TOMOYO: Allow using owner/group etc. of file objects as conditions.
commit8761afd49ebff8ae04c1a7888af090177441d07d
authorTetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
Fri, 8 Jul 2011 04:22:41 +0000 (8 13:22 +0900)
committerJames Morris <jmorris@namei.org>
Mon, 11 Jul 2011 01:05:32 +0000 (11 11:05 +1000)
treef43b52e1b8467eeea465762d2f9d0b81a336faa0
parent2066a36125fcbf5220990173b9d8e8bc49ad7538
TOMOYO: Allow using owner/group etc. of file objects as conditions.

This patch adds support for permission checks using file object's DAC
attributes (e.g. owner/group) when checking file's pathnames. Hooks for passing
file object's pointers are in the last patch of this pathset.

Signed-off-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
Signed-off-by: James Morris <jmorris@namei.org>
security/tomoyo/audit.c
security/tomoyo/common.c
security/tomoyo/common.h
security/tomoyo/condition.c