Page MenuHomeFreeBSD

Support for setting labels via veriexec
ClosedPublic

Authored by stevek on May 17 2019, 6:39 PM.
Tags
None
Referenced Files
Unknown Object (File)
Wed, Aug 19, 1:49 AM
Unknown Object (File)
Fri, Aug 14, 3:59 PM
Unknown Object (File)
Thu, Aug 13, 7:23 AM
Unknown Object (File)
Wed, Aug 12, 2:45 AM
Unknown Object (File)
Tue, Aug 11, 2:01 PM
Unknown Object (File)
Tue, Aug 11, 3:04 AM
Unknown Object (File)
Mon, Aug 10, 8:17 PM
Unknown Object (File)
Mon, Aug 10, 7:04 PM
Subscribers

Details

Summary

Add a new ioctl for the larger params struct that includes the label.

We need to make the find_veriexec_file() function available publicly, so
rename it to mac_veriexec_metadata_find_file_info() and make it non-static.

Bump the version of the veriexec device interface so user space will know
the labelized version of fingerprint loading is available.

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

Return the size of the allocated space for the label, even if we copied in a smaller label.

This revision is now accepted and ready to land.May 17 2019, 7:16 PM
This revision was automatically updated to reflect the committed changes.