diff options
author | Daniel Jurgens <danielj@mellanox.com> | 2017-05-19 15:48:53 +0300 |
---|---|---|
committer | Paul Moore <paul@paul-moore.com> | 2017-05-23 12:27:11 -0400 |
commit | 8f408ab64be6319cb7736cbc6982838dcc362306 (patch) | |
tree | fa7169e96ad81ac38d6d78ac03668196dde902c4 /scripts | |
parent | d291f1a6523292d916fe1659c67f6db061fbd1b5 (diff) | |
download | linux-8f408ab64be6319cb7736cbc6982838dcc362306.tar.bz2 |
selinux lsm IB/core: Implement LSM notification system
Add a generic notificaiton mechanism in the LSM. Interested consumers
can register a callback with the LSM and security modules can produce
events.
Because access to Infiniband QPs are enforced in the setup phase of a
connection security should be enforced again if the policy changes.
Register infiniband devices for policy change notification and check all
QPs on that device when the notification is received.
Add a call to the notification mechanism from SELinux when the AVC
cache changes or setenforce is cleared.
Signed-off-by: Daniel Jurgens <danielj@mellanox.com>
Acked-by: James Morris <james.l.morris@oracle.com>
Acked-by: Doug Ledford <dledford@redhat.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Diffstat (limited to 'scripts')
0 files changed, 0 insertions, 0 deletions