AppArmor: core policy routines
The basic routines and defines for AppArmor policy. AppArmor policy is defined by a few basic components. profiles - the basic unit of confinement contain all the information to enforce policy on a task Profiles tend to be named after an executable that they will attach to but this is not required. namespaces - a container for a set of profiles that will be used during attachment and transitions between profiles. sids - which provide a unique id for each profile Signed-off-by:John Johansen <john.johansen@canonical.com> Signed-off-by:
James Morris <jmorris@namei.org>
Showing
- security/apparmor/include/policy.h 305 additions, 0 deletionssecurity/apparmor/include/policy.h
- security/apparmor/include/sid.h 24 additions, 0 deletionssecurity/apparmor/include/sid.h
- security/apparmor/policy.c 1184 additions, 0 deletionssecurity/apparmor/policy.c
- security/apparmor/sid.c 55 additions, 0 deletionssecurity/apparmor/sid.c
Loading
Please register or sign in to comment