summaryrefslogtreecommitdiffstats
path: root/security/capability.c
diff options
context:
space:
mode:
authorPaul Moore <pmoore@redhat.com>2013-01-14 08:12:13 +0100
committerDavid S. Miller <davem@davemloft.net>2013-01-15 00:16:59 +0100
commit6f96c142f77c96a34ac377a3616ee7abcd77fb4d (patch)
treea481cf442e39dae7f0392b38db461f5b3076e7eb /security/capability.c
parenttcp: fix a panic on UP machines in reqsk_fastopen_remove (diff)
downloadlinux-6f96c142f77c96a34ac377a3616ee7abcd77fb4d.tar.xz
linux-6f96c142f77c96a34ac377a3616ee7abcd77fb4d.zip
selinux: add the "attach_queue" permission to the "tun_socket" class
Add a new permission to align with the new TUN multiqueue support, "tun_socket:attach_queue". The corresponding SELinux reference policy patch is show below: diff --git a/policy/flask/access_vectors b/policy/flask/access_vectors index 28802c5..a0664a1 100644 --- a/policy/flask/access_vectors +++ b/policy/flask/access_vectors @@ -827,6 +827,9 @@ class kernel_service class tun_socket inherits socket +{ + attach_queue +} class x_pointer inherits x_device Signed-off-by: Paul Moore <pmoore@redhat.com> Acked-by: Eric Paris <eparis@parisplace.org> Tested-by: Jason Wang <jasowang@redhat.com> Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'security/capability.c')
0 files changed, 0 insertions, 0 deletions