HomeFreeBSD

Introduce support for Mandatory Access Control and extensible
rS101158Unpublished

Unpublished Commit ยท Learn More

No further details are available.

Description

Introduce support for Mandatory Access Control and extensible
kernel access control.

Invoke an appropriate MAC entry point to authorize execution of
a file by a process. The check is placed slightly differently
than it appears in the trustedbsd_mac tree so that it prevents
a little more information leakage about the target of the execve()
operation.

Obtained from: TrustedBSD Project
Sponsored by: DARPA, NAI Labs

Details

Provenance
rwatsonAuthored on
Parents
rS101157: Move the MAC label init/destroy stuff to more appropriate places so that
Branches
Unknown
Tags
Unknown

Event Timeline