Skip to content
  • Casey Schaufler's avatar
    Smack: secmark support for netfilter · 69f287ae
    Casey Schaufler authored
    
    
    Smack uses CIPSO to label internet packets and thus provide
    for access control on delivery of packets. The netfilter facility
    was not used to allow for Smack to work properly without netfilter
    configuration. Smack does not need netfilter, however there are
    cases where it would be handy.
    
    As a side effect, the labeling of local IPv4 packets can be optimized
    and the handling of local IPv6 packets is just all out better.
    
    The best part is that the netfilter tools use "contexts" that
    are just strings, and they work just as well for Smack as they
    do for SELinux.
    
    All of the conditional compilation for IPv6 was implemented
    by Rafal Krypa <r.krypa@samsung.com>
    
    Signed-off-by: default avatarCasey Schaufler <casey@schaufler-ca.com>
    69f287ae