Page MenuHomeFreeBSD

Support for setting labels via veriexec
ClosedPublic

Authored by stevek on May 17 2019, 6:39 PM.
Tags
None
Referenced Files
Unknown Object (File)
Wed, Sep 9, 12:02 AM
Unknown Object (File)
Sun, Sep 6, 11:31 AM
Unknown Object (File)
Tue, Sep 1, 4:36 PM
Unknown Object (File)
Mon, Aug 31, 4:30 PM
Unknown Object (File)
Fri, Aug 28, 11:02 PM
Unknown Object (File)
Fri, Aug 28, 11:01 PM
Unknown Object (File)
Aug 19 2026, 1:49 AM
Unknown Object (File)
Aug 14 2026, 3:59 PM
Subscribers

Details

Summary

Add a new ioctl for the larger params struct that includes the label.

We need to make the find_veriexec_file() function available publicly, so
rename it to mac_veriexec_metadata_find_file_info() and make it non-static.

Bump the version of the veriexec device interface so user space will know
the labelized version of fingerprint loading is available.

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

Return the size of the allocated space for the label, even if we copied in a smaller label.

This revision is now accepted and ready to land.May 17 2019, 7:16 PM
This revision was automatically updated to reflect the committed changes.