Re: [PATCH][SELINUX] Add name_connect permission check

From: Stephen Smalley
Date: Wed Mar 23 2005 - 09:52:29 EST


On Wed, 2005-03-23 at 09:40 -0500, Stephen Smalley wrote:
> This patch adds a name_connect permission check to SELinux to provide
> control over outbound TCP connections to particular ports distinct
> from the general controls over sending and receiving packets. Please
> apply.
>
> security/selinux/hooks.c | 48 ++++++++++++++++++++++++++-
> security/selinux/include/av_perm_to_string.h | 1
> security/selinux/include/av_permissions.h | 1
> 3 files changed, 49 insertions(+), 1 deletion(-)

Ah, sorry - forgot the Signed-off-by lines.

Signed-off-by: Stephen Smalley <sds@xxxxxxxxxxxxx>
Signed-off-by: James Morris <jmorris@xxxxxxxxxx>

--
Stephen Smalley <sds@xxxxxxxxxxxxx>
National Security Agency

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/