1. 24 Mar, 2018 1 commit
  2. 14 Mar, 2018 3 commits
    • John Johansen's avatar
      apparmor: update MAINTAINERS file git and wiki locations · e540c3c9
      John Johansen authored
      The apparmor information in the MAINTAINERS file is out of date
      update it to the correct git reference for the master apparmor tree.
      
      And update the wiki location to use apparmor.net which forwards to
      the current wiki location on gitlab.com.
      Signed-off-by: default avatarJohn Johansen <john.johansen@canonical.com>
      e540c3c9
    • John Johansen's avatar
      apparmor: remove POLICY_MEDIATES_SAFE · b9590ad4
      John Johansen authored
      The unpack code now makes sure every profile has a dfa so the safe
      version of POLICY_MEDIATES is no longer needed.
      Signed-off-by: default avatarJohn Johansen <john.johansen@canonical.com>
      b9590ad4
    • John Johansen's avatar
      apparmor: add base infastructure for socket mediation · 56974a6f
      John Johansen authored
      version 2 - Force an abi break. Network mediation will only be
                  available in v8 abi complaint policy.
      
      Provide a basic mediation of sockets. This is not a full net mediation
      but just whether a spcific family of socket can be used by an
      application, along with setting up some basic infrastructure for
      network mediation to follow.
      
      the user space rule hav the basic form of
        NETWORK RULE = [ QUALIFIERS ] 'network' [ DOMAIN ]
                       [ TYPE | PROTOCOL ]
      
        DOMAIN = ( 'inet' | 'ax25' | 'ipx' | 'appletalk' | 'netrom' |
                   'bridge' | 'atmpvc' | 'x25' | 'inet6' | 'rose' |
      	     'netbeui' | 'security' | 'key' | 'packet' | 'ash' |
      	     'econet' | 'atmsvc' | 'sna' | 'irda' | 'pppox' |
      	     'wanpipe' | 'bluetooth' | 'netlink' | 'unix' | 'rds' |
      	     'llc' | 'can' | 'tipc' | 'iucv' | 'rxrpc' | 'isdn' |
      	     'phonet' | 'ieee802154' | 'caif' | 'alg' | 'nfc' |
      	     'vsock' | 'mpls' | 'ib' | 'kcm' ) ','
      
        TYPE = ( 'stream' | 'dgram' | 'seqpacket' |  'rdm' | 'raw' |
                 'packet' )
      
        PROTOCOL = ( 'tcp' | 'udp' | 'icmp' )
      
      eg.
        network,
        network inet,
      Signed-off-by: default avatarJohn Johansen <john.johansen@canonical.com>
      Acked-by: default avatarSeth Arnold <seth.arnold@canonical.com>
      56974a6f
  3. 09 Feb, 2018 29 commits
  4. 28 Jan, 2018 7 commits