aboutsummaryrefslogtreecommitdiff
path: root/sys/security/mac
Commit message (Expand)AuthorAgeFilesLines
...
* An inappropriate ASSERT slipped in during the recent merge of theRobert Watson2002-10-288-16/+0
* Centrally manage enforcement of {reboot,swapon,sysctl} using theRobert Watson2002-10-278-104/+72
* Implement mac_check_system_sysctl(), a MAC Framework entry point toRobert Watson2002-10-2710-0/+231
* Hook up mac_check_system_reboot(), a MAC Framework entry point thatRobert Watson2002-10-2710-0/+187
* Merge from MAC tree: rename mac_check_vnode_swapon() toRobert Watson2002-10-2710-148/+148
* Slightly change the semantics of vnode labels for MAC: rather thanRobert Watson2002-10-2610-3911/+744
* Comment describing the semantics of mac_late.Robert Watson2002-10-258-8/+48
* Remove the mac_te policy bits from 'struct oldmac' -- we're not goingRobert Watson2002-10-221-6/+0
* Introduce MAC_CHECK_VNODE_SWAPON, which permits MAC policies toRobert Watson2002-10-2210-0/+180
* Missed in previous merge: export sizeof(struct oldmac) rather thanRobert Watson2002-10-228-8/+8
* Support the new MAC user API in kernel: modify existing system callsRobert Watson2002-10-228-1352/+7336
* Revised APIs for user process label management; the existing APIs reliedRobert Watson2002-10-222-97/+108
* Add compartment support to Biba and MLS policies. The logic of theRobert Watson2002-10-211-0/+4
* Use if_printf(ifp, "blah") instead ofBrooks Davis2002-10-218-16/+8
* If MAC_MAX_POLICIES isn't defined, don't try to define it, just let theRobert Watson2002-10-208-24/+8
* Make sure to clear the 'registered' flag for MAC policies when theyRobert Watson2002-10-198-0/+8
* Integrate mac_check_socket_send() and mac_check_socket_receive()Robert Watson2002-10-0610-0/+280
* Sync from MAC tree: break out the single mmap entry point intoRobert Watson2002-10-0610-150/+517
* Modify label allocation semantics for sockets: pass in soalloc's mallocRobert Watson2002-10-0510-108/+556
* Integrate a devfs/MAC fix from the MAC tree: avoid a race condition duringRobert Watson2002-10-0510-0/+110
* Merge support for mac_check_vnode_link(), a MAC framework/policy entryRobert Watson2002-10-0510-0/+246
* While the MAC API has supported the ability to handle M_NOWAIT passedRobert Watson2002-10-058-24/+88
* Rearrange object and label init/destroy functions to match theRobert Watson2002-10-058-808/+808
* Sync to MAC tree: use 'flag' instead of 'how' for mac_init_mbuf();Robert Watson2002-10-058-24/+24
* Another big diff, little functional change: move label internalization,Robert Watson2002-10-058-520/+520
* Move all object label init/destroy routines to the head of theRobert Watson2002-10-058-2280/+2280
* Synch from TrustedBSD MAC tree:Robert Watson2002-10-058-24/+200
* Cosmetic line wrap synchronization.Robert Watson2002-10-058-16/+32
* Push the debugging obect label counters into security.mac.debug.countersRobert Watson2002-10-058-88/+128
* Begin another merge from the TrustedBSD MAC branch:Robert Watson2002-10-059-594/+741
* Add a new MAC entry point, mac_thread_userret(td), which permits policyRobert Watson2002-10-0210-0/+92
* Remember to include "opt_devfs.h" so we get any relevant changesPoul-Henning Kamp2002-10-018-0/+8
* Improve locking of pipe mutexes in the context of MAC:Robert Watson2002-10-018-0/+272
* Push 'security.mac.debug_label_fallback' behind options MAC_DEBUG.Robert Watson2002-10-018-80/+112
* Add tunables for the existing sysctl twiddles for pipe and vmRobert Watson2002-09-308-0/+16
* Remove un-needed stack variable 'ops'.Robert Watson2002-09-188-24/+16
* Add a toggle to disable VM enforcement.Robert Watson2002-09-188-0/+56
* At the cost of seeming a little gauche, make use of more traditionalRobert Watson2002-09-188-32/+32
* Remove all use of vnode->v_tag, replacing with appropriate substitutes.Nate Lawson2002-09-148-32/+32
* Add security.mac.mmap_revocation, a flag indicating whether weRobert Watson2002-09-098-0/+64
* Minor code sync to MAC tree: push Giant locking up fromRobert Watson2002-09-098-16/+16
* Include <sys/malloc.h> instead of depending on namespace pollution 2Bruce Evans2002-09-058-48/+40
* Close a race in process label changing opened due to dropping theRobert Watson2002-08-198-56/+80
* Pass active_cred and file_cred into the MAC framework explicitlyRobert Watson2002-08-1910-104/+176
* Provide an implementation of mac_syscall() so that security modulesRobert Watson2002-08-1910-1/+318
* Break out mac_check_pipe_op() into component check entry points:Robert Watson2002-08-1910-49/+384
* Break out mac_check_vnode_op() into three seperate checks:Robert Watson2002-08-1910-84/+468
* Assert process locks in proces-related access control checks.Robert Watson2002-08-198-0/+48
* Add a missing vnode assertion for the exec() check.Robert Watson2002-08-198-0/+16
* Wrap maintenance of varios nmac{objectname} counters in MAC_DEBUG so weRobert Watson2002-08-168-0/+368