viro <viro@ZenIV.linux.org.uk >
Signed-off-by: John Johansen <john.johansen@canonical.com >
Acked-by: David Howells <dhowells@redhat.com >
Acked-by: James Morris <james.l.morris@oracle.com >
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org >
2012-10-17 16:29:46 -07:00
David Howells
8a1ab3155c
UAPI: (Scripted) Disintegrate include/asm-generic
...
Signed-off-by: David Howells <dhowells@redhat.com >
Acked-by: Arnd Bergmann <arnd@arndb.de >
Acked-by: Thomas Gleixner <tglx@linutronix.de >
Acked-by: Michael Kerrisk <mtk.manpages@gmail.com >
Acked-by: Paul E. McKenney <paulmck@linux.vnet.ibm.com >
Acked-by: Dave Jones <davej@redhat.com >
2012-10-04 18:20:15 +01:00
Tetsuo Handa
7e570145cb
AppArmor: Fix location of const qualifier on generated string tables
...
Signed-off-by: Tetsuo Handa <penguin-kernel@i-love.sakura.ne.jp >
Signed-off-by: John Johansen <john.johansen@canonical.com >
2012-03-19 18:22:46 -07:00
John Johansen
33e521acff
AppArmor: Add const qualifiers to generated string tables
...
Signed-off-by: John Johansen <john.johansen@canonical.com >
2012-03-14 06:15:12 -07:00
Kees Cook
d384b0a1a3
AppArmor: export known rlimit names/value mappings in securityfs
...
Since the parser needs to know which rlimits are known to the kernel,
export the list via a mask file in the "rlimit" subdirectory in the
securityfs "features" directory.
Signed-off-by: Kees Cook <kees@ubuntu.com >
Signed-off-by: John Johansen <john.johansen@canonical.com >
2012-02-27 11:38:19 -08:00
Michal Hocko
0f82502656
AppArmor: cleanup generated files correctly
...
clean-files should be defined as a variable not a target.
Signed-off-by: Michal Hocko <mhocko@suse.cz >
Signed-off-by: John Johansen <john.johansen@canonical.com >
2011-03-08 17:03:53 -08:00
John Johansen
4fdef2183e
AppArmor: Cleanup make file to remove cruft and make it easier to read
...
Cleanups based on comments from Sam Ravnborg,
* remove references to the currently unused af_names.h
* add rlim_names.h to clean-files:
* rework cmd_make-XXX to make them more readable by adding comments,
reworking the expressions to put logical components on individual lines,
and keep lines < 80 characters.
Signed-off-by: John Johansen <john.johansen@canonical.com >
Acked-by: Sam Ravnborg <sam@ravnborg.org >
2011-03-05 02:46:26 -08:00
John Johansen
016d825fe0
AppArmor: Enable configuring and building of the AppArmor security module
...
Kconfig and Makefiles to enable configuration and building of AppArmor.
Signed-off-by: John Johansen <john.johansen@canonical.com >
Signed-off-by: James Morris <jmorris@namei.org >
2010-08-02 15:38:39 +10:00