summaryrefslogtreecommitdiff
path: root/security/apparmor/label.c
diff options
context:
space:
mode:
authorJohn Johansen <john.johansen@canonical.com>2017-06-09 21:58:42 +0300
committerJohn Johansen <john.johansen@canonical.com>2017-06-11 03:11:37 +0300
commit192ca6b55a866e838aee98d9cb6a0b5086467c03 (patch)
treeeba93d671a1476432f357fa68e6842f548e2cb2f /security/apparmor/label.c
parent2835a13bbdc09d330eafdf5e67eb407c90c01ab7 (diff)
downloadlinux-192ca6b55a866e838aee98d9cb6a0b5086467c03.tar.xz
apparmor: revalidate files during exec
Instead of running file revalidation lazily when read/write are called copy selinux and revalidate the file table on exec. This avoids extra mediation overhead in read/write and also prevents file handles being passed through to a grand child unchecked. Signed-off-by: John Johansen <john.johansen@canonical.com>
Diffstat (limited to 'security/apparmor/label.c')
0 files changed, 0 insertions, 0 deletions