aboutsummaryrefslogtreecommitdiff
path: root/sys/security
Commit message (Expand)AuthorAgeFilesLines
* Update policy modules for changes in arguments associated with supportRobert Watson2002-11-056-12/+18
* Bring in two sets of changes:Robert Watson2002-11-0510-55/+467
* Since neither the Biba policy nor the MLS policy make use ofRobert Watson2002-11-052-46/+0
* Assert that appropriate vnodes are locked in mac_execve_will_transition().Robert Watson2002-11-058-0/+64
* Implement mpo_check_system_acct and mpo_check_system_settime() for Biba:Robert Watson2002-11-041-0/+46
* Correct use of mac_biba_subject_privileged() in swapon() code.Robert Watson2002-11-041-2/+4
* Permit MAC policies to instrument the access control decisions forRobert Watson2002-11-0410-0/+253
* Remove mac_cache_fslabel_in_vnode sysctl -- with the new VFS/MACRobert Watson2002-11-048-48/+0
* License and wording updates: NAI has authorized the removal of clauseRobert Watson2002-11-0413-91/+52
* License clarification and wording changes: NAI has approved removal ofRobert Watson2002-11-0410-70/+40
* Introduce mac_check_system_settime(), a MAC check allowing policies toRobert Watson2002-11-0310-0/+106
* Change privilege model for mac_partition such that BSD superuser can changeRobert Watson2002-11-031-6/+4
* Fix some warnings on 64 bit architectures. The vn_extattr_get()Maxime Henrion2002-11-022-4/+2
* Add MAC checks for various kenv() operations: dump, get, set, unset,Robert Watson2002-11-0110-0/+425
* Move to C99 sparse structure initialization for the mac_policy_opsRobert Watson2002-10-3018-6258/+729
* Various minor type, prototype tweaks -- clean up cruft due to lack ofRobert Watson2002-10-305-10/+10
* While 'mode_t' seemed like a good idea for the access mode argument forRobert Watson2002-10-3016-41/+41
* Try again to fix the KASSERT.Robert Watson2002-10-301-1/+1
* Fix a KASSERT bug that showed up only in the LINT build, not theRobert Watson2002-10-301-1/+1
* Hook up no-op stubs for reboot, swapon, sysctl entry points.Robert Watson2002-10-292-0/+58
* Implement Biba policy entry points for mac_check_system_swapon()Robert Watson2002-10-291-0/+59
* Require Biba privilege to relabel a network interface.Robert Watson2002-10-291-0/+7
* Correct a typo in a previously commented include entry that was madeRobert Watson2002-10-281-1/+1
* Remove all reference to 'struct oldmac', since it's no longer requiredRobert Watson2002-10-283-49/+61
* Add a return type for mac_biba_high_single(), apparently lost in anRobert Watson2002-10-281-0/+1
* Rename mac_biba_subject_equal_ok() to mac_biba_subject_privileged()Robert Watson2002-10-281-6/+6
* Zero the trusted_interface buffer before starting parsing.Robert Watson2002-10-281-0/+6
* An inappropriate ASSERT slipped in during the recent merge of theRobert Watson2002-10-288-16/+0
* Centrally manage enforcement of {reboot,swapon,sysctl} using theRobert Watson2002-10-278-104/+72
* Implement mac_check_system_sysctl(), a MAC Framework entry point toRobert Watson2002-10-2710-0/+231
* Hook up mac_check_system_reboot(), a MAC Framework entry point thatRobert Watson2002-10-2710-0/+187
* Merge from MAC tree: rename mac_check_vnode_swapon() toRobert Watson2002-10-2710-148/+148
* Slightly change the semantics of vnode labels for MAC: rather thanRobert Watson2002-10-2615-4151/+1091
* Comment describing the semantics of mac_late.Robert Watson2002-10-258-8/+48
* Provide a simple sample labeled access control policy, mac_partition.Robert Watson2002-10-232-0/+337
* Style fix: space between 'switch' and '('.Robert Watson2002-10-222-2/+2
* s/mls/biba/ in a copy+paste error for a printf.Robert Watson2002-10-221-1/+1
* Remove the mac_te policy bits from 'struct oldmac' -- we're not goingRobert Watson2002-10-221-6/+0
* Don't enforce MAC Biba policy for socket visibility if Biba is notRobert Watson2002-10-221-0/+3
* Introduce MAC_CHECK_VNODE_SWAPON, which permits MAC policies toRobert Watson2002-10-2210-0/+180
* Missed in previous merge: export sizeof(struct oldmac) rather thanRobert Watson2002-10-228-8/+8
* Adapt MAC policies for the new user API changes; teach policies howRobert Watson2002-10-227-94/+691
* Support the new MAC user API in kernel: modify existing system callsRobert Watson2002-10-228-1352/+7336
* Revised APIs for user process label management; the existing APIs reliedRobert Watson2002-10-222-97/+108
* mac_none is a stub policy without any functional implementation.Robert Watson2002-10-212-14/+14
* Introduce mac_biba_copy() and mac_mls_copy(), which conditionallyRobert Watson2002-10-212-17/+49
* Add compartment support to Biba and MLS policies. The logic of theRobert Watson2002-10-215-32/+140
* More in the way of minor consistency improvements: trim 'mac_mls_'Robert Watson2002-10-211-8/+7
* Demote sockets to single-label objects rather than maintaining aRobert Watson2002-10-212-32/+0
* Synchonize variable spelling with the MAC tree: we shortened some ofRobert Watson2002-10-211-9/+8