Skip to content
Snippets Groups Projects
Commit bac4ccce authored by Stephen Smalley's avatar Stephen Smalley Committed by Nick Kralevich
Browse files

Prevent adding transitions to kernel or init domains.


Add neverallow rules to prohibit adding any transitions into
the kernel or init domains.  Rewrite the domain self:process
rule to use a positive permission list and omit the transition
and dyntransition permissions from this list as well as other
permissions only checked when changing contexts.  This should be
a no-op since these permissions are only checked when
changing contexts but avoids needing to exclude kernel or init
from the neverallow rules.

Change-Id: Id114b1085cec4b51684c7bd86bd2eaad8df3d6f8
Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
parent 718bf84b
No related branches found
No related tags found
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment